Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   [Schadprogramm] Windows Restore beseitigt und t.w. noch Probleme (https://www.trojaner-board.de/98419-schadprogramm-windows-restore-beseitigt-t-w-noch-probleme.html)

Drummer_Shoo 28.04.2011 18:32

[Schadprogramm] Windows Restore beseitigt und t.w. noch Probleme
 
Vor 2-3 Wochen hatte ich mir das Schadprogramm Windows Restore eingefangen und die Hilfestellungen hier im Forum angewand.
Soweit funktionierte der Rechner dann auch wieder relativ normal.

2 Dinge blieben jedoch:
1. Wurden Links über die google-Suche zum Teil weitergeleitet und auf zweifelhafte Seite verlinkt wo man als nächstes irgendwelche Programme installieren sollte. Ausserdem ist verlangsamt sich die Zugriffszeit auf Seiten nach einigen Stunden stark.
2. Es taucht während der Nutzung des Rechners auch immer wieder ein Scriptfehler auf, der auf eine Internetadresse (www2a.glam.com/mobile/detect.act?affiliateId=38198522) zurückzuführen ist.

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
 
Datenbank Version: 6336
 
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
 
11.04.2011 22:56:21
mbam-log-2011-04-11 (22-56-21).txt
 
Art des Suchlaufs: Vollständiger Suchlauf (C:\|N:\|)
Durchsuchte Objekte: 467047
Laufzeit: 1 Stunde(n), 23 Minute(n), 12 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 1
Infizierte Dateien: 5
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\oMaNKFWcCnXLENt (Trojan.FakeAlert) -> Value: oMaNKFWcCnXLENt -> Quarantined and deleted successfully.
 
Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 
Infizierte Verzeichnisse:
c:\Users\Melms\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 
Infizierte Dateien:
c:\programdata\omankfwccnxlent.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Melms\AppData\LocalLow\Sun\Java\deployment\cache\6.0\19\6a44c13-186c571b (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\34791176.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Melms\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore\uninstall windows restore.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Melms\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore\windows restore.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
 
Datenbank Version: 6336
 
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
 
14.04.2011 21:49:38
mbam-log-2011-04-14 (21-49-38).txt
 
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 159030
Laufzeit: 5 Minute(n), 52 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
 
Datenbank Version: 6459
 
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
 
27.04.2011 23:31:49
mbam-log-2011-04-27 (23-31-49).txt
 
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 154773
Laufzeit: 4 Minute(n), 17 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien:
c:\Windows\System32\spool\prtprocs\w32x86\7352869.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
 
Datenbank Version: 6459
 
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
 
28.04.2011 08:29:08
mbam-log-2011-04-28 (08-29-08).txt
 
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 154831
Laufzeit: 5 Minute(n), 4 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
 
Datenbank Version: 6459
 
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
 
28.04.2011 19:50:11
mbam-log-2011-04-28 (19-50-11).txt
 
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 155344
Laufzeit: 5 Minute(n), 18 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
 
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

OTL logfile created on: 28.04.2011 08:17:53 - Run 2
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Melms\Desktop
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 44,00% Memory free
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 60,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 443,13 Gb Total Space | 313,72 Gb Free Space | 70,80% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Unable to calculate disk information.
Drive N: | 232,83 Gb Total Space | 108,88 Gb Free Space | 46,77% Space Free | Partition Type: FAT32
 
Computer Name: MELMS-PC | User Name: Melms | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.04.20 23:43:35 | 013,007,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SoftwareDistribution\Download\Install\windows-kb890830-v3.18.exe
PRC - [2011.04.18 15:46:44 | 000,079,304 | ---- | M] (Microsoft Corporation) -- c:\ecebd7d2dd50074cfa1593d09b\mrtstub.exe
PRC - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
PRC - [2011.03.28 15:41:14 | 001,910,152 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011.03.21 07:49:56 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.02.15 03:32:52 | 001,230,704 | ---- | M] () -- C:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.09 12:45:58 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Winamp\winampa.exe
PRC - [2010.11.12 19:53:18 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Java\jre6\bin\java.exe
PRC - [2010.11.03 09:32:50 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.11.03 09:32:50 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.06.18 19:38:22 | 000,619,800 | ---- | M] (hxxp://tortoisesvn.net) -- C:\Programme\TortoiseSVN\bin\TSVNCache.exe
PRC - [2010.06.13 13:54:52 | 004,574,208 | ---- | M] (Shareaza Development Team) -- C:\Programme\Shareaza\Shareaza.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2010.04.16 22:12:28 | 003,872,080 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Messenger\msnmsgr.exe
PRC - [2010.03.22 12:50:18 | 000,219,976 | ---- | M] () -- C:\Programme\BumpTop\TexHelper.exe
PRC - [2010.03.22 12:49:58 | 007,162,184 | ---- | M] () -- C:\Programme\BumpTop\BumpTop.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.11.20 13:17:54 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Programme\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2008.11.04 11:06:36 | 001,105,920 | ---- | M] (TerraTec Electronic GmbH) -- C:\Programme\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2007.09.11 00:43:54 | 000,067,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Photoshop Elements 6.0\apdproxy.exe
PRC - [2007.07.11 18:18:54 | 000,237,568 | ---- | M] () -- C:\Windows\tsnp2uvc.exe
PRC - [2007.03.22 11:09:18 | 000,132,704 | ---- | M] (ashampoo Technology GmbH & Co. KG) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\defragMonitorService.exe
PRC - [2007.03.22 11:09:16 | 004,540,120 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe
PRC - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
PRC - [2007.03.22 11:09:16 | 000,079,456 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\defragActivityMonitor.exe
PRC - [2006.07.09 21:58:00 | 001,777,664 | ---- | M] (Idea2) -- C:\Programme\Desktop Sidebar\dsidebar.exe
PRC - [2005.03.08 12:46:00 | 000,651,264 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\StCenter.exe
PRC - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE
PRC - [2004.12.09 13:14:34 | 001,068,032 | ---- | M] (Nokia Mobile Phones Ltd.) -- C:\Programme\Common Files\PCSuite\DataLayer\DataLayer.exe
PRC - [2004.12.01 14:20:28 | 000,456,192 | ---- | M] (Nokia Corporation) -- C:\Programme\Common Files\Nokia\MPAPI\MPAPI3s.exe
PRC - [2004.11.25 13:59:06 | 000,143,360 | ---- | M] (Nokia) -- C:\Programme\Nokia\Nokia PC Suite 6\Launch Application 2.exe
PRC - [2004.11.24 13:29:38 | 000,880,640 | ---- | M] (Time Information Services Ltd.) -- C:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe
PRC - [2004.11.16 12:55:16 | 000,089,088 | ---- | M] (Nokia.) -- C:\Programme\Common Files\PCSuite\Services\ServiceLayer.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.12.21 07:38:22 | 000,350,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010.11.03 09:32:50 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.07.04 11:44:03 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) [Auto | Running] -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe -- (AshampooDefragService)
SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005.03.04 12:42:08 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Programme\Common Files\AVM\De_serv.exe -- (de_serv)
SRV - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.03.20 11:42:20 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.11.22 23:55:16 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.10.13 22:49:42 | 000,022,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbsermpt.sys -- (usbsermpt)
DRV - [2010.08.14 17:59:32 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.08.14 17:59:32 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.07.10 06:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.12.22 02:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009.11.20 13:15:18 | 000,137,728 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2009.11.20 13:15:16 | 000,058,880 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.05.05 03:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV - [2009.04.29 15:37:26 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTERx86)
DRV - [2009.03.18 17:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.05.02 11:58:14 | 000,020,864 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008.05.02 11:58:14 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2008.05.02 11:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2007.07.27 12:46:06 | 000,251,680 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2007.07.27 10:13:08 | 000,330,144 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007.05.11 16:17:25 | 000,221,184 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Cinergy_HT_PCI_MKII.sys -- (Cinergy_HT_PCI_MKII) Cinergy HT PCI (MKII)
DRV - [2004.07.14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 13 EE 64 48 11 CB 01  [binary data]
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://www.gmx.net/"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..extensions.enabledItems: longurlplease@darragh.curran:0.4.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: FirefoxAddon@similarWeb.com:1.2.06
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.21 07:49:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.19 11:55:34 | 000,000,000 | ---D | M]
 
