Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   IE öffnet komplett andere Seiten durch Trojaner (https://www.trojaner-board.de/98063-ie-oeffnet-komplett-andere-seiten-trojaner.html)

Cloud84 24.04.2011 21:55

IE öffnet komplett andere Seiten durch Trojaner
 
Hallo,

heute mittag habe ich mir durch den Download einer Datei Trojaner eingefangen... . Gemerkt habe ich dies, dass mein Microsoft Essentials (dass sich nicht mehr öffnen lässt), einen Trojaner gefunden hat - Im Anschluss öffneten sich alle 2-3 minuten irgendwelche willkürlichen Seiten im Internet Explorer (z.B. parship, diverse Sexseiten und so weiter)...Auf Rat von mehreren Leuten, habe ich mir Malwarebytes heruntergeladen, durchlaufen lassen, prompt 10 infizierte Dateien, die es auch gelöscht hat(Vorher habe ich den Prozess unzyl.exe oder so ähnlich, der seit dem Download der Datei aktiv war, beendet, was zum stoppen des Seitenaufrufs führte).

Nun, danach habe ich den Pc neugestartet, und gehofft /bzw. gedacht, ich habe Ruhe. Aber anscheinend fehlt noch ein hartnäckiger Trojaner...
Wenn ich z.B. auf eine Seite möchte, öffnet sich eine komische URL, und im Anschluss kommen wieder irgendwelche Seiten, die zu 100% nix damit zu tun haben. Das geht ca 5-6x mit zurück Taste und erneutem Draufklicken, bis ich endlich da bin, wo ich hinmöchte... .

Habe mittlerweile Malware noch ein paar mal Komplett suchen lassen, aber keine Funde, was mich doch stutzig macht... Avira findet ebenso nichts.

Im Anhang ist die hijackthis.log Datei.

Hoffe auf baldige Rückmeldung.

HiJackthis Logfile:
Code:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:51:43, on 24.04.2011
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\HsMgr.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
C:\Program Files\ASUS Xonar DX Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\CCCDsPreview.exe
C:\Program Files (x86)\HTC\HTC Sync 3.0\adb.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\TSTheme.exe
C:\Windows\SysWOW64\svchost.exe
C:\Users\User\Downloads\HiJackThis204.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {33b974a8-e892-4f5f-bd17-f7b0331843d5} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,C:\Users\User\AppData\Roaming\appconf32.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Razer Mamba Driver] C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
O4 - HKLM\..\Run: [DivX Download Manager] "C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe" start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: de71.die-staemme.de
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBBC9FEA-46B8-41DF-909C-5566F8219919}: NameServer = 192.168.2.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Realtek11nSU - Realtek - C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8514 bytes

--- --- ---

cosinus 25.04.2011 15:59

Zitat:

Auf Rat von mehreren Leuten, habe ich mir Malwarebytes heruntergeladen, durchlaufen lassen, prompt 10 infizierte Dateien,
Alle Logs posten! Hijackthis ist uninteressant!

Cloud84 25.04.2011 16:54

[spoiler]Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

24.04.2011 18:04:58
mbam-log-2011-04-24 (18-04-58).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 58737
Laufzeit: 5 Minute(n), 10 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)[/spoiler]

[spoiler]Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

24.04.2011 18:07:12
mbam-log-2011-04-24 (18-07-12).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 158699
Laufzeit: 1 Minute(n), 24 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 2
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 6

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\User\AppData\Local\Temp\937D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Local\Temp\0.7801378520669445.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Local\Temp\0.9258477933542707.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Local\Temp\0.9794606178131235.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully.
[/spoiler]

[spoiler]Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

24.04.2011 18:11:01
mbam-log-2011-04-24 (18-11-01).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 158977
Laufzeit: 1 Minute(n), 54 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
[/spoiler]

[spoiler]
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

24.04.2011 18:34:19
mbam-log-2011-04-24 (18-34-19).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 267494
Laufzeit: 17 Minute(n), 37 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
[/spoiler]

[spoiler]
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

24.04.2011 21:57:43
mbam-log-2011-04-24 (21-57-43).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 159312
Laufzeit: 1 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
[/spoiler]

[spoiler]
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.04.2011 12:14:40
mbam-log-2011-04-25 (12-14-40).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 158954
Laufzeit: 1 Minute(n), 40 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (userinit.exe,C:\Users\User\AppData\Roaming\appconf32.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\User\AppData\Local\Temp\0.1779834518952148.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
[/spoiler]

[spoiler]
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.04.2011 12:23:56
mbam-log-2011-04-25 (12-23-56).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 159100
Laufzeit: 1 Minute(n), 17 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
[/spoiler]

[spoiler]
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6433

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.04.2011 12:24:31
mbam-log-2011-04-25 (12-24-31).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 158925
Laufzeit: 28 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
[/spoiler]

cosinus 25.04.2011 20:10

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Cloud84 26.04.2011 10:49

OTL Logfile:
Code:

OTL logfile created on: 26.04.2011 11:43:55 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\User\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 75,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,39 Gb Total Space | 97,36 Gb Free Space | 66,51% Space Free | Partition Type: NTFS
Drive D: | 1250,78 Gb Total Space | 629,45 Gb Free Space | 50,32% Space Free | Partition Type: NTFS
 
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Programme\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe (CMedia)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files (x86)\Razer\Mamba\RazerTray.exe (Razer USA Ltd)
PRC - C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWlan.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe (Realtek)
PRC - C:\Windows\SysWOW64\HsMgr.exe ()
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\HsSrv.dll (C-Media Electronics Inc.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\powrprof.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\dsound.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Realtek11nSU) -- C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe (Realtek)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (cmudaxp) -- C:\Windows\SysNative\drivers\cmudaxp.sys (C-Media Inc)
DRV:64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8192su) -- C:\Windows\SysNative\drivers\rtl8192su.sys (Realtek Semiconductor Corporation                          )
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) -- C:\Windows\SysNative\drivers\s0017unic.sys (MCCI Corporation)
DRV:64bit: - (s0017obex) -- C:\Windows\SysNative\drivers\s0017obex.sys (MCCI Corporation)
DRV:64bit: - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) -- C:\Windows\SysNative\drivers\s0017nd5.sys (MCCI Corporation)
DRV:64bit: - (s0017mdm) -- C:\Windows\SysNative\drivers\s0017mdm.sys (MCCI Corporation)
DRV:64bit: - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\drivers\s0017mgmt.sys (MCCI Corporation)
DRV:64bit: - (s0017mdfl) -- C:\Windows\SysNative\drivers\s0017mdfl.sys (MCCI Corporation)
DRV:64bit: - (s0017bus) Sony Ericsson Device 0017 driver (WDM) -- C:\Windows\SysNative\drivers\s0017bus.sys (MCCI Corporation)
DRV:64bit: - (regi) -- C:\Windows\SysNative\drivers\regi.sys (InterVideo)
DRV:64bit: - (6077757b) -- C:\Windows\SysNative\drivers\regi.sys (InterVideo)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 47 9A DE 8E 85 6D CB 01  [binary data]
IE - HKCU\..\URLSearchHook: {33b974a8-e892-4f5f-bd17-f7b0331843d5} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {bee6eb20-01e0-ebd1-da83-080329fb9a3a}:0.2
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.1
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011.01.07 23:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011.01.07 23:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.04.11 20:17:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.04.01 23:35:00 | 000,000,000 | ---D | M]
 
[2010.09.19 01:30:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2011.04.25 21:50:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions
[2011.02.06 16:01:32 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.04.01 23:29:20 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.04.10 22:19:05 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2011.04.10 22:22:59 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2011.04.07 17:15:56 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.11.20 12:19:48 | 000,002,059 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wwjhbt5a.default\searchplugins\daemon-search.xml
[2011.04.25 21:50:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.01.07 23:36:58 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011.01.07 23:36:58 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2005.09.05 10:11:48 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files (x86)\mozilla firefox\plugins\npzylomgamesplayer.dll
[2010.09.14 23:32:39 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.09.14 23:32:39 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.09.14 23:32:39 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.09.14 23:32:39 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.09.14 23:32:39 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {33B974A8-E892-4F5F-BD17-F7B0331843D5} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Cmaudio8788] C:\Windows\Syswow64\cmicnfgp.dll (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Cmaudio8788GX] C:\Windows\syswow64\HsMgr.exe ()
O4:64bit: - HKLM..\Run: [Cmaudio8788GX64] C:\Windows\system\HsMgr64.exe ()
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [Razer Mamba Driver] C:\Program Files (x86)\Razer\Mamba\RazerTray.exe (Razer USA Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ugrllhsluukjoafhzxbuTaskMgr = 0
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: die-staemme.de ([de71] * in Vertrauenswürdige Sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.25 17:35:59 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\RaisingStorm
[2011.04.25 15:49:28 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Funky2
[2011.04.24 22:57:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\UAs
[2011.04.24 22:32:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\xmldm
[2011.04.24 22:32:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\kock
[2011.04.24 17:59:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2011.04.24 17:58:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011.04.24 17:58:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.24 17:58:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.24 17:58:48 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.04.24 17:58:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.04.22 20:27:33 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Apricus-World
[2011.04.22 20:15:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.04.22 14:44:47 | 000,000,000 | ---D | C] -- C:\files
[2011.04.17 16:37:59 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Neuer Lioan World 2
[2011.04.16 09:21:32 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Switch
[2011.04.15 18:47:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTR2010
[2011.04.14 20:31:00 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011.04.14 20:31:00 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011.04.14 20:30:58 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011.04.14 20:30:58 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011.04.14 20:30:58 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011.04.14 20:30:51 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll
[2011.04.14 20:30:51 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll
[2011.04.14 20:30:51 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll
[2011.04.14 20:30:51 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll
[2011.04.14 20:30:47 | 000,367,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2011.04.14 20:30:47 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2011.04.14 20:30:47 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2011.04.14 20:30:47 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2011.04.14 20:30:39 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011.04.14 20:30:39 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011.04.14 20:30:39 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011.04.14 20:30:38 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011.04.14 20:30:38 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011.04.14 20:30:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.04.14 20:30:38 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011.04.14 20:30:38 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.04.14 20:30:38 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011.04.14 20:30:38 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011.04.14 20:30:38 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011.04.14 20:30:38 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011.04.14 20:30:37 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011.04.14 20:30:37 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011.04.14 20:29:12 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2011.04.14 20:29:12 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe
[2011.04.14 20:29:12 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe
[2011.04.14 20:29:07 | 000,640,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2011.04.14 20:29:07 | 000,603,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2011.04.14 20:29:07 | 000,556,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2011.04.14 20:29:07 | 000,518,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2011.04.14 20:29:07 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe
[2011.04.14 20:29:07 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll
[2011.04.14 20:29:07 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll
[2011.04.14 20:29:07 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll
[2011.04.12 15:26:29 | 000,000,000 | ---D | C] -- C:\Programme\SD EnterNET
[2011.04.11 20:21:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Urgesoft
[2011.04.10 22:29:48 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\My Streaming Media
[2011.04.10 22:29:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Jaksta_Technologies_Pty_L
[2011.04.10 22:29:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Applian
[2011.04.10 22:28:59 | 000,000,000 | ---D | C] -- C:\Windows\Applian Director
[2011.04.05 20:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2
[2011.04.05 20:00:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metin2
[2011.04.01 23:29:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2011.04.01 14:33:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2011.04.01 14:33:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Edimax 11n USB Wireless LAN Utility
[2011.04.01 14:32:54 | 000,676,864 | R--- | C] (Realtek Semiconductor Corporation                          ) -- C:\Windows\SysNative\drivers\rtl8192su.sys
[2011.04.01 14:32:53 | 000,614,400 | R--- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\SysNative\Rtlihvs.dll
[2011.04.01 14:32:53 | 000,614,400 | R--- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\Rtlihvs.dll
[2011.04.01 14:32:53 | 000,380,928 | R--- | C] (Realtek) -- C:\Windows\RtlUI2.exe
[2011.04.01 14:32:53 | 000,188,416 | R--- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\RTLExtUI.dll
[2011.04.01 14:32:52 | 000,380,928 | R--- | C] (Realtek) -- C:\Windows\SysNative\RtlUI2.exe
[2011.04.01 14:32:51 | 000,188,416 | R--- | C] (Realtek Semiconductor Corp. ) -- C:\Windows\SysNative\RTLExtUI.dll
[2011.04.01 14:32:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Edimax
[2011.03.31 20:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011.03.31 19:56:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2011.03.31 19:55:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2011.03.31 19:54:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2011.03.31 19:52:51 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011.03.31 19:52:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011.03.30 17:45:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\avidemux
[2011.03.30 17:43:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2011.03.30 17:43:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid
[2011.03.30 17:30:20 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Cuttermaran
[2011.03.29 23:10:05 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\XMedia Recode
[2011.03.29 19:45:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMedia Recode
[2011.03.29 19:11:04 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft
[2011.03.29 19:10:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\doubleTwist Corporation
[2011.03.29 19:10:13 | 000,060,273 | ---- | C] (Open Source Software community project) -- C:\Windows\SysWow64\pthreadGC2.dll
[2011.03.29 19:10:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ffdshow
[2011.03.29 16:26:37 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\My Photos
[2011.03.29 16:26:37 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\My Documents
[2011.03.29 16:25:38 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011.03.29 16:25:14 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\HTC
[2011.03.29 16:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2011.03.29 16:23:03 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Downloaded Installations
[2011.03.29 16:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
[2011.03.29 16:22:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spirent Communications
[2011.03.29 16:22:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTC
[2011.03.29 16:22:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.26 10:43:48 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.04.26 10:43:48 | 000,696,832 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.04.26 10:43:48 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.04.26 10:43:48 | 000,148,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.04.26 10:43:48 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.04.26 10:42:56 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.26 10:42:56 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.26 10:37:57 | 000,000,302 | -HS- | M] () -- C:\Windows\tasks\Mvciox.job
[2011.04.26 10:37:51 | 000,000,354 | -HS- | M] () -- C:\Windows\tasks\GMBRL.job
[2011.04.26 10:37:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.24 21:57:18 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.04.24 15:47:06 | 000,098,304 | RHS- | M] () -- C:\Windows\SysWow64\wmdrmsdkh.dll
[2011.04.15 07:12:19 | 000,416,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.04.13 21:40:28 | 001,596,946 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.03.31 20:00:33 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2011.03.29 19:10:22 | 000,000,133 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
 
========== Files Created - No Company Name ==========
 
[2011.04.24 15:47:06 | 000,098,304 | RHS- | C] () -- C:\Windows\SysWow64\wmdrmsdkh.dll
[2011.04.24 15:47:06 | 000,000,354 | -HS- | C] () -- C:\Windows\tasks\GMBRL.job
[2011.04.24 15:47:06 | 000,000,302 | -HS- | C] () -- C:\Windows\tasks\Mvciox.job
[2011.04.01 14:32:48 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2011.03.31 20:00:33 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.03.30 17:43:19 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011.03.30 17:43:19 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011.03.30 17:43:19 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2011.03.29 19:10:22 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011.03.29 19:10:13 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011.02.18 22:50:16 | 000,003,113 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.02.04 23:12:16 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2011.02.04 23:12:16 | 000,000,048 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2011.02.04 23:12:15 | 000,042,386 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2011.02.04 23:12:12 | 000,000,909 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2011.02.04 23:12:08 | 000,004,969 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2011.02.04 23:12:08 | 000,000,560 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2011.02.02 22:53:43 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2011.01.07 20:38:28 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2011.01.07 20:38:28 | 000,000,088 | RHS- | C] () -- C:\ProgramData\612C76385A.sys
[2010.11.28 16:32:02 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010.11.13 19:09:13 | 001,596,946 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.05 19:33:54 | 000,001,790 | ---- | C] () -- C:\Users\User\AppData\Roaming\Profile0.dat
[2010.10.05 18:24:04 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.09.26 10:36:15 | 000,000,016 | ---- | C] () -- C:\Windows\popcinfo.dat
[2010.09.26 08:38:42 | 000,000,120 | ---- | C] () -- C:\Windows\disney.ini
[2010.09.23 19:04:59 | 000,007,605 | ---- | C] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2010.09.23 18:42:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.09.19 02:03:50 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.09.19 01:30:06 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.09.18 23:25:30 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.09.18 23:25:29 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.09.18 23:25:28 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008.12.09 17:23:13 | 000,047,848 | RHS- | C] () -- C:\Users\User\AppData\Roaming\appconf32.exe
[2007.07.19 12:50:12 | 000,104,520 | ---- | C] () -- C:\Windows\SysWow64\OSD.dll
[2003.02.20 15:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI

< End of report >

--- --- ---


OTL Logfile:
Code:

OTL Extras logfile created on: 26.04.2011 11:43:55 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\User\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 75,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,39 Gb Total Space | 97,36 Gb Free Space | 66,51% Space Free | Partition Type: NTFS
Drive D: | 1250,78 Gb Total Space | 629,45 Gb Free Space | 50,32% Space Free | Partition Type: NTFS
 
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5E2BDF97-E0C7-75AE-29E1-5EA9DA262F2F}" = WMV9/VC-1 Video Playback
"{6CC95B76-D380-46B2-9022-9353938E48BA}" = Logitech GamePanel Software 3.03.133
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{AE57C044-8912-A181-A0E4-BC2DAB3A092A}" = ATI Catalyst Install Manager
"{B2C5B378-546F-75A7-7757-C1EAAFAF9E33}" = ccc-utility64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{E6456858-8C0C-35CE-96B8-AFFCD205C9FC}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"C-Media Oxygen HD Audio Driver" = ASUS Xonar DX Audio Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"WinRAR archiver" = WinRAR
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5645FB61-898F-4F59-AF80-52FEF3D63A64}" = HTC Sync
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6592FDEC-2C1A-413A-9985-25FEC2F0848D}" = Star Wars Empire at War Forces of Corruption
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B9F5775-8C8C-2A4E-0CAB-74EA7AF5CB09}" = ccc-core-static
"{7BE49DA7-EDA4-4C63-AA06-DCDF6858C3F3}" = Razer Mamba
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C049499-055C-4a0c-A916-1D8CA1FF45EB}" = Edimax Wireless LAN Driver and Utility
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AA945C94-285E-DE48-A30F-70105C6580DE}" = Catalyst Control Center Graphics Previews Common
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.1 - Deutsch
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{CC29B835-95A5-3CD9-087B-F94D7B9ECC9B}" = Catalyst Control Center InstallProxy
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"DivX Setup.divx.com" = DivX-Setup
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"HandBrake" = HandBrake 0.9.5
"hon" = Heroes of Newerth
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Metin2_is1" = Metin2
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"StarCraft II" = StarCraft II
"Steam App 42700" = Call of Duty: Black Ops
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"The KMPlayer" = The KMPlayer (remove only)
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.5
"Xvid_is1" = Xvid 1.2.2 final uninstall
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 24.04.2011 15:58:24 | Computer Name = User-PC | Source = VSS | ID = 12292
Description =
 
Error - 24.04.2011 15:58:24 | Computer Name = User-PC | Source = VSS | ID = 13
Description =
 
Error - 24.04.2011 15:58:24 | Computer Name = User-PC | Source = VSS | ID = 12292
Description =
 
Error - 24.04.2011 15:58:38 | Computer Name = User-PC | Source = VSS | ID = 13
Description =
 
Error - 24.04.2011 15:58:38 | Computer Name = User-PC | Source = VSS | ID = 12292
Description =
 
Error - 25.04.2011 12:49:40 | Computer Name = User-PC | Source = Application Hang | ID = 1002
Description = Programm Metin2.exe, Version 1.1.1.1 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 9e8    Startzeit:
01cc0361d72981bd    Endzeit: 47    Anwendungspfad: C:\Users\User\Desktop\RaisingStorm\Metin2.exe

Berichts-ID:
 
 
Error - 25.04.2011 18:17:37 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: null0.19771568843115184.exe, Version:
 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Name des fehlerhaften Moduls: null0.19771568843115184.exe,
 Version: 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Ausnahmecode: 0xc0000005  Fehleroffset:
 0x000185b0  ID des fehlerhaften Prozesses: 0xe94  Startzeit der fehlerhaften Anwendung:
 0x01cc039694a132ff  Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla
 Firefox\null0.19771568843115184.exe  Pfad des fehlerhaften Moduls: C:\Program Files
 (x86)\Mozilla Firefox\null0.19771568843115184.exe  Berichtskennung: d2fd49fa-6f89-11e0-93d4-0026188852a5
 
Error - 25.04.2011 18:17:38 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: null0.5399563998682995.exe, Version:
 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Name des fehlerhaften Moduls: null0.5399563998682995.exe,
 Version: 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Ausnahmecode: 0xc0000005  Fehleroffset:
 0x000185b0  ID des fehlerhaften Prozesses: 0xb80  Startzeit der fehlerhaften Anwendung:
 0x01cc0396957a581d  Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla
 Firefox\null0.5399563998682995.exe  Pfad des fehlerhaften Moduls: C:\Program Files
 (x86)\Mozilla Firefox\null0.5399563998682995.exe  Berichtskennung: d3923929-6f89-11e0-93d4-0026188852a5
 
Error - 25.04.2011 18:17:40 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: null0.09438208857365815.exe, Version:
 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Name des fehlerhaften Moduls: null0.09438208857365815.exe,
 Version: 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Ausnahmecode: 0xc0000005  Fehleroffset:
 0x000185b0  ID des fehlerhaften Prozesses: 0x5e8  Startzeit der fehlerhaften Anwendung:
 0x01cc039696a9b4cf  Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla
 Firefox\null0.09438208857365815.exe  Pfad des fehlerhaften Moduls: C:\Program Files
 (x86)\Mozilla Firefox\null0.09438208857365815.exe  Berichtskennung: d4c2321c-6f89-11e0-93d4-0026188852a5
 
Error - 25.04.2011 18:17:41 | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: null0.21189351611425766.exe, Version:
 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Name des fehlerhaften Moduls: null0.21189351611425766.exe,
 Version: 5.1033.1066.1047, Zeitstempel: 0x4db090bd  Ausnahmecode: 0xc0000005  Fehleroffset:
 0x000185b0  ID des fehlerhaften Prozesses: 0xa38  Startzeit der fehlerhaften Anwendung:
 0x01cc0396975e6174  Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla
 Firefox\null0.21189351611425766.exe  Pfad des fehlerhaften Moduls: C:\Program Files
 (x86)\Mozilla Firefox\null0.21189351611425766.exe  Berichtskennung: d57c3605-6f89-11e0-93d4-0026188852a5
 
[ System Events ]
Error - 26.04.2011 04:37:50 | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "iPodDrv" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 26.04.2011 04:37:51 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:37:53 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:37:53 | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "regi" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 26.04.2011 04:37:54 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:38:02 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:38:07 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:38:09 | Computer Name = User-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Fehler beim Lesen der Datei für lokale Hosts.
 
Error - 26.04.2011 04:38:09 | Computer Name = User-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1058
 
Error - 26.04.2011 04:38:12 | Computer Name = User-PC | Source = WMPNetworkSvc | ID = 866300
Description =
 
 
< End of report >

--- --- ---

cosinus 26.04.2011 12:38

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
[2011.04.24 22:57:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\UAs
[2011.04.24 22:32:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\xmldm
[2011.04.24 22:32:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\kock
[2011.04.24 21:57:18 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.04.24 15:47:06 | 000,098,304 | RHS- | M] () -- C:\Windows\SysWow64\wmdrmsdkh.dll
[2011.04.24 15:47:06 | 000,098,304 | RHS- | C] () -- C:\Windows\SysWow64\wmdrmsdkh.dll
[2011.04.24 15:47:06 | 000,000,354 | -HS- | C] () -- C:\Windows\tasks\GMBRL.job
[2011.04.24 15:47:06 | 000,000,302 | -HS- | C] () -- C:\Windows\tasks\Mvciox.job
[2011.04.01 14:32:48 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2008.12.09 17:23:13 | 000,047,848 | RHS- | C] () -- C:\Users\User\AppData\Roaming\appconf32.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Autorun.exe
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Cloud84 27.04.2011 17:27

Habe ich erledigt.
Das Problem ist bisher leider noch nicht erledigt.