[2010.06.26 15:07:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Extensions
[2011.04.15 23:44:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions
[2011.02.04 09:34:03 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2011.01.14 09:29:30 | 000,000,000 | ---D | M] ("CoolPreviews") -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2011.03.12 09:14:20 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011.02.19 16:23:41 | 000,000,000 | ---D | M] (SimilarWeb) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\FirefoxAddon@similarWeb.com
[2011.03.27 11:05:20 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\toolbar@ask.com
[2011.04.25 23:21:55 | 000,001,056 | ---- | M] () -- C:\Users\Melms\AppData\Roaming\Mozilla\Firefox\Profiles\xsdvpeay.default\searchplugins\icqplugin.xml
[2011.03.19 11:55:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) --
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
[2011.03.21 07:49:56 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.11.12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.06.21 17:10:13 | 000,072,960 | ---- | M] (Foxit Software Company) -- C:\Programme\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010.12.09 12:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Programme\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DataLayer] C:\Programme\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe (Nokia)
O4 - HKLM..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe ()
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKCU..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (Shareaza Development Team)
O4 - HKCU..\Run: [SIDEBAR] C:\Program Files\Desktop Sidebar\dsidebar.exe (Idea2)
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TV-Browser.url ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Download with &Shareaza - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell\AutoRun\command - "" = F:\EasySuite.exe
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell\AutoRun\command - "" = K:\autorun.exe de
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.28 08:17:32 | 000,000,000 | ---D | C] -- C:\ecebd7d2dd50074cfa1593d09b
[2011.04.22 17:45:07 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.04.22 17:16:59 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Local\Electronic_Arts_Inc
[2011.04.18 19:48:41 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2011.04.11 21:18:53 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Malwarebytes
[2011.04.11 21:18:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.11 21:18:48 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.11 21:18:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.11 21:18:45 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.11 21:17:26 | 007,734,208 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Melms\Desktop\herbert.exe
[2011.04.11 20:21:31 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
[2011.04.10 15:32:20 | 000,000,000 | ---D | C] -- C:\Programme\Yuna Software
[2011.04.01 15:04:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.4
[2011.04.01 15:03:56 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.4
[2011.04.01 13:20:30 | 000,026,176 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\hamachi.sys
[2011.04.01 13:20:28 | 000,000,000 | ---D | C] -- C:\Programme\LogMeIn Hamachi
[2011.04.01 13:20:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011.03.29 09:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!Box
[2011.03.29 09:55:12 | 000,053,760 | R--- | C] (AVM GmbH) -- C:\Windows\System32\avmadd32.dll
[2010.10.11 21:12:07 | 000,180,224 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.28 08:20:48 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 08:20:48 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 08:19:41 | 000,668,302 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.28 08:19:41 | 000,619,894 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.28 08:19:41 | 000,134,150 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.28 08:19:41 | 000,110,082 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.28 08:19:05 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.28 08:13:34 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.28 08:13:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.28 08:13:19 | 1610,309,632 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.27 21:58:56 | 000,010,610 | ---- | M] () -- C:\Users\Melms\Desktop\schafe.png
[2011.04.27 21:34:00 | 000,014,591 | ---- | M] () -- C:\Users\Melms\Desktop\7lx41k8ykeq.png
[2011.04.25 20:56:50 | 005,722,575 | ---- | M] () -- C:\Users\Melms\Desktop\newstime_ausgabe43.pdf
[2011.04.22 17:16:39 | 000,002,167 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.04.21 18:58:11 | 000,293,488 | ---- | M] () -- C:\Users\Melms\Desktop\driving-at-night-1280x960.jpg
[2011.04.16 22:50:30 | 000,000,381 | ---- | M] () -- C:\Windows\BeatBox.INI
[2011.04.16 22:50:30 | 000,000,028 | ---- | M] () -- C:\Windows\Robota.INI
[2011.04.15 20:14:58 | 000,334,200 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.12 18:00:16 | 000,025,336 | ---- | M] () -- C:\Users\Melms\Desktop\Checkliste Unterlagen ESt.pdf
[2011.04.11 22:59:52 | 000,504,657 | ---- | M] () -- C:\Users\Melms\Desktop\unhide.exe
[2011.04.11 21:18:49 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.11 21:17:42 | 007,734,208 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Melms\Desktop\herbert.exe
[2011.04.11 21:10:03 | 320,021,172 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.04.11 21:07:59 | 001,006,778 | ---- | M] () -- C:\Users\Melms\Desktop\iExplorer.exe.com
[2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
[2011.04.11 20:08:44 | 000,000,392 | ---- | M] () -- C:\ProgramData\34791176
[2011.04.11 20:06:52 | 000,000,136 | ---- | M] () -- C:\ProgramData\~34791176r
[2011.04.11 20:06:52 | 000,000,104 | ---- | M] () -- C:\ProgramData\~34791176
[2011.04.02 18:44:40 | 000,420,467 | ---- | M] () -- C:\Users\Melms\Desktop\image.png
[2011.03.30 21:39:07 | 000,001,236 | ---- | M] () -- C:\Users\Melms\Desktop\Eigene Dateien.lnk
[2011.03.30 21:38:54 | 000,000,798 | ---- | M] () -- C:\Users\Melms\Desktop\mircG5.0.exe - Verknüpfung.lnk
[2011.03.29 09:56:06 | 000,000,994 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.04.27 21:58:56 | 000,010,610 | ---- | C] () -- C:\Users\Melms\Desktop\schafe.png
[2011.04.27 21:33:54 | 000,014,591 | ---- | C] () -- C:\Users\Melms\Desktop\7lx41k8ykeq.png
[2011.04.25 20:56:38 | 005,722,575 | ---- | C] () -- C:\Users\Melms\Desktop\newstime_ausgabe43.pdf
[2011.04.22 17:16:39 | 000,002,167 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.04.21 18:58:00 | 000,293,488 | ---- | C] () -- C:\Users\Melms\Desktop\driving-at-night-1280x960.jpg
[2011.04.12 18:00:15 | 000,025,336 | ---- | C] () -- C:\Users\Melms\Desktop\Checkliste Unterlagen ESt.pdf
[2011.04.11 22:59:53 | 000,504,657 | ---- | C] () -- C:\Users\Melms\Desktop\unhide.exe
[2011.04.11 21:18:49 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.11 21:10:03 | 320,021,172 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.04.11 21:07:56 | 001,006,778 | ---- | C] () -- C:\Users\Melms\Desktop\iExplorer.exe.com
[2011.04.11 20:02:31 | 000,000,136 | ---- | C] () -- C:\ProgramData\~34791176r
[2011.04.11 20:02:30 | 000,000,104 | ---- | C] () -- C:\ProgramData\~34791176
[2011.04.11 20:02:28 | 000,000,392 | ---- | C] () -- C:\ProgramData\34791176
[2011.04.02 18:44:38 | 000,420,467 | ---- | C] () -- C:\Users\Melms\Desktop\image.png
[2011.03.20 20:48:15 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.02.27 01:45:09 | 000,000,381 | ---- | C] () -- C:\Windows\BeatBox.INI
[2011.02.27 01:45:09 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2011.02.27 00:58:31 | 000,124,596 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011.02.05 20:09:24 | 000,139,152 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.02.05 20:09:18 | 000,139,152 | ---- | C] () -- C:\Users\Melms\AppData\Roaming\PnkBstrK.sys
[2011.02.05 20:08:43 | 000,111,928 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.02.05 20:08:40 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2011.02.05 20:08:40 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.02.03 21:56:57 | 000,000,019 | ---- | C] () -- C:\Windows\SoundConverter.INI
[2010.12.29 21:00:43 | 000,000,180 | ---- | C] () -- C:\Windows\System32\msftpd.exe
[2010.12.19 20:34:53 | 000,000,221 | ---- | C] () -- C:\Windows\SOFTEK.INI
[2010.10.19 17:18:19 | 000,002,464 | ---- | C] () -- C:\Windows\netdet.ini
[2010.10.15 21:00:00 | 000,006,656 | ---- | C] () -- C:\Users\Melms\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.11 21:12:07 | 000,237,568 | ---- | C] () -- C:\Windows\tsnp2uvc.exe
[2010.08.28 19:41:48 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2010.08.28 19:34:40 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.08.28 19:34:13 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2010.08.14 17:26:47 | 000,007,597 | ---- | C] () -- C:\Users\Melms\AppData\Local\Resmon.ResmonCfg
[2010.08.14 17:14:19 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010.08.14 17:14:14 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2010.07.27 13:00:39 | 000,000,614 | ---- | C] () -- C:\Windows\eReg.dat
[2010.07.04 11:29:04 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2009.08.03 00:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2009.07.14 10:47:43 | 000,668,302 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,134,150 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,334,200 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,619,894 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,110,082 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2010.07.20 15:35:15 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\#Company short name
[2011.01.23 20:41:11 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Aston
[2011.01.23 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Bump Technologies, Inc
[2011.04.27 23:35:21 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Desktop Sidebar
[2010.12.29 14:42:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FileZilla
[2010.06.21 17:10:18 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Foxit
[2010.10.09 10:25:23 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Foxit Software
[2011.03.13 11:46:42 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FRITZ!
[2011.04.27 23:19:21 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\ICQ
[2010.11.14 21:51:58 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Jasc
[2010.08.29 13:58:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Lern-o-Mat
[2010.08.28 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\MAGIX
[2011.04.22 17:45:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.02.21 23:21:18 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Nokia Multimedia Player
[2010.07.04 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\OpenOffice.org
[2011.02.21 23:18:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\PC Suite
[2011.02.16 13:00:53 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Shareaza
[2010.06.26 20:34:09 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra
[2010.06.26 20:20:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra Entertainment
[2010.06.27 21:49:29 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Subversion
[2010.06.26 18:59:17 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TerraTec
[2010.10.31 14:46:00 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Tokback
[2011.04.28 08:13:44 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2011.02.16 23:05:57 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\wargaming.net
[2011.03.25 15:10:55 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 16 bytes -> C:\Users\Melms\Downloads:Shareaza.GUID
 
< End of report >

Code:

OTL logfile created on: 28.04.2011 21:27:50 - Run 3
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Melms\Desktop
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 39,00% Memory free
4,00 Gb Paging File | 1,00 Gb Available in Paging File | 36,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 443,13 Gb Total Space | 312,99 Gb Free Space | 70,63% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Unable to calculate disk information.
Drive N: | 232,83 Gb Total Space | 108,88 Gb Free Space | 46,77% Space Free | Partition Type: FAT32
 
Computer Name: MELMS-PC | User Name: Melms | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
PRC - [2011.04.01 15:04:02 | 000,119,608 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.4\ICQ.exe
PRC - [2011.03.28 15:41:14 | 001,910,152 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011.03.21 07:49:56 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.02.15 03:32:52 | 001,230,704 | ---- | M] () -- C:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.09 12:47:04 | 001,595,744 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Winamp\winamp.exe
PRC - [2010.12.09 12:45:58 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Winamp\winampa.exe
PRC - [2010.11.12 19:53:18 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Java\jre6\bin\java.exe
PRC - [2010.11.03 09:32:50 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.11.03 09:32:50 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.09.01 06:26:04 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmplayer.exe
PRC - [2010.06.18 19:38:22 | 000,619,800 | ---- | M] (hxxp://tortoisesvn.net) -- C:\Programme\TortoiseSVN\bin\TSVNCache.exe
PRC - [2010.06.13 13:54:52 | 004,574,208 | ---- | M] (Shareaza Development Team) -- C:\Programme\Shareaza\Shareaza.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2010.05.14 11:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Common Files\Java\Java Update\jucheck.exe
PRC - [2010.04.16 22:12:28 | 003,872,080 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Messenger\msnmsgr.exe
PRC - [2010.04.16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Contacts\wlcomm.exe
PRC - [2010.03.22 12:50:18 | 000,219,976 | ---- | M] () -- C:\Programme\BumpTop\TexHelper.exe
PRC - [2010.03.22 12:49:58 | 007,162,184 | ---- | M] () -- C:\Programme\BumpTop\BumpTop.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.11.20 13:17:54 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Programme\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2008.11.04 11:26:04 | 006,209,536 | ---- | M] (TerraTec Electronic GmbH) -- C:\Programme\TerraTec\TerraTec Home Cinema\CinergyDvr.exe
PRC - [2008.11.04 11:06:36 | 001,105,920 | ---- | M] (TerraTec Electronic GmbH) -- C:\Programme\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2007.11.01 20:57:24 | 002,756,096 | ---- | M] (mIRC Co. Ltd.) -- N:\[G]Script50\mircG5.0.exe
PRC - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2007.09.11 00:43:54 | 000,067,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Photoshop Elements 6.0\apdproxy.exe
PRC - [2007.07.11 18:18:54 | 000,237,568 | ---- | M] () -- C:\Windows\tsnp2uvc.exe
PRC - [2007.03.22 11:09:16 | 004,540,120 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe
PRC - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
PRC - [2006.07.09 21:58:00 | 001,777,664 | ---- | M] (Idea2) -- C:\Programme\Desktop Sidebar\dsidebar.exe
PRC - [2005.03.08 12:46:00 | 000,651,264 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\StCenter.exe
PRC - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE
PRC - [2004.12.09 13:14:34 | 001,068,032 | ---- | M] (Nokia Mobile Phones Ltd.) -- C:\Programme\Common Files\PCSuite\DataLayer\DataLayer.exe
PRC - [2004.12.01 14:20:28 | 000,456,192 | ---- | M] (Nokia Corporation) -- C:\Programme\Common Files\Nokia\MPAPI\MPAPI3s.exe
PRC - [2004.11.25 13:59:06 | 000,143,360 | ---- | M] (Nokia) -- C:\Programme\Nokia\Nokia PC Suite 6\Launch Application 2.exe
PRC - [2004.11.24 13:29:38 | 000,880,640 | ---- | M] (Time Information Services Ltd.) -- C:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe
PRC - [2004.11.16 12:55:16 | 000,089,088 | ---- | M] (Nokia.) -- C:\Programme\Common Files\PCSuite\Services\ServiceLayer.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.12.21 07:38:22 | 000,350,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010.11.03 09:32:50 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.07.04 11:44:03 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) [Auto | Running] -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe -- (AshampooDefragService)
SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005.03.04 12:42:08 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Programme\Common Files\AVM\De_serv.exe -- (de_serv)
SRV - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.03.20 11:42:20 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.11.22 23:55:16 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.10.13 22:49:42 | 000,022,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbsermpt.sys -- (usbsermpt)
DRV - [2010.08.14 17:59:32 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.08.14 17:59:32 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.07.10 06:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.12.22 02:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009.11.20 13:15:18 | 000,137,728 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2009.11.20 13:15:16 | 000,058,880 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.05.05 03:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV - [2009.04.29 15:37:26 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTERx86)
DRV - [2009.03.18 17:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.05.02 11:58:14 | 000,020,864 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008.05.02 11:58:14 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2008.05.02 11:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2007.07.27 12:46:06 | 000,251,680 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2007.07.27 10:13:08 | 000,330,144 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007.05.11 16:17:25 | 000,221,184 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Cinergy_HT_PCI_MKII.sys -- (Cinergy_HT_PCI_MKII) Cinergy HT PCI (MKII)
DRV - [2004.07.14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 13 EE 64 48 11 CB 01  [binary data]
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://www.gmx.net/"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..extensions.enabledItems: longurlplease@darragh.curran:0.4.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: FirefoxAddon@similarWeb.com:1.2.06
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.21 07:49:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.19 11:55:34 | 000,000,000 | ---D | M]
 