Gruß,
Manuel

cosinus 27.04.2011 18:41

Log fehlt!

Cloud84 28.04.2011 12:53

Wo finde ich die Logfile im nachhinein? Habe sie, denke ich zugemacht, und bisher auch nicht weiter gefunden.

cosinus 28.04.2011 15:40

Schau in C:\_OTL nach

Cloud84 28.04.2011 22:19

All processes killed
========== OTL ==========
C:\Users\User\AppData\Roaming\UAs folder moved successfully.
C:\Users\User\AppData\Roaming\xmldm folder moved successfully.
C:\Users\User\AppData\Roaming\kock folder moved successfully.
C:\Windows\epplauncher.mif moved successfully.
C:\Windows\SysWOW64\wmdrmsdkh.dll moved successfully.
File C:\Windows\SysWow64\wmdrmsdkh.dll not found.
C:\Windows\Tasks\GMBRL.job moved successfully.
C:\Windows\Tasks\Mvciox.job moved successfully.
C:\Windows\SysWOW64\ISSRemoveSP.exe moved successfully.
C:\Users\User\AppData\Roaming\appconf32.exe moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\Autorun.exe not found.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: User
->Temp folder emptied: 1248294 bytes
->Temporary Internet Files folder emptied: 1291526 bytes
->Java cache emptied: 35871 bytes
->FireFox cache emptied: 95201936 bytes
->Flash cache emptied: 63840 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 22800 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes
RecycleBin emptied: 2270702458 bytes

Total Files Cleaned = 2.259,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04272011_182401

Files\Folders moved on Reboot...
C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

cosinus 29.04.2011 10:32

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Cloud84 29.04.2011 10:56

[spoiler]2011/04/29 11:52:38.0652 3444 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/04/29 11:52:38.0887 3444 ================================================================================
2011/04/29 11:52:38.0887 3444 SystemInfo:
2011/04/29 11:52:38.0887 3444
2011/04/29 11:52:38.0887 3444 OS Version: 6.1.7600 ServicePack: 0.0
2011/04/29 11:52:38.0887 3444 Product type: Workstation
2011/04/29 11:52:38.0887 3444 ComputerName: USER-PC
2011/04/29 11:52:38.0888 3444 UserName: User
2011/04/29 11:52:38.0888 3444 Windows directory: C:\Windows
2011/04/29 11:52:38.0888 3444 System windows directory: C:\Windows
2011/04/29 11:52:38.0888 3444 Running under WOW64
2011/04/29 11:52:38.0888 3444 Processor architecture: Intel x64
2011/04/29 11:52:38.0888 3444 Number of processors: 8
2011/04/29 11:52:38.0888 3444 Page size: 0x1000
2011/04/29 11:52:38.0888 3444 Boot type: Normal boot
2011/04/29 11:52:38.0888 3444 ================================================================================
2011/04/29 11:52:39.0199 3444 Initialize success
2011/04/29 11:52:40.0375 4064 ================================================================================
2011/04/29 11:52:40.0375 4064 Scan started
2011/04/29 11:52:40.0375 4064 Mode: Manual;
2011/04/29 11:52:40.0375 4064 ================================================================================
2011/04/29 11:52:40.0696 4064 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/04/29 11:52:40.0732 4064 6077757b (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:52:40.0751 4064 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2011/04/29 11:52:40.0766 4064 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/04/29 11:52:40.0789 4064 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/04/29 11:52:40.0816 4064 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/04/29 11:52:40.0837 4064 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/04/29 11:52:40.0869 4064 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2011/04/29 11:52:40.0887 4064 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2011/04/29 11:52:40.0916 4064 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2011/04/29 11:52:40.0936 4064 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2011/04/29 11:52:40.0950 4064 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/04/29 11:52:41.0075 4064 amdkmdag (dcc8177244fe79c61c4e73c65e63922a) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/04/29 11:52:41.0145 4064 amdkmdap (7fe67d107329dc2cf89136a8e19bceb7) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/04/29 11:52:41.0165 4064 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/04/29 11:52:41.0195 4064 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
2011/04/29 11:52:41.0220 4064 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/04/29 11:52:41.0235 4064 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
2011/04/29 11:52:41.0259 4064 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2011/04/29 11:52:41.0306 4064 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/04/29 11:52:41.0316 4064 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/04/29 11:52:41.0350 4064 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/04/29 11:52:41.0364 4064 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2011/04/29 11:52:41.0386 4064 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/04/29 11:52:41.0416 4064 AtiHdmiService (2d648572ba9a610952fcafba1e119c2d) C:\Windows\system32\drivers\AtiHdmi.sys
2011/04/29 11:52:41.0451 4064 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/04/29 11:52:41.0480 4064 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/04/29 11:52:41.0507 4064 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/04/29 11:52:41.0544 4064 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/04/29 11:52:41.0576 4064 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
2011/04/29 11:52:41.0592 4064 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/04/29 11:52:41.0610 4064 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/04/29 11:52:41.0636 4064 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/04/29 11:52:41.0646 4064 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/04/29 11:52:41.0660 4064 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/04/29 11:52:41.0671 4064 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/04/29 11:52:41.0681 4064 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/04/29 11:52:41.0714 4064 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/04/29 11:52:41.0732 4064 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2011/04/29 11:52:41.0754 4064 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/04/29 11:52:41.0795 4064 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/04/29 11:52:41.0817 4064 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/04/29 11:52:41.0827 4064 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2011/04/29 11:52:41.0870 4064 cmudaxp (3cd27b6666d0a6a71a7b6834dd5c97f7) C:\Windows\system32\drivers\cmudaxp.sys
2011/04/29 11:52:41.0902 4064 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2011/04/29 11:52:41.0934 4064 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/04/29 11:52:41.0962 4064 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/04/29 11:52:41.0992 4064 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/04/29 11:52:42.0021 4064 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2011/04/29 11:52:42.0045 4064 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2011/04/29 11:52:42.0057 4064 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/04/29 11:52:42.0069 4064 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/04/29 11:52:42.0102 4064 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/04/29 11:52:42.0139 4064 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
2011/04/29 11:52:42.0217 4064 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/04/29 11:52:42.0272 4064 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/04/29 11:52:42.0290 4064 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2011/04/29 11:52:42.0309 4064 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/04/29 11:52:42.0331 4064 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/04/29 11:52:42.0350 4064 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/04/29 11:52:42.0372 4064 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/04/29 11:52:42.0389 4064 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/04/29 11:52:42.0397 4064 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/04/29 11:52:42.0412 4064 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2011/04/29 11:52:42.0434 4064 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/04/29 11:52:42.0449 4064 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/04/29 11:52:42.0462 4064 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/04/29 11:52:42.0475 4064 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/04/29 11:52:42.0516 4064 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
2011/04/29 11:52:42.0536 4064 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/04/29 11:52:42.0565 4064 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2011/04/29 11:52:42.0584 4064 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/04/29 11:52:42.0592 4064 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/04/29 11:52:42.0626 4064 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/04/29 11:52:42.0637 4064 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/04/29 11:52:42.0659 4064 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2011/04/29 11:52:42.0682 4064 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/04/29 11:52:42.0726 4064 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2011/04/29 11:52:42.0754 4064 htcnprot (b8b1b284362e1d8135112573395d5da5) C:\Windows\system32\DRIVERS\htcnprot.sys
2011/04/29 11:52:42.0779 4064 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2011/04/29 11:52:42.0794 4064 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2011/04/29 11:52:42.0812 4064 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/04/29 11:52:42.0837 4064 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
2011/04/29 11:52:42.0862 4064 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/04/29 11:52:42.0914 4064 IntcAzAudAddService (491dadcc74327fabc85e0ab80af8f204) C:\Windows\system32\drivers\RTKVHD64.sys
2011/04/29 11:52:42.0932 4064 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2011/04/29 11:52:42.0950 4064 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/04/29 11:52:42.0971 4064 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/04/29 11:52:42.0982 4064 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/04/29 11:52:42.0994 4064 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/04/29 11:52:43.0019 4064 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/04/29 11:52:43.0027 4064 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2011/04/29 11:52:43.0050 4064 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/04/29 11:52:43.0069 4064 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/04/29 11:52:43.0090 4064 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/04/29 11:52:43.0121 4064 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2011/04/29 11:52:43.0140 4064 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2011/04/29 11:52:43.0161 4064 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/04/29 11:52:43.0195 4064 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/04/29 11:52:43.0221 4064 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/04/29 11:52:43.0240 4064 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/04/29 11:52:43.0257 4064 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/04/29 11:52:43.0276 4064 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/04/29 11:52:43.0287 4064 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/04/29 11:52:43.0320 4064 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/04/29 11:52:43.0341 4064 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/04/29 11:52:43.0365 4064 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/04/29 11:52:43.0389 4064 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/04/29 11:52:43.0397 4064 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/04/29 11:52:43.0417 4064 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/04/29 11:52:43.0426 4064 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2011/04/29 11:52:43.0450 4064 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2011/04/29 11:52:43.0472 4064 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/04/29 11:52:43.0497 4064 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2011/04/29 11:52:43.0546 4064 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/04/29 11:52:43.0565 4064 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/04/29 11:52:43.0585 4064 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/04/29 11:52:43.0605 4064 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2011/04/29 11:52:43.0626 4064 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2011/04/29 11:52:43.0662 4064 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/04/29 11:52:43.0682 4064 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/04/29 11:52:43.0691 4064 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/04/29 11:52:43.0719 4064 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/04/29 11:52:43.0735 4064 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/04/29 11:52:43.0744 4064 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/04/29 11:52:43.0762 4064 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2011/04/29 11:52:43.0784 4064 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/04/29 11:52:43.0792 4064 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/04/29 11:52:43.0816 4064 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/04/29 11:52:43.0839 4064 MTsensor (2219a3d695405e7ba2186ba6b9ede14a) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/04/29 11:52:43.0847 4064 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/04/29 11:52:43.0882 4064 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/04/29 11:52:43.0919 4064 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2011/04/29 11:52:43.0940 4064 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/04/29 11:52:43.0950 4064 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/04/29 11:52:43.0971 4064 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/04/29 11:52:43.0989 4064 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/04/29 11:52:44.0006 4064 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2011/04/29 11:52:44.0015 4064 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/04/29 11:52:44.0039 4064 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2011/04/29 11:52:44.0069 4064 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/04/29 11:52:44.0092 4064 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/04/29 11:52:44.0105 4064 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/04/29 11:52:44.0164 4064 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
2011/04/29 11:52:44.0202 4064 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/04/29 11:52:44.0226 4064 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
2011/04/29 11:52:44.0245 4064 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
2011/04/29 11:52:44.0274 4064 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/04/29 11:52:44.0291 4064 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/04/29 11:52:44.0334 4064 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/04/29 11:52:44.0342 4064 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2011/04/29 11:52:44.0371 4064 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2011/04/29 11:52:44.0382 4064 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2011/04/29 11:52:44.0401 4064 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/04/29 11:52:44.0420 4064 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/04/29 11:52:44.0449 4064 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/04/29 11:52:44.0506 4064 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2011/04/29 11:52:44.0516 4064 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/04/29 11:52:44.0534 4064 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2011/04/29 11:52:44.0569 4064 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/04/29 11:52:44.0601 4064 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/04/29 11:52:44.0624 4064 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/04/29 11:52:44.0641 4064 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/04/29 11:52:44.0661 4064 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/04/29 11:52:44.0674 4064 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/04/29 11:52:44.0686 4064 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/04/29 11:52:44.0696 4064 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/04/29 11:52:44.0729 4064 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2011/04/29 11:52:44.0739 4064 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/04/29 11:52:44.0760 4064 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/04/29 11:52:44.0785 4064 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2011/04/29 11:52:44.0795 4064 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/04/29 11:52:44.0811 4064 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/04/29 11:52:44.0824 4064 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2011/04/29 11:52:44.0846 4064 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2011/04/29 11:52:44.0896 4064 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:52:44.0930 4064 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/04/29 11:52:44.0967 4064 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/04/29 11:52:44.0999 4064 RTL8192su (fc00c0de6dc83de1b2b01420e2195b21) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/04/29 11:52:45.0115 4064 s0017bus (032f537623a7b2fb81aaa184c30b70c3) C:\Windows\system32\DRIVERS\s0017bus.sys
2011/04/29 11:52:45.0164 4064 s0017mdfl (9964a28e569b4ff105b446ef8978fd5c) C:\Windows\system32\DRIVERS\s0017mdfl.sys
2011/04/29 11:52:45.0185 4064 s0017mdm (06347087d274c23dcfa8c4ab5c4314db) C:\Windows\system32\DRIVERS\s0017mdm.sys
2011/04/29 11:52:45.0204 4064 s0017mgmt (f0f0747b3fa50272de6b1bf575fa4700) C:\Windows\system32\DRIVERS\s0017mgmt.sys
2011/04/29 11:52:45.0224 4064 s0017nd5 (7224412cea2ff2df7d4842c1b0e71045) C:\Windows\system32\DRIVERS\s0017nd5.sys
2011/04/29 11:52:45.0241 4064 s0017obex (3feadbc7f09b8b596cbfb82f12aba87f) C:\Windows\system32\DRIVERS\s0017obex.sys
2011/04/29 11:52:45.0251 4064 s0017unic (2b63bea31d939888b2a8f3f14d89b5c1) C:\Windows\system32\DRIVERS\s0017unic.sys
2011/04/29 11:52:45.0269 4064 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/04/29 11:52:45.0290 4064 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/04/29 11:52:45.0307 4064 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2011/04/29 11:52:45.0329 4064 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/04/29 11:52:45.0347 4064 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/04/29 11:52:45.0366 4064 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/04/29 11:52:45.0375 4064 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/04/29 11:52:45.0420 4064 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/04/29 11:52:45.0440 4064 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/04/29 11:52:45.0449 4064 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/04/29 11:52:45.0469 4064 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/04/29 11:52:45.0491 4064 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/04/29 11:52:45.0511 4064 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/04/29 11:52:45.0530 4064 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/04/29 11:52:45.0555 4064 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/04/29 11:52:45.0597 4064 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/04/29 11:52:45.0599 4064 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
2011/04/29 11:52:45.0601 4064 sptd - detected Locked file (1)
2011/04/29 11:52:45.0637 4064 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
2011/04/29 11:52:45.0659 4064 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
2011/04/29 11:52:45.0694 4064 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
2011/04/29 11:52:45.0736 4064 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/04/29 11:52:45.0751 4064 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/04/29 11:52:45.0761 4064 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2011/04/29 11:52:45.0771 4064 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2011/04/29 11:52:45.0834 4064 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2011/04/29 11:52:45.0867 4064 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2011/04/29 11:52:45.0900 4064 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/04/29 11:52:45.0926 4064 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/04/29 11:52:45.0935 4064 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/04/29 11:52:45.0959 4064 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2011/04/29 11:52:45.0969 4064 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2011/04/29 11:52:46.0000 4064 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/04/29 11:52:46.0017 4064 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2011/04/29 11:52:46.0036 4064 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/04/29 11:52:46.0060 4064 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2011/04/29 11:52:46.0090 4064 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/04/29 11:52:46.0100 4064 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2011/04/29 11:52:46.0110 4064 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/04/29 11:52:46.0146 4064 USBAAPL64 (cd03479f2da26500b203ed075c146a7a) C:\Windows\system32\Drivers\usbaapl64.sys
2011/04/29 11:52:46.0176 4064 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2011/04/29 11:52:46.0197 4064 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/04/29 11:52:46.0207 4064 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2011/04/29 11:52:46.0226 4064 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
2011/04/29 11:52:46.0240 4064 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
2011/04/29 11:52:46.0256 4064 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2011/04/29 11:52:46.0274 4064 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/04/29 11:52:46.0300 4064 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/04/29 11:52:46.0329 4064 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS
2011/04/29 11:52:46.0350 4064 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/04/29 11:52:46.0380 4064 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
2011/04/29 11:52:46.0407 4064 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/04/29 11:52:46.0426 4064 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/04/29 11:52:46.0435 4064 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/04/29 11:52:46.0465 4064 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/04/29 11:52:46.0475 4064 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2011/04/29 11:52:46.0490 4064 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2011/04/29 11:52:46.0511 4064 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/04/29 11:52:46.0521 4064 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/04/29 11:52:46.0534 4064 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2011/04/29 11:52:46.0546 4064 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2011/04/29 11:52:46.0570 4064 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/04/29 11:52:46.0582 4064 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/04/29 11:52:46.0614 4064 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/04/29 11:52:46.0634 4064 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/04/29 11:52:46.0644 4064 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:52:46.0651 4064 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:52:46.0681 4064 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/04/29 11:52:46.0694 4064 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/04/29 11:52:46.0722 4064 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/04/29 11:52:46.0735 4064 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/04/29 11:52:46.0791 4064 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/04/29 11:52:46.0802 4064 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/04/29 11:52:46.0839 4064 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/04/29 11:52:46.0880 4064 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2011/04/29 11:52:46.0905 4064 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/04/29 11:52:47.0022 4064 xusb21 (38f55d07b1d3391065c40ec065f984e2) C:\Windows\system32\DRIVERS\xusb21.sys
2011/04/29 11:52:47.0056 4064 ================================================================================
2011/04/29 11:52:47.0056 4064 Scan finished
2011/04/29 11:52:47.0056 4064 ================================================================================
2011/04/29 11:52:47.0064 3632 Detected object count: 1
2011/04/29 11:52:54.0976 3632 Locked file(sptd) - User select action: Skip
2011/04/29 11:53:04.0425 2148 ================================================================================
2011/04/29 11:53:04.0425 2148 Scan started
2011/04/29 11:53:04.0425 2148 Mode: Manual;
2011/04/29 11:53:04.0425 2148 ================================================================================
2011/04/29 11:53:04.0685 2148 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/04/29 11:53:04.0709 2148 6077757b (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:53:04.0728 2148 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2011/04/29 11:53:04.0749 2148 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/04/29 11:53:04.0771 2148 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/04/29 11:53:04.0793 2148 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/04/29 11:53:04.0813 2148 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/04/29 11:53:04.0845 2148 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2011/04/29 11:53:04.0863 2148 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2011/04/29 11:53:04.0893 2148 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2011/04/29 11:53:04.0910 2148 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2011/04/29 11:53:04.0935 2148 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/04/29 11:53:05.0055 2148 amdkmdag (dcc8177244fe79c61c4e73c65e63922a) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/04/29 11:53:05.0111 2148 amdkmdap (7fe67d107329dc2cf89136a8e19bceb7) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/04/29 11:53:05.0133 2148 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/04/29 11:53:05.0164 2148 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
2011/04/29 11:53:05.0189 2148 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/04/29 11:53:05.0210 2148 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
2011/04/29 11:53:05.0228 2148 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2011/04/29 11:53:05.0266 2148 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/04/29 11:53:05.0275 2148 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/04/29 11:53:05.0301 2148 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/04/29 11:53:05.0316 2148 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2011/04/29 11:53:05.0338 2148 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/04/29 11:53:05.0360 2148 AtiHdmiService (2d648572ba9a610952fcafba1e119c2d) C:\Windows\system32\drivers\AtiHdmi.sys
2011/04/29 11:53:05.0393 2148 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/04/29 11:53:05.0413 2148 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/04/29 11:53:05.0434 2148 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/04/29 11:53:05.0454 2148 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/04/29 11:53:05.0479 2148 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
2011/04/29 11:53:05.0494 2148 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/04/29 11:53:05.0509 2148 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/04/29 11:53:05.0539 2148 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/04/29 11:53:05.0548 2148 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/04/29 11:53:05.0558 2148 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/04/29 11:53:05.0568 2148 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/04/29 11:53:05.0579 2148 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/04/29 11:53:05.0605 2148 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/04/29 11:53:05.0624 2148 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2011/04/29 11:53:05.0645 2148 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/04/29 11:53:05.0674 2148 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/04/29 11:53:05.0695 2148 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/04/29 11:53:05.0706 2148 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2011/04/29 11:53:05.0739 2148 cmudaxp (3cd27b6666d0a6a71a7b6834dd5c97f7) C:\Windows\system32\drivers\cmudaxp.sys
2011/04/29 11:53:05.0755 2148 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2011/04/29 11:53:05.0775 2148 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/04/29 11:53:05.0783 2148 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/04/29 11:53:05.0795 2148 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/04/29 11:53:05.0821 2148 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2011/04/29 11:53:05.0844 2148 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2011/04/29 11:53:05.0868 2148 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/04/29 11:53:05.0876 2148 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/04/29 11:53:05.0914 2148 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/04/29 11:53:05.0955 2148 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
2011/04/29 11:53:06.0020 2148 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/04/29 11:53:06.0064 2148 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/04/29 11:53:06.0081 2148 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2011/04/29 11:53:06.0099 2148 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/04/29 11:53:06.0116 2148 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/04/29 11:53:06.0128 2148 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/04/29 11:53:06.0144 2148 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/04/29 11:53:06.0158 2148 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/04/29 11:53:06.0165 2148 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/04/29 11:53:06.0180 2148 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2011/04/29 11:53:06.0200 2148 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/04/29 11:53:06.0218 2148 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/04/29 11:53:06.0238 2148 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/04/29 11:53:06.0246 2148 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/04/29 11:53:06.0278 2148 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
2011/04/29 11:53:06.0289 2148 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/04/29 11:53:06.0315 2148 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2011/04/29 11:53:06.0329 2148 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/04/29 11:53:06.0338 2148 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/04/29 11:53:06.0368 2148 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/04/29 11:53:06.0376 2148 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/04/29 11:53:06.0401 2148 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2011/04/29 11:53:06.0425 2148 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/04/29 11:53:06.0445 2148 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2011/04/29 11:53:06.0464 2148 htcnprot (b8b1b284362e1d8135112573395d5da5) C:\Windows\system32\DRIVERS\htcnprot.sys
2011/04/29 11:53:06.0489 2148 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2011/04/29 11:53:06.0500 2148 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2011/04/29 11:53:06.0520 2148 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/04/29 11:53:06.0545 2148 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
2011/04/29 11:53:06.0568 2148 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/04/29 11:53:06.0613 2148 IntcAzAudAddService (491dadcc74327fabc85e0ab80af8f204) C:\Windows\system32\drivers\RTKVHD64.sys
2011/04/29 11:53:06.0629 2148 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2011/04/29 11:53:06.0651 2148 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/04/29 11:53:06.0674 2148 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/04/29 11:53:06.0686 2148 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/04/29 11:53:06.0700 2148 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/04/29 11:53:06.0721 2148 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/04/29 11:53:06.0730 2148 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2011/04/29 11:53:06.0753 2148 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/04/29 11:53:06.0770 2148 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/04/29 11:53:06.0785 2148 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/04/29 11:53:06.0803 2148 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2011/04/29 11:53:06.0818 2148 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2011/04/29 11:53:06.0838 2148 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/04/29 11:53:06.0864 2148 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/04/29 11:53:06.0890 2148 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/04/29 11:53:06.0914 2148 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/04/29 11:53:06.0935 2148 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/04/29 11:53:06.0953 2148 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/04/29 11:53:06.0961 2148 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/04/29 11:53:06.0988 2148 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/04/29 11:53:07.0009 2148 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/04/29 11:53:07.0026 2148 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/04/29 11:53:07.0050 2148 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/04/29 11:53:07.0059 2148 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/04/29 11:53:07.0079 2148 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/04/29 11:53:07.0086 2148 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2011/04/29 11:53:07.0109 2148 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2011/04/29 11:53:07.0124 2148 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/04/29 11:53:07.0148 2148 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2011/04/29 11:53:07.0183 2148 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/04/29 11:53:07.0205 2148 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/04/29 11:53:07.0228 2148 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/04/29 11:53:07.0249 2148 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2011/04/29 11:53:07.0269 2148 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2011/04/29 11:53:07.0296 2148 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/04/29 11:53:07.0311 2148 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/04/29 11:53:07.0319 2148 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/04/29 11:53:07.0345 2148 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/04/29 11:53:07.0360 2148 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/04/29 11:53:07.0369 2148 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/04/29 11:53:07.0383 2148 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2011/04/29 11:53:07.0401 2148 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/04/29 11:53:07.0410 2148 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/04/29 11:53:07.0428 2148 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/04/29 11:53:07.0450 2148 MTsensor (2219a3d695405e7ba2186ba6b9ede14a) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/04/29 11:53:07.0470 2148 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/04/29 11:53:07.0505 2148 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/04/29 11:53:07.0531 2148 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2011/04/29 11:53:07.0551 2148 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/04/29 11:53:07.0560 2148 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/04/29 11:53:07.0581 2148 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/04/29 11:53:07.0590 2148 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/04/29 11:53:07.0609 2148 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2011/04/29 11:53:07.0619 2148 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/04/29 11:53:07.0640 2148 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2011/04/29 11:53:07.0669 2148 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/04/29 11:53:07.0690 2148 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/04/29 11:53:07.0705 2148 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/04/29 11:53:07.0754 2148 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
2011/04/29 11:53:07.0773 2148 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/04/29 11:53:07.0803 2148 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
2011/04/29 11:53:07.0826 2148 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
2011/04/29 11:53:07.0844 2148 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/04/29 11:53:07.0863 2148 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/04/29 11:53:07.0893 2148 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/04/29 11:53:07.0903 2148 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2011/04/29 11:53:07.0925 2148 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2011/04/29 11:53:07.0934 2148 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2011/04/29 11:53:07.0955 2148 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/04/29 11:53:07.0964 2148 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/04/29 11:53:07.0995 2148 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/04/29 11:53:08.0045 2148 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2011/04/29 11:53:08.0055 2148 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/04/29 11:53:08.0073 2148 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2011/04/29 11:53:08.0104 2148 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/04/29 11:53:08.0128 2148 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/04/29 11:53:08.0151 2148 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/04/29 11:53:08.0168 2148 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/04/29 11:53:08.0193 2148 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/04/29 11:53:08.0204 2148 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/04/29 11:53:08.0218 2148 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/04/29 11:53:08.0228 2148 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/04/29 11:53:08.0249 2148 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2011/04/29 11:53:08.0259 2148 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/04/29 11:53:08.0271 2148 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/04/29 11:53:08.0298 2148 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2011/04/29 11:53:08.0306 2148 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/04/29 11:53:08.0324 2148 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/04/29 11:53:08.0335 2148 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2011/04/29 11:53:08.0345 2148 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2011/04/29 11:53:08.0375 2148 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:53:08.0406 2148 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/04/29 11:53:08.0431 2148 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/04/29 11:53:08.0461 2148 RTL8192su (fc00c0de6dc83de1b2b01420e2195b21) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/04/29 11:53:08.0486 2148 s0017bus (032f537623a7b2fb81aaa184c30b70c3) C:\Windows\system32\DRIVERS\s0017bus.sys
2011/04/29 11:53:08.0508 2148 s0017mdfl (9964a28e569b4ff105b446ef8978fd5c) C:\Windows\system32\DRIVERS\s0017mdfl.sys
2011/04/29 11:53:08.0529 2148 s0017mdm (06347087d274c23dcfa8c4ab5c4314db) C:\Windows\system32\DRIVERS\s0017mdm.sys
2011/04/29 11:53:08.0549 2148 s0017mgmt (f0f0747b3fa50272de6b1bf575fa4700) C:\Windows\system32\DRIVERS\s0017mgmt.sys
2011/04/29 11:53:08.0570 2148 s0017nd5 (7224412cea2ff2df7d4842c1b0e71045) C:\Windows\system32\DRIVERS\s0017nd5.sys
2011/04/29 11:53:08.0579 2148 s0017obex (3feadbc7f09b8b596cbfb82f12aba87f) C:\Windows\system32\DRIVERS\s0017obex.sys
2011/04/29 11:53:08.0589 2148 s0017unic (2b63bea31d939888b2a8f3f14d89b5c1) C:\Windows\system32\DRIVERS\s0017unic.sys
2011/04/29 11:53:08.0608 2148 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/04/29 11:53:08.0634 2148 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/04/29 11:53:08.0704 2148 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2011/04/29 11:53:08.0750 2148 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/04/29 11:53:08.0768 2148 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/04/29 11:53:08.0786 2148 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/04/29 11:53:08.0795 2148 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/04/29 11:53:08.0831 2148 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/04/29 11:53:08.0853 2148 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/04/29 11:53:08.0861 2148 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/04/29 11:53:08.0880 2148 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/04/29 11:53:08.0904 2148 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/04/29 11:53:08.0921 2148 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/04/29 11:53:08.0940 2148 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/04/29 11:53:08.0958 2148 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/04/29 11:53:09.0003 2148 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/04/29 11:53:09.0003 2148 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
2011/04/29 11:53:09.0005 2148 sptd - detected Locked file (1)
2011/04/29 11:53:09.0033 2148 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
2011/04/29 11:53:09.0055 2148 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
2011/04/29 11:53:09.0078 2148 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
2011/04/29 11:53:09.0108 2148 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/04/29 11:53:09.0119 2148 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/04/29 11:53:09.0129 2148 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2011/04/29 11:53:09.0139 2148 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2011/04/29 11:53:09.0201 2148 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2011/04/29 11:53:09.0229 2148 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2011/04/29 11:53:09.0258 2148 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/04/29 11:53:09.0279 2148 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/04/29 11:53:09.0289 2148 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/04/29 11:53:09.0310 2148 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2011/04/29 11:53:09.0320 2148 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2011/04/29 11:53:09.0354 2148 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/04/29 11:53:09.0370 2148 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2011/04/29 11:53:09.0391 2148 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/04/29 11:53:09.0413 2148 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2011/04/29 11:53:09.0443 2148 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/04/29 11:53:09.0451 2148 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2011/04/29 11:53:09.0461 2148 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/04/29 11:53:09.0499 2148 USBAAPL64 (cd03479f2da26500b203ed075c146a7a) C:\Windows\system32\Drivers\usbaapl64.sys
2011/04/29 11:53:09.0516 2148 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2011/04/29 11:53:09.0535 2148 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/04/29 11:53:09.0545 2148 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2011/04/29 11:53:09.0564 2148 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
2011/04/29 11:53:09.0578 2148 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
2011/04/29 11:53:09.0594 2148 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2011/04/29 11:53:09.0609 2148 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/04/29 11:53:09.0635 2148 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/04/29 11:53:09.0666 2148 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS
2011/04/29 11:53:09.0685 2148 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/04/29 11:53:09.0708 2148 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
2011/04/29 11:53:09.0721 2148 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/04/29 11:53:09.0739 2148 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/04/29 11:53:09.0748 2148 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/04/29 11:53:09.0770 2148 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/04/29 11:53:09.0780 2148 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2011/04/29 11:53:09.0791 2148 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2011/04/29 11:53:09.0816 2148 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/04/29 11:53:09.0825 2148 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/04/29 11:53:09.0840 2148 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2011/04/29 11:53:09.0853 2148 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2011/04/29 11:53:09.0874 2148 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/04/29 11:53:09.0891 2148 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/04/29 11:53:09.0908 2148 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/04/29 11:53:09.0930 2148 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/04/29 11:53:09.0939 2148 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:53:09.0948 2148 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:53:09.0983 2148 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/04/29 11:53:09.0995 2148 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/04/29 11:53:10.0024 2148 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/04/29 11:53:10.0034 2148 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/04/29 11:53:10.0085 2148 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/04/29 11:53:10.0096 2148 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/04/29 11:53:10.0126 2148 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/04/29 11:53:10.0159 2148 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2011/04/29 11:53:10.0183 2148 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/04/29 11:53:10.0276 2148 xusb21 (38f55d07b1d3391065c40ec065f984e2) C:\Windows\system32\DRIVERS\xusb21.sys
2011/04/29 11:53:10.0309 2148 ================================================================================
2011/04/29 11:53:10.0309 2148 Scan finished
2011/04/29 11:53:10.0309 2148 ================================================================================
2011/04/29 11:53:10.0315 0992 Detected object count: 1
2011/04/29 11:53:20.0542 0992 Locked file(sptd) - User select action: Skip
2011/04/29 11:54:55.0671 3576 ================================================================================
2011/04/29 11:54:55.0671 3576 Scan started
2011/04/29 11:54:55.0671 3576 Mode: Manual;
2011/04/29 11:54:55.0671 3576 ================================================================================
2011/04/29 11:54:57.0841 3576 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/04/29 11:54:57.0899 3576 6077757b (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:54:57.0943 3576 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2011/04/29 11:54:57.0971 3576 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/04/29 11:54:58.0003 3576 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/04/29 11:54:58.0058 3576 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/04/29 11:54:58.0099 3576 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/04/29 11:54:58.0143 3576 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2011/04/29 11:54:58.0174 3576 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2011/04/29 11:54:58.0216 3576 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2011/04/29 11:54:58.0256 3576 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2011/04/29 11:54:58.0287 3576 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/04/29 11:54:58.0646 3576 amdkmdag (dcc8177244fe79c61c4e73c65e63922a) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/04/29 11:54:58.0724 3576 amdkmdap (7fe67d107329dc2cf89136a8e19bceb7) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/04/29 11:54:58.0754 3576 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/04/29 11:54:58.0817 3576 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
2011/04/29 11:54:58.0852 3576 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/04/29 11:54:58.0878 3576 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
2011/04/29 11:54:58.0932 3576 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2011/04/29 11:54:58.0978 3576 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/04/29 11:54:59.0008 3576 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/04/29 11:54:59.0047 3576 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/04/29 11:54:59.0062 3576 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2011/04/29 11:54:59.0108 3576 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/04/29 11:54:59.0133 3576 AtiHdmiService (2d648572ba9a610952fcafba1e119c2d) C:\Windows\system32\drivers\AtiHdmi.sys
2011/04/29 11:54:59.0188 3576 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/04/29 11:54:59.0231 3576 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/04/29 11:54:59.0263 3576 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/04/29 11:54:59.0299 3576 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/04/29 11:54:59.0349 3576 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
2011/04/29 11:54:59.0373 3576 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/04/29 11:54:59.0411 3576 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/04/29 11:54:59.0481 3576 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/04/29 11:54:59.0531 3576 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/04/29 11:54:59.0566 3576 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/04/29 11:54:59.0583 3576 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/04/29 11:54:59.0606 3576 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/04/29 11:54:59.0647 3576 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/04/29 11:54:59.0676 3576 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2011/04/29 11:54:59.0696 3576 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/04/29 11:54:59.0741 3576 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/04/29 11:54:59.0773 3576 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/04/29 11:54:59.0796 3576 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2011/04/29 11:54:59.0867 3576 cmudaxp (3cd27b6666d0a6a71a7b6834dd5c97f7) C:\Windows\system32\drivers\cmudaxp.sys
2011/04/29 11:54:59.0908 3576 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2011/04/29 11:54:59.0958 3576 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/04/29 11:54:59.0986 3576 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/04/29 11:54:59.0997 3576 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/04/29 11:55:00.0029 3576 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2011/04/29 11:55:00.0052 3576 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2011/04/29 11:55:00.0064 3576 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/04/29 11:55:00.0092 3576 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/04/29 11:55:00.0141 3576 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/04/29 11:55:00.0191 3576 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
2011/04/29 11:55:00.0292 3576 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/04/29 11:55:00.0342 3576 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/04/29 11:55:00.0364 3576 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2011/04/29 11:55:00.0382 3576 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/04/29 11:55:00.0422 3576 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/04/29 11:55:00.0436 3576 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/04/29 11:55:00.0473 3576 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/04/29 11:55:00.0512 3576 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/04/29 11:55:00.0533 3576 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/04/29 11:55:00.0577 3576 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2011/04/29 11:55:00.0624 3576 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/04/29 11:55:00.0652 3576 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/04/29 11:55:00.0677 3576 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/04/29 11:55:00.0718 3576 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/04/29 11:55:00.0753 3576 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
2011/04/29 11:55:00.0807 3576 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/04/29 11:55:00.0912 3576 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2011/04/29 11:55:00.0961 3576 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/04/29 11:55:00.0998 3576 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/04/29 11:55:01.0039 3576 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/04/29 11:55:01.0057 3576 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/04/29 11:55:01.0116 3576 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2011/04/29 11:55:01.0142 3576 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/04/29 11:55:01.0162 3576 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2011/04/29 11:55:01.0181 3576 htcnprot (b8b1b284362e1d8135112573395d5da5) C:\Windows\system32\DRIVERS\htcnprot.sys
2011/04/29 11:55:01.0206 3576 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2011/04/29 11:55:01.0219 3576 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2011/04/29 11:55:01.0239 3576 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/04/29 11:55:01.0268 3576 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
2011/04/29 11:55:01.0298 3576 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/04/29 11:55:01.0396 3576 IntcAzAudAddService (491dadcc74327fabc85e0ab80af8f204) C:\Windows\system32\drivers\RTKVHD64.sys
2011/04/29 11:55:01.0421 3576 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2011/04/29 11:55:01.0434 3576 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/04/29 11:55:01.0481 3576 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/04/29 11:55:01.0492 3576 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/04/29 11:55:01.0503 3576 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/04/29 11:55:01.0528 3576 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/04/29 11:55:01.0537 3576 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2011/04/29 11:55:01.0609 3576 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/04/29 11:55:01.0642 3576 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/04/29 11:55:01.0699 3576 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/04/29 11:55:01.0756 3576 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2011/04/29 11:55:01.0851 3576 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2011/04/29 11:55:01.0883 3576 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/04/29 11:55:01.0913 3576 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/04/29 11:55:01.0956 3576 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/04/29 11:55:02.0026 3576 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/04/29 11:55:02.0066 3576 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/04/29 11:55:02.0114 3576 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/04/29 11:55:02.0124 3576 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/04/29 11:55:02.0149 3576 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/04/29 11:55:02.0181 3576 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/04/29 11:55:02.0207 3576 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/04/29 11:55:02.0331 3576 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/04/29 11:55:02.0347 3576 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/04/29 11:55:02.0368 3576 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/04/29 11:55:02.0433 3576 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2011/04/29 11:55:02.0478 3576 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2011/04/29 11:55:02.0517 3576 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/04/29 11:55:02.0551 3576 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2011/04/29 11:55:02.0612 3576 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/04/29 11:55:02.0649 3576 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/04/29 11:55:02.0663 3576 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/04/29 11:55:02.0712 3576 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2011/04/29 11:55:02.0764 3576 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2011/04/29 11:55:02.0814 3576 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/04/29 11:55:02.0881 3576 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/04/29 11:55:02.0911 3576 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/04/29 11:55:03.0006 3576 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/04/29 11:55:03.0053 3576 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/04/29 11:55:03.0073 3576 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/04/29 11:55:03.0103 3576 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2011/04/29 11:55:03.0136 3576 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/04/29 11:55:03.0156 3576 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/04/29 11:55:03.0181 3576 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/04/29 11:55:03.0237 3576 MTsensor (2219a3d695405e7ba2186ba6b9ede14a) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/04/29 11:55:03.0256 3576 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/04/29 11:55:03.0297 3576 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/04/29 11:55:03.0364 3576 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2011/04/29 11:55:03.0437 3576 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/04/29 11:55:03.0446 3576 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/04/29 11:55:03.0472 3576 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/04/29 11:55:03.0489 3576 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/04/29 11:55:03.0537 3576 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2011/04/29 11:55:03.0577 3576 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/04/29 11:55:03.0626 3576 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2011/04/29 11:55:03.0672 3576 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/04/29 11:55:03.0699 3576 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/04/29 11:55:03.0717 3576 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/04/29 11:55:03.0802 3576 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
2011/04/29 11:55:03.0874 3576 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/04/29 11:55:03.0917 3576 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
2011/04/29 11:55:03.0994 3576 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
2011/04/29 11:55:04.0028 3576 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/04/29 11:55:04.0128 3576 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/04/29 11:55:04.0183 3576 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/04/29 11:55:04.0204 3576 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2011/04/29 11:55:04.0233 3576 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2011/04/29 11:55:04.0263 3576 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2011/04/29 11:55:04.0288 3576 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/04/29 11:55:04.0327 3576 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/04/29 11:55:04.0377 3576 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/04/29 11:55:04.0459 3576 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2011/04/29 11:55:04.0498 3576 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/04/29 11:55:04.0538 3576 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2011/04/29 11:55:04.0592 3576 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/04/29 11:55:04.0627 3576 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/04/29 11:55:04.0651 3576 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/04/29 11:55:04.0664 3576 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/04/29 11:55:04.0689 3576 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/04/29 11:55:04.0703 3576 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/04/29 11:55:04.0717 3576 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/04/29 11:55:04.0739 3576 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/04/29 11:55:04.0782 3576 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2011/04/29 11:55:04.0792 3576 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/04/29 11:55:04.0821 3576 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/04/29 11:55:04.0846 3576 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2011/04/29 11:55:04.0857 3576 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/04/29 11:55:04.0882 3576 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/04/29 11:55:04.0897 3576 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2011/04/29 11:55:04.0932 3576 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2011/04/29 11:55:04.0973 3576 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/04/29 11:55:05.0028 3576 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/04/29 11:55:05.0078 3576 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/04/29 11:55:05.0134 3576 RTL8192su (fc00c0de6dc83de1b2b01420e2195b21) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/04/29 11:55:05.0179 3576 s0017bus (032f537623a7b2fb81aaa184c30b70c3) C:\Windows\system32\DRIVERS\s0017bus.sys
2011/04/29 11:55:05.0212 3576 s0017mdfl (9964a28e569b4ff105b446ef8978fd5c) C:\Windows\system32\DRIVERS\s0017mdfl.sys
2011/04/29 11:55:05.0233 3576 s0017mdm (06347087d274c23dcfa8c4ab5c4314db) C:\Windows\system32\DRIVERS\s0017mdm.sys
2011/04/29 11:55:05.0261 3576 s0017mgmt (f0f0747b3fa50272de6b1bf575fa4700) C:\Windows\system32\DRIVERS\s0017mgmt.sys
2011/04/29 11:55:05.0293 3576 s0017nd5 (7224412cea2ff2df7d4842c1b0e71045) C:\Windows\system32\DRIVERS\s0017nd5.sys
2011/04/29 11:55:05.0302 3576 s0017obex (3feadbc7f09b8b596cbfb82f12aba87f) C:\Windows\system32\DRIVERS\s0017obex.sys
2011/04/29 11:55:05.0313 3576 s0017unic (2b63bea31d939888b2a8f3f14d89b5c1) C:\Windows\system32\DRIVERS\s0017unic.sys
2011/04/29 11:55:05.0338 3576 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/04/29 11:55:05.0371 3576 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/04/29 11:55:05.0394 3576 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2011/04/29 11:55:05.0423 3576 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/04/29 11:55:05.0450 3576 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/04/29 11:55:05.0510 3576 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/04/29 11:55:05.0542 3576 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/04/29 11:55:05.0605 3576 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/04/29 11:55:05.0626 3576 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/04/29 11:55:05.0642 3576 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/04/29 11:55:05.0671 3576 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/04/29 11:55:05.0702 3576 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/04/29 11:55:05.0726 3576 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/04/29 11:55:05.0745 3576 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/04/29 11:55:05.0795 3576 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/04/29 11:55:06.0231 3576 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/04/29 11:55:06.0231 3576 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
2011/04/29 11:55:06.0235 3576 sptd - detected Locked file (1)
2011/04/29 11:55:06.0577 3576 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
2011/04/29 11:55:06.0616 3576 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
2011/04/29 11:55:06.0668 3576 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
2011/04/29 11:55:06.0776 3576 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/04/29 11:55:06.0841 3576 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/04/29 11:55:06.0865 3576 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2011/04/29 11:55:06.0900 3576 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2011/04/29 11:55:07.0101 3576 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2011/04/29 11:55:07.0171 3576 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2011/04/29 11:55:07.0217 3576 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/04/29 11:55:07.0276 3576 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/04/29 11:55:07.0342 3576 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/04/29 11:55:07.0376 3576 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2011/04/29 11:55:07.0386 3576 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2011/04/29 11:55:07.0425 3576 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/04/29 11:55:07.0453 3576 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2011/04/29 11:55:07.0507 3576 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/04/29 11:55:07.0543 3576 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2011/04/29 11:55:07.0590 3576 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/04/29 11:55:07.0606 3576 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2011/04/29 11:55:07.0617 3576 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/04/29 11:55:07.0655 3576 USBAAPL64 (cd03479f2da26500b203ed075c146a7a) C:\Windows\system32\Drivers\usbaapl64.sys
2011/04/29 11:55:07.0730 3576 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2011/04/29 11:55:07.0752 3576 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/04/29 11:55:07.0768 3576 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2011/04/29 11:55:07.0788 3576 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
2011/04/29 11:55:07.0811 3576 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
2011/04/29 11:55:07.0861 3576 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2011/04/29 11:55:07.0881 3576 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/04/29 11:55:07.0923 3576 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/04/29 11:55:07.0960 3576 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS
2011/04/29 11:55:07.0990 3576 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/04/29 11:55:08.0012 3576 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
2011/04/29 11:55:08.0036 3576 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/04/29 11:55:08.0056 3576 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/04/29 11:55:08.0071 3576 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/04/29 11:55:08.0097 3576 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/04/29 11:55:08.0123 3576 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2011/04/29 11:55:08.0135 3576 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2011/04/29 11:55:08.0148 3576 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/04/29 11:55:08.0165 3576 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/04/29 11:55:08.0181 3576 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2011/04/29 11:55:08.0196 3576 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2011/04/29 11:55:08.0223 3576 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/04/29 11:55:08.0235 3576 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/04/29 11:55:08.0256 3576 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/04/29 11:55:08.0282 3576 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/04/29 11:55:08.0303 3576 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:55:08.0312 3576 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/04/29 11:55:08.0346 3576 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/04/29 11:55:08.0358 3576 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/04/29 11:55:08.0398 3576 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/04/29 11:55:08.0410 3576 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/04/29 11:55:08.0465 3576 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/04/29 11:55:08.0476 3576 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/04/29 11:55:08.0513 3576 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/04/29 11:55:08.0545 3576 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2011/04/29 11:55:08.0565 3576 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/04/29 11:55:08.0688 3576 xusb21 (38f55d07b1d3391065c40ec065f984e2) C:\Windows\system32\DRIVERS\xusb21.sys
2011/04/29 11:55:08.0722 3576 ================================================================================
2011/04/29 11:55:08.0722 3576 Scan finished
2011/04/29 11:55:08.0722 3576 ================================================================================
2011/04/29 11:55:08.0728 2408 Detected object count: 1
2011/04/29 11:55:23.0902 2408 Locked file(sptd) - User select action: Skip[/spoiler]