[2010.06.26 15:07:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Extensions
[2011.04.15 23:44:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions
[2011.02.04 09:34:03 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2011.01.14 09:29:30 | 000,000,000 | ---D | M] ("CoolPreviews") -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2011.03.12 09:14:20 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011.02.19 16:23:41 | 000,000,000 | ---D | M] (SimilarWeb) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\FirefoxAddon@similarWeb.com
[2011.03.27 11:05:20 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\toolbar@ask.com
[2011.04.25 23:21:55 | 000,001,056 | ---- | M] () -- C:\Users\Melms\AppData\Roaming\Mozilla\Firefox\Profiles\xsdvpeay.default\searchplugins\icqplugin.xml
[2011.03.19 11:55:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) --
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
[2011.03.21 07:49:56 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2010.11.12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.06.21 17:10:13 | 000,072,960 | ---- | M] (Foxit Software Company) -- C:\Programme\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010.12.09 12:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Programme\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DataLayer] C:\Programme\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe (Nokia)
O4 - HKLM..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe ()
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKCU..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (Shareaza Development Team)
O4 - HKCU..\Run: [SIDEBAR] C:\Program Files\Desktop Sidebar\dsidebar.exe (Idea2)
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TV-Browser.url ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Download with &Shareaza - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell\AutoRun\command - "" = F:\EasySuite.exe
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell\AutoRun\command - "" = K:\autorun.exe de
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.22 17:45:07 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.04.22 17:16:59 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Local\Electronic_Arts_Inc
[2011.04.18 19:48:41 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2011.04.11 21:18:53 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Malwarebytes
[2011.04.11 21:18:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.11 21:18:48 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.11 21:18:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.11 21:18:45 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.11 21:17:26 | 007,734,208 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Melms\Desktop\herbert.exe
[2011.04.11 20:21:31 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
[2011.04.10 15:32:20 | 000,000,000 | ---D | C] -- C:\Programme\Yuna Software
[2011.04.01 15:04:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.4
[2011.04.01 15:03:56 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.4
[2011.04.01 13:20:30 | 000,026,176 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\hamachi.sys
[2011.04.01 13:20:28 | 000,000,000 | ---D | C] -- C:\Programme\LogMeIn Hamachi
[2011.04.01 13:20:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2010.10.11 21:12:07 | 000,180,224 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.28 21:24:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.28 18:24:00 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.28 18:00:46 | 000,668,302 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.28 18:00:46 | 000,619,894 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.28 18:00:46 | 000,134,150 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.28 18:00:46 | 000,110,082 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.28 17:59:57 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 17:59:57 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 17:54:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.28 17:54:22 | 1610,309,632 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.25 20:56:50 | 005,722,575 | ---- | M] () -- C:\Users\Melms\Desktop\newstime_ausgabe43.pdf
[2011.04.22 17:16:39 | 000,002,167 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.04.16 22:50:30 | 000,000,381 | ---- | M] () -- C:\Windows\BeatBox.INI
[2011.04.16 22:50:30 | 000,000,028 | ---- | M] () -- C:\Windows\Robota.INI
[2011.04.15 20:14:58 | 000,334,200 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.12 18:00:16 | 000,025,336 | ---- | M] () -- C:\Users\Melms\Desktop\Checkliste Unterlagen ESt.pdf
[2011.04.11 22:59:52 | 000,504,657 | ---- | M] () -- C:\Users\Melms\Desktop\unhide.exe
[2011.04.11 21:18:49 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.11 21:17:42 | 007,734,208 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Melms\Desktop\herbert.exe
[2011.04.11 21:10:03 | 320,021,172 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.04.11 21:07:59 | 001,006,778 | ---- | M] () -- C:\Users\Melms\Desktop\iExplorer.exe.com
[2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
[2011.04.11 20:08:44 | 000,000,392 | ---- | M] () -- C:\ProgramData\34791176
[2011.04.11 20:06:52 | 000,000,136 | ---- | M] () -- C:\ProgramData\~34791176r
[2011.04.11 20:06:52 | 000,000,104 | ---- | M] () -- C:\ProgramData\~34791176
[2011.04.02 18:44:40 | 000,420,467 | ---- | M] () -- C:\Users\Melms\Desktop\image.png
[2011.03.30 21:39:07 | 000,001,236 | ---- | M] () -- C:\Users\Melms\Desktop\Eigene Dateien.lnk
[2011.03.30 21:38:54 | 000,000,798 | ---- | M] () -- C:\Users\Melms\Desktop\mircG5.0.exe - Verknüpfung.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.04.25 20:56:38 | 005,722,575 | ---- | C] () -- C:\Users\Melms\Desktop\newstime_ausgabe43.pdf
[2011.04.22 17:16:39 | 000,002,167 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.04.12 18:00:15 | 000,025,336 | ---- | C] () -- C:\Users\Melms\Desktop\Checkliste Unterlagen ESt.pdf
[2011.04.11 22:59:53 | 000,504,657 | ---- | C] () -- C:\Users\Melms\Desktop\unhide.exe
[2011.04.11 21:18:49 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.11 21:10:03 | 320,021,172 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.04.11 21:07:56 | 001,006,778 | ---- | C] () -- C:\Users\Melms\Desktop\iExplorer.exe.com
[2011.04.11 20:02:31 | 000,000,136 | ---- | C] () -- C:\ProgramData\~34791176r
[2011.04.11 20:02:30 | 000,000,104 | ---- | C] () -- C:\ProgramData\~34791176
[2011.04.11 20:02:28 | 000,000,392 | ---- | C] () -- C:\ProgramData\34791176
[2011.04.02 18:44:38 | 000,420,467 | ---- | C] () -- C:\Users\Melms\Desktop\image.png
[2011.03.20 20:48:15 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.02.27 01:45:09 | 000,000,381 | ---- | C] () -- C:\Windows\BeatBox.INI
[2011.02.27 01:45:09 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2011.02.27 00:58:31 | 000,124,596 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011.02.05 20:09:24 | 000,139,152 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.02.05 20:09:18 | 000,139,152 | ---- | C] () -- C:\Users\Melms\AppData\Roaming\PnkBstrK.sys
[2011.02.05 20:08:43 | 000,111,928 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.02.05 20:08:40 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2011.02.05 20:08:40 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.02.03 21:56:57 | 000,000,019 | ---- | C] () -- C:\Windows\SoundConverter.INI
[2010.12.29 21:00:43 | 000,000,180 | ---- | C] () -- C:\Windows\System32\msftpd.exe
[2010.12.19 20:34:53 | 000,000,221 | ---- | C] () -- C:\Windows\SOFTEK.INI
[2010.10.19 17:18:19 | 000,002,464 | ---- | C] () -- C:\Windows\netdet.ini
[2010.10.15 21:00:00 | 000,006,656 | ---- | C] () -- C:\Users\Melms\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.11 21:12:07 | 000,237,568 | ---- | C] () -- C:\Windows\tsnp2uvc.exe
[2010.08.28 19:41:48 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2010.08.28 19:34:40 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.08.28 19:34:13 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2010.08.14 17:26:47 | 000,007,597 | ---- | C] () -- C:\Users\Melms\AppData\Local\Resmon.ResmonCfg
[2010.08.14 17:14:19 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010.08.14 17:14:14 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2010.07.27 13:00:39 | 000,000,614 | ---- | C] () -- C:\Windows\eReg.dat
[2010.07.04 11:29:04 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2009.08.03 00:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2009.07.14 10:47:43 | 000,668,302 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,134,150 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,334,200 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,619,894 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,110,082 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2010.07.20 15:35:15 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\#Company short name
[2011.01.23 20:41:11 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Aston
[2011.01.23 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Bump Technologies, Inc
[2011.04.28 08:46:03 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Desktop Sidebar
[2010.12.29 14:42:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FileZilla
[2010.06.21 17:10:18 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Foxit
[2010.10.09 10:25:23 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Foxit Software
[2011.03.13 11:46:42 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FRITZ!
[2011.04.28 19:42:17 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\ICQ
[2010.11.14 21:51:58 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Jasc
[2010.08.29 13:58:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Lern-o-Mat
[2010.08.28 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\MAGIX
[2011.04.22 17:45:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.02.21 23:21:18 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Nokia Multimedia Player
[2010.07.04 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\OpenOffice.org
[2011.02.21 23:18:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\PC Suite
[2011.02.16 13:00:53 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Shareaza
[2010.06.26 20:34:09 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra
[2010.06.26 20:20:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra Entertainment
[2010.06.27 21:49:29 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Subversion
[2010.06.26 18:59:17 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TerraTec
[2010.10.31 14:46:00 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Tokback
[2011.04.28 21:14:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2011.02.16 23:05:57 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\wargaming.net
[2011.03.25 15:10:55 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 16 bytes -> C:\Users\Melms\Downloads:Shareaza.GUID
 
< End of report >


cosinus 06.05.2011 12:01

Die Scans sind schon etwas her. Bitte Malwarebytes updaten und einen neuen Vollscan machen.

Drummer_Shoo 06.05.2011 14:57

Hier die frische Log:

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6519

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

06.05.2011 15:01:26
mbam-log-2011-05-06 (15-01-26).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|N:\|)
Durchsuchte Objekte: 458406
Laufzeit: 1 Stunde(n), 25 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


cosinus 06.05.2011 18:00

Zitat:

OTL logfile created on: 28.04.2011 08:17:53 - Run 2
Bedeutet, dass das Log vom 2. Scan mit OTL ist - wo ist das Log vom ersten Durchgang?

Drummer_Shoo 06.05.2011 20:00

Wenn ich mich recht erinnere, gelöscht - evtl. überschrieben durch die 2. Log ...

cosinus 06.05.2011 20:42

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\Shell\AutoRun\command - "" = F:\EasySuite.exe
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell - "" = AutoRun
O33 - MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\Shell\AutoRun\command - "" = K:\autorun.exe de
[2011.04.11 20:08:44 | 000,000,392 | ---- | M] () -- C:\ProgramData\34791176
[2011.04.11 20:06:52 | 000,000,136 | ---- | M] () -- C:\ProgramData\~34791176r
[2011.04.11 20:06:52 | 000,000,104 | ---- | M] () -- C:\ProgramData\~34791176
@Alternate Data Stream - 16 bytes -> C:\Users\Melms\Downloads:Shareaza.GUID
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Drummer_Shoo 06.05.2011 21:24

Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280400cd-59da-11e0-b01d-6cf049e2f3ee}\ not found.
File F:\EasySuite.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2133406-85c9-11df-916f-6cf049e2f3ee}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a2133406-85c9-11df-916f-6cf049e2f3ee}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a2133406-85c9-11df-916f-6cf049e2f3ee}\ not found.
File K:\autorun.exe de not found.
C:\ProgramData\34791176 moved successfully.
C:\ProgramData\~34791176r moved successfully.
C:\ProgramData\~34791176 moved successfully.
Unable to delete ADS C:\Users\Melms\Downloads:Shareaza.GUID .
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Melms
->Temp folder emptied: 3251542807 bytes
->Temporary Internet Files folder emptied: 40645649 bytes
->Java cache emptied: 476687 bytes
->FireFox cache emptied: 103188202 bytes
->Flash cache emptied: 137944 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9537682 bytes
RecycleBin emptied: 11407047629 bytes
 
Total Files Cleaned = 14.126,00 mb
 
 
OTL by OldTimer - Version 3.2.22.3 log created on 05062011_221746

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


cosinus 07.05.2011 14:08

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Drummer_Shoo 08.05.2011 12:42

Ein Starten der .exe ist nicht möglich.
Nach dem Doppelklick auf die TDSSKiller.exe erscheint wie immer eine Bestätigungsabfrage durch Windows. Nach dem Klick auf "Ausführen" passiert dann allerdings nichts mehr. Auch mit "Als Administrator" ausführen passiert nichts.

cosinus 08.05.2011 14:33

Dann bitte jetzt CF ausführen, probier den tdsskiller danach nochmal.

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Drummer_Shoo 08.05.2011 15:04

Code:

ComboFix 11-05-07.02 - Melms 08.05.2011  15:52:28.1.2 - x86
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.2048.1190 [GMT 2:00]
ausgeführt von:: c:\users\Melms\Desktop\cofi.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\bassmod.dll
c:\program files\INSTALL.LOG
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-04-08 bis 2011-05-08  ))))))))))))))))))))))))))))))
.
.
2011-05-08 13:58 . 2011-05-08 13:59        --------        d-----w-        c:\users\Melms\AppData\Local\temp
2011-05-08 13:58 . 2011-05-08 13:58        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-05-07 05:53 . 2011-04-11 07:04        7071056        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{B438D3AE-3519-44F5-80FE-5157D9320E45}\mpengine.dll
2011-05-06 20:20 . 2011-05-06 20:31        --------        d-----w-        c:\users\Melms\AppData\Roaming\Nokia
2011-05-06 20:20 . 2011-05-06 20:20        --------        d-----w-        c:\users\Melms\AppData\Roaming\PC Suite
2011-05-06 20:20 . 2011-05-06 20:20        --------        d-----w-        c:\programdata\PC Suite
2011-05-06 20:17 . 2011-05-06 20:17        --------        d-----w-        C:\_OTL
2011-05-06 20:04 . 2011-05-06 20:04        --------        d-----w-        c:\program files\Common Files\PCSuite
2011-05-06 20:04 . 2011-05-06 20:04        --------        d-----w-        c:\program files\Common Files\Nokia
2011-05-06 20:03 . 2008-08-26 07:26        18816        ----a-w-        c:\windows\system32\drivers\pccsmcfd.sys
2011-05-06 20:03 . 2011-05-06 20:03        --------        d-----w-        c:\program files\PC Connectivity Solution
2011-05-06 20:00 . 2011-05-06 20:00        --------        d-----w-        c:\programdata\Installations
2011-05-05 16:55 . 2011-05-05 16:55        --------        d-----w-        c:\users\Melms\AppData\Local\FT Software Updates
2011-05-03 18:06 . 2011-05-03 18:06        --------        d-----w-        c:\program files\iPod
2011-05-03 18:06 . 2011-05-03 18:07        --------        d-----w-        c:\program files\iTunes
2011-05-03 18:04 . 2011-05-03 18:04        --------        d-----w-        c:\program files\Bonjour
2011-05-03 18:02 . 2011-05-03 18:02        --------        d-----w-        c:\program files\Common Files\Java
2011-04-27 15:55 . 2011-02-18 05:33        31232        ----a-w-        c:\windows\system32\prevhost.exe
2011-04-27 15:55 . 2011-03-11 05:44        146304        ----a-w-        c:\windows\system32\drivers\storport.sys
2011-04-27 15:55 . 2011-03-11 05:44        143744        ----a-w-        c:\windows\system32\drivers\nvstor.sys
2011-04-27 15:55 . 2011-03-11 05:44        1210240        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2011-04-27 15:55 . 2011-03-11 05:44        117120        ----a-w-        c:\windows\system32\drivers\nvraid.sys
2011-04-27 15:55 . 2011-03-11 05:43        80256        ----a-w-        c:\windows\system32\drivers\amdsata.sys
2011-04-27 15:55 . 2011-03-11 05:39        1686016        ----a-w-        c:\windows\system32\esent.dll
2011-04-27 15:55 . 2011-03-11 05:43        332160        ----a-w-        c:\windows\system32\drivers\iaStorV.sys
2011-04-27 15:55 . 2011-03-11 05:43        22400        ----a-w-        c:\windows\system32\drivers\amdxata.sys
2011-04-27 15:55 . 2011-03-11 05:37        74240        ----a-w-        c:\windows\system32\fsutil.exe
2011-04-27 15:55 . 2011-03-12 11:31        442880        ----a-w-        c:\windows\system32\XpsPrint.dll
2011-04-27 15:55 . 2011-02-26 05:33        2614784        ----a-w-        c:\windows\explorer.exe
2011-04-22 15:45 . 2011-04-22 15:45        --------        d-----w-        c:\users\Melms\AppData\Roaming\Need for Speed World
2011-04-22 15:16 . 2011-04-22 15:16        --------        d-----w-        c:\users\Melms\AppData\Local\Electronic_Arts_Inc
2011-04-18 17:48 . 2011-05-08 13:36        --------        d-----w-        c:\users\Melms\AppData\Roaming\TV-Browser
2011-04-14 15:53 . 2011-03-11 05:40        1164288        ----a-w-        c:\windows\system32\mfc42u.dll
2011-04-14 15:53 . 2011-03-11 05:40        1137664        ----a-w-        c:\windows\system32\mfc42.dll
2011-04-14 15:53 . 2011-02-23 05:05        221696        ----a-w-        c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 15:53 . 2011-02-23 05:05        95744        ----a-w-        c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 15:53 . 2011-02-23 05:05        123392        ----a-w-        c:\windows\system32\drivers\mrxsmb.sys
2011-04-14 15:53 . 2011-02-23 05:05        69632        ----a-w-        c:\windows\system32\drivers\bowser.sys
2011-04-11 19:18 . 2011-04-11 19:18        --------        d-----w-        c:\users\Melms\AppData\Roaming\Malwarebytes
2011-04-11 19:18 . 2011-04-11 19:18        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-11 19:18 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-11 19:18 . 2011-04-11 19:18        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-04-10 13:32 . 2011-04-10 13:32        --------        d-----w-        c:\program files\Yuna Software
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-28 18:15 . 2010-08-25 21:20        1152832        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-04-14 15:57 . 2011-01-13 19:12        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-04-14 15:57 . 2011-01-13 19:12        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-04-14 03:07 . 2010-07-17 07:13        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-04-06 14:20 . 2011-04-06 14:20        91424        ----a-w-        c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20        75040        ----a-w-        c:\windows\system32\jdns_sd.dll
2011-04-06 14:20 . 2011-04-06 14:20        197920        ----a-w-        c:\windows\system32\dnssdX.dll
2011-04-06 14:20 . 2011-04-06 14:20        107808        ----a-w-        c:\windows\system32\dns-sd.exe
2011-03-29 18:51 . 2010-06-26 13:27        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-03-29 18:51 . 2010-06-26 13:27        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-03-22 15:07 . 2011-03-20 18:48        43520        ----a-w-        c:\windows\system32\CmdLineExt03.dll
2011-03-20 09:42 . 2010-07-21 19:13        137656        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-02-19 05:33 . 2011-03-09 07:29        802304        ----a-w-        c:\windows\system32\FntCache.dll
2011-02-19 05:32 . 2011-03-09 07:29        1074176        ----a-w-        c:\windows\system32\DWrite.dll
2011-02-19 05:32 . 2011-03-09 07:29        739840        ----a-w-        c:\windows\system32\d2d1.dll
2011-02-17 12:45 . 2011-02-17 12:45        586        ----a-w-        C:\cc_20110217_134503.reg
2011-02-17 12:44 . 2011-02-17 12:44        41290        ----a-w-        C:\cc_20110217_134408.reg
2011-04-14 16:40 . 2011-05-04 15:40        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-04-23 16:50        66312        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Remote Control Editor"="c:\program files\Common Files\TerraTec\Remote\TTTvRc.exe" [2008-11-04 1105920]
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" [2010-06-13 4574208]
"SIDEBAR"="c:\program files\Desktop Sidebar\dsidebar.exe" [2006-07-09 1777664]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2007-07-11 237568]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-09-03 9726568]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-02-15 1230704]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-03-28 1910152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-26 421160]
.
c:\users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
TV-Browser.url [2011-1-29 164]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Ashampoo Magical Defrag.lnk - c:\program files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe [2010-7-21 4540120]
FRITZ!DSL Startcenter.lnk - c:\program files\FRITZ!DSL\StCenter.exe [2011-2-17 651264]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-26 23:22        421160        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NowWatching]
2010-10-31 12:46        280064        ----a-w-        c:\users\Melms\AppData\Roaming\Tokback\NowWatching\2.2.0.0\NowWatching.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-12 136176]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-12 136176]
S2 acedrv10;acedrv10;c:\windows\system32\drivers\acedrv10.sys [2007-07-27 330144]
S2 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2007-07-27 251680]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 1242504]
S3 Cinergy_HT_PCI_MKII;Cinergy HT PCI (MKII) service;c:\windows\system32\DRIVERS\Cinergy_HT_PCI_MKII.sys [2007-05-11 221184]
S3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 58880]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 137728]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 30392]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-12 22:13]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-12 22:13]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: Download with &Shareaza - c:\program files\Shareaza\RazaWebHook32.dll/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\users\Melms\AppData\Roaming\Mozilla\Firefox\Profiles\xsdvpeay.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.gmx.net/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-PcSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
AddRemove-Project Reality_is1 - c:\program files\EA GAMES\Battlefield 2\unins000.exe
AddRemove-FileZilla Client - c:\program files\FileZilla FTP Client\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-05-08  16:01:01
ComboFix-quarantined-files.txt  2011-05-08 14:01
.
Vor Suchlauf: 11 Verzeichnis(se), 358.527.016.960 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 358.582.726.656 Bytes frei
.
- - End Of File - - 875F60F54CE20DB067A642DE08F66B20


Drummer_Shoo 08.05.2011 19:59

Der tdsskiller lässt aber immer noch nicht starten.

cosinus 09.05.2011 12:22

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Drummer_Shoo 09.05.2011 18:33

Code:

GMER 1.0.15.15627 - hxxp://www.gmer.net
Rootkit scan 2011-05-09 19:32:14
Windows 6.1.7600  Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 SAMSUNG_HD103SJ rev.1AJ10001
Running: co0xc7nu.exe; Driver: C:\Users\Melms\AppData\Local\Temp\kgloypoc.sys


---- Kernel code sections - GMER 1.0.15 ----

.text                                                                                                                                ntoskrnl.exe!ZwSaveKeyEx + 13B1                                                                                            82C738A9 1 Byte  [06]
.text                                                                                                                                ntoskrnl.exe!KiDispatchInterrupt + 5A2                                                                                      82C93312 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.reloc                                                                                                                                C:\Windows\system32\drivers\acehlp10.sys                                                                                    section is executable [0x83FA4B80, 0x37FC7, 0xE0000060]
.reloc                                                                                                                                C:\Windows\system32\drivers\acedrv10.sys                                                                                    section is executable [0xA34B7000, 0x459C1, 0xE0000060]
.text                                                                                                                                C:\Windows\system32\DRIVERS\atksgt.sys                                                                                      section is writeable [0xA34FD300, 0x3B6D8, 0xE8000020]
.text                                                                                                                                C:\Windows\system32\drivers\hardlock.sys                                                                                    section is writeable [0xA3540400, 0x82482, 0xE8000020]
.protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xA35E0420]  C:\Windows\system32\drivers\hardlock.sys                                                                                    entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xA35E0420]
.protectÿÿÿÿhardlockunknown last code section [0xA35E0200, 0x5105, 0xE0000020]                                                        C:\Windows\system32\drivers\hardlock.sys                                                                                    unknown last code section [0xA35E0200, 0x5105, 0xE0000020]
.text                                                                                                                                C:\Windows\system32\DRIVERS\lirsgt.sys                                                                                      section is writeable [0xA35E6300, 0x1BEE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text                                                                                                                                C:\Windows\Explorer.EXE[1992] WININET.dll!HttpAddRequestHeadersA                                                            775E9ABA 5 Bytes  JMP 0051164F
.text                                                                                                                                C:\Windows\Explorer.EXE[1992] WININET.dll!HttpAddRequestHeadersW                                                            775F0848 5 Bytes  JMP 00511817

---- User IAT/EAT - GMER 1.0.15 ----

IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                            [746D2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                        [746B5624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                      [746B56E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                              [746D250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                    [746C8573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                      [746C4D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                    [746C50CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                    [746C51A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                          [746C66D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                    [746C82CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                [746C8819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                              [746C907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                    [746CE21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Windows\Explorer.EXE[1992] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                        [746C4C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW]              [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW]                [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]  [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]    [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                  [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]    [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                  [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                    [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW]                  [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter]  [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW]                [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                  [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter]  [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                    [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]  [6E1F45F8] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW]                [6E1F5455] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)
IAT                                                                                                                                  C:\Program Files\Shareaza\Shareaza.exe[2520] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                  [6E1F549E] C:\Program Files\Shareaza\BugTrap.dll (BugTrap dynamic link library/IntelleSoft)

---- Devices - GMER 1.0.15 ----

AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume1                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume2                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort0                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort1                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort2                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort3                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort4                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort5                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort6                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdePort7                                                                                          85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1                                                                                85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-4                                                                                85F641ED
Device                                                                                                                                \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-5                                                                                85F641ED

AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume3                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume4                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume5                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume6                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice                                                                                                                        \Driver\volmgr \Device\HarddiskVolume7                                                                                      fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device                                                                                                                                \Driver\ACPI_HAL \Device\0000004b                                                                                          halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice                                                                                                                        \FileSystem\fastfat \Fat                                                                                                    fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- Threads - GMER 1.0.15 ----

Thread                                                                                                                                System [4:248]                                                                                                              85F68E84
Thread                                                                                                                                System [4:252]                                                                                                              85F6B084

---- EOF - GMER 1.0.15 ----

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:40:28 on 09.05.2011

OS: Windows 7 Home Premium Edition (Build 7600), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Adobe Gamma" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma.cpl
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~1\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"acedrv10" (acedrv10) - "Protect Software GmbH" - C:\Windows\system32\drivers\acedrv10.sys
"acehlp10" (acehlp10) - "Protect Software GmbH" - C:\Windows\system32\drivers\acehlp10.sys
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\Melms\AppData\Local\Temp\catchme.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"kgloypoc" (kgloypoc) - ? - C:\Users\Melms\AppData\Local\Temp\kgloypoc.sys  (Hidden registry entry, rootkit activity | File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"Motorola USB Modem Driver for MPT" (usbsermpt) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\usbsermpt.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )-----
{E31004D1-A431-41B8-826F-E902F9D95C81} "Windows DreamScene" - "Microsoft Corporation" - C:\Windows\System32\DreamScene.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{F2185E5D-720E-4956-90D9-75F6AC141575} "SidebarIconHandler Class" - "Idea2" - C:\Program Files\Desktop Sidebar\sbhelp.dll
{30351346-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{30351347-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{30351348-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{30351349-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134A-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134B-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134C-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134D-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134E-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{3035134F-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{30351350-7B7D-4FCC-81B4-1E394CA267EB} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
{C5994560-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994561-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994562-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994563-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994564-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994565-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994566-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994567-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{C5994568-53D9-4125-87C9-F193FC689CB2} "TortoiseSVN" - "hxxp://tortoisesvn.net" - C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
 "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_25" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_25.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10p.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"ICQ7.5" - "ICQ, LLC." - C:\Program Files\ICQ7.5\ICQ.exe
{45AD732C-2CE2-4666-B366-B2214AD57A49} "Subscribe in Desktop Sidebar" - "Idea2" - C:\Program Files\Desktop Sidebar\sbhelp.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{855F3B16-6D32-4FE6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
{AD6E6555-FB2C-47D4-8339-3E2965509877} "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{593DDEC6-7468-4cdd-90E1-42DADAA222E9} "DivX HiQ" - ? - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll  (File not found)
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - ? - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll  (File not found)
{45AD732C-2CE2-4666-B366-B2214AD57A49} "Idea2 SidebarBrowserMonitor Class" - "Idea2" - C:\Program Files\Desktop Sidebar\sbhelp.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{0EEDB912-C5FA-486F-8334-57288578C627} "Shareaza Web Download Hook" - "Shareaza Development Team" - C:\Program Files\Shareaza\RazaWebHook32.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? -  (File not found | COM-object registry key not found)