So.

cosinus 29.04.2011 12:07

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Cloud84 29.04.2011 15:07

Combofix Logfile:
Code:

ComboFix 11-04-28.03 - User 29.04.2011  15:59:29.1.8 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.49.1031.18.6135.4431 [GMT 2:00]
ausgeführt von:: c:\users\User\Desktop\cofi.exe.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\User\AppData\Roaming\Local
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\(2).ddr
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\(3).ddr
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\.ddr
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\(2)
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\(3)
c:\users\User\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
c:\users\User\AppData\Roaming\MSA
c:\users\User\infinst.exe
c:\windows\system32\hosts
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-03-28 bis 2011-04-29  ))))))))))))))))))))))))))))))
.
.
2011-04-29 10:05 . 2011-04-29 10:05        --------        d-----w-        c:\program files (x86)\Tunatic
2011-04-27 16:24 . 2011-04-27 16:24        --------        d-----w-        C:\_OTL
2011-04-27 10:32 . 2011-02-18 06:33        31232        ----a-w-        c:\windows\system32\prevhost.exe
2011-04-27 10:32 . 2011-02-18 05:33        31232        ----a-w-        c:\windows\SysWow64\prevhost.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.21189351611425766.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.09438208857365815.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.5399563998682995.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.19771568843115184.exe
2011-04-24 15:59 . 2011-04-24 15:59        --------        d-----w-        c:\users\User\AppData\Roaming\Malwarebytes
2011-04-24 15:58 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-24 15:58 . 2010-12-20 16:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.3177135607912589.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.7264726497121414.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.019164675131827957.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.17757153460061625.exe
2011-04-22 12:44 . 2011-04-22 12:44        --------        d-----w-        C:\files
2011-04-14 18:31 . 2011-02-24 06:30        476160        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2011-04-14 18:31 . 2011-02-24 05:32        288256        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2011-04-14 18:29 . 2011-03-03 06:17        182272        ----a-w-        c:\windows\system32\dnsrslvr.dll
2011-04-12 13:26 . 2011-04-12 13:26        --------        d-----w-        c:\program files\SD EnterNET
2011-04-12 13:26 . 2005-11-13 21:19        65024        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-04-11 18:21 . 2011-04-11 18:21        --------        d-----w-        c:\users\User\AppData\Local\Urgesoft
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\users\User\AppData\Local\Jaksta_Technologies_Pty_L
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\programdata\Applian
2011-04-10 20:28 . 2011-04-10 20:28        --------        d-----w-        c:\windows\Applian Director
2011-04-05 18:00 . 2011-04-13 15:07        --------        d-----w-        c:\program files (x86)\Metin2
2011-04-01 21:29 . 2011-04-17 14:22        --------        d-----w-        c:\program files (x86)\DVDVideoSoft
2011-04-01 12:33 . 2011-04-01 12:33        --------        d-----w-        c:\program files (x86)\Cisco
2011-04-01 12:32 . 2010-02-26 10:37        676864        ----a-r-        c:\windows\system32\drivers\rtl8192su.sys
2011-04-01 12:32 . 2010-02-26 10:37        188416        ------r-        c:\windows\RTLExtUI.dll
2011-04-01 12:32 . 2010-02-26 10:37        614400        ------r-        c:\windows\system32\Rtlihvs.dll
2011-04-01 12:32 . 2010-02-26 10:37        614400        ------r-        c:\windows\Rtlihvs.dll
2011-04-01 12:32 . 2010-02-26 10:37        380928        ------r-        c:\windows\RtlUI2.exe
2011-04-01 12:32 . 2010-02-26 10:37        380928        ------r-        c:\windows\system32\RtlUI2.exe
2011-04-01 12:32 . 2010-02-26 10:37        188416        ------r-        c:\windows\system32\RTLExtUI.dll
2011-04-01 12:32 . 2011-04-01 12:32        --------        d-----w-        c:\program files (x86)\Edimax
2011-03-31 17:55 . 2011-03-31 17:55        --------        d-----w-        c:\program files (x86)\Microsoft Works
2011-03-31 17:52 . 2011-03-31 17:52        --------        d-----w-        c:\windows\PCHEALTH
2011-03-30 15:45 . 2011-03-30 15:45        --------        d-----w-        c:\users\User\AppData\Roaming\avidemux
2011-03-30 15:43 . 2011-03-30 15:43        --------        d-----w-        c:\program files (x86)\Xvid
2011-03-30 15:43 . 2009-06-07 14:25        77824        ----a-w-        c:\windows\SysWow64\xvid.ax
2011-03-30 15:43 . 2009-06-07 14:24        180224        ----a-w-        c:\windows\SysWow64\xvidvfw.dll
2011-03-30 15:43 . 2009-06-07 14:16        819200        ----a-w-        c:\windows\SysWow64\xvidcore.dll
2011-03-30 15:30 . 2011-03-30 15:37        --------        d-----w-        c:\users\User\AppData\Roaming\Cuttermaran
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 06:17 . 2011-04-27 10:33        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:17 . 2011-04-27 10:33        347648        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-02-19 06:37 . 2011-03-09 09:56        1135104        ----a-w-        c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 09:56        1540608        ----a-w-        c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 09:56        902656        ----a-w-        c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 09:56        1074176        ----a-w-        c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 09:56        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll
2011-02-18 20:50 . 2011-02-18 20:50        22295040        ----a-w-        c:\windows\system32\atio6axx.dll
2011-02-18 20:50 . 2011-02-18 20:50        38400        ----a-w-        c:\windows\system32\atiu9p64.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atig6txx.dll
2011-02-18 20:50 . 2011-02-18 20:50        4847616        ----a-w-        c:\windows\system32\atidxx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\ATIODCLI.exe
2011-02-18 20:50 . 2011-02-18 20:50        17204736        ----a-w-        c:\windows\SysWow64\atioglxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        423424        ----a-w-        c:\windows\system32\atipdl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        1912832        ----a-w-        c:\windows\SysWow64\atiumdmv.dll
2011-02-18 20:50 . 2011-02-18 20:50        9085952        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-02-18 20:50 . 2011-02-18 20:50        44032        ----a-w-        c:\windows\SysWow64\aticalcl.dll
2011-02-18 20:50 . 2011-02-18 20:50        3222016        ----a-w-        c:\windows\system32\atiumd6a.dll
2011-02-18 20:50 . 2011-02-18 20:50        46080        ----a-w-        c:\windows\SysWow64\aticalrt.dll
2011-02-18 20:50 . 2010-07-07 01:54        596480        ----a-w-        c:\windows\SysWow64\aticfx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\atimpc32.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\amdpcom32.dll
2011-02-18 20:50 . 2011-02-18 20:50        43520        ----a-w-        c:\windows\SysWow64\ati2edxx.dll
2011-02-18 20:50 . 2010-04-07 01:40        4170752        ----a-w-        c:\windows\SysWow64\atiumdag.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\atimpc64.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\amdpcom64.dll
2011-02-18 20:50 . 2011-02-18 20:50        278528        ----a-w-        c:\windows\SysWow64\Oemdspif.dll
2011-02-18 20:50 . 2011-02-18 20:50        115216        ----a-w-        c:\windows\system32\drivers\AtihdW76.sys
2011-02-18 20:50 . 2011-02-18 20:50        462848        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-02-18 20:50 . 2011-02-18 20:50        479232        ----a-w-        c:\windows\system32\atieclxx.exe
2011-02-18 20:50 . 2010-09-23 16:39        58880        ----a-w-        c:\windows\system32\coinst.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atiuxp64.dll
2011-02-18 20:50 . 2011-02-18 20:50        299520        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-02-18 20:50 . 2011-02-18 20:50        5316096        ----a-w-        c:\windows\system32\atiumd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        6982144        ----a-w-        c:\windows\system32\aticaldd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        30720        ----a-w-        c:\windows\SysWow64\atiuxpag.dll
2011-02-18 20:50 . 2011-02-18 20:50        5580800        ----a-w-        c:\windows\SysWow64\aticaldd.dll
2011-02-18 20:50 . 2011-02-18 20:50        332800        ----a-w-        c:\windows\system32\ATIODE.exe
2011-02-18 20:50 . 2011-02-18 20:50        14848        ----a-w-        c:\windows\system32\atig6pxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        143360        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-02-18 20:50 . 2011-02-18 20:50        356352        ----a-w-        c:\windows\SysWow64\atipdlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        203776        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-02-18 20:50 . 2010-04-07 01:21        3463680        ----a-w-        c:\windows\SysWow64\atiumdva.dll
2011-02-18 20:50 . 2011-02-18 20:50        249856        ----a-w-        c:\windows\SysWow64\atiadlxy.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\aticalrt64.dll
2011-02-18 20:50 . 2011-02-18 20:50        32768        ----a-w-        c:\windows\SysWow64\atigktxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        16384        ----a-w-        c:\windows\system32\atimuixx.dll
2011-02-18 20:50 . 2011-02-18 20:50        708608        ----a-w-        c:\windows\system32\aticfx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        44544        ----a-w-        c:\windows\system32\aticalcl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        354304        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        1208320        ----a-w-        c:\windows\system32\atiumd6v.dll
2011-02-18 20:50 . 2011-02-18 20:50        4105728        ----a-w-        c:\windows\SysWow64\atidxx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        120320        ----a-w-        c:\windows\system32\atitmm64.dll
2011-02-18 20:50 . 2011-02-18 20:50        59392        ----a-w-        c:\windows\system32\atiedu64.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\SysWow64\atiglpxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-02-18 20:50 . 2010-04-07 01:22        28672        ----a-w-        c:\windows\SysWow64\atiu9pag.dll
2011-02-11 07:30 . 2011-03-18 11:37        7947600        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE269F37-198C-4267-91F0-BA9282130E30}\mpengine.dll
2011-02-04 21:12 . 2011-02-04 21:12        419840        ----a-w-        c:\windows\system32\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        413696        ----a-w-        c:\windows\SysWow64\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        111616        ----a-w-        c:\windows\system32\OpenAL32.dll
2011-02-04 21:12 . 2011-02-04 21:12        102400        ----a-w-        c:\windows\SysWow64\OpenAL32.dll
2011-02-02 16:11 . 2010-09-18 16:35        270720        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-02-18 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ugrllhsluukjoafhzxbuTaskMgr"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [x]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 X6va003;X6va003;c:\users\User\AppData\Local\Temp\0039253.tmp [x]
R3 X6va005;X6va005;c:\users\User\AppData\Local\Temp\005A835.tmp [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 6077757b;6077757b;c:\windows\system32\drivers\regi.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 Realtek11nSU;Realtek11nSU;c:\program files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-13 415752]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-13 4195848]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296]
"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2010-09-16 8761344]
"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - c:\users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: die-staemme.de\de71
TCP: {CBBC9FEA-46B8-41DF-909C-5566F8219919} = 192.168.2.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wwjhbt5a.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Flash and Video Download: {bee6eb20-01e0-ebd1-da83-080329fb9a3a} - %profile%\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - Ext: DivX Plus Web Player HTML5 &lt;video&gt;: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\wpa
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{33b974a8-e892-4f5f-bd17-f7b0331843d5} - (no file)
WebBrowser-{33B974A8-E892-4F5F-BD17-F7B0331843D5} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va003]
"ImagePath"="\??\c:\users\User\AppData\Local\Temp\0039253.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va005]
"ImagePath"="\??\c:\users\User\AppData\Local\Temp\005A835.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Edimax\11n USB Wireless LAN Utility\RtWlan.exe
c:\program files\ASUS Xonar DX Audio\Customapp\ASUSAUDIOCENTER.EXE
c:\program files (x86)\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-04-29  16:05:07 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-04-29 14:05
.
Vor Suchlauf: 11 Verzeichnis(se), 106.482.020.352 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 106.973.278.208 Bytes frei
.
- - End Of File - - 4796962A0819B9428CA55844B3104696

--- --- ---

cosinus 29.04.2011 20:36

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.21189351611425766.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.09438208857365815.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.5399563998682995.exe
2011-04-25 22:17 . 2011-04-25 22:17        311296        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.19771568843115184.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.3177135607912589.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.7264726497121414.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.019164675131827957.exe
2011-04-24 14:49 . 2011-04-24 14:49        569344        ----a-w-        c:\program files (x86)\Mozilla Firefox\null0.17757153460061625.exe
2011-04-22 12:44 . 2011-04-22 12:44        --------        d-----w-        C:\files
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Cloud84 30.04.2011 00:07

All processes killed
========== OTL ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: AppData
->Temp folder emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: User
->Temp folder emptied: 2792 bytes
->Temporary Internet Files folder emptied: 1502454 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 88396645 bytes
->Flash cache emptied: 1145 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32768 bytes
RecycleBin emptied: 996467304 bytes

Total Files Cleaned = 1.036,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04302011_005709

Files\Folders moved on Reboot...
C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

cosinus 30.04.2011 02:43

Sry hatte einen kleinen Blackout :crazy:

Mach den Fix bitte nochmal aber mit diesem Script:

Code:

:OTL
c:\program files (x86)\Mozilla Firefox\null0.21189351611425766.exe
c:\program files (x86)\Mozilla Firefox\null0.09438208857365815.exe
c:\program files (x86)\Mozilla Firefox\null0.5399563998682995.exe
c:\program files (x86)\Mozilla Firefox\null0.19771568843115184.exe
c:\program files (x86)\Mozilla Firefox\null0.3177135607912589.exe
c:\program files (x86)\Mozilla Firefox\null0.7264726497121414.exe
c:\program files (x86)\Mozilla Firefox\null0.019164675131827957.exe
c:\program files (x86)\Mozilla Firefox\null0.17757153460061625.exe
C:\files
:Commands
[purity]
[resethosts]
[emptytemp]


Cloud84 30.04.2011 16:33

All processes killed
========== OTL ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: AppData
->Temp folder emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1516470 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 91335393 bytes
->Flash cache emptied: 1671 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 89,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04302011_172625

Files\Folders moved on Reboot...
C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

cosinus 01.05.2011 13:49

Sry irgendwie hab ich es bei dir mti dem Script, da war schon wieder ein Fehler drin :headbang:
Mach es bitte nochmal mit diesem jetzt endlich korrektem Script:



Zitat:

:Files
c:\program files (x86)\Mozilla Firefox\null0.21189351611425766.exe
c:\program files (x86)\Mozilla Firefox\null0.09438208857365815.exe
c:\program files (x86)\Mozilla Firefox\null0.5399563998682995.exe
c:\program files (x86)\Mozilla Firefox\null0.19771568843115184.exe
c:\program files (x86)\Mozilla Firefox\null0.3177135607912589.exe
c:\program files (x86)\Mozilla Firefox\null0.7264726497121414.exe
c:\program files (x86)\Mozilla Firefox\null0.019164675131827957.exe
c:\program files (x86)\Mozilla Firefox\null0.17757153460061625.exe
C:\files
:Commands
[purity]
[resethosts]
[emptytemp]

Cloud84 01.05.2011 15:03

All processes killed
========== FILES ==========
c:\program files (x86)\Mozilla Firefox\null0.21189351611425766.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.09438208857365815.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.5399563998682995.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.19771568843115184.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.3177135607912589.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.7264726497121414.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.019164675131827957.exe moved successfully.
c:\program files (x86)\Mozilla Firefox\null0.17757153460061625.exe moved successfully.
C:\files folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: AppData
->Temp folder emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 65670 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 45021563 bytes
->Flash cache emptied: 521 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 43,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05012011_155949

Files\Folders moved on Reboot...
C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

cosinus 01.05.2011 15:26

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

cosinus 01.05.2011 18:50

Log ist unvollstöndig!

Cloud84 01.05.2011 20:00

2011/05/01 17:53:42.0856 4588 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/05/01 17:53:43.0011 4588 ================================================================================
2011/05/01 17:53:43.0011 4588 SystemInfo:
2011/05/01 17:53:43.0011 4588
2011/05/01 17:53:43.0011 4588 OS Version: 6.1.7600 ServicePack: 0.0
2011/05/01 17:53:43.0011 4588 Product type: Workstation
2011/05/01 17:53:43.0011 4588 ComputerName: USER-PC
2011/05/01 17:53:43.0011 4588 UserName: User
2011/05/01 17:53:43.0011 4588 Windows directory: C:\Windows
2011/05/01 17:53:43.0011 4588 System windows directory: C:\Windows
2011/05/01 17:53:43.0011 4588 Running under WOW64
2011/05/01 17:53:43.0011 4588 Processor architecture: Intel x64
2011/05/01 17:53:43.0011 4588 Number of processors: 8
2011/05/01 17:53:43.0011 4588 Page size: 0x1000
2011/05/01 17:53:43.0011 4588 Boot type: Normal boot
2011/05/01 17:53:43.0011 4588 ================================================================================
2011/05/01 17:53:43.0261 4588 Initialize success
2011/05/01 17:53:45.0031 4384 ================================================================================
2011/05/01 17:53:45.0031 4384 Scan started
2011/05/01 17:53:45.0031 4384 Mode: Manual;
2011/05/01 17:53:45.0031 4384 ================================================================================
2011/05/01 17:53:45.0831 4384 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/05/01 17:53:45.0865 4384 6077757b (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/05/01 17:53:45.0882 4384 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2011/05/01 17:53:45.0902 4384 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/05/01 17:53:45.0926 4384 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/05/01 17:53:45.0950 4384 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/05/01 17:53:45.0968 4384 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/05/01 17:53:46.0006 4384 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2011/05/01 17:53:46.0023 4384 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2011/05/01 17:53:46.0047 4384 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2011/05/01 17:53:46.0065 4384 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2011/05/01 17:53:46.0082 4384 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/05/01 17:53:46.0196 4384 amdkmdag (dcc8177244fe79c61c4e73c65e63922a) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/05/01 17:53:46.0242 4384 amdkmdap (7fe67d107329dc2cf89136a8e19bceb7) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/05/01 17:53:46.0263 4384 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/05/01 17:53:46.0293 4384 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
2011/05/01 17:53:46.0311 4384 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/05/01 17:53:46.0330 4384 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
2011/05/01 17:53:46.0350 4384 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2011/05/01 17:53:46.0388 4384 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/05/01 17:53:46.0397 4384 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/05/01 17:53:46.0413 4384 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/01 17:53:46.0430 4384 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2011/05/01 17:53:46.0451 4384 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/05/01 17:53:46.0477 4384 AtiHdmiService (2d648572ba9a610952fcafba1e119c2d) C:\Windows\system32\drivers\AtiHdmi.sys
2011/05/01 17:53:46.0512 4384 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/05/01 17:53:46.0540 4384 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/05/01 17:53:46.0573 4384 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/05/01 17:53:46.0610 4384 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/05/01 17:53:46.0642 4384 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/01 17:53:46.0658 4384 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/05/01 17:53:46.0671 4384 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/05/01 17:53:46.0693 4384 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/05/01 17:53:46.0702 4384 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/05/01 17:53:46.0716 4384 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/05/01 17:53:46.0725 4384 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/05/01 17:53:46.0735 4384 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/05/01 17:53:46.0791 4384 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/01 17:53:46.0811 4384 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/01 17:53:46.0832 4384 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/05/01 17:53:46.0868 4384 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/05/01 17:53:46.0891 4384 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/01 17:53:46.0901 4384 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2011/05/01 17:53:46.0947 4384 cmudaxp (3cd27b6666d0a6a71a7b6834dd5c97f7) C:\Windows\system32\drivers\cmudaxp.sys
2011/05/01 17:53:46.0965 4384 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2011/05/01 17:53:46.0986 4384 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/01 17:53:47.0003 4384 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/05/01 17:53:47.0016 4384 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/05/01 17:53:47.0050 4384 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2011/05/01 17:53:47.0070 4384 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2011/05/01 17:53:47.0082 4384 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/05/01 17:53:47.0092 4384 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/05/01 17:53:47.0127 4384 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/05/01 17:53:47.0167 4384 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/01 17:53:47.0232 4384 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/05/01 17:53:47.0276 4384 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/05/01 17:53:47.0293 4384 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2011/05/01 17:53:47.0310 4384 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/05/01 17:53:47.0337 4384 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/05/01 17:53:47.0357 4384 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/01 17:53:47.0373 4384 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/05/01 17:53:47.0391 4384 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/05/01 17:53:47.0400 4384 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/01 17:53:47.0413 4384 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2011/05/01 17:53:47.0437 4384 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/05/01 17:53:47.0456 4384 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/01 17:53:47.0475 4384 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/05/01 17:53:47.0483 4384 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/05/01 17:53:47.0523 4384 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
2011/05/01 17:53:47.0543 4384 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/05/01 17:53:47.0571 4384 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2011/05/01 17:53:47.0581 4384 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/01 17:53:47.0591 4384 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/05/01 17:53:47.0621 4384 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/05/01 17:53:47.0628 4384 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/05/01 17:53:47.0655 4384 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/01 17:53:47.0681 4384 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/05/01 17:53:47.0717 4384 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2011/05/01 17:53:47.0745 4384 htcnprot (b8b1b284362e1d8135112573395d5da5) C:\Windows\system32\DRIVERS\htcnprot.sys
2011/05/01 17:53:47.0768 4384 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2011/05/01 17:53:47.0783 4384 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2011/05/01 17:53:47.0803 4384 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/01 17:53:47.0832 4384 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
2011/05/01 17:53:47.0853 4384 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/05/01 17:53:47.0901 4384 IntcAzAudAddService (491dadcc74327fabc85e0ab80af8f204) C:\Windows\system32\drivers\RTKVHD64.sys
2011/05/01 17:53:47.0917 4384 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2011/05/01 17:53:47.0936 4384 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/01 17:53:47.0956 4384 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/01 17:53:47.0967 4384 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/05/01 17:53:47.0977 4384 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/05/01 17:53:48.0001 4384 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/05/01 17:53:48.0010 4384 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2011/05/01 17:53:48.0041 4384 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/01 17:53:48.0057 4384 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/01 17:53:48.0072 4384 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/01 17:53:48.0103 4384 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/01 17:53:48.0122 4384 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2011/05/01 17:53:48.0140 4384 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/05/01 17:53:48.0171 4384 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/01 17:53:48.0195 4384 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/05/01 17:53:48.0217 4384 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/05/01 17:53:48.0231 4384 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/05/01 17:53:48.0247 4384 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/05/01 17:53:48.0256 4384 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/05/01 17:53:48.0282 4384 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/05/01 17:53:48.0305 4384 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/05/01 17:53:48.0322 4384 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/05/01 17:53:48.0346 4384 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/01 17:53:48.0355 4384 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/01 17:53:48.0377 4384 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/01 17:53:48.0385 4384 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2011/05/01 17:53:48.0408 4384 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2011/05/01 17:53:48.0426 4384 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/01 17:53:48.0451 4384 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2011/05/01 17:53:48.0496 4384 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/01 17:53:48.0517 4384 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/01 17:53:48.0538 4384 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/01 17:53:48.0553 4384 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2011/05/01 17:53:48.0573 4384 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2011/05/01 17:53:48.0600 4384 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/05/01 17:53:48.0616 4384 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/05/01 17:53:48.0623 4384 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/05/01 17:53:48.0657 4384 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/01 17:53:48.0671 4384 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/01 17:53:48.0680 4384 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/05/01 17:53:48.0703 4384 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2011/05/01 17:53:48.0715 4384 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/01 17:53:48.0725 4384 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/05/01 17:53:48.0741 4384 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/05/01 17:53:48.0763 4384 MTsensor (2219a3d695405e7ba2186ba6b9ede14a) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/05/01 17:53:48.0772 4384 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/05/01 17:53:48.0808 4384 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/01 17:53:48.0835 4384 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2011/05/01 17:53:48.0856 4384 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/05/01 17:53:48.0865 4384 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/01 17:53:48.0883 4384 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/01 17:53:48.0901 4384 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/01 17:53:48.0913 4384 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2011/05/01 17:53:48.0933 4384 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/01 17:53:48.0953 4384 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/01 17:53:48.0985 4384 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/05/01 17:53:49.0007 4384 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/05/01 17:53:49.0021 4384 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/01 17:53:49.0080 4384 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
2011/05/01 17:53:49.0111 4384 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/05/01 17:53:49.0138 4384 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
2011/05/01 17:53:49.0157 4384 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
2011/05/01 17:53:49.0173 4384 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/05/01 17:53:49.0191 4384 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/01 17:53:49.0230 4384 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/05/01 17:53:49.0238 4384 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2011/05/01 17:53:49.0271 4384 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2011/05/01 17:53:49.0280 4384 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2011/05/01 17:53:49.0301 4384 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/05/01 17:53:49.0320 4384 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/05/01 17:53:49.0348 4384 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/05/01 17:53:49.0406 4384 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/01 17:53:49.0415 4384 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/05/01 17:53:49.0431 4384 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/01 17:53:49.0465 4384 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/05/01 17:53:49.0498 4384 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/05/01 17:53:49.0522 4384 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/01 17:53:49.0537 4384 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/01 17:53:49.0562 4384 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/05/01 17:53:49.0573 4384 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/01 17:53:49.0586 4384 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/01 17:53:49.0596 4384 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/01 17:53:49.0612 4384 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/01 17:53:49.0622 4384 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/05/01 17:53:49.0635 4384 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/01 17:53:49.0651 4384 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2011/05/01 17:53:49.0661 4384 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/01 17:53:49.0673 4384 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/05/01 17:53:49.0685 4384 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2011/05/01 17:53:49.0712 4384 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2011/05/01 17:53:49.0762 4384 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
2011/05/01 17:53:49.0801 4384 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/01 17:53:49.0833 4384 RTL8167 (4b42bc58294e83a6a92ec8b88c14c4a3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/05/01 17:53:49.0860 4384 RTL8192su (fc00c0de6dc83de1b2b01420e2195b21) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/05/01 17:53:49.0895 4384 s0017bus (032f537623a7b2fb81aaa184c30b70c3) C:\Windows\system32\DRIVERS\s0017bus.sys
2011/05/01 17:53:49.0918 4384 s0017mdfl (9964a28e569b4ff105b446ef8978fd5c) C:\Windows\system32\DRIVERS\s0017mdfl.sys
2011/05/01 17:53:49.0940 4384 s0017mdm (06347087d274c23dcfa8c4ab5c4314db) C:\Windows\system32\DRIVERS\s0017mdm.sys
2011/05/01 17:53:49.0966 4384 s0017mgmt (f0f0747b3fa50272de6b1bf575fa4700) C:\Windows\system32\DRIVERS\s0017mgmt.sys
2011/05/01 17:53:49.0990 4384 s0017nd5 (7224412cea2ff2df7d4842c1b0e71045) C:\Windows\system32\DRIVERS\s0017nd5.sys
2011/05/01 17:53:50.0000 4384 s0017obex (3feadbc7f09b8b596cbfb82f12aba87f) C:\Windows\system32\DRIVERS\s0017obex.sys
2011/05/01 17:53:50.0012 4384 s0017unic (2b63bea31d939888b2a8f3f14d89b5c1) C:\Windows\system32\DRIVERS\s0017unic.sys
2011/05/01 17:53:50.0027 4384 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/05/01 17:53:50.0047 4384 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/05/01 17:53:50.0066 4384 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2011/05/01 17:53:50.0128 4384 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/05/01 17:53:50.0170 4384 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/05/01 17:53:50.0191 4384 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/05/01 17:53:50.0200 4384 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/05/01 17:53:50.0236 4384 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/05/01 17:53:50.0256 4384 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/05/01 17:53:50.0265 4384 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/05/01 17:53:50.0285 4384 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/05/01 17:53:50.0307 4384 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/05/01 17:53:50.0323 4384 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/05/01 17:53:50.0342 4384 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/05/01 17:53:50.0371 4384 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/05/01 17:53:50.0415 4384 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/05/01 17:53:50.0415 4384 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
2011/05/01 17:53:50.0417 4384 sptd - detected Locked file (1)
2011/05/01 17:53:50.0456 4384 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
2011/05/01 17:53:50.0480 4384 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/01 17:53:50.0512 4384 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/01 17:53:50.0561 4384 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/05/01 17:53:50.0572 4384 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/05/01 17:53:50.0586 4384 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2011/05/01 17:53:50.0596 4384 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/01 17:53:50.0661 4384 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2011/05/01 17:53:50.0693 4384 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/01 17:53:50.0721 4384 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/01 17:53:50.0738 4384 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/05/01 17:53:50.0747 4384 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/05/01 17:53:50.0763 4384 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/01 17:53:50.0772 4384 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/01 17:53:50.0807 4384 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/01 17:53:50.0822 4384 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/01 17:53:50.0836 4384 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/05/01 17:53:50.0856 4384 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/01 17:53:50.0886 4384 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/05/01 17:53:50.0896 4384 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/01 17:53:50.0905 4384 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/05/01 17:53:50.0942 4384 USBAAPL64 (cd03479f2da26500b203ed075c146a7a) C:\Windows\system32\Drivers\usbaapl64.sys
2011/05/01 17:53:50.0968 4384 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2011/05/01 17:53:50.0990 4384 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/01 17:53:50.0998 4384 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2011/05/01 17:53:51.0017 4384 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/01 17:53:51.0031 4384 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/01 17:53:51.0056 4384 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2011/05/01 17:53:51.0070 4384 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/01 17:53:51.0096 4384 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2011/05/01 17:53:51.0120 4384 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS
2011/05/01 17:53:51.0137 4384 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/01 17:53:51.0167 4384 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
2011/05/01 17:53:51.0191 4384 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/05/01 17:53:51.0210 4384 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/01 17:53:51.0218 4384 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/05/01 17:53:51.0245 4384 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/05/01 17:53:51.0253 4384 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2011/05/01 17:53:51.0265 4384 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2011/05/01 17:53:51.0278 4384 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/05/01 17:53:51.0288 4384 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/05/01 17:53:51.0300 4384 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2011/05/01 17:53:51.0312 4384 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2011/05/01 17:53:51.0328 4384 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/05/01 17:53:51.0341 4384 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/05/01 17:53:51.0368 4384 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/05/01 17:53:51.0392 4384 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/05/01 17:53:51.0401 4384 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/01 17:53:51.0410 4384 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/01 17:53:51.0443 4384 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/05/01 17:53:51.0456 4384 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/01 17:53:51.0483 4384 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/05/01 17:53:51.0493 4384 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/05/01 17:53:51.0546 4384 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/05/01 17:53:51.0556 4384 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/01 17:53:51.0588 4384 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/01 17:53:51.0633 4384 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2011/05/01 17:53:51.0652 4384 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/01 17:53:51.0785 4384 xusb21 (38f55d07b1d3391065c40ec065f984e2) C:\Windows\system32\DRIVERS\xusb21.sys
2011/05/01 17:53:51.0827 4384 ================================================================================
2011/05/01 17:53:51.0827 4384 Scan finished
2011/05/01 17:53:51.0827 4384 ================================================================================
2011/05/01 17:53:51.0833 4812 Detected object count: 1
2011/05/01 17:53:55.0558 4812 Locked file(sptd) - User select action: Skip
2011/05/01 17:54:56.0487 4940 Deinitialize success