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.2.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
"TV-Browser.url" - ? - C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TV-Browser.url
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Ashampoo Magical Defrag.lnk" - " " - C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"FRITZ!DSL Startcenter.lnk" - "AVM Berlin" - C:\Program Files\FRITZ!DSL\StCenter.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"msnmsgr" - "Microsoft Corporation" - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
"PC Suite Tray" - "Nokia" - "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"Remote Control Editor" - "TerraTec Electronic GmbH" - "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
"Shareaza" - "Shareaza Development Team" - "C:\Program Files\Shareaza\Shareaza.exe" -tray
"SIDEBAR" - "Idea2" - "C:\Program Files\Desktop Sidebar\dsidebar.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Photo Downloader" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LogMeIn Hamachi Ui" - "LogMeIn Inc." - "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"NUSB3MON" - "NEC Electronics Corporation" - "C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"tsnp2uvc" - ? - C:\Windows\tsnp2uvc.exe
"VirtualCloneDrive" - "Elaborate Bytes AG" - "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"avm:" - "AVM Berlin GmbH" - C:\Windows\system32\avmprmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Active File Monitor V6" (AdobeActiveFileMonitor6.0) - ? - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe  (File found, but it contains no detailed information)
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Ashampoo Defrag Service" (AshampooDefragService) - " " - C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"AVM FRITZ!web Routing Service" (de_serv) - "AVM Berlin" - C:\Program Files\Common Files\AVM\de_serv.exe
"AVM IGD CTRL Service" (AVM IGD CTRL Service) - "AVM Berlin" - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"ICQ Service" (ICQ Service) - ? - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File found, but it contains no detailed information)
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows 7 Home Premium Edition
Windows Information:                (build 7600), 32-bit
Base Board Manufacturer:        Gigabyte Technology Co., Ltd.
BIOS Manufacturer:                Award Software International, Inc.
System Manufacturer:                Gigabyte Technology Co., Ltd.
System Product Name:                GA-890XA-UD3
Logical Drives Mask:                0x00003fdc

Kernel Drivers (total 201):
  0x82C3E000 \SystemRoot\system32\ntoskrnl.exe
  0x82C07000 \SystemRoot\system32\halmacpi.dll
  0x80BA2000 \SystemRoot\system32\kdcom.dll
  0x83C06000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
  0x83C11000 \SystemRoot\system32\PSHED.dll
  0x83C22000 \SystemRoot\system32\BOOTVID.dll
  0x83C2A000 \SystemRoot\system32\CLFS.SYS
  0x83C6C000 \SystemRoot\system32\CI.dll
  0x83D17000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x83D88000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x83D96000 \SystemRoot\system32\DRIVERS\ACPI.sys
  0x83DDE000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
  0x83DE7000 \SystemRoot\system32\DRIVERS\msisadrv.sys
  0x83DEF000 \SystemRoot\system32\DRIVERS\pci.sys
  0x83E19000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
  0x83E24000 \SystemRoot\System32\drivers\partmgr.sys
  0x83E35000 \SystemRoot\system32\DRIVERS\volmgr.sys
  0x83E45000 \SystemRoot\System32\drivers\volmgrx.sys
  0x83E90000 \SystemRoot\system32\DRIVERS\pciide.sys
  0x83E97000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
  0x83EA5000 \SystemRoot\System32\drivers\mountmgr.sys
  0x83EBB000 \SystemRoot\system32\DRIVERS\atapi.sys
  0x83EC4000 \SystemRoot\system32\DRIVERS\ataport.SYS
  0x83EE7000 \SystemRoot\system32\DRIVERS\msahci.sys
  0x83EF1000 \SystemRoot\system32\drivers\amdxata.sys
  0x83EFA000 \SystemRoot\system32\drivers\fltmgr.sys
  0x83F2E000 \SystemRoot\system32\drivers\fileinfo.sys
  0x83F3F000 \SystemRoot\System32\Drivers\PxHelp20.sys
  0x8983B000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8996A000 \SystemRoot\System32\Drivers\msrpc.sys
  0x89995000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x899A8000 \SystemRoot\System32\Drivers\cng.sys
  0x89A05000 \SystemRoot\System32\drivers\pcw.sys
  0x89A13000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x89A1C000 \SystemRoot\system32\drivers\ndis.sys
  0x89AD3000 \SystemRoot\system32\drivers\NETIO.SYS
  0x89B11000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x89C1C000 \SystemRoot\System32\drivers\tcpip.sys
  0x89D65000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x89D96000 \SystemRoot\system32\DRIVERS\volsnap.sys
  0x89DD5000 \SystemRoot\System32\Drivers\spldr.sys
  0x89DDD000 \SystemRoot\System32\drivers\rdyboost.sys
  0x89E0A000 \SystemRoot\System32\Drivers\mup.sys
  0x89E1A000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x89E22000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x89E54000 \SystemRoot\system32\DRIVERS\disk.sys
  0x89E65000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x89E8A000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
  0x89EC4000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x89EE3000 \SystemRoot\System32\Drivers\Null.SYS
  0x89EEA000 \SystemRoot\System32\Drivers\Beep.SYS
  0x89EF1000 \SystemRoot\System32\drivers\vga.sys
  0x89EFD000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x89F1E000 \SystemRoot\System32\drivers\watchdog.sys
  0x89F2B000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x89F33000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x89F3B000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x89F43000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x89F4E000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x89F5C000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x89F73000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x89F7E000 \SystemRoot\system32\drivers\afd.sys
  0x89B36000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x89FD8000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x89FDF000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x89C00000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x89B68000 \SystemRoot\system32\DRIVERS\serial.sys
  0x89B82000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x89B95000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x89C0E000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
  0x89BA5000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x89BE6000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x89BF0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x89C14000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
  0x89800000 \SystemRoot\System32\drivers\discache.sys
  0x8980C000 \SystemRoot\System32\Drivers\dfsc.sys
  0x89824000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x83F49000 \SystemRoot\system32\DRIVERS\avipbb.sys
  0x83F6F000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x83F90000 \SystemRoot\system32\DRIVERS\amdppm.sys
  0x89832000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
  0x90407000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
  0x90E85000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
  0x90E87000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x90F3E000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x90F77000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
  0x90F99000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x90F9B000 \SystemRoot\system32\DRIVERS\usbfilter.sys
  0x83FA1000 \??\C:\Windows\system32\drivers\acehlp10.sys
  0x90FC6000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
  0x90FCC000 \SystemRoot\system32\DRIVERS\usbohci.sys
  0x99416000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x99461000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x99470000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x9948F000 \SystemRoot\system32\DRIVERS\Cinergy_HT_PCI_MKII.sys
  0x994C5000 \SystemRoot\system32\DRIVERS\ks.sys
  0x994F9000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
  0x994FC000 \SystemRoot\system32\DRIVERS\1394ohci.sys
  0x99528000 \SystemRoot\system32\DRIVERS\serenum.sys
  0x99532000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
  0x9953F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x99551000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x99569000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x99574000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x99596000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x995AE000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x995C5000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x995E1000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x995EE000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x995FB000 \SystemRoot\system32\DRIVERS\VClone.sys
  0x99606000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
  0x9962C000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x9962E000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x9963C000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
  0x9964B000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x9968F000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x8200F000 \SystemRoot\system32\drivers\RTKVHDA.sys
  0x82318000 \SystemRoot\system32\drivers\portcls.sys
  0x82347000 \SystemRoot\system32\drivers\drmk.sys
  0x82360000 \SystemRoot\system32\drivers\USBSTOR.SYS
  0x82377000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0x8238E000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x82399000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x823AC000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x823B3000 \SystemRoot\system32\DRIVERS\kbdhid.sys
  0x823BF000 \SystemRoot\system32\DRIVERS\KMWDFILTER.sys
  0x823C8000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x98490000 \SystemRoot\System32\win32k.sys
  0x823D3000 \SystemRoot\System32\drivers\Dxapi.sys
  0x823DD000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x996A0000 \SystemRoot\System32\Drivers\fastfat.SYS
  0x823F3000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x986F0000 \SystemRoot\System32\TSDDD.dll
  0x98720000 \SystemRoot\System32\cdd.dll
  0x82000000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x996CA000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x996D5000 \SystemRoot\System32\Drivers\dump_atapi.sys
  0x996DE000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x996EF000 \SystemRoot\system32\drivers\luafv.sys
  0x9970A000 \SystemRoot\system32\DRIVERS\avgntflt.sys
  0x9971F000 \SystemRoot\system32\drivers\WudfPf.sys
  0x99739000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x99749000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x9975C000 \SystemRoot\system32\drivers\HTTP.sys
  0x997E1000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x99400000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x90FD6000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0xA3439000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0xA3474000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0xA34A7000 \??\C:\Windows\system32\drivers\acedrv10.sys
  0xA34FD000 \SystemRoot\system32\DRIVERS\atksgt.sys
  0xA3540000 \??\C:\Windows\system32\drivers\hardlock.sys
  0xA35E6000 \SystemRoot\system32\DRIVERS\lirsgt.sys
  0xA35EB000 \SystemRoot\system32\drivers\peauth.sys
  0xA3682000 \SystemRoot\System32\Drivers\secdrv.SYS
  0xA368C000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0xA36AD000 \SystemRoot\System32\drivers\tcpipreg.sys
  0xA36BA000 \SystemRoot\System32\DRIVERS\srv2.sys
  0xA3709000 \SystemRoot\System32\DRIVERS\srv.sys
  0xA37E6000 \SystemRoot\system32\DRIVERS\asyncmac.sys
  0xA3400000 \??\C:\Users\Melms\AppData\Local\Temp\kgloypoc.sys
  0xA375B000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
  0x778D0000 \Windows\System32\ntdll.dll
  0x47B90000 \Windows\System32\smss.exe
  0x77B10000 \Windows\System32\apisetschema.dll
  0x00EB0000 \Windows\System32\autochk.exe
  0x77AE0000 \Windows\System32\sechost.dll
  0x77A80000 \Windows\System32\difxapi.dll
  0x776D0000 \Windows\System32\iertutil.dll
  0x77A70000 \Windows\System32\normaliz.dll
  0x775D0000 \Windows\System32\wininet.dll
  0x77A50000 \Windows\System32\imm32.dll
  0x774F0000 \Windows\System32\kernel32.dll
  0x77490000 \Windows\System32\shlwapi.dll
  0x77400000 \Windows\System32\oleaut32.dll
  0x77360000 \Windows\System32\advapi32.dll
  0x77310000 \Windows\System32\gdi32.dll
  0x77A40000 \Windows\System32\lpk.dll
  0x77260000 \Windows\System32\rpcrt4.dll
  0x77220000 \Windows\System32\ws2_32.dll
  0x765D0000 \Windows\System32\shell32.dll
  0x77A30000 \Windows\System32\nsi.dll
  0x76520000 \Windows\System32\msvcrt.dll
  0x764D0000 \Windows\System32\Wldap32.dll
  0x76330000 \Windows\System32\setupapi.dll
  0x76260000 \Windows\System32\msctf.dll
  0x761E0000 \Windows\System32\comdlg32.dll
  0x76150000 \Windows\System32\clbcatq.dll
  0x76080000 \Windows\System32\user32.dll
  0x75F20000 \Windows\System32\ole32.dll
  0x75E80000 \Windows\System32\usp10.dll
  0x75D40000 \Windows\System32\urlmon.dll
  0x75D10000 \Windows\System32\imagehlp.dll
  0x77A20000 \Windows\System32\psapi.dll
  0x75BF0000 \Windows\System32\crypt32.dll
  0x75B60000 \Windows\System32\comctl32.dll
  0x75B40000 \Windows\System32\devobj.dll
  0x75B10000 \Windows\System32\wintrust.dll
  0x75AC0000 \Windows\System32\KernelBase.dll
  0x75A90000 \Windows\System32\cfgmgr32.dll
  0x77A10000 \Windows\System32\msasn1.dll

Processes (total 76):
      0 System Idle Process
      4 System
    288 C:\Windows\System32\smss.exe
    512 csrss.exe
    572 C:\Windows\System32\wininit.exe
    592 csrss.exe
    628 C:\Windows\System32\services.exe
    652 C:\Windows\System32\lsass.exe
    660 C:\Windows\System32\lsm.exe
    800 C:\Windows\System32\winlogon.exe
    836 C:\Windows\System32\svchost.exe
    916 C:\Windows\System32\nvvsvc.exe
    956 C:\Windows\System32\svchost.exe
    1036 C:\Windows\System32\svchost.exe
    1088 C:\Windows\System32\svchost.exe
    1132 C:\Windows\System32\svchost.exe
    1260 C:\Windows\System32\svchost.exe
    1344 C:\Windows\System32\svchost.exe
    1444 C:\Windows\System32\nvvsvc.exe
    1500 C:\Windows\System32\spoolsv.exe
    1552 C:\Program Files\Avira\AntiVir Desktop\sched.exe
    1624 C:\Windows\System32\svchost.exe
    1724 C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    1816 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    1912 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1944 C:\Windows\System32\dwm.exe
    1992 C:\Windows\explorer.exe
    2024 C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
    2036 C:\Windows\System32\taskhost.exe
    620 C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
    564 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    656 C:\Windows\System32\conhost.exe
    508 C:\Program Files\Bonjour\mDNSResponder.exe
    2072 C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
    2196 C:\Program Files\ICQ6Toolbar\ICQ Service.exe
    2308 C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    2316 C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    2324 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
    2332 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    2340 C:\Windows\tsnp2uvc.exe
    2360 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    2448 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    2476 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    2484 C:\Program Files\iTunes\iTunesHelper.exe
    2508 C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
    2520 C:\Program Files\Shareaza\Shareaza.exe
    2568 C:\PROGRA~1\Ashampoo\ASHAMP~1\bin\DEFRAG~2.EXE
    2588 C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    2620 C:\Windows\System32\PnkBstrA.exe
    2632 C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
    2660 C:\Windows\System32\svchost.exe
    2684 C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe
    3076 C:\Program Files\FRITZ!DSL\StCenter.exe
    3088 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    3188 C:\Program Files\OpenOffice.org 3\program\soffice.exe
    3200 C:\PROGRA~1\Ashampoo\ASHAMP~1\bin\defragActivityMonitor.exe
    3208 C:\Program Files\OpenOffice.org 3\program\soffice.bin
    3528 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    3692 C:\Windows\System32\svchost.exe
    3720 C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    3748 C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    2108 C:\Program Files\iPod\bin\iPodService.exe
    2208 C:\Windows\System32\SearchIndexer.exe
    4540 C:\Program Files\Windows Media Player\wmpnetwk.exe
    5016 C:\Windows\System32\svchost.exe
    5168 C:\Windows\System32\svchost.exe
    6132 C:\Program Files\Winamp\winamp.exe
    4748 C:\Windows\System32\audiodg.exe
    764 C:\Program Files\Mozilla Firefox\firefox.exe
    4764 C:\Program Files\Mozilla Firefox\plugin-container.exe
    5468 MpCmdRun.exe
    2224 C:\Windows\System32\SearchProtocolHost.exe
    4136 C:\Windows\System32\SearchFilterHost.exe
    5244 C:\Users\Melms\Desktop\MBRCheck.exe
    1456 C:\Windows\System32\conhost.exe
    1028 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000  (NTFS)
\\.\N: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00  (FAT32)

PhysicalDrive0 Model Number: SAMSUNGHD103SJ, Rev: 1AJ10001
PhysicalDrive1 Model Number: WD2500BB External, Rev: 0602

      Size  Device Name          MBR Status
  --------------------------------------------
    931 GB  \\.\PhysicalDrive0  Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
    232 GB  \\.\PhysicalDrive1  RE: Unknown MBR code
            SHA1: CE7DBBBEE43059700485C7835F4E1ED6D2FADB1C


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!


cosinus 09.05.2011 19:17

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Drummer_Shoo 09.05.2011 20:53

Code:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6540

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

09.05.2011 21:51:30
mbam-log-2011-05-09 (21-51-30).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|N:\|)
Durchsuchte Objekte: 450641
Laufzeit: 1 Stunde(n), 17 Minute(n), 17 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Die Log von SASW folgt morgen.

Drummer_Shoo 10.05.2011 20:45

Liste der Anhänge anzeigen (Anzahl: 1)
Hier nun die Log von SASW:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 05/10/2011 at 09:39 PM

Application Version : 4.52.1000

Core Rules Database Version : 7024
Trace Rules Database Version: 4836

Scan type      : Complete Scan
Total Scan Time : 02:14:13

Memory items scanned      : 782
Memory threats detected  : 0
Registry items scanned    : 8973
Registry threats detected : 0
File items scanned        : 299074
File threats detected    : 1

Trojan.Agent/Gen-OnlineGames[Wilao]
        N:\PROGRAMME\WINTERBERGUPDATER.EXE

Ausserdem bekam ich gestern und heute folgende Meldung:
http://www.trojaner-board.de/attachm...1&d=1305056689

cosinus 10.05.2011 21:04

Zitat:

N:\PROGRAMME\WINTERBERGUPDATER.EXE
Das Teil sagt dir was?

Zitat:

Ausserdem bekam ich gestern und heute folgende Meldung:
Einfach so oder warst du am Surfen? Wenn ja, mit welchem Browser auf welcher Website?

Drummer_Shoo 10.05.2011 21:08

Zu 1. Ja das Teil kenn ich.

Zu 2. Es war kein Brwoser offen und Programme liege, heut zumindest keine als ich die Meldung bekam.

cosinus 10.05.2011 21:18

Melde dich einfach nochmal falls die Meldung immer noch auftaucht.

Drummer_Shoo 14.05.2011 16:19

Die Meldung erscheint weiterhin täglich, wenn der PC läuft.
Ausserdem gibt es weiterhin Weiterleitung auf andere Seiten, wenn ich auf google Suchergebnisse klicke.

cosinus 14.05.2011 17:42

Mach nochmal ein frisches OTL-Log:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Drummer_Shoo 15.05.2011 09:17

Code:

OTL logfile created on: 15.05.2011 08:43:43 - Run 4
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Melms\Desktop
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 443,13 Gb Total Space | 334,41 Gb Free Space | 75,47% Space Free | Partition Type: NTFS
Drive D: | 7,02 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 517,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive N: | 232,83 Gb Total Space | 108,89 Gb Free Space | 46,77% Space Free | Partition Type: FAT32
 
Computer Name: MELMS-PC | User Name: Melms | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.05.01 23:00:36 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
PRC - [2011.03.28 15:41:14 | 001,910,152 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.02.15 03:32:52 | 001,230,704 | ---- | M] () -- C:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.12.08 14:31:06 | 000,628,736 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.11.16 14:48:32 | 000,152,576 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2010.11.03 09:32:50 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.06.18 19:38:22 | 000,619,800 | ---- | M] (hxxp://tortoisesvn.net) -- C:\Programme\TortoiseSVN\bin\TSVNCache.exe
PRC - [2010.05.20 23:59:30 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2010.05.20 23:59:28 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.11.20 13:17:54 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Programme\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009.10.27 09:15:02 | 000,120,832 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2008.11.04 11:06:36 | 001,105,920 | ---- | M] (TerraTec Electronic GmbH) -- C:\Programme\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2007.03.22 11:09:16 | 004,540,120 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe
PRC - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
PRC - [2005.03.08 12:46:00 | 000,651,264 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\StCenter.exe
PRC - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE
 
 
========== Modules (SafeList) ==========
 
MOD - [2011.04.11 20:21:31 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Melms\Desktop\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.05.01 23:00:36 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.03.28 15:41:12 | 001,242,504 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.03.20 11:42:20 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.12.08 14:31:06 | 000,628,736 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.11.21 11:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.07.04 11:44:03 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.09.11 00:45:04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Programme\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2007.03.22 11:09:16 | 001,689,304 | ---- | M] ( ) [Auto | Running] -- C:\Programme\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe -- (AshampooDefragService)
SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005.03.04 12:42:08 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Programme\Common Files\AVM\De_serv.exe -- (de_serv)
SRV - [2005.03.04 11:50:00 | 000,118,784 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Programme\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.03.20 11:42:20 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.12.02 12:13:28 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010.12.02 12:13:22 | 000,018,304 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010.11.22 23:55:16 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.10.13 22:49:42 | 000,022,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbsermpt.sys -- (usbsermpt)
DRV - [2010.08.14 17:59:32 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.08.14 17:59:32 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.07.10 06:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010.05.10 20:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.17 20:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009.12.22 02:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009.11.20 13:15:18 | 000,137,728 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2009.11.20 13:15:16 | 000,058,880 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.05.05 03:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV - [2009.04.29 15:37:26 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTERx86)
DRV - [2009.03.18 17:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007.07.27 12:46:06 | 000,251,680 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2007.07.27 10:13:08 | 000,330,144 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007.05.11 16:17:25 | 000,221,184 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Cinergy_HT_PCI_MKII.sys -- (Cinergy_HT_PCI_MKII) Cinergy HT PCI (MKII)
DRV - [2004.07.14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 13 EE 64 48 11 CB 01  [binary data]
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://www.gmx.net/"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..extensions.enabledItems: longurlplease@darragh.curran:0.4.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: FirefoxAddon@similarWeb.com:1.2.06
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.03.18 21:07:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.05.04 17:40:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.04 17:28:20 | 000,000,000 | ---D | M]
 
[2010.06.26 15:07:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Extensions
[2011.05.08 20:26:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions
[2011.02.04 09:34:03 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2011.01.14 09:29:30 | 000,000,000 | ---D | M] ("CoolPreviews") -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2011.03.12 09:14:20 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011.02.19 16:23:41 | 000,000,000 | ---D | M] (SimilarWeb) -- C:\Users\Melms\AppData\Roaming\mozilla\Firefox\Profiles\xsdvpeay.default\extensions\FirefoxAddon@similarWeb.com
[2011.05.10 08:24:38 | 000,001,056 | ---- | M] () -- C:\Users\Melms\AppData\Roaming\Mozilla\Firefox\Profiles\xsdvpeay.default\searchplugins\icqplugin.xml
[2011.05.04 17:40:05 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.05.03 20:02:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
[2010.07.17 09:13:10 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.12 09:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.05.03 20:02:49 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) -- C:\USERS\MELMS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XSDVPEAY.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
[2011.04.14 18:40:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2011.04.14 05:08:00 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.12.09 12:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.08 15:58:58 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Programme\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} -  File not found
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} -  File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe ()
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKCU..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (Shareaza Development Team)
O4 - HKCU..\Run: [SIDEBAR] C:\Program Files\Desktop Sidebar\dsidebar.exe (Idea2)
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TV-Browser.url ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with &Shareaza - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.10.08 11:01:14 | 000,000,025 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: NowWatching - hkey= - key= - C:\Users\Melms\AppData\Roaming\Tokback\NowWatching\2.2.0.0\NowWatching.exe (Tokback)
MsConfig - State: "bootini" - 2
 