cosinus 02.05.2011 11:04

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Cloud84 02.05.2011 19:55

Combofix Logfile:
Code:

ComboFix 11-05-01.04 - User 02.05.2011  16:05:47.3.8 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.49.1031.18.6135.4784 [GMT 2:00]
ausgeführt von:: c:\users\User\Desktop\cofi.exe.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-02 bis 2011-05-02  ))))))))))))))))))))))))))))))
.
.
2011-05-02 14:07 . 2011-05-02 14:07        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-05-02 13:38 . 2011-05-02 13:38        --------        d-----w-        c:\users\User\AppData\Local\The Lord of the Rings Online
2011-05-01 20:07 . 2011-05-02 13:17        --------        d-----w-        c:\users\User\AppData\Local\Turbine
2011-05-01 20:07 . 2011-05-02 13:53        --------        d-----w-        c:\users\User\AppData\Local\ApplicationHistory
2011-05-01 20:06 . 2011-05-01 20:06        --------        d-----w-        c:\windows\SysWow64\URTTEMP
2011-05-01 19:42 . 2011-05-01 19:42        --------        d-----w-        c:\program files (x86)\Codemasters
2011-05-01 15:49 . 2011-05-02 14:07        --------        d-----w-        c:\users\User\AppData\Local\PMB Files
2011-05-01 15:49 . 2011-05-01 15:56        --------        d-----w-        c:\programdata\PMB Files
2011-04-29 10:05 . 2011-04-29 10:05        --------        d-----w-        c:\program files (x86)\Tunatic
2011-04-27 16:24 . 2011-04-27 16:24        --------        d-----w-        C:\_OTL
2011-04-27 10:32 . 2011-02-18 06:33        31232        ----a-w-        c:\windows\system32\prevhost.exe
2011-04-27 10:32 . 2011-02-18 05:33        31232        ----a-w-        c:\windows\SysWow64\prevhost.exe
2011-04-24 15:59 . 2011-04-24 15:59        --------        d-----w-        c:\users\User\AppData\Roaming\Malwarebytes
2011-04-24 15:58 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-24 15:58 . 2010-12-20 16:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-04-14 18:31 . 2011-02-24 06:30        476160        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2011-04-14 18:31 . 2011-02-24 05:32        288256        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2011-04-14 18:29 . 2011-03-03 06:17        182272        ----a-w-        c:\windows\system32\dnsrslvr.dll
2011-04-12 13:26 . 2011-04-12 13:26        --------        d-----w-        c:\program files\SD EnterNET
2011-04-12 13:26 . 2005-11-13 21:19        65024        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-04-11 18:21 . 2011-04-11 18:21        --------        d-----w-        c:\users\User\AppData\Local\Urgesoft
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\users\User\AppData\Local\Jaksta_Technologies_Pty_L
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\programdata\Applian
2011-04-10 20:28 . 2011-04-10 20:28        --------        d-----w-        c:\windows\Applian Director
2011-04-05 18:00 . 2011-04-13 15:07        --------        d-----w-        c:\program files (x86)\Metin2
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 06:17 . 2011-04-27 10:33        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:17 . 2011-04-27 10:33        347648        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-02-19 06:37 . 2011-03-09 09:56        1135104        ----a-w-        c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 09:56        1540608        ----a-w-        c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 09:56        902656        ----a-w-        c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 09:56        1074176        ----a-w-        c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 09:56        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll
2011-02-18 20:50 . 2011-02-18 20:50        22295040        ----a-w-        c:\windows\system32\atio6axx.dll
2011-02-18 20:50 . 2011-02-18 20:50        38400        ----a-w-        c:\windows\system32\atiu9p64.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atig6txx.dll
2011-02-18 20:50 . 2011-02-18 20:50        4847616        ----a-w-        c:\windows\system32\atidxx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\ATIODCLI.exe
2011-02-18 20:50 . 2011-02-18 20:50        17204736        ----a-w-        c:\windows\SysWow64\atioglxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        423424        ----a-w-        c:\windows\system32\atipdl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        1912832        ----a-w-        c:\windows\SysWow64\atiumdmv.dll
2011-02-18 20:50 . 2011-02-18 20:50        9085952        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-02-18 20:50 . 2011-02-18 20:50        44032        ----a-w-        c:\windows\SysWow64\aticalcl.dll
2011-02-18 20:50 . 2011-02-18 20:50        3222016        ----a-w-        c:\windows\system32\atiumd6a.dll
2011-02-18 20:50 . 2011-02-18 20:50        46080        ----a-w-        c:\windows\SysWow64\aticalrt.dll
2011-02-18 20:50 . 2010-07-07 01:54        596480        ----a-w-        c:\windows\SysWow64\aticfx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\atimpc32.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\amdpcom32.dll
2011-02-18 20:50 . 2011-02-18 20:50        43520        ----a-w-        c:\windows\SysWow64\ati2edxx.dll
2011-02-18 20:50 . 2010-04-07 01:40        4170752        ----a-w-        c:\windows\SysWow64\atiumdag.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\atimpc64.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\amdpcom64.dll
2011-02-18 20:50 . 2011-02-18 20:50        278528        ----a-w-        c:\windows\SysWow64\Oemdspif.dll
2011-02-18 20:50 . 2011-02-18 20:50        115216        ----a-w-        c:\windows\system32\drivers\AtihdW76.sys
2011-02-18 20:50 . 2011-02-18 20:50        462848        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-02-18 20:50 . 2011-02-18 20:50        479232        ----a-w-        c:\windows\system32\atieclxx.exe
2011-02-18 20:50 . 2010-09-23 16:39        58880        ----a-w-        c:\windows\system32\coinst.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atiuxp64.dll
2011-02-18 20:50 . 2011-02-18 20:50        299520        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-02-18 20:50 . 2011-02-18 20:50        5316096        ----a-w-        c:\windows\system32\atiumd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        6982144        ----a-w-        c:\windows\system32\aticaldd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        30720        ----a-w-        c:\windows\SysWow64\atiuxpag.dll
2011-02-18 20:50 . 2011-02-18 20:50        5580800        ----a-w-        c:\windows\SysWow64\aticaldd.dll
2011-02-18 20:50 . 2011-02-18 20:50        332800        ----a-w-        c:\windows\system32\ATIODE.exe
2011-02-18 20:50 . 2011-02-18 20:50        14848        ----a-w-        c:\windows\system32\atig6pxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        143360        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-02-18 20:50 . 2011-02-18 20:50        356352        ----a-w-        c:\windows\SysWow64\atipdlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        203776        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-02-18 20:50 . 2010-04-07 01:21        3463680        ----a-w-        c:\windows\SysWow64\atiumdva.dll
2011-02-18 20:50 . 2011-02-18 20:50        249856        ----a-w-        c:\windows\SysWow64\atiadlxy.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\aticalrt64.dll
2011-02-18 20:50 . 2011-02-18 20:50        32768        ----a-w-        c:\windows\SysWow64\atigktxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        16384        ----a-w-        c:\windows\system32\atimuixx.dll
2011-02-18 20:50 . 2011-02-18 20:50        708608        ----a-w-        c:\windows\system32\aticfx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        44544        ----a-w-        c:\windows\system32\aticalcl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        354304        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        1208320        ----a-w-        c:\windows\system32\atiumd6v.dll
2011-02-18 20:50 . 2011-02-18 20:50        4105728        ----a-w-        c:\windows\SysWow64\atidxx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        120320        ----a-w-        c:\windows\system32\atitmm64.dll
2011-02-18 20:50 . 2011-02-18 20:50        59392        ----a-w-        c:\windows\system32\atiedu64.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\SysWow64\atiglpxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-02-18 20:50 . 2010-04-07 01:22        28672        ----a-w-        c:\windows\SysWow64\atiu9pag.dll
2011-02-11 07:30 . 2011-03-18 11:37        7947600        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE269F37-198C-4267-91F0-BA9282130E30}\mpengine.dll
2011-02-04 21:12 . 2011-02-04 21:12        419840        ----a-w-        c:\windows\system32\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        413696        ----a-w-        c:\windows\SysWow64\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        111616        ----a-w-        c:\windows\system32\OpenAL32.dll
2011-02-04 21:12 . 2011-02-04 21:12        102400        ----a-w-        c:\windows\SysWow64\OpenAL32.dll
2011-02-02 16:11 . 2010-09-18 16:35        270720        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-02-18 1242448]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-05-01 3071384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ugrllhsluukjoafhzxbuTaskMgr"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [x]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 X6va003;X6va003;c:\users\User\AppData\Local\Temp\0039253.tmp [x]
R3 X6va005;X6va005;c:\users\User\AppData\Local\Temp\005A835.tmp [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 6077757b;6077757b;c:\windows\system32\drivers\regi.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 Realtek11nSU;Realtek11nSU;c:\program files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-13 415752]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-13 4195848]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296]
"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2010-09-16 8761344]
"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - c:\users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: die-staemme.de\de71
TCP: {CBBC9FEA-46B8-41DF-909C-5566F8219919} = 192.168.2.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wwjhbt5a.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Flash and Video Download: {bee6eb20-01e0-ebd1-da83-080329fb9a3a} - %profile%\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - Ext: DivX Plus Web Player HTML5 &lt;video&gt;: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\wpa
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va003]
"ImagePath"="\??\c:\users\User\AppData\Local\Temp\0039253.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va005]
"ImagePath"="\??\c:\users\User\AppData\Local\Temp\005A835.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-05-02  16:08:55
ComboFix-quarantined-files.txt  2011-05-02 14:08
ComboFix2.txt  2011-05-02 14:01
ComboFix3.txt  2011-04-29 14:05
.
Vor Suchlauf: 11 Verzeichnis(se), 82.181.541.888 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 82.106.580.992 Bytes frei
.
- - End Of File - - 2DE234CF934A18A52C98DDF8148CE3A9

--- --- ---

cosinus 02.05.2011 20:35

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ugrllhsluukjoafhzxbuTaskMgr"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va003]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\X6va005]

File::
c:\users\User\AppData\Local\Temp\0039253.tmp
c:\users\User\AppData\Local\Temp\005A835.tmp

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Cloud84 02.05.2011 23:30

Combofix Logfile:
Code:

ComboFix 11-05-02.03 - User 03.05.2011  0:26.4.8 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.49.1031.18.6135.4666 [GMT 2:00]
ausgeführt von:: c:\users\User\Desktop\cofi.exe.exe
Benutzte Befehlsschalter :: c:\users\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
FILE ::
"c:\users\User\AppData\Local\Temp\0039253.tmp"
"c:\users\User\AppData\Local\Temp\005A835.tmp"
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-02 bis 2011-05-02  ))))))))))))))))))))))))))))))
.
.
2011-05-02 22:28 . 2011-05-02 22:28        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-05-02 13:38 . 2011-05-02 13:38        --------        d-----w-        c:\users\User\AppData\Local\The Lord of the Rings Online
2011-05-01 20:07 . 2011-05-02 13:17        --------        d-----w-        c:\users\User\AppData\Local\Turbine
2011-05-01 20:07 . 2011-05-02 18:35        --------        d-----w-        c:\users\User\AppData\Local\ApplicationHistory
2011-05-01 20:06 . 2011-05-01 20:06        --------        d-----w-        c:\windows\SysWow64\URTTEMP
2011-05-01 19:42 . 2011-05-01 19:42        --------        d-----w-        c:\program files (x86)\Codemasters
2011-05-01 15:49 . 2011-05-02 22:28        --------        d-----w-        c:\users\User\AppData\Local\PMB Files
2011-05-01 15:49 . 2011-05-01 15:56        --------        d-----w-        c:\programdata\PMB Files
2011-04-29 10:05 . 2011-04-29 10:05        --------        d-----w-        c:\program files (x86)\Tunatic
2011-04-27 16:24 . 2011-04-27 16:24        --------        d-----w-        C:\_OTL
2011-04-27 10:32 . 2011-02-18 06:33        31232        ----a-w-        c:\windows\system32\prevhost.exe
2011-04-27 10:32 . 2011-02-18 05:33        31232        ----a-w-        c:\windows\SysWow64\prevhost.exe
2011-04-24 15:59 . 2011-04-24 15:59        --------        d-----w-        c:\users\User\AppData\Roaming\Malwarebytes
2011-04-24 15:58 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-24 15:58 . 2011-04-24 15:58        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-24 15:58 . 2010-12-20 16:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-04-14 18:31 . 2011-02-24 06:30        476160        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2011-04-14 18:31 . 2011-02-24 05:32        288256        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2011-04-14 18:29 . 2011-03-03 06:17        182272        ----a-w-        c:\windows\system32\dnsrslvr.dll
2011-04-12 13:26 . 2011-04-12 13:26        --------        d-----w-        c:\program files\SD EnterNET
2011-04-12 13:26 . 2005-11-13 21:19        65024        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-04-11 18:21 . 2011-04-11 18:21        --------        d-----w-        c:\users\User\AppData\Local\Urgesoft
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\users\User\AppData\Local\Jaksta_Technologies_Pty_L
2011-04-10 20:29 . 2011-04-10 20:29        --------        d-----w-        c:\programdata\Applian
2011-04-10 20:28 . 2011-04-10 20:28        --------        d-----w-        c:\windows\Applian Director
2011-04-05 18:00 . 2011-04-13 15:07        --------        d-----w-        c:\program files (x86)\Metin2
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 06:17 . 2011-04-27 10:33        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:17 . 2011-04-27 10:33        347648        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-02-19 06:37 . 2011-03-09 09:56        1135104        ----a-w-        c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 09:56        1540608        ----a-w-        c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 09:56        902656        ----a-w-        c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 09:56        1074176        ----a-w-        c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 09:56        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll
2011-02-18 20:50 . 2011-02-18 20:50        22295040        ----a-w-        c:\windows\system32\atio6axx.dll
2011-02-18 20:50 . 2011-02-18 20:50        38400        ----a-w-        c:\windows\system32\atiu9p64.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atig6txx.dll
2011-02-18 20:50 . 2011-02-18 20:50        4847616        ----a-w-        c:\windows\system32\atidxx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\ATIODCLI.exe
2011-02-18 20:50 . 2011-02-18 20:50        17204736        ----a-w-        c:\windows\SysWow64\atioglxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        423424        ----a-w-        c:\windows\system32\atipdl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        1912832        ----a-w-        c:\windows\SysWow64\atiumdmv.dll
2011-02-18 20:50 . 2011-02-18 20:50        9085952        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-02-18 20:50 . 2011-02-18 20:50        44032        ----a-w-        c:\windows\SysWow64\aticalcl.dll
2011-02-18 20:50 . 2011-02-18 20:50        3222016        ----a-w-        c:\windows\system32\atiumd6a.dll
2011-02-18 20:50 . 2011-02-18 20:50        46080        ----a-w-        c:\windows\SysWow64\aticalrt.dll
2011-02-18 20:50 . 2010-07-07 01:54        596480        ----a-w-        c:\windows\SysWow64\aticfx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\atimpc32.dll
2011-02-18 20:50 . 2011-02-18 20:50        52736        ----a-w-        c:\windows\SysWow64\amdpcom32.dll
2011-02-18 20:50 . 2011-02-18 20:50        43520        ----a-w-        c:\windows\SysWow64\ati2edxx.dll
2011-02-18 20:50 . 2010-04-07 01:40        4170752        ----a-w-        c:\windows\SysWow64\atiumdag.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\atimpc64.dll
2011-02-18 20:50 . 2011-02-18 20:50        53760        ----a-w-        c:\windows\system32\amdpcom64.dll
2011-02-18 20:50 . 2011-02-18 20:50        278528        ----a-w-        c:\windows\SysWow64\Oemdspif.dll
2011-02-18 20:50 . 2011-02-18 20:50        115216        ----a-w-        c:\windows\system32\drivers\AtihdW76.sys
2011-02-18 20:50 . 2011-02-18 20:50        462848        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-02-18 20:50 . 2011-02-18 20:50        479232        ----a-w-        c:\windows\system32\atieclxx.exe
2011-02-18 20:50 . 2010-09-23 16:39        58880        ----a-w-        c:\windows\system32\coinst.dll
2011-02-18 20:50 . 2011-02-18 20:50        39936        ----a-w-        c:\windows\system32\atiuxp64.dll
2011-02-18 20:50 . 2011-02-18 20:50        299520        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-02-18 20:50 . 2011-02-18 20:50        5316096        ----a-w-        c:\windows\system32\atiumd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        6982144        ----a-w-        c:\windows\system32\aticaldd64.dll
2011-02-18 20:50 . 2011-02-18 20:50        30720        ----a-w-        c:\windows\SysWow64\atiuxpag.dll
2011-02-18 20:50 . 2011-02-18 20:50        5580800        ----a-w-        c:\windows\SysWow64\aticaldd.dll
2011-02-18 20:50 . 2011-02-18 20:50        332800        ----a-w-        c:\windows\system32\ATIODE.exe
2011-02-18 20:50 . 2011-02-18 20:50        14848        ----a-w-        c:\windows\system32\atig6pxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        143360        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-02-18 20:50 . 2011-02-18 20:50        356352        ----a-w-        c:\windows\SysWow64\atipdlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        203776        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-02-18 20:50 . 2010-04-07 01:21        3463680        ----a-w-        c:\windows\SysWow64\atiumdva.dll
2011-02-18 20:50 . 2011-02-18 20:50        249856        ----a-w-        c:\windows\SysWow64\atiadlxy.dll
2011-02-18 20:50 . 2011-02-18 20:50        51200        ----a-w-        c:\windows\system32\aticalrt64.dll
2011-02-18 20:50 . 2011-02-18 20:50        32768        ----a-w-        c:\windows\SysWow64\atigktxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        16384        ----a-w-        c:\windows\system32\atimuixx.dll
2011-02-18 20:50 . 2011-02-18 20:50        708608        ----a-w-        c:\windows\system32\aticfx64.dll
2011-02-18 20:50 . 2011-02-18 20:50        44544        ----a-w-        c:\windows\system32\aticalcl64.dll
2011-02-18 20:50 . 2011-02-18 20:50        354304        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        1208320        ----a-w-        c:\windows\system32\atiumd6v.dll
2011-02-18 20:50 . 2011-02-18 20:50        4105728        ----a-w-        c:\windows\SysWow64\atidxx32.dll
2011-02-18 20:50 . 2011-02-18 20:50        120320        ----a-w-        c:\windows\system32\atitmm64.dll
2011-02-18 20:50 . 2011-02-18 20:50        59392        ----a-w-        c:\windows\system32\atiedu64.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\SysWow64\atiglpxx.dll
2011-02-18 20:50 . 2011-02-18 20:50        12800        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-02-18 20:50 . 2010-04-07 01:22        28672        ----a-w-        c:\windows\SysWow64\atiu9pag.dll
2011-02-11 07:30 . 2011-03-18 11:37        7947600        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE269F37-198C-4267-91F0-BA9282130E30}\mpengine.dll
2011-02-04 21:12 . 2011-02-04 21:12        419840        ----a-w-        c:\windows\system32\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        413696        ----a-w-        c:\windows\SysWow64\wrap_oal.dll
2011-02-04 21:12 . 2011-02-04 21:12        111616        ----a-w-        c:\windows\system32\OpenAL32.dll
2011-02-04 21:12 . 2011-02-04 21:12        102400        ----a-w-        c:\windows\SysWow64\OpenAL32.dll
2011-02-02 16:11 . 2010-09-18 16:35        270720        ------w-        c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((  SnapShot_2011-05-02_14.00.37  )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:46 . 2011-05-02 15:27        72456              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-09-18 15:32 . 2011-05-02 22:00        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-18 15:32 . 2011-05-02 13:06        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-18 15:32 . 2011-05-02 13:06        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-18 15:32 . 2011-05-02 22:00        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 02:36 . 2011-05-02 20:00        661064              c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-05-02 13:53        661064              c:\windows\system32\perfh009.dat
+ 2009-07-14 17:58 . 2011-05-02 20:00        707446              c:\windows\system32\perfh007.dat
- 2009-07-14 17:58 . 2011-05-02 13:53        707446              c:\windows\system32\perfh007.dat
+ 2009-07-14 02:36 . 2011-05-02 20:00        125254              c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-05-02 13:53        125254              c:\windows\system32\perfc009.dat
- 2009-07-14 17:58 . 2011-05-02 13:53        153038              c:\windows\system32\perfc007.dat
+ 2009-07-14 17:58 . 2011-05-02 20:00        153038              c:\windows\system32\perfc007.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-02-18 1242448]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-05-01 3071384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [x]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 6077757b;6077757b;c:\windows\system32\drivers\regi.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 Realtek11nSU;Realtek11nSU;c:\program files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [x]
S3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-13 415752]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-13 4195848]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296]
"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2010-09-16 8761344]
"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - c:\users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: die-staemme.de\de71
TCP: {CBBC9FEA-46B8-41DF-909C-5566F8219919} = 192.168.2.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wwjhbt5a.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Flash and Video Download: {bee6eb20-01e0-ebd1-da83-080329fb9a3a} - %profile%\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
FF - Ext: Fast Video Download (with SearchMenu): {c50ca3c4-5656-43c2-a061-13e717f73fc8} - %profile%\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
FF - Ext: DivX Plus Web Player HTML5 &lt;video&gt;: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\wpa
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10i.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-05-03  00:30:00
ComboFix-quarantined-files.txt  2011-05-02 22:29
ComboFix2.txt  2011-05-02 14:01
ComboFix3.txt  2011-04-29 14:05
.
Vor Suchlauf: 11 Verzeichnis(se), 82.086.477.824 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 82.011.013.120 Bytes frei
.
- - End Of File - - 8234897BE9AEBA35660437A58276ED49