SafeBootMin: AppMgmt -  File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt -  File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Hamachi2Svc - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.05.09 21:54:31 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\SUPERAntiSpyware.com
[2011.05.09 21:54:31 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.05.09 21:54:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.05.09 21:54:22 | 000,000,000 | ---D | C] -- C:\Programme\SUPERAntiSpyware
[2011.05.09 20:32:14 | 011,061,040 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Melms\Desktop\SUPERAntiSpyware.exe
[2011.05.08 20:46:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.05.08 20:31:27 | 000,000,000 | ---D | C] -- C:\cofi4728c
[2011.05.08 20:30:55 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.05.08 20:27:25 | 001,407,280 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Melms\Desktop\tdsskiller.exe
[2011.05.08 16:31:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.5
[2011.05.08 16:31:22 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.5
[2011.05.08 15:58:57 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Local\temp
[2011.05.08 15:51:03 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.05.08 15:51:03 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.05.08 15:51:03 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.05.08 15:50:58 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.05.08 15:50:57 | 000,000,000 | ---D | C] -- C:\cofi
[2011.05.08 15:48:13 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.05.08 15:40:10 | 003,063,136 | ---- | C] (Piriform Ltd) -- C:\Users\Melms\Desktop\ccsetup306.exe
[2011.05.06 22:20:31 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Nokia
[2011.05.06 22:20:27 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\PC Suite
[2011.05.06 22:20:27 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite
[2011.05.06 22:17:46 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.05.06 22:04:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC Suite
[2011.05.06 22:04:04 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\PCSuite
[2011.05.06 22:04:02 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Nokia
[2011.05.06 22:03:56 | 000,018,816 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
[2011.05.06 22:03:44 | 000,000,000 | ---D | C] -- C:\Programme\PC Connectivity Solution
[2011.05.06 22:00:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Installations
[2011.05.06 20:39:52 | 001,582,304 | ---- | C] (Piriform Ltd) -- C:\Users\Melms\Desktop\rcsetup140_slim.exe
[2011.05.05 18:55:00 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Local\FT Software Updates
[2011.05.03 20:07:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.05.03 20:06:48 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2011.05.03 20:06:47 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2011.05.03 20:04:40 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour
[2011.05.03 20:02:57 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2011.05.03 20:01:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.05.03 20:01:08 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2011.04.22 17:45:07 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.04.22 17:16:59 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Local\Electronic_Arts_Inc
[2011.04.18 19:48:41 | 000,000,000 | ---D | C] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2010.10.11 21:12:07 | 000,180,224 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011.05.15 08:43:17 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.05.15 08:43:17 | 000,014,624 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.05.15 08:42:09 | 000,668,302 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.05.15 08:42:09 | 000,619,894 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.05.15 08:42:09 | 000,134,150 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.05.15 08:42:09 | 000,110,082 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.05.15 08:36:18 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.05.15 08:36:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.05.15 08:35:54 | 1610,309,632 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.15 00:24:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.05.10 21:44:16 | 000,025,473 | ---- | M] () -- C:\Users\Melms\Desktop\Bild2.png
[2011.05.09 21:54:24 | 000,001,965 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.05.09 20:32:36 | 011,061,040 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Melms\Desktop\SUPERAntiSpyware.exe
[2011.05.09 19:42:20 | 000,080,384 | ---- | M] () -- C:\Users\Melms\Desktop\MBRCheck.exe
[2011.05.09 19:03:34 | 000,302,080 | ---- | M] () -- C:\Users\Melms\Desktop\co0xc7nu.exe
[2011.05.08 20:30:46 | 004,343,565 | R--- | M] () -- C:\Users\Melms\Desktop\cofi.exe
[2011.05.08 20:27:27 | 001,407,280 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Melms\Desktop\tdsskiller.exe
[2011.05.08 16:14:03 | 000,065,446 | ---- | M] () -- C:\Users\Melms\Desktop\hilfäää.png
[2011.05.08 15:58:58 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.05.08 15:40:44 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.05.08 15:40:23 | 003,063,136 | ---- | M] (Piriform Ltd) -- C:\Users\Melms\Desktop\ccsetup306.exe
[2011.05.08 14:56:10 | 000,901,830 | ---- | M] () -- C:\Users\Melms\Desktop\Spulenbeispiele.PNG
[2011.05.08 14:30:23 | 000,037,261 | ---- | M] () -- C:\Users\Melms\Desktop\Img_00991.jpg
[2011.05.06 22:32:09 | 000,007,168 | ---- | M] () -- C:\Users\Melms\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.06 22:27:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2011.05.06 22:04:05 | 000,001,996 | ---- | M] () -- C:\Users\Public\Desktop\Nokia PC Suite.lnk
[2011.05.06 21:59:28 | 036,657,376 | ---- | M] () -- C:\Users\Melms\Desktop\Nokia_PC_Suite_ger_web.exe
[2011.05.06 20:39:55 | 001,582,304 | ---- | M] (Piriform Ltd) -- C:\Users\Melms\Desktop\rcsetup140_slim.exe
[2011.05.03 07:27:40 | 000,520,382 | ---- | M] () -- C:\Users\Melms\Desktop\woistderthread.png
[2011.04.30 14:38:47 | 000,358,993 | ---- | M] () -- C:\Users\Melms\Desktop\image.png
[2011.04.29 23:36:01 | 000,007,597 | ---- | M] () -- C:\Users\Melms\AppData\Local\Resmon.ResmonCfg
[2011.04.22 17:16:39 | 000,002,167 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.04.16 22:50:30 | 000,000,381 | ---- | M] () -- C:\Windows\BeatBox.INI
[2011.04.16 22:50:30 | 000,000,028 | ---- | M] () -- C:\Windows\Robota.INI
[2011.04.15 20:14:58 | 000,334,200 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2011.05.10 21:44:16 | 000,025,473 | ---- | C] () -- C:\Users\Melms\Desktop\Bild2.png
[2011.05.09 21:54:24 | 000,001,965 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.05.09 19:42:20 | 000,080,384 | ---- | C] () -- C:\Users\Melms\Desktop\MBRCheck.exe
[2011.05.09 19:03:31 | 000,302,080 | ---- | C] () -- C:\Users\Melms\Desktop\co0xc7nu.exe
[2011.05.08 16:14:03 | 000,065,446 | ---- | C] () -- C:\Users\Melms\Desktop\hilfäää.png
[2011.05.08 15:51:03 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.05.08 15:51:03 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.05.08 15:51:03 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.05.08 15:51:03 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.05.08 15:51:03 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.05.08 15:40:44 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.05.08 15:36:59 | 004,343,565 | R--- | C] () -- C:\Users\Melms\Desktop\cofi.exe
[2011.05.08 14:56:01 | 000,901,830 | ---- | C] () -- C:\Users\Melms\Desktop\Spulenbeispiele.PNG
[2011.05.08 14:30:23 | 000,037,261 | ---- | C] () -- C:\Users\Melms\Desktop\Img_00991.jpg
[2011.05.06 22:27:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2011.05.06 22:04:05 | 000,001,996 | ---- | C] () -- C:\Users\Public\Desktop\Nokia PC Suite.lnk
[2011.05.06 21:58:27 | 036,657,376 | ---- | C] () -- C:\Users\Melms\Desktop\Nokia_PC_Suite_ger_web.exe
[2011.05.04 17:40:05 | 000,001,112 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.05.03 07:27:40 | 000,520,382 | ---- | C] () -- C:\Users\Melms\Desktop\woistderthread.png
[2011.04.30 14:38:41 | 000,358,993 | ---- | C] () -- C:\Users\Melms\Desktop\image.png
[2011.04.22 17:16:39 | 000,002,167 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.03.20 20:48:15 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.02.27 01:45:09 | 000,000,381 | ---- | C] () -- C:\Windows\BeatBox.INI
[2011.02.27 01:45:09 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2011.02.27 00:58:31 | 000,124,596 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011.02.05 20:09:24 | 000,139,152 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.02.05 20:09:18 | 000,139,152 | ---- | C] () -- C:\Users\Melms\AppData\Roaming\PnkBstrK.sys
[2011.02.05 20:08:43 | 000,111,928 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.02.05 20:08:40 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2011.02.05 20:08:40 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.02.03 21:56:57 | 000,000,019 | ---- | C] () -- C:\Windows\SoundConverter.INI
[2010.12.29 21:00:43 | 000,000,180 | ---- | C] () -- C:\Windows\System32\msftpd.exe
[2010.12.19 20:34:53 | 000,000,221 | ---- | C] () -- C:\Windows\SOFTEK.INI
[2010.10.19 17:18:19 | 000,002,464 | ---- | C] () -- C:\Windows\netdet.ini
[2010.10.15 21:00:00 | 000,007,168 | ---- | C] () -- C:\Users\Melms\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.11 21:12:07 | 000,237,568 | ---- | C] () -- C:\Windows\tsnp2uvc.exe
[2010.08.28 19:41:48 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2010.08.28 19:34:40 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.08.28 19:34:13 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2010.08.14 17:26:47 | 000,007,597 | ---- | C] () -- C:\Users\Melms\AppData\Local\Resmon.ResmonCfg
[2010.08.14 17:14:19 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010.08.14 17:14:14 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2010.07.27 13:00:39 | 000,000,614 | ---- | C] () -- C:\Windows\eReg.dat
[2010.07.04 11:29:04 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2009.08.03 00:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2009.08.03 00:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2009.08.03 00:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2009.07.14 10:47:43 | 000,668,302 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,134,150 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,334,200 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,619,894 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,110,082 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2010.07.20 15:35:15 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\#Company short name
[2011.01.23 20:41:11 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Aston
[2011.01.23 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Bump Technologies, Inc
[2011.05.15 08:42:12 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Desktop Sidebar
[2011.05.08 15:44:46 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FileZilla
[2011.03.13 11:46:42 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FRITZ!
[2011.05.15 00:35:20 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\ICQ
[2010.11.14 21:51:58 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Jasc
[2010.08.29 13:58:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Lern-o-Mat
[2010.08.28 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\MAGIX
[2011.04.22 17:45:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.05.06 22:31:16 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Nokia
[2010.07.04 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\OpenOffice.org
[2011.05.06 22:20:27 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\PC Suite
[2011.02.16 13:00:53 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Shareaza
[2010.06.26 20:34:09 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra
[2010.06.26 20:20:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra Entertainment
[2010.06.27 21:49:29 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Subversion
[2011.05.05 20:26:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TerraTec
[2010.10.31 14:46:00 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Tokback
[2011.05.15 08:42:01 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2011.02.16 23:05:57 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\wargaming.net
[2011.03.25 15:10:55 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.07.20 15:35:15 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\#Company short name
[2010.12.19 19:53:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Adobe
[2010.10.01 16:11:13 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Apple Computer
[2011.01.23 20:41:11 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Aston
[2010.07.22 10:19:49 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Avira
[2011.01.23 17:12:59 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Bump Technologies, Inc
[2011.05.15 08:42:12 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Desktop Sidebar
[2011.03.18 21:17:18 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\DivX
[2011.05.13 21:10:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\dvdcss
[2011.05.08 15:44:46 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FileZilla
[2011.03.13 11:46:42 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\FRITZ!
[2011.05.15 00:35:20 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\ICQ
[2010.06.21 15:44:21 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Identities
[2010.06.26 22:11:03 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\InstallShield
[2010.11.14 21:51:58 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Jasc
[2010.08.29 13:58:48 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Lern-o-Mat
[2010.06.21 15:49:08 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Macromedia
[2010.08.28 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\MAGIX
[2011.04.11 21:18:53 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Media Center Programs
[2010.10.31 14:46:04 | 000,000,000 | --SD | M] -- C:\Users\Melms\AppData\Roaming\Microsoft
[2011.02.17 13:25:31 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\mIRC
[2010.06.26 15:07:01 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Mozilla
[2011.04.22 17:45:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Need for Speed World
[2011.05.06 22:31:16 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Nokia
[2010.07.04 13:01:02 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\OpenOffice.org
[2011.05.06 22:20:27 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\PC Suite
[2011.02.16 13:00:53 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Shareaza
[2010.06.26 20:34:09 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra
[2010.06.26 20:20:43 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Sierra Entertainment
[2010.06.27 21:49:29 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Subversion
[2011.05.09 21:54:31 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\SUPERAntiSpyware.com
[2011.05.05 20:26:07 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TerraTec
[2010.10.31 14:46:00 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Tokback
[2010.07.17 08:46:19 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TortoiseSVN
[2011.05.15 08:42:01 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\TV-Browser
[2010.06.26 15:56:08 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\vlc
[2011.02.16 23:05:57 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\wargaming.net
[2011.05.12 22:57:10 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\Winamp
[2010.07.02 19:03:57 | 000,000,000 | ---D | M] -- C:\Users\Melms\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.10.31 14:46:03 | 000,280,064 | ---- | M] (Tokback) -- C:\Users\Melms\AppData\Roaming\Tokback\NowWatching\2.2.0.0\NowWatching.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
 
< MD5 for: AHCIX86.SYS  >
[2009.07.01 08:18:34 | 000,184,328 | ---- | M] (Advanced Micro Devices, Inc) MD5=48002180D09FCB6A7BDA367CA9E2BC3D -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB7xx\RAID\XP\ahcix86.sys
[2010.01.06 12:27:18 | 000,190,256 | ---- | M] (Advanced Micro Devices, Inc) MD5=7E65511294917BF1C10AEE9F16D81ABD -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB8xx\RAID\XP\ahcix86.sys
 
< MD5 for: AHCIX86S.SYS  >
[2010.01.06 12:26:34 | 000,190,768 | ---- | M] (Advanced Micro Devices, Inc) MD5=1837E346202F9359088C6CD964F5C6AA -- C:\Users\Melms\Downloads\RAID_win7\W7\ahcix86s.sys
[2010.01.06 12:26:34 | 000,190,768 | ---- | M] (Advanced Micro Devices, Inc) MD5=1837E346202F9359088C6CD964F5C6AA -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB8xx\RAID\LH\ahcix86s.sys
[2010.01.06 12:26:34 | 000,190,768 | ---- | M] (Advanced Micro Devices, Inc) MD5=1837E346202F9359088C6CD964F5C6AA -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB8xx\RAID\W7\ahcix86s.sys
[2009.07.14 04:36:04 | 000,184,120 | ---- | M] (Advanced Micro Devices, Inc) MD5=4F104D2C68E39E5282E8E47DCF07BF25 -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB7xx\RAID\W7\ahcix86s.sys
[2009.07.07 08:57:12 | 000,184,120 | ---- | M] (Advanced Micro Devices, Inc) MD5=6EEE47ADFE3BC5694DF661DCA0F78D04 -- C:\Users\Melms\Downloads\win7_chipset\Packages\Drivers\SBDrv\SB7xx\RAID\LH\ahcix86s.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\ERDNT\cache\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\ERDNT\cache\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\ERDNT\cache\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 16 bytes -> C:\Users\Melms\Downloads:Shareaza.GUID

< End of report >


cosinus 15.05.2011 11:47

Sieht unauffällig aus.
hast du rein zufällig einen Router? Wenn ja wurde da das Adminpasswort geändert?
Wenn nicht, setz diesen Router auf Werkseinstellungen zurück und konfiguriere ihn neu. Wichtig ist, dass du das unsichere vordefinierte Adminkennwort zum Router änderst!

Drummer_Shoo 25.05.2011 15:37

Die Routereinstellungen habe ich zur Zeit noch nicht zurückgesetzt.
Allerdings ist mir aufgefallen, dass diese Meldungen mit 2 Einträgen in dem Taskmanager über einstimmen, die iexplore.exe heissen.
Diese laufen ohne, dass ich den Internetexplorer laufen haben.

Sobald so eine Meldung erscheint und ich die .exe im Taskmanager beende, verschwindet auch die Meldung.

Ein beenden der .exe bringt allerdings auch nichts, da die .exe nach kurzer Zeit wieder im Tasmanger zu finden ist.

cosinus 25.05.2011 20:38

Setz erstmal den Router zurück bevor wir weiterbuddeln.
Denk an die Vergabe eines sicheren Passworts als erstes, damit durch ein unsicheres Standardpasswort ein potentieller Schädling nicht alles wieder umbiegen kann.