--- --- ---

cosinus 03.05.2011 08:31

Bitte nun Logs mit GMER und mbrcheck erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg

Anleitung zu mbrcheck:
Downloade Dir MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Cloud84 03.05.2011 21:15

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x000000dc

Kernel Drivers (total 157):
0x0380E000 \SystemRoot\system32\ntoskrnl.exe
0x03DEB000 \SystemRoot\system32\hal.dll
0x00BA1000 \SystemRoot\system32\kdcom.dll
0x00CDC000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D20000 \SystemRoot\system32\PSHED.dll
0x00D34000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E72000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F16000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x010CB000 \SystemRoot\System32\Drivers\spwc.sys
0x011F1000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x01000000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x0102F000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x01086000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x01090000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00F25000 \SystemRoot\system32\DRIVERS\pci.sys
0x0109D000 \SystemRoot\System32\drivers\partmgr.sys
0x010B2000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00F58000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FB4000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00FBB000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00FCB000 \SystemRoot\System32\drivers\mountmgr.sys
0x012D5000 \SystemRoot\system32\drivers\iaStorV.sys
0x013F3000 \SystemRoot\system32\DRIVERS\atapi.sys
0x01200000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x0122A000 \SystemRoot\system32\drivers\amdxata.sys
0x01235000 \SystemRoot\system32\drivers\fltmgr.sys
0x01281000 \SystemRoot\system32\drivers\fileinfo.sys
0x0145C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x00E00000 \SystemRoot\System32\Drivers\msrpc.sys
0x01400000 \SystemRoot\System32\Drivers\ksecdd.sys
0x0162D000 \SystemRoot\System32\Drivers\cng.sys
0x016A0000 \SystemRoot\System32\drivers\pcw.sys
0x016B1000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016BB000 \SystemRoot\system32\drivers\ndis.sys
0x00D92000 \SystemRoot\system32\drivers\NETIO.SYS
0x017AD000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01801000 \SystemRoot\System32\drivers\tcpip.sys
0x01ADA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01B24000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x01B34000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01B80000 \SystemRoot\System32\Drivers\spldr.sys
0x01B88000 \SystemRoot\System32\drivers\rdyboost.sys
0x01BC2000 \SystemRoot\System32\Drivers\mup.sys
0x01BD4000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01A00000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01A3A000 \SystemRoot\system32\DRIVERS\disk.sys
0x01A50000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01A80000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x01AAA000 \SystemRoot\System32\Drivers\Null.SYS
0x01AB3000 \SystemRoot\System32\Drivers\Beep.SYS
0x01ABA000 \SystemRoot\System32\drivers\vga.sys
0x017D8000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01AC8000 \SystemRoot\System32\drivers\watchdog.sys
0x01BDD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01BE6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01BEF000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01600000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0160B000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0141A000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0161C000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02E6E000 \SystemRoot\system32\drivers\afd.sys
0x02EF8000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02F3D000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02F46000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02F6C000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02F82000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02F91000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02FAC000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02E00000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02E51000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02E5D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02FC0000 \SystemRoot\System32\drivers\discache.sys
0x03E6E000 \SystemRoot\system32\drivers\csc.sys
0x03EF1000 \SystemRoot\System32\Drivers\dfsc.sys
0x03F0F000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x03F20000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x03F46000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x03F5C000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x04AEE000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x0409F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04193000 \SystemRoot\System32\drivers\dxgmms1.sys
0x041D9000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x04000000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x0400D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04063000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04202000 \SystemRoot\system32\drivers\cmudaxp.sys
0x04A00000 \SystemRoot\system32\drivers\portcls.sys
0x043C7000 \SystemRoot\system32\drivers\drmk.sys
0x04A3D000 \SystemRoot\system32\drivers\ks.sys
0x043E9000 \SystemRoot\system32\drivers\ksthunk.sys
0x04A80000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x03FAA000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x043EF000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x04074000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x04084000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x03E00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04AD6000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x03E24000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x03E53000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02FCF000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x01438000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x04AE2000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x053EA000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x03FE8000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x043F7000 \SystemRoot\system32\DRIVERS\swenum.sys
0x01295000 \SystemRoot\system32\DRIVERS\umbus.sys
0x05865000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x058BF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x058D4000 \SystemRoot\system32\drivers\AtihdW76.sys
0x07AB0000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x07D0C000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x07D29000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x000A0000 \SystemRoot\System32\win32k.sys
0x07D2B000 \SystemRoot\System32\drivers\Dxapi.sys
0x07D37000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x07D45000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x07D5E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x07D74000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x058F4000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x07D82000 \SystemRoot\System32\drivers\vwifibus.sys
0x07D8F000 \SystemRoot\system32\DRIVERS\monitor.sys
0x07D9D000 \SystemRoot\system32\drivers\USBSTOR.SYS
0x00400000 \SystemRoot\System32\TSDDD.dll
0x00680000 \SystemRoot\System32\cdd.dll
0x07DB8000 \SystemRoot\system32\drivers\luafv.sys
0x07DDB000 \SystemRoot\system32\drivers\WudfPf.sys
0x07A00000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x07A15000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x07A68000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x07A7B000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0567B000 \SystemRoot\system32\drivers\HTTP.sys
0x05743000 \SystemRoot\system32\DRIVERS\bowser.sys
0x05761000 \SystemRoot\System32\drivers\mpsdrv.sys
0x05779000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x057A6000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x05600000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x05623000 \??\C:\Windows\system32\drivers\regi.sys
0x0904D000 \SystemRoot\system32\drivers\peauth.sys
0x090F3000 \SystemRoot\System32\Drivers\secdrv.SYS
0x090FE000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0912B000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0913D000 \SystemRoot\System32\DRIVERS\srv2.sys
0x09351000 \SystemRoot\System32\DRIVERS\srv.sys
0x09200000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x0921D000 \SystemRoot\system32\DRIVERS\klif.sys
0x092B3000 \SystemRoot\system32\DRIVERS\klim6.sys
0x0AE1D000 \SystemRoot\system32\DRIVERS\kl1.sys
0x0B57C000 \SystemRoot\system32\DRIVERS\kl2.sys
0x0B59A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x0B5A7000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x77830000 \Windows\System32\ntdll.dll
0x47900000 \Windows\System32\smss.exe
0xFFB50000 \Windows\System32\apisetschema.dll
0xFF720000 \Windows\System32\autochk.exe
0xFFB20000 \Windows\System32\sechost.dll
0xFFA80000 \Windows\System32\msvcrt.dll

Processes (total 60):
0 System Idle Process
4 System
328 C:\Windows\System32\smss.exe
452 csrss.exe
524 C:\Windows\System32\wininit.exe
548 csrss.exe
580 C:\Windows\System32\winlogon.exe
636 C:\Windows\System32\services.exe
656 C:\Windows\System32\lsass.exe
664 C:\Windows\System32\lsm.exe
768 C:\Windows\System32\svchost.exe
848 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\atiesrxx.exe
972 C:\Windows\System32\svchost.exe
1012 C:\Windows\System32\svchost.exe
308 C:\Windows\System32\svchost.exe
352 C:\Windows\System32\svchost.exe
1084 C:\Windows\System32\svchost.exe
1180 C:\Windows\System32\atieclxx.exe
1216 C:\Windows\System32\taskeng.exe
1248 C:\Windows\System32\spoolsv.exe
1280 C:\Windows\System32\svchost.exe
1324 C:\Windows\System32\rundll32.exe
1336 C:\Windows\System32\rundll32.exe
1440 C:\Windows\SysWOW64\rundll32.exe
1504 C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
1596 C:\Windows\System32\taskhost.exe
1752 C:\Windows\explorer.exe
1884 C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
1960 C:\Windows\SysWOW64\PnkBstrA.exe
1984 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe
2024 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWLan.exe
2444 C:\Windows\System32\svchost.exe
2280 C:\Windows\System32\svchost.exe
728 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
1900 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
1908 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
2244 C:\Windows\SysWOW64\HsMgr.exe
2772 C:\Windows\system\HsMgr64.exe
2768 C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2872 C:\Program Files\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe
2892 C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
2880 C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
2632 C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
1876 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
704 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
3460 C:\Windows\System32\svchost.exe
3840 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3948 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
4992 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
2852 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
1460 C:\Program Files\Windows Sidebar\sidebar.exe
2664 C:\Windows\System32\taskhost.exe
3052 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
4076 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtblfs.exe
4072 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
4092 C:\Windows\System32\audiodg.exe
3128 C:\Users\User\Downloads\MBRCheck.exe
4188 C:\Windows\System32\conhost.exe
3836 C:\Windows\System32\dllhost.exe

\\.\C: --> error 5
\\.\D: --> error 5

PhysicalDrive0 Model Number: <error opening>
PhysicalDrive1 Model Number: <error opening>
PhysicalDrive2 Model Number: <error opening>

Size Device Name MBR Status
--------------------------------------------
ERROR Opening: \\.\PhysicalDrive0 (5)
ERROR Opening: \\.\PhysicalDrive1 (5)
ERROR Opening: \\.\PhysicalDrive2 (5)


Done!

Anmerkung:Habe mir heute Kaspersky 2011 gekauft, und direkt installiert und komplett durchlaufen lassen...11Trojaner, seitdem scheint mir das Problem behoben..kann das aber noch nicht genau sagen.

Ich nehme an dass kannst du aus dem Log hier rauslesen, ob das Problem noch vorhanden ist?
Auf jeden Fall möchte ich mich recht herzlich bedanken, für die klasse Hilfe bis jetzt.

cosinus 04.05.2011 11:12

Zitat:

Anmerkung:Habe mir heute Kaspersky 2011 gekauft, und direkt installiert und komplett durchlaufen lassen...11Trojaner, seitdem scheint mir das Problem behoben..kann das aber noch nicht genau sagen.
Was soll das werden? Wieso postest du nicht das Log?!

Hast du MBRCheck per Rechtsklick als Admin ausgeführt? Was ist mit den anderen Logs?

Cloud84 04.05.2011 16:27

Vergessen..sorry.
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x000000dc

Kernel Drivers (total 157):
0x0380E000 \SystemRoot\system32\ntoskrnl.exe
0x03DEB000 \SystemRoot\system32\hal.dll
0x00BA1000 \SystemRoot\system32\kdcom.dll
0x00CDC000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D20000 \SystemRoot\system32\PSHED.dll
0x00D34000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E72000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F16000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x010CB000 \SystemRoot\System32\Drivers\spwc.sys
0x011F1000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x01000000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x0102F000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x01086000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x01090000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00F25000 \SystemRoot\system32\DRIVERS\pci.sys
0x0109D000 \SystemRoot\System32\drivers\partmgr.sys
0x010B2000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00F58000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FB4000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00FBB000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00FCB000 \SystemRoot\System32\drivers\mountmgr.sys
0x012D5000 \SystemRoot\system32\drivers\iaStorV.sys
0x013F3000 \SystemRoot\system32\DRIVERS\atapi.sys
0x01200000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x0122A000 \SystemRoot\system32\drivers\amdxata.sys
0x01235000 \SystemRoot\system32\drivers\fltmgr.sys
0x01281000 \SystemRoot\system32\drivers\fileinfo.sys
0x0145C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x00E00000 \SystemRoot\System32\Drivers\msrpc.sys
0x01400000 \SystemRoot\System32\Drivers\ksecdd.sys
0x0162D000 \SystemRoot\System32\Drivers\cng.sys
0x016A0000 \SystemRoot\System32\drivers\pcw.sys
0x016B1000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016BB000 \SystemRoot\system32\drivers\ndis.sys
0x00D92000 \SystemRoot\system32\drivers\NETIO.SYS
0x017AD000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01801000 \SystemRoot\System32\drivers\tcpip.sys
0x01ADA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01B24000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x01B34000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01B80000 \SystemRoot\System32\Drivers\spldr.sys
0x01B88000 \SystemRoot\System32\drivers\rdyboost.sys
0x01BC2000 \SystemRoot\System32\Drivers\mup.sys
0x01BD4000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01A00000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01A3A000 \SystemRoot\system32\DRIVERS\disk.sys
0x01A50000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01A80000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x01AAA000 \SystemRoot\System32\Drivers\Null.SYS
0x01AB3000 \SystemRoot\System32\Drivers\Beep.SYS
0x01ABA000 \SystemRoot\System32\drivers\vga.sys
0x017D8000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01AC8000 \SystemRoot\System32\drivers\watchdog.sys
0x01BDD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01BE6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01BEF000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01600000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0160B000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0141A000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0161C000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02E6E000 \SystemRoot\system32\drivers\afd.sys
0x02EF8000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02F3D000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02F46000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02F6C000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02F82000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02F91000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02FAC000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02E00000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02E51000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02E5D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02FC0000 \SystemRoot\System32\drivers\discache.sys
0x03E6E000 \SystemRoot\system32\drivers\csc.sys
0x03EF1000 \SystemRoot\System32\Drivers\dfsc.sys
0x03F0F000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x03F20000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x03F46000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x03F5C000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x04AEE000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x0409F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04193000 \SystemRoot\System32\drivers\dxgmms1.sys
0x041D9000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x04000000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x0400D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04063000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04202000 \SystemRoot\system32\drivers\cmudaxp.sys
0x04A00000 \SystemRoot\system32\drivers\portcls.sys
0x043C7000 \SystemRoot\system32\drivers\drmk.sys
0x04A3D000 \SystemRoot\system32\drivers\ks.sys
0x043E9000 \SystemRoot\system32\drivers\ksthunk.sys
0x04A80000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x03FAA000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x043EF000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x04074000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x04084000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x03E00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04AD6000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x03E24000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x03E53000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02FCF000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x01438000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x04AE2000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x053EA000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x03FE8000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x043F7000 \SystemRoot\system32\DRIVERS\swenum.sys
0x01295000 \SystemRoot\system32\DRIVERS\umbus.sys
0x05865000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x058BF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x058D4000 \SystemRoot\system32\drivers\AtihdW76.sys
0x07AB0000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x07D0C000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x07D29000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x000A0000 \SystemRoot\System32\win32k.sys
0x07D2B000 \SystemRoot\System32\drivers\Dxapi.sys
0x07D37000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x07D45000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x07D5E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x07D74000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x058F4000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x07D82000 \SystemRoot\System32\drivers\vwifibus.sys
0x07D8F000 \SystemRoot\system32\DRIVERS\monitor.sys
0x07D9D000 \SystemRoot\system32\drivers\USBSTOR.SYS
0x00400000 \SystemRoot\System32\TSDDD.dll
0x00680000 \SystemRoot\System32\cdd.dll
0x07DB8000 \SystemRoot\system32\drivers\luafv.sys
0x07DDB000 \SystemRoot\system32\drivers\WudfPf.sys
0x07A00000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x07A15000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x07A68000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x07A7B000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0567B000 \SystemRoot\system32\drivers\HTTP.sys
0x05743000 \SystemRoot\system32\DRIVERS\bowser.sys
0x05761000 \SystemRoot\System32\drivers\mpsdrv.sys
0x05779000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x057A6000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x05600000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x05623000 \??\C:\Windows\system32\drivers\regi.sys
0x0904D000 \SystemRoot\system32\drivers\peauth.sys
0x090F3000 \SystemRoot\System32\Drivers\secdrv.SYS
0x090FE000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0912B000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0913D000 \SystemRoot\System32\DRIVERS\srv2.sys
0x09351000 \SystemRoot\System32\DRIVERS\srv.sys
0x09200000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x0921D000 \SystemRoot\system32\DRIVERS\klif.sys
0x092B3000 \SystemRoot\system32\DRIVERS\klim6.sys
0x0AE1D000 \SystemRoot\system32\DRIVERS\kl1.sys
0x0B57C000 \SystemRoot\system32\DRIVERS\kl2.sys
0x0B59A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x0B5A7000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x77830000 \Windows\System32\ntdll.dll
0x47900000 \Windows\System32\smss.exe
0xFFB50000 \Windows\System32\apisetschema.dll
0xFF720000 \Windows\System32\autochk.exe
0xFFB20000 \Windows\System32\sechost.dll
0xFFA80000 \Windows\System32\msvcrt.dll

Processes (total 60):
0 System Idle Process
4 System
328 C:\Windows\System32\smss.exe
452 csrss.exe
524 C:\Windows\System32\wininit.exe
548 csrss.exe
580 C:\Windows\System32\winlogon.exe
636 C:\Windows\System32\services.exe
656 C:\Windows\System32\lsass.exe
664 C:\Windows\System32\lsm.exe
768 C:\Windows\System32\svchost.exe
848 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\atiesrxx.exe
972 C:\Windows\System32\svchost.exe
1012 C:\Windows\System32\svchost.exe
308 C:\Windows\System32\svchost.exe
352 C:\Windows\System32\svchost.exe
1084 C:\Windows\System32\svchost.exe
1180 C:\Windows\System32\atieclxx.exe
1216 C:\Windows\System32\taskeng.exe
1248 C:\Windows\System32\spoolsv.exe
1280 C:\Windows\System32\svchost.exe
1324 C:\Windows\System32\rundll32.exe
1336 C:\Windows\System32\rundll32.exe
1440 C:\Windows\SysWOW64\rundll32.exe
1504 C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
1596 C:\Windows\System32\taskhost.exe
1752 C:\Windows\explorer.exe
1884 C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
1960 C:\Windows\SysWOW64\PnkBstrA.exe
1984 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe
2024 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWLan.exe
2444 C:\Windows\System32\svchost.exe
2280 C:\Windows\System32\svchost.exe
728 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
1900 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
1908 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
2244 C:\Windows\SysWOW64\HsMgr.exe
2772 C:\Windows\system\HsMgr64.exe
2768 C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2872 C:\Program Files\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe
2892 C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
2880 C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
2632 C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
1876 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
704 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
3460 C:\Windows\System32\svchost.exe
3840 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3948 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
4992 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
2852 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
1460 C:\Program Files\Windows Sidebar\sidebar.exe
2664 C:\Windows\System32\taskhost.exe
3052 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
4076 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtblfs.exe
4072 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
4092 C:\Windows\System32\audiodg.exe
3128 C:\Users\User\Downloads\MBRCheck.exe
4188 C:\Windows\System32\conhost.exe
3836 C:\Windows\System32\dllhost.exe

\\.\C: --> error 5
\\.\D: --> error 5

PhysicalDrive0 Model Number: <error opening>
PhysicalDrive1 Model Number: <error opening>
PhysicalDrive2 Model Number: <error opening>

Size Device Name MBR Status
--------------------------------------------
ERROR Opening: \\.\PhysicalDrive0 (5)
ERROR Opening: \\.\PhysicalDrive1 (5)
ERROR Opening: \\.\PhysicalDrive2 (5)


Done!

Cloud84 04.05.2011 16:27

Außerdem ist das Problem noch nicht behoben...wie ich jetzt bestätigen kann.

cosinus 04.05.2011 17:53

Außerdem ist Log von Kaspersky immer noch nicht gepostet... :balla:

Cloud84 05.05.2011 16:35

Wenn du mir verraten hättest, wo ich die Logfile finde, hätte ich sie schon lange gepostet :balla:

cosinus 05.05.2011 19:16

Wieso muss ich dir verraten wo du das Log findest? Soll ich jeden Scanner und dessen Bedienung auswendig kennen? Ist es zuviel von dir verlangt, mal selbst nachzusehen im Hauptmenü oder Handbuch? :balla:

Cloud84 06.05.2011 14:19

Ich habe mich damit schon ein wenig auseinander gesetzt und auch im Internet gesucht...deshalb frage ich
Aber vll. find ich ja noch den Log..

cosinus 06.05.2011 14:23

Das Log kannst du auch später nachreichen. Wir sollten erstmal den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Windows7 installiert? Win7-DVD 64-Bit zur Hand?
Wenn nicht: Schau mal hier => Vista Notfall/Recovery-CD 64-Bit - Dr. Windows

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten).

Falls Du eine normale Win7-Installations-DVD hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.

Cloud84 07.05.2011 16:11

Uff, das mach ich mal gleich
War leider gestern und heute nicht mehr da...

Cloud84 07.05.2011 20:11

[spoiler]MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x000000dc

Kernel Drivers (total 190):
0x03865000 \SystemRoot\system32\ntoskrnl.exe
0x0381C000 \SystemRoot\system32\hal.dll
0x00B97000 \SystemRoot\system32\kdcom.dll
0x00C63000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CA7000 \SystemRoot\system32\PSHED.dll
0x00CBB000 \SystemRoot\system32\CLFS.SYS
0x00D19000 \SystemRoot\system32\CI.dll
0x00ED2000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F76000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x0104F000 \SystemRoot\System32\Drivers\spms.sys
0x01175000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x0117E000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x00F85000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x011AD000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x011B7000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x011C4000 \SystemRoot\system32\DRIVERS\pci.sys
0x01000000 \SystemRoot\System32\drivers\partmgr.sys
0x01015000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00E00000 \SystemRoot\System32\drivers\volmgrx.sys
0x0102A000 \SystemRoot\system32\DRIVERS\pciide.sys
0x01031000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00E5C000 \SystemRoot\System32\drivers\mountmgr.sys
0x012D5000 \SystemRoot\system32\drivers\iaStorV.sys
0x013F3000 \SystemRoot\system32\DRIVERS\atapi.sys
0x01200000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x0122A000 \SystemRoot\system32\drivers\amdxata.sys
0x01235000 \SystemRoot\system32\drivers\fltmgr.sys
0x01281000 \SystemRoot\system32\drivers\fileinfo.sys
0x0144F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x00C00000 \SystemRoot\System32\Drivers\msrpc.sys
0x01400000 \SystemRoot\System32\Drivers\ksecdd.sys
0x016D0000 \SystemRoot\System32\Drivers\cng.sys
0x01743000 \SystemRoot\System32\drivers\pcw.sys
0x01754000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01877000 \SystemRoot\system32\drivers\ndis.sys
0x01969000 \SystemRoot\system32\drivers\NETIO.SYS
0x019C9000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01A02000 \SystemRoot\System32\drivers\tcpip.sys
0x01800000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0184A000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x0175E000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x0185A000 \SystemRoot\System32\Drivers\spldr.sys
0x017AA000 \SystemRoot\System32\drivers\rdyboost.sys
0x01862000 \SystemRoot\System32\Drivers\mup.sys
0x01C41000 \SystemRoot\system32\DRIVERS\kl1.sys
0x023A0000 \SystemRoot\System32\drivers\hwpolicy.sys
0x023A9000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x023E3000 \SystemRoot\system32\DRIVERS\disk.sys
0x01C00000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01600000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0162A000 \SystemRoot\system32\DRIVERS\klif.sys
0x01C30000 \SystemRoot\System32\Drivers\Null.SYS
0x01C39000 \SystemRoot\System32\Drivers\Beep.SYS
0x016C0000 \SystemRoot\System32\drivers\vga.sys
0x0141A000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x017E4000 \SystemRoot\System32\drivers\watchdog.sys
0x019F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x017F4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x0143F000 \SystemRoot\system32\drivers\rdprefmp.sys
0x015F1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01295000 \SystemRoot\System32\Drivers\Npfs.SYS
0x012A6000 \SystemRoot\system32\DRIVERS\tdx.sys
0x012C4000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x023F9000 \SystemRoot\system32\DRIVERS\kl2.sys
0x0362A000 \SystemRoot\system32\drivers\afd.sys
0x036B4000 \SystemRoot\System32\DRIVERS\netbt.sys
0x036F9000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x03702000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03728000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x0373E000 \SystemRoot\system32\DRIVERS\klim6.sys
0x03747000 \SystemRoot\system32\DRIVERS\netbios.sys
0x03756000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03771000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03785000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x037D6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x037E2000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x037ED000 \SystemRoot\System32\drivers\discache.sys
0x04A96000 \SystemRoot\system32\drivers\csc.sys
0x04B19000 \SystemRoot\System32\Drivers\dfsc.sys
0x04B37000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x04B48000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04B6E000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x04B84000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x0522E000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x04C92000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04D86000 \SystemRoot\System32\drivers\dxgmms1.sys
0x04DCC000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x04DF0000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04C00000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04C56000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04E15000 \SystemRoot\system32\drivers\cmudaxp.sys
0x05B2A000 \SystemRoot\system32\drivers\portcls.sys
0x04FDA000 \SystemRoot\system32\drivers\drmk.sys
0x05B67000 \SystemRoot\system32\drivers\ks.sys
0x04E00000 \SystemRoot\system32\drivers\ksthunk.sys
0x05BAA000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04A00000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04E06000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x04C67000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x04C77000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x05200000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04A3E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04A4A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04A79000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04BD2000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x03600000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x04BF3000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x0361A000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x00E76000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x04E0E000 \SystemRoot\system32\DRIVERS\swenum.sys
0x00E85000 \SystemRoot\system32\DRIVERS\umbus.sys
0x062EB000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x06345000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x0635A000 \SystemRoot\system32\drivers\AtihdW76.sys
0x082E3000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x000B0000 \SystemRoot\System32\win32k.sys
0x0853F000 \SystemRoot\System32\drivers\Dxapi.sys
0x08200000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x082C1000 \SystemRoot\System32\drivers\vwifibus.sys
0x082CE000 \SystemRoot\system32\DRIVERS\monitor.sys
0x0854B000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x08568000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x0856A000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x08578000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x08591000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x0859A000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x00450000 \SystemRoot\System32\TSDDD.dll
0x00730000 \SystemRoot\System32\cdd.dll
0x085A8000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x085B5000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x085BF000 \SystemRoot\system32\drivers\luafv.sys
0x0637A000 \SystemRoot\system32\drivers\WudfPf.sys
0x085E2000 \SystemRoot\system32\drivers\USBSTOR.SYS
0x0639B000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x06200000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x06253000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x06266000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x05E13000 \SystemRoot\system32\drivers\HTTP.sys
0x05EDB000 \SystemRoot\system32\DRIVERS\bowser.sys
0x05EF9000 \SystemRoot\System32\drivers\mpsdrv.sys
0x05F11000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x05F3E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x05F8C000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x05FAF000 \??\C:\Windows\system32\drivers\regi.sys
0x096EC000 \SystemRoot\system32\drivers\peauth.sys
0x09792000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0979D000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x097CA000 \SystemRoot\System32\drivers\tcpipreg.sys
0x09600000 \SystemRoot\System32\DRIVERS\srv2.sys
0x09667000 \SystemRoot\system32\drivers\spsys.sys
0x098C4000 \SystemRoot\System32\DRIVERS\srv.sys
0x770B0000 \Windows\System32\ntdll.dll
0x47C60000 \Windows\System32\smss.exe
0xFF3D0000 \Windows\System32\apisetschema.dll
0xFFA80000 \Windows\System32\autochk.exe
0xFF350000 \Windows\System32\gdi32.dll
0xFF2B0000 \Windows\System32\clbcatq.dll
0xFE520000 \Windows\System32\shell32.dll
0x77280000 \Windows\System32\normaliz.dll
0xFE510000 \Windows\System32\lpk.dll
0xFE490000 \Windows\System32\difxapi.dll
0xFE3B0000 \Windows\System32\oleaut32.dll
0xFE2D0000 \Windows\System32\advapi32.dll
0xFE2B0000 \Windows\System32\sechost.dll
0xFE280000 \Windows\System32\imm32.dll
0xFE170000 \Windows\System32\msctf.dll
0xFDF60000 \Windows\System32\ole32.dll
0x76F90000 \Windows\System32\kernel32.dll
0xFDEC0000 \Windows\System32\comdlg32.dll
0xFDD90000 \Windows\System32\wininet.dll
0xFDC10000 \Windows\System32\urlmon.dll
0xFDC00000 \Windows\System32\nsi.dll
0xFDB60000 \Windows\System32\msvcrt.dll
0xFDB10000 \Windows\System32\ws2_32.dll
0xFD9E0000 \Windows\System32\rpcrt4.dll
0x77270000 \Windows\System32\psapi.dll
0xFD910000 \Windows\System32\usp10.dll
0xFD890000 \Windows\System32\shlwapi.dll
0xFD870000 \Windows\System32\imagehlp.dll
0xFD610000 \Windows\System32\iertutil.dll
0xFD430000 \Windows\System32\setupapi.dll
0xFD3E0000 \Windows\System32\Wldap32.dll
0x76E90000 \Windows\System32\user32.dll
0xFD3A0000 \Windows\System32\cfgmgr32.dll
0xFD360000 \Windows\System32\wintrust.dll
0xFD1F0000 \Windows\System32\crypt32.dll
0xFD180000 \Windows\System32\KernelBase.dll
0xFD160000 \Windows\System32\devobj.dll
0xFD0C0000 \Windows\System32\comctl32.dll
0xFD0B0000 \Windows\System32\msasn1.dll

Processes (total 55):
0 System Idle Process
4 System
408 C:\Windows\System32\smss.exe
532 csrss.exe
604 C:\Windows\System32\wininit.exe
628 csrss.exe
664 C:\Windows\System32\services.exe
680 C:\Windows\System32\lsass.exe
688 C:\Windows\System32\lsm.exe
780 C:\Windows\System32\winlogon.exe
840 C:\Windows\System32\svchost.exe
916 C:\Windows\System32\svchost.exe
980 C:\Windows\System32\atiesrxx.exe
1020 C:\Windows\System32\svchost.exe
308 C:\Windows\System32\svchost.exe
548 C:\Windows\System32\svchost.exe
1048 C:\Windows\System32\audiodg.exe
1096 C:\Windows\System32\svchost.exe
1168 C:\Windows\System32\svchost.exe
1232 C:\Windows\System32\atieclxx.exe
1392 C:\Windows\explorer.exe
1492 C:\Windows\System32\spoolsv.exe
1520 C:\Windows\System32\svchost.exe
1604 C:\Windows\System32\taskeng.exe
1636 C:\Windows\System32\rundll32.exe
1668 C:\Windows\System32\rundll32.exe
1676 C:\Windows\SysWOW64\rundll32.exe
1684 C:\Windows\System32\taskhost.exe
1844 C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
1904 C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
1992 C:\Windows\SysWOW64\PnkBstrA.exe
2016 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe
1032 C:\Windows\System32\sppsvc.exe
1036 C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWLan.exe
2136 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
2156 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
2396 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
2480 C:\Windows\SysWOW64\HsMgr.exe
2488 C:\Windows\system\HsMgr64.exe
2624 C:\Program Files\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe
2836 C:\Program Files (x86)\Steam\Steam.exe
2844 C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2876 C:\Program Files\Windows Sidebar\sidebar.exe
2948 C:\Program Files (x86)\Razer\Mamba\RazerTray.exe
2980 C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
2988 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
3052 C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
856 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2264 WmiPrvSE.exe
3788 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
3896 C:\Windows\System32\svchost.exe
4184 C:\Windows\System32\svchost.exe
4792 C:\Users\User\Downloads\MBRCheck.exe
4804 C:\Windows\System32\conhost.exe
4848 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000024`9f000000 (NTFS)

PhysicalDrive0 Model Number: Ñø€ÿÿ

Size Device Name MBR Status
--------------------------------------------
1397 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done![/spoiler]

Bei GMER kommt ...
C:\Windows\system32\config\system:Das System kann die angegebene Datei nicht finden.

cosinus 07.05.2011 20:53

Das sieht schon mal wesentlich besser aus.
hast du das Log von deinem kasperksy mittlerweile gefunden?

Cloud84 07.05.2011 21:10

Nein, tut mir leid.

Habe aber ein noch viel größeres Problem seit dem ausführen der oben genannten Schritte.

Windows 7 Build 7600
Die Echtheit dieser Windows-Kopie wurde noch nicht bestätigt

Ich kann zu 100% versichern dass ich nur Computerreparatur und dann Eingabeaufforderung ausgeführt habe...
Nun möchte Microsoft dauernd einen Schlüssel, den ich nicht habe da Windows auf dem PC vorinstalliert war...
Woran liegt das denn nun?

cosinus 07.05.2011 21:13

Evtl musst du Windows neu aktivieren

Cloud84 07.05.2011 21:14

Und das geht durch welchen Key? Den ich ja nicht habe...

cosinus 07.05.2011 21:33

Den Key braucht man bei der Installation. bei der Aktivierung wird er nicht abgefragt, oder fragt der dich nach dem Windows-Key?

Cloud84 07.05.2011 21:35

Beim neustarten kommt ein Fenster über den ganzen Bildschirm verteilt:

Ihre Windowsversion ist möglicherweise kein Orginal.

->Product Key eingeben
->Testversion (oder so ähnlich)
->Abbrechen

cosinus 07.05.2011 21:36

Aus welcher Quelle stammt dein Windows? Wer hat es installiert?

Cloud84 07.05.2011 21:39

Das war ein Privatkauf von einem Maschinenbauingenieur. Er hat mir gesagt, Windows 7 64Bit Ultimate ist bereits vorinstalliert, er hat aber keine CD mehr zum mitgeben.
Aber ansonsten war es meines Wissens eine Orginalversion...

cosinus 07.05.2011 21:41

Downloade Dir bitte WVCheck von Artellos.com
  • Speichere die Datei auf dem Desktop. ( solltest Du dir die .zip Datei herunter geladen haben musst Du diese zuerst entpacken )
  • Starte die .exe mit Doppelklick
    Vista und Win7 User: mit Rechtsklick "als Admin ausführen" starten
  • Wie beschrieben, kann das Tool eine Weile brauchen.
  • Wenn es erledigt ist, kopiere den Inhalt des Textdokumentes hier in deinen Thread

Cloud84 07.05.2011 21:45

Windows Validation Check
Version: 1.9.12.5
Log Created On: 2243_07-05-2011
-----------------------

Windows Information
-----------------------
Windows Version: Windows 7
Windows Mode: Normal
Systemroot Path: C:\Windows

WVCheck's Auto Update Check
-----------------------
Auto-Update Option: Download updates and install them automatically.
-----------------------
Last Success Time for Update Detection: 2011-05-07 14:47:34
Last Success Time for Update Download: 2011-04-27 10:33:07
Last Success Time for Update Installation: 2011-04-28 01:00:33


WVCheck's Registry Check Check
-----------------------
Antiwpa: Not Found
-----------------------
Chew7Hale: Not Found
-----------------------


WVCheck's File Dump
-----------------------
WVCheck found no known bad files.


WVCheck's Dir Dump
-----------------------
WVCheck found no known bad directories.


WVCheck's Missing File Check
-----------------------
WVCheck found no missing Windows files.


WVCheck's MBAM Quarantine Check
-----------------------
There were no bad files quarantined by MBAM.


WVCheck's HOSTS File Check
-----------------------
WVCheck found no bad lines in the hosts file.


WVCheck's MD5 Check
EXPERIMENTAL!!
-----------------------
user32.dll - e8b0ffc209e504cb7e79fc24e6c085f0


-------- End of File, program close at 2244_07-05-2011 --------

Außerdem kam am Anfang die Fehlermeldung:
Der Prozedurseinsprungpunkt"PowerReadACValue" wurde in der dll "POWRPROF.dll" nicht gefunden (Ja hab ich als Admin ausgeführt)

cosinus 07.05.2011 22:16

Sieht nach einer Originalversion aus. Bekommst du die Meldung jetzt weg mit der Prüfung?

Cloud84 07.05.2011 22:20

Mit welcher Prüfung?
Bisher kriege ich die Orginalversion nicht wieder hin, das einzige was kommt ist eine dauernde Meldung von Windows

Aktivieren sie ihr Windows.

cosinus 07.05.2011 22:49

Ja - und welche Meldung kommt wenn du versuchst Windows zu aktvieren? :wtf:

Cloud84 07.05.2011 22:57

Wenn ich versuche ihn ohne Eingaben zu aktivieren kommt "Aktivierung durch aktuell genutzten Schlüssel" oder so ähnlich
Klick darauf -> Bitte Warten ->danach Fehlercode

Der Fehlercode bdt. "Fehler bei Lizenzauswertung"

Ergo..nein geht bisher nicht

cosinus 07.05.2011 23:47

Ich hab es mir genauer vorgestellt - geht ein Screenshot?
Womöglich hat der Verkäufer - der Maschinenbauingingeneur - diesen einen Key auf mehreren Rechnern benutzt. Und unter gewissen Umständen äußert sich das so. Es kann aber auch was anderes sein, ist erstmal nur eine Vermutung, daher würde ich um den Screenshot bitten.

Achso auf dem Rechner klebt ein Lizenzaufkleber ja oder nein?

Cloud84 07.05.2011 23:59

Liste der Anhänge anzeigen (Anzahl: 3)
Nein es klebt kein Kleber darauf.

Screenshots sind im Anhang zu dem ganzen Ablauf was da kommt.
Das Popup kommt erst wieder nach einer Weile von daher...

cosinus 08.05.2011 00:03

D.h. auf deinem Rechner klebt kein Windows und so ein Lizenzaufkleber wurde dir niemals ausgehändigt? Wenn du nicht so einen Aufkleber hast, hast du offiziell auch keine Windows-Lizenz, ich hoffe das ist dir klar!

Vllt sprichst du erstmal mit diesem Ingeneur, was er dir da verkauft hat!
Offesichtlich gehörte zum Verkauf keine Windows-Lizenz zum Deal! :nixda:

Cloud84 08.05.2011 00:04

Das ist allerdings nicht gut...
Mensch, hättest du mir das nicht früher sagen können, dass ich Win7 neu aktivieren muss? Jetzt sitz ich dumm da

cosinus 08.05.2011 00:10

Sry das wusste ich nicht!
Ich geh als erstes immer davon aus, dass jeder ein legales Windows hat! Erst wenn die Hinweise auf illegale Versionen häufen frag/forsche ich weiter. Bei dir hört sich das an, als wärst du das OPFER! Dir wurde ein Gerät mit Windows verkauft, aber offensichtlich ohne gültige Lizenz! Frag den Verkäufer bitte mal erstmal vorsichtig, vllt hat er nur den Aufkleber vergessen :pfeiff: sollte er bestimmte Sachen abstreiten, kann man damit drohen, dass es strafbar ist, illegale Software (d.h. nicht lizensierte kommerzielle Software!) an ahnungslose Kunden zu verkaufen! Sowas sollte man als Ingeneur erst recht wissen!

Cloud84 08.05.2011 00:13

Werde ich wohl mal tun...evl. muss ich mal nachschauen, ob in der riesigen Kiste die er mir mitgab (Verpackungen jeglicher eingebauter Teil + Rechnung etc.) doch noch etwas versteckt drin liegt..
Ansonsten rufe ich ihn heute mal an, wenn ich Nummer finde (ja, die werde ich suchen!)

Das wäre ja sonst jetzt dumm für mich gelaufen...

Cloud84 09.05.2011 17:36

Bisher hat dieser nicht auf meine Emails reagiert..

cosinus 09.05.2011 19:07

Das ist natürlich ne doofe Situation jetzt. Windows lässt sich nicht mehr übers Internet aktivieren, richtig? Hast du es mit der telefonischen Aktivierung versucht? Ist zwar ein wenig nervig, aber machbar. Halt unbedingt Stift und Zettel bereit, AFAIK musst du dir von der Computerstimme einen lange Zeichenkette notieren... => Wie kann ich Windows-7 telefonisch aktivieren?

Cloud84 10.05.2011 15:19

Das kommt unter der Anleitung nicht.
Die Auswahl beschänkt sich auf Microsoft Online Support, Anderen Key eingeben und Neu kaufen
-_-
Ich sollte da mal anrufen, also bei der Hotline

Cloud84 10.05.2011 15:34

Ahja...Der Anruf sei kostenpflichtig, ich könne auswählen zwischen Chat, Email und Telefon...kostet alles jeweils 72 Euro +Mws
Super Support, ich bin stolz.

Meinst du, wenn ich mein System auf einen älteren Punkt zurücksetze, dass das alles wieder funktioniert wie vorher?

cosinus 10.05.2011 15:46

Zitat:

kostet alles jeweils 72 Euro +Mws
72,00 EUR für ein Telefonat?? :eek:
Wird darüber gleich der Kaufpreis eines neuen Windowskeys abgerechnet? :rofl:

Zitat:

Meinst du, wenn ich mein System auf einen älteren Punkt zurücksetze, dass das alles wieder funktioniert wie vorher?
Versuch macht klug.

Cloud84 10.05.2011 16:41

Hm, ich denke ich werde das mal ausprobieren...
Und nein, da ist nix mit einberechnet...nur ein Gespräch mit einem Berater lol

cosinus 10.05.2011 18:37

Schau auch nochmal hier => bei aktivierung fehlercode 0xC004E003 - Microsoft Answers

Cloud84 12.05.2011 18:38

Nichts davon hat geklappt..

cosinus 12.05.2011 19:00

Hm, Aktivierung funktioniert nicht, Lizenzaufkleber ist nicht da :balla:
Installations-DVD zu Windows wurde dir gegeben?

Cloud84 13.05.2011 06:50

Hab mal nach gesucht, aber nix davon im riesigen Karton gefunden...
werde mir wohl eine neue Lizenz holen müssen...

cosinus 13.05.2011 17:14

Sehr wahrscheinlich ja :teufel1:
Hat der Typ denn Geld für Windows verlangt? Oder einfach nur Rechnerverkauf so wie er ist? :balla:

Cloud84 15.05.2011 13:23

Nur für den Rechner, so wie er ist.

cosinus 15.05.2011 14:34

Dann offensichtlich ohne Lizenz, denn wenn du eine hättest, wäre ein normalerweise ein Lizenzaufkleber dabei. Der ist Muss bei einer richtigen Lizenz und eigentlich hätte er dir auch eine Windows-DVD mitgeben müssen...

hast du ihn mittlerweile telefonisch erreicht?

Cloud84 16.05.2011 13:09

Nein, per Email nicht, und zum telefonischen...er ist umgezogen.

cosinus 16.05.2011 14:37

Dann wird es sich wohl nicht mehr aufklären wenn er nicht greifbar ist.
Musst dir wohl ein Windows kaufen oder steig auf ein freies OS um

Cloud84 17.05.2011 14:32

Was für freie OS wären da denn zur Auswahl? Linux hab ich schon von gehört, soll aber ja nur was für PC Profis sein :)

Cloud84 17.05.2011 14:38

Um aber zum eigentlichen Thema zurück zu kommen...wie soll ich fortfahren, um diesen hartnäckigen Drecksack vom PC zu kriegen?

cosinus 17.05.2011 14:38

Zitat:

Zitat von Cloud84 (Beitrag 659734)
Was für freie OS wären da denn zur Auswahl? Linux hab ich schon von gehört, soll aber ja nur was für PC Profis sein :)

Was heißt für Profis. Ein Windows ist auch für (Windows-)Profis :rolleyes:
Linux funktioniert anders aber deswegen heißt das nicht, dass Linux schlechter oder schwieriger ist. In einigen Sachen finde ich Linux sogar logischer und einfacher, v.a. das Aktualisieren ist einfacher und nicht so umständlich wie unter Windows. (BTW: Linux ist eigentlich nur der Kernel, was wir umgangssprachlich mit "Linux" meinen ist eine Distro wie zB Debian, OpenSuse oder zB Ubuntu)

Schau dir doch einfach mal Ubuntu an => http://de.wikipedia.org/wiki/Ubuntu

Cloud84 19.05.2011 16:03

So, mein OS geht.
Danke dir trotzdem.

Kannst du mir denn nun weiterhelfen, bei meinem Virusproblem?

cosinus 19.05.2011 18:49

Zitat:

So, mein OS geht.
Danke dir trotzdem.
Welches? Win7? Was genau hast du gemacht?

Cloud84 19.05.2011 22:33

Aktivierung über Microsoft Hotline. (Telefonisch)

Dieser Virus treibt mich in den Wahnsinn.

cosinus 20.05.2011 09:07

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Nach dieser etwas längeren Zeit wäre auch ein frisches OTL-Log angebracht:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Cloud84 21.05.2011 11:33

[spoiler]Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6583

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

21.05.2011 12:32:16
mbam-log-2011-05-21 (12-32-16).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 293708
Laufzeit: 26 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)[/spoiler]

cosinus 21.05.2011 13:43

Zitat:

Datenbank Version: 6583
Du solltest doch vorher ein Update machen...

Cloud84 21.05.2011 17:49

Dachte, der würde automatisch updaten, wenn ich ihn starte und welche verfügbar sind, siehe AntiMalware und Cofi :O
Naja, mache den Rest morgen früh, bin jetzt erstmal (mal wieder) weg.

Cloud84 22.05.2011 16:59

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 05/21/2011 at 12:40 PM

Application Version : 4.52.1000

Core Rules Database Version : 7106
Trace Rules Database Version: 4918

Scan type : Complete Scan
Total Scan Time : 00:36:10

Memory items scanned : 697
Memory threats detected : 0
Registry items scanned : 15543
Registry threats detected : 0
File items scanned : 42354
File threats detected : 5

Adware.Tracking Cookie
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[1].txt

Trojan.Agent/Gen-FakeAlert[WinFiles]
C:\PROGRAM FILES (X86)\BBO ALMANACH\ALMANACH\ALMANACH.EXE

Trojan.Agent/Gen-Faldesc[RE]
C:\PROGRAM FILES (X86)\REFERENCE ASSEMBLIES\WMDRMSDKH.DLL
C:\_OTL\MOVEDFILES\04272011_182401\C_WINDOWS\SYSWOW64\WMDRMSDKH.DLL

Trojan.Agent/Gen
D:\GAME IMAGES\ZYLOM\BEJEWELED 2 DELUXE\MEDIZIN\ZYLOM PATCHER.EXE

Richtiger Log?

Cloud84 22.05.2011 17:22

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6640

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

22.05.2011 18:20:47
mbam-log-2011-05-22 (18-20-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 294644
Laufzeit: 36 Minute(n), 24 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Cloud84 22.05.2011 17:33

OTL Logfile:
Code:

OTL logfile created on: 22.05.2011 18:23:35 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\User\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 65,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s):  [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,39 Gb Total Space | 83,33 Gb Free Space | 56,93% Space Free | Partition Type: NTFS
Drive D: | 1250,78 Gb Total Space | 655,56 Gb Free Space | 52,41% Space Free | Partition Type: NTFS
Drive E: | 7,05 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
 
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Programme\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe (CMedia)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWlan.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe (Realtek)
PRC - C:\Windows\SysWOW64\HsMgr.exe ()
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\HsSrv.dll (C-Media Electronics Inc.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\powrprof.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\dsound.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Realtek11nSU) -- C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe (Realtek)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (KLIF) -- C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (cmudaxp) -- C:\Windows\SysNative\drivers\cmudaxp.sys (C-Media Inc)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0CFA) -- C:\Windows\SysNative\drivers\SaiK0CFA.sys (Saitek)
DRV:64bit: - (SaiU0CFA) -- C:\Windows\SysNative\drivers\SaiU0CFA.sys (Saitek)
DRV:64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (kl2) -- C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) -- C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8192su) -- C:\Windows\SysNative\drivers\rtl8192su.sys (Realtek Semiconductor Corporation                          )
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (ScreamBAudioSvc) -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) -- C:\Windows\SysNative\drivers\s0017unic.sys (MCCI Corporation)
DRV:64bit: - (s0017obex) -- C:\Windows\SysNative\drivers\s0017obex.sys (MCCI Corporation)
DRV:64bit: - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) -- C:\Windows\SysNative\drivers\s0017nd5.sys (MCCI Corporation)
DRV:64bit: - (s0017mdm) -- C:\Windows\SysNative\drivers\s0017mdm.sys (MCCI Corporation)
DRV:64bit: - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\drivers\s0017mgmt.sys (MCCI Corporation)
DRV:64bit: - (s0017mdfl) -- C:\Windows\SysNative\drivers\s0017mdfl.sys (MCCI Corporation)
DRV:64bit: - (s0017bus) Sony Ericsson Device 0017 driver (WDM) -- C:\Windows\SysNative\drivers\s0017bus.sys (MCCI Corporation)
DRV:64bit: - (regi) -- C:\Windows\SysNative\drivers\regi.sys (InterVideo)
DRV:64bit: - (6077757b) -- C:\Windows\SysNative\drivers\regi.sys (InterVideo)
DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 47 9A DE 8E 85 6D CB 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.1
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.2.556
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.2.556
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011.01.07 23:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011.01.07 23:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.05.08 18:43:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.05.09 22:03:49 | 000,000,000 | ---D | M]
 
[2010.09.19 01:30:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2011.05.13 07:05:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions
[2011.05.10 21:39:16 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\wwjhbt5a.default\extensions\engine@conduit.com
[2010.11.20 12:19:48 | 000,002,059 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wwjhbt5a.default\searchplugins\daemon-search.xml
[2011.05.08 17:21:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.05.03 19:43:19 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files (x86)\mozilla firefox\extensions\KavAntiBanner@Kaspersky.ru
[2011.05.03 19:43:18 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- C:\Program Files (x86)\mozilla firefox\extensions\linkfilter@kaspersky.ru
File not found (No name found) --
() (No name found) -- C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\WWJHBT5A.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011.05.08 18:43:56 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2005.09.05 10:11:48 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files (x86)\mozilla firefox\plugins\npzylomgamesplayer.dll
[2011.05.08 18:43:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.05.08 18:43:57 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.05.08 18:43:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.05.08 18:43:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.05.08 18:43:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.05.08 18:43:57 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.01 15:59:50 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Cmaudio8788] C:\Windows\Syswow64\cmicnfgp.dll (C-Media Corporation)
O4:64bit: - HKLM..\Run: [Cmaudio8788GX] C:\Windows\syswow64\HsMgr.exe ()
O4:64bit: - HKLM..\Run: [Cmaudio8788GX64] C:\Windows\system\HsMgr64.exe ()
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Programme\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Programme\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O15 - HKCU\..Trusted Domains: die-staemme.de ([de71] * in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll (Kaspersky Lab ZAO)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.05.25 06:16:57 | 000,000,046 | -H-- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Error creating restore point.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.05.21 12:02:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SUPERAntiSpyware.com
[2011.05.21 12:02:15 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.05.21 12:02:11 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2011.05.21 12:02:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.05.21 12:02:09 | 000,000,000 | ---D | C] -- C:\Programme\SUPERAntiSpyware
[2011.05.19 20:27:43 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\LBZ ALPHA Game Data
[2011.05.19 20:23:27 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\LBZalphaversion
[2011.05.19 18:12:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LBZalphaversion
[2011.05.19 17:50:46 | 000,000,000 | -H-D | C] -- C:\Users\User\Documents\Runes of Magic
[2011.05.19 17:48:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runes of Magic
[2011.05.19 17:33:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Runes of Magic
[2011.05.18 18:31:52 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Runes_of_Magic_3.0.8.2349_full_EU
[2011.05.18 18:31:52 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\FOG Downloader
[2011.05.18 15:21:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Opera
[2011.05.18 15:21:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Opera
[2011.05.18 15:21:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2011.05.15 21:02:22 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\by_Niondir
[2011.05.15 21:01:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DS-Timer
[2011.05.12 19:54:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\IrfanView
[2011.05.12 17:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype Extras
[2011.05.12 17:48:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.05.12 17:48:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2011.05.10 18:31:34 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\gtk-2.0
[2011.05.10 16:49:58 | 000,000,000 | ---D | C] -- C:\Users\User\.thumbnails
[2011.05.10 16:47:02 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\gegl-0.0
[2011.05.10 16:47:02 | 000,000,000 | ---D | C] -- C:\Users\User\.gimp-2.6
[2011.05.10 16:43:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.05.10 16:08:10 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2011.05.10 16:08:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2011.05.10 15:40:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Saitek SD6 Profiles
[2011.05.10 15:39:15 | 000,050,056 | ---- | C] (Saitek) -- C:\Windows\SysNative\drivers\SaiBus.sys
[2011.05.10 15:39:15 | 000,022,792 | ---- | C] (Saitek) -- C:\Windows\SysNative\drivers\SaiMini.sys
[2011.05.10 15:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Technology
[2011.05.10 15:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Saitek
[2011.05.10 15:38:48 | 000,000,000 | ---D | C] -- C:\Programme\Saitek
[2011.05.10 15:38:33 | 000,041,352 | ---- | C] (Saitek) -- C:\Windows\SysNative\drivers\SaiU0CFA.sys
[2011.05.10 15:38:31 | 000,174,600 | ---- | C] (Saitek) -- C:\Windows\SysNative\drivers\SaiK0CFA.sys
[2011.05.09 20:10:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Screaming Bee
[2011.05.09 18:21:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\.minecraft
[2011.05.03 19:43:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011.05.03 19:42:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011.05.03 19:42:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab
[2011.05.03 19:42:44 | 000,556,120 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2011.05.03 18:49:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.05.03 00:30:01 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.05.03 00:25:31 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.05.02 15:38:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\The Lord of the Rings Online
[2011.05.01 22:07:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Turbine
[2011.05.01 22:07:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\ApplicationHistory
[2011.05.01 22:06:27 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
[2011.05.01 21:42:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Codemasters
[2011.05.01 17:49:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\PMB Files
[2011.05.01 17:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2011.04.29 15:58:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.04.29 15:58:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.04.29 15:58:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.04.29 15:58:48 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.04.29 15:58:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.04.27 18:24:01 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.04.24 17:59:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2011.04.24 17:58:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011.04.24 17:58:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.24 17:58:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.24 17:58:48 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.04.24 17:58:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.22 14:22:18 | 001,642,740 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.05.22 14:22:18 | 000,707,446 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.05.22 14:22:18 | 000,661,064 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.05.22 14:22:18 | 000,153,038 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.05.22 14:22:18 | 000,125,254 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.05.22 14:22:11 | 000,016,624 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.22 14:22:11 | 000,016,624 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.22 14:17:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.21 12:03:47 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.05.19 20:59:58 | 000,004,306 | ---- | M] () -- C:\Users\User\Desktop\lbzwin.exe - Verknüpfung.lnk
[2011.05.19 17:48:30 | 000,001,952 | ---- | M] () -- C:\Users\User\Desktop\Runes of Magic.lnk
[2011.05.17 17:12:05 | 000,001,393 | ---- | M] () -- C:\Users\User\Desktop\Heroes of Newerth.lnk
[2011.05.12 22:33:58 | 000,000,011 | R--- | M] () -- C:\Windows\amunres.lsl
[2011.05.12 19:40:32 | 000,004,542 | ---- | M] () -- C:\Users\User\.recently-used.xbel
[2011.05.11 17:42:56 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.05.11 17:42:55 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011.05.10 15:38:32 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SaiK0CFA_01009.Wdf
[2011.05.09 18:22:23 | 000,270,142 | ---- | M] () -- C:\Users\User\Desktop\Minecraft.exe
[2011.05.03 19:53:22 | 000,151,619 | ---- | M] () -- C:\Windows\SysNative\drivers\klin.dat
[2011.05.03 19:53:22 | 000,107,075 | ---- | M] () -- C:\Windows\SysNative\drivers\klick.dat
[2011.05.03 19:42:44 | 000,556,120 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2011.05.01 22:07:15 | 000,000,092 | ---- | M] () -- C:\Users\User\AppData\Local\fusioncache.dat
[2011.05.01 22:07:10 | 001,669,102 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.05.01 15:59:50 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
 
========== Files Created - No Company Name ==========
 
[2011.05.21 12:02:10 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.05.19 20:59:58 | 000,004,306 | ---- | C] () -- C:\Users\User\Desktop\lbzwin.exe - Verknüpfung.lnk
[2011.05.19 17:48:30 | 000,001,952 | ---- | C] () -- C:\Users\User\Desktop\Runes of Magic.lnk
[2011.05.17 17:12:05 | 000,001,393 | ---- | C] () -- C:\Users\User\Desktop\Heroes of Newerth.lnk
[2011.05.12 22:33:58 | 000,000,011 | R--- | C] () -- C:\Windows\amunres.lsl
[2011.05.12 19:40:32 | 000,004,542 | ---- | C] () -- C:\Users\User\.recently-used.xbel
[2011.05.11 17:42:56 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.05.11 17:42:55 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011.05.10 15:38:32 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SaiK0CFA_01009.Wdf
[2011.05.09 18:22:23 | 000,270,142 | ---- | C] () -- C:\Users\User\Desktop\Minecraft.exe
[2011.05.08 18:44:00 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.05.03 19:43:15 | 000,151,619 | ---- | C] () -- C:\Windows\SysNative\drivers\klin.dat
[2011.05.03 19:43:15 | 000,107,075 | ---- | C] () -- C:\Windows\SysNative\drivers\klick.dat
[2011.05.01 22:07:15 | 000,000,092 | ---- | C] () -- C:\Users\User\AppData\Local\fusioncache.dat
[2011.04.29 15:58:50 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.04.29 15:58:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.04.29 15:58:50 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.04.29 15:58:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.04.29 15:58:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.03.31 20:00:33 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.03.30 17:43:19 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011.03.30 17:43:19 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011.03.29 19:10:22 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011.03.29 19:10:13 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011.02.18 22:50:16 | 000,003,113 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.02.04 23:12:16 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2011.02.04 23:12:16 | 000,000,048 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2011.02.04 23:12:15 | 000,042,386 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2011.02.04 23:12:12 | 000,000,909 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2011.02.04 23:12:08 | 000,004,969 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2011.02.04 23:12:08 | 000,000,560 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2011.02.02 22:53:43 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2011.01.07 20:38:28 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2011.01.07 20:38:28 | 000,000,088 | RHS- | C] () -- C:\ProgramData\612C76385A.sys
[2010.11.28 16:32:02 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010.11.13 19:09:13 | 001,669,102 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.05 19:33:54 | 000,001,790 | ---- | C] () -- C:\Users\User\AppData\Roaming\Profile0.dat
[2010.10.05 18:24:04 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.09.26 10:36:15 | 000,000,016 | ---- | C] () -- C:\Windows\popcinfo.dat
[2010.09.26 08:38:42 | 000,000,120 | ---- | C] () -- C:\Windows\disney.ini
[2010.09.23 19:04:59 | 000,007,605 | ---- | C] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2010.09.23 18:42:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.09.19 02:03:50 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.09.19 01:30:06 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.09.18 23:25:30 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.09.18 23:25:29 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.09.18 23:25:28 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2003.02.20 15:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI
[2002.09.18 00:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
 
========== LOP Check ==========
 
[2011.05.09 18:21:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\.minecraft
[2011.02.02 22:53:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ASUS
[2011.03.30 17:45:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\avidemux
[2011.01.25 00:29:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canneverbe Limited
[2011.05.10 16:43:53 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010.09.22 15:31:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\CPUControl
[2011.03.30 17:37:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Cuttermaran
[2010.11.20 14:00:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2010.09.22 13:19:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Net
[2010.12.25 04:52:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.18 18:31:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FOG Downloader
[2011.05.12 19:39:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\gtk-2.0
[2011.01.14 18:19:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HandBrake
[2011.03.29 16:25:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC
[2011.03.29 16:25:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011.05.21 12:17:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IrfanView
[2011.01.07 21:00:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\mkvtoolnix
[2011.04.01 14:34:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\NetSpeedMonitor
[2011.04.17 16:33:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Notepad++
[2011.05.21 12:16:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Opera
[2011.03.15 21:05:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Petroglyph
[2010.09.19 00:42:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Reviversoft
[2011.01.22 12:24:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Rovio
[2011.05.09 20:10:00 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Screaming Bee
[2011.02.25 16:39:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TeamViewer
[2010.09.26 16:15:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\The Creative Assembly
[2010.09.26 09:07:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Touchstone
[2011.01.08 00:16:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2011.01.07 23:35:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ubisoft
[2011.01.07 20:51:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Xilisoft
[2011.03.29 23:10:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\XMedia Recode
[2010.09.26 10:36:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Zylom
[2011.05.22 14:17:02 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.05.09 18:21:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\.minecraft
[2011.03.29 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Adobe
[2010.09.20 05:56:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Apple Computer
[2011.02.02 22:53:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ASUS
[2010.09.23 18:43:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ATI
[2011.03.30 17:45:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\avidemux
[2011.01.25 00:29:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canneverbe Limited
[2011.05.10 16:43:53 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.01.07 20:38:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Corel
[2010.09.22 15:31:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\CPUControl
[2011.03.30 17:37:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Cuttermaran
[2010.11.20 14:00:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2010.09.22 13:19:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Net
[2010.10.15 14:53:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DivX
[2011.02.04 23:11:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Download Manager
[2011.04.09 15:43:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\dvdcss
[2010.12.25 04:52:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.05.18 18:31:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FOG Downloader
[2011.05.12 19:39:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\gtk-2.0
[2011.01.14 18:19:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HandBrake
[2011.03.29 16:25:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC
[2011.03.29 16:25:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2010.09.26 10:36:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Identities
[2011.03.15 20:52:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\InstallShield
[2011.05.21 12:17:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IrfanView
[2010.09.18 23:12:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Macromedia
[2011.04.24 17:59:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Media Center Programs
[2011.04.01 14:40:28 | 000,000,000 | --SD | M] -- C:\Users\User\AppData\Roaming\Microsoft
[2011.03.12 17:39:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\mIRC
[2011.01.07 21:00:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\mkvtoolnix
[2010.09.19 01:30:09 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mozilla
[2010.11.21 11:16:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Nero
[2011.04.01 14:34:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\NetSpeedMonitor
[2011.04.17 16:33:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Notepad++
[2011.05.21 12:16:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Opera
[2011.03.15 21:05:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Petroglyph
[2010.09.19 00:42:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Reviversoft
[2011.01.22 12:24:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Rovio
[2011.05.09 20:10:00 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Screaming Bee
[2011.03.03 22:54:45 | 000,000,000 | R--D | M] -- C:\Users\User\AppData\Roaming\SecuROM
[2011.05.22 18:22:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Skype
[2011.05.22 16:07:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\skypePM
[2011.05.21 12:02:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SUPERAntiSpyware.com
[2011.02.25 16:39:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TeamViewer
[2010.09.26 16:15:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\The Creative Assembly
[2010.09.26 09:07:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Touchstone
[2011.01.08 00:16:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2011.01.07 23:35:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ubisoft
[2011.04.09 15:44:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\vlc
[2010.09.19 13:12:12 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WinRAR
[2011.01.07 20:51:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Xilisoft
[2011.03.29 23:10:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\XMedia Recode
[2010.09.26 10:36:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Zylom
 
< %APPDATA%\*.exe /s >
[2011.03.29 16:22:41 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\User\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\ERDNT\cache64\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache86\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\ERDNT\cache64\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\ERDNT\cache64\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\ERDNT\cache86\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache86\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\ERDNT\cache64\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\ERDNT\cache64\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\ERDNT\cache86\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache86\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\ERDNT\cache64\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\ERDNT\cache64\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache86\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2009.07.14 03:15:20 | 000,380,957 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\expsrv.dll
[2009.07.14 03:15:50 | 001,386,496 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\msvbvm60.dll

< End of report >

--- --- ---

cosinus 23.05.2011 09:27

Zitat:

Trojan.Agent/Gen-FakeAlert[WinFiles]
C:\PROGRAM FILES (X86)\BBO ALMANACH\ALMANACH\ALMANACH.EXE

Trojan.Agent/Gen-Faldesc[RE]
C:\PROGRAM FILES (X86)\REFERENCE ASSEMBLIES\WMDRMSDKH.DLL

Trojan.Agent/Gen
D:\GAME IMAGES\ZYLOM\BEJEWELED 2 DELUXE\MEDIZIN\ZYLOM PATCHER.EXE
Diese Dateien sind dir bekannt?

Cloud84 23.05.2011 21:58

Reference Assemblies Bla bla ist mir nicht bekannt, und auch nicht so zu finden?
Auf jeden Fall hab ich die anderen beiden grade gelöscht.

cosinus 24.05.2011 11:22

Eine zusätzliche "Meinung" über das System verschafft uns auch der OnlineScanner von ESET:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Cloud84 24.05.2011 15:01

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=81b6183b3ed15c459debbf76a4954a89
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-24 01:52:27
# local_time=2011-05-24 03:52:27 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1280 16777215 100 0 1798801 1798801 0 0
# compatibility_mode=5893 16776574 100 94 5798720 58649042 0 0
# compatibility_mode=8192 67108863 100 0 110 110 0 0
# scanned=165875
# found=0
# cleaned=0
# scan_time=1776

cosinus 24.05.2011 17:24

Gut. Keine Funde.
Rechner wieder im Lot?

Cloud84 24.05.2011 20:29

Da der Virus mir bisher keine neuen Seiten durch die Googlesuche geöffnet hat, würde ich mal behaupten ja..Bin mir allerdings noch nicht zu 100% sicher.


Auf jeden fall ein großes Dankeschön, für die viele investierte Zeit & Mühe, bist wirklich ein klasse Helfer gewesen :heilig:

cosinus 24.05.2011 21:54

Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:38 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131