Drummer_Shoo 28.05.2011 11:01

So, der Router wurde nun zurückgesetzt und das PW geändert.

cosinus 28.05.2011 23:01

Ok. Bitte mal ESET ausführen.


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Drummer_Shoo 29.05.2011 12:57

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=35747d3ece915c45930be9419a55cfd5
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-29 11:55:21
# local_time=2011-05-29 01:55:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=768 16777215 100 0 29530823 29530823 0 0
# compatibility_mode=1797 16775165 100 94 49955 43195634 74138 0
# compatibility_mode=5893 16776573 100 94 95606 59097521 0 0
# compatibility_mode=8192 67108863 100 0 179 179 0 0
# scanned=336309
# found=7
# cleaned=0
# scan_time=11342
C:\Users\Melms\AppData\Local\temp\jar_cache3565516834617809017.tmp        a variant of Java/TrojanDownloader.OpenStream.NBV trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\65c97c66-61b7cc59        Java/TrojanDownloader.OpenStream.NBV trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\24d66229-57fd53a8        Java/TrojanDownloader.OpenStream.NBV trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\Downloads\MsgPlusLive-484.exe        a variant of Win32/MessengerPlus application (unable to clean)        00000000000000000000000000000000        I
N:\Programme\Nero-8.3.2.1_deu_trial.exe        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
N:\Programme\AIX_2.0_CORE_MOD.exe        a variant of Win32/Packed.ExeScript.B trojan (unable to clean)        00000000000000000000000000000000        I
N:\MELMS-PC\Backup Set 2010-07-04 105534\Backup Files 2010-07-04 105534\Backup files 1.zip        a variant of Win32/MessengerPlus application (unable to clean)        00000000000000000000000000000000        I


cosinus 29.05.2011 14:39

Zitat:

N:\Programme\AIX_2.0_CORE_MOD.exe a variant of Win32/Packed.ExeScript.B trojan (unable to clean)
N:\MELMS-PC\Backup Set 2010-07-04 105534\Backup Files 2010-07-04 105534\Backup files 1.zip a variant of Win32/MessengerPlus application (unable to clean)
Wasndas? AIX?
Ist das backupSet noch relevant für dich?

Drummer_Shoo 29.05.2011 19:20

AIX ist eine Modifikation für das Spiel Battlefiel2. Das BackupSet brauche ich nicht mehr.

cosinus 30.05.2011 09:19

Zitat:

AIX ist eine Modifikation für das Spiel Battlefiel2.
Bei sowas wäre ich vorsichtig. Aus welcher Quelle stammt das?
Kannst du die Datei mal bei Virustotal auswerten?

Drummer_Shoo 30.05.2011 14:05

Virustotal verarbeitet nur bis 20MB die Datei ist über 700MB groß.

cosinus 30.05.2011 14:54

Ok, dass die soo groß ist wusste ich nicht :D

Drummer_Shoo 26.06.2011 16:02

Tach, ich mal wieder.

Problem 1.
Die letzten 2 Tage bekommen ich wieder PopUps auf dem Desktop "Sie haben eine IPhone 4 gewonnen" und andere lustige Meldungen in diesem Zusammenhang.

Problem 2.
Bei Suchanfragen mit Google und dem Klick auf entsprechende Treffer, leitet mit der Browser häufig auf andere Seiten weiter, so sich dann ein PopUp öffnet welches mir sagt, ich solle iwas installieren. Ein Umgehen dieser Nerverei ist t.w. nur möglich wenn ich bspw. eine andere Rubrik, die in den Treffern gelistet ist aufrufe oder den Link öffne, ich dem ich ihn in einem neuen Fester öffnen lasse. Dies ist ziemlich Nervenaufreibend ...

cosinus 26.06.2011 16:05

In den letzten vier Wochen kann soviel passiert sein.
Wiederhol den letzten Schritt nochmal. Den mit den Drei Scans mit MBAM,SASW und ESET

Drummer_Shoo 26.06.2011 21:36

Hier die Logs von MBAM und SASW, ESET gibts morgen.

Code:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Datenbank Version: 6954

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

26.06.2011 18:57:45
mbam-log-2011-06-26 (18-57-45).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|N:\|)
Durchsuchte Objekte: 541872
Laufzeit: 1 Stunde(n), 44 Minute(n), 28 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 06/26/2011 at 10:17 PM

Application Version : 4.52.1000

Core Rules Database Version : 7329
Trace Rules Database Version: 5141

Scan type      : Complete Scan
Total Scan Time : 03:08:50

Memory items scanned      : 885
Memory threats detected  : 0
Registry items scanned    : 9583
Registry threats detected : 0
File items scanned        : 378664
File threats detected    : 114

Adware.Tracking Cookie
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@e-2dj6wbl4shd5wcp.stats.esomniture[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@myroitracking[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@xm.xtendmedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tribalfusion[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@cdn.at.atwola[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adfarm1.adition[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@mediaplex[6].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.adition[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tracking.foxnews[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@yadro[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@live.realtimewebstats[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@atdmt.combing[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tacoda.at.atwola[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@eu.gomeotrack[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@dc.tremormedia[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@serving-sys[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ru4[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad3.adfarm1.adition[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adxpose[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@content.yieldmanager[4].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@vid-finder[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@apmebf[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@weborama[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@zbox.zanox[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@zedo[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@clicks.bestfastget[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.usenext[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@click.xmlmonetize[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@realmedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@bs.serving-sys[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad1.adfarm1.adition[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@eyewonder[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@overture[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.ad-srv[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@questionmarket[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@usatoday1.112.2o7[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.zanox-affiliate[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@atdmt[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@statcounter[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@advertise[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@cdn.jemamedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@firesexteen[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@de.sitestat[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ar.atwola[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.yieldmanager[4].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@pornhublive[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@mediabrandsww[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.active-tracking[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@pornhub[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.cpcadnet[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.burstnet[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ads.creative-serving[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@burstnet[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@advertising[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@clicksor[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@zanox-affiliate[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@doubleclick[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@trafficengine[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@revsci[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad4.adfarm1.adition[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@fastclick[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.pornhublive[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.dyntracker[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@eclickz[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@search.clicksare[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@invitemedia[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adinterax[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adviva[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tracking.mlsat02[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@traffictrack[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@at.atwola[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@webmasterplan[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@xml.trafficengine[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@specificclick[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adtech[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tracking.quisma[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@smartadserver[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@legolas-media[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@p411t1s5332072.kronos.bravenetmedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@media6degrees[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@habitat.solution.weborama[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.zanox[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adultfriendfinder[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@content.yieldmanager[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.webcamsex[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@imrworldwide[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@zanox[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad2.adfarm1.adition[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adbrite[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@clicks.thespecialsearch[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.dyntracker[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.googleadservices[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ads.247activemedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@findology[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@adsrv1.admediate[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@clickbank[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.etracker[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tech.multifind24[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@ad.jmg[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@collective-media[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@xml.happytofind[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.etracker[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@mediacontactses.solution.weborama[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@track.adform[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@yieldmanager[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@eas.apm.emediate[3].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@tradedoubler[2].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@p418t1s4361650.kronos.bravenetmedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@mediatraffic[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@p443t1s5332368.kronos.bravenetmedia[1].txt
        C:\Users\Melms\AppData\Roaming\Microsoft\Windows\Cookies\melms@www.cpcadnet[2].txt
        media.mtvnservices.com [ C:\Users\Melms\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SLCKLDN6 ]
        www.m7media.de [ C:\Users\Melms\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SLCKLDN6 ]
        www.naiadsystems.com [ C:\Users\Melms\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\SLCKLDN6 ]


Drummer_Shoo 28.06.2011 06:21

Hier die ESET Log:

Code:

# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=35747d3ece915c45930be9419a55cfd5
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-06-27 11:28:48
# local_time=2011-06-28 01:28:48 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=768 16777215 100 0 32075855 32075855 0 0
# compatibility_mode=1797 16775165 100 94 12767 45740666 5560 0
# compatibility_mode=5893 16776573 100 94 306209 61642553 0 0
# compatibility_mode=8192 67108863 100 0 2545211 2545211 0 0
# scanned=403122
# found=9
# cleaned=0
# scan_time=13518
C:\Users\Melms\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7V4C1EFB\forum[1].htm        JS/Kryptik.AX trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W2TK0PNQ\index[2].htm        JS/Kryptik.AX trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\Local\temp\jar_cache1158771414361430518.tmp.vir        a variant of Java/TrojanDownloader.OpenStream.NCE trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\Local\temp\jar_cache2208603737778574750.tmp.vir        a variant of Java/TrojanDownloader.OpenStream.NCE trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\AppData\Local\temp\jar_cache3565516834617809017.tmp        a variant of Java/TrojanDownloader.OpenStream.NBV trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Melms\Downloads\MsgPlusLive-484.exe        a variant of Win32/MessengerPlus application (unable to clean)        00000000000000000000000000000000        I
N:\Programme\Nero-8.3.2.1_deu_trial.exe        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
N:\Programme\AIX_2.0_CORE_MOD.exe        a variant of Win32/Packed.ExeScript.B trojan (unable to clean)        00000000000000000000000000000000        I
N:\MELMS-PC\Backup Set 2010-07-04 105534\Backup Files 2010-07-04 105534\Backup files 1.zip        a variant of Win32/MessengerPlus application (unable to clean)        00000000000000000000000000000000        I


cosinus 28.06.2011 13:51

Nur Cookies, Überreste und ein paar hysterische Funde durch ESET. Was du nicht mehr brauchst an den gefundenen Setups kann weg.

Rechner ansonsten wieder im Lot?

Drummer_Shoo 28.06.2011 18:41

Sieht bislang so aus. Danke.

Sollte ich wieder ähnliche Probleme haben, reichen diese 3 Schritte als Maßnahme aus ?

cosinus 28.06.2011 20:33

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Drummer_Shoo 28.06.2011 21:07

Liste der Anhänge anzeigen (Anzahl: 1)
Zu früh gefreut. :headbang:

Hab grad folgende Meldung bekommen:
http://www.trojaner-board.de/attachm...1&d=1309291533

Ausserdem hab ich heut' die Meldung bekommen Internet Explorer funktioniert nicht richtung muss beendet werden ...

Ohne das ich den IE am laufen hatte.

cosinus 28.06.2011 21:09

Hast du das nur beim IE oder auch bei anderen Browsern?

Drummer_Shoo 28.06.2011 21:12

Ich habe nur den IE (standartmäßig) und FireFox drauf.
Und nutzen tu ich nur FireFox.

cosinus 28.06.2011 21:13

Falls Du kein Brennprogramm installiert hast, lade dir bitte ISOBurner herunter. Das Programm wird Dir erlauben, OTLPE auf eine CD zu brennen und sie bootfähig zu machen. Du brauchst das Tool nur zu installieren, der Rest läuft automatisch => Wie brenne ich eine ISO Datei auf CD/DVD.
  • Lade OTLPENet.exe von OldTimer herunter und speichere sie auf Deinem Desktop. Anmerkung: Die Datei ist ca. 120 MB groß und es wird bei langsamer Internet-Verbindung ein wenig dauern, bis Du sie runtergeladen hast.
  • Wenn der Download fertig ist, mache einen Doppelklick auf die Datei und beantworte die Frage "Do you want to burn the CD?" mit Yes.
  • Lege eine leere CD in Deinen Brenner.
  • ImgBurn (oder Dein Brennprogramm) wird das Archiv extrahieren und OTLPE Network auf die CD brennen.
  • Wenn der Brenn-Vorgang abgeschlossen ist, wirst Du eine Dialogbox sehen => "Operation successfully completed".
  • Du kannst nun die Fenster des Brennprogramms schließen.
Nun boote von der OTLPE CD. Hinweis: Wie boote ich von CD
  • Dein System sollte nach einigen Minuten den REATOGO-X-PE Desktop anzeigen.
  • Mache einen Doppelklick auf das OTLPE Icon.
  • Wenn Du gefragt wirst "Do you wish to load the remote registry", dann wähle Yes.
  • Wenn Du gefragt wirst "Do you wish to load remote user profile(s) for scanning", dann wähle Yes.
  • Vergewissere Dich, dass die Box "Automatically Load All Remaining Users" gewählt ist und drücke OK.
  • OTLpe sollte nun starten.
  • Drücke Run Scan, um den Scan zu starten.
  • Wenn der Scan fertig ist, werden die Dateien C:\OTL.Txt und C:\Extras.Txt erstellt
  • Kopiere diese Datei auf Deinen USB-Stick, wenn Du keine Internetverbindung auf diesem System hast.
  • Bitte poste den Inhalt von C:\OTL.Txt und Extras.Txt.

Drummer_Shoo 29.06.2011 19:08

Ich hab nur die OTL.txt:

Code:

OTL logfile created on: 6/29/2011 8:56:04 PM - Run
OTLPE by OldTimer - Version 3.1.46.0    Folder = X:\Programs\OTLPE
Windows 7 Home Premium  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 92.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = I: | %SystemRoot% = I:\Windows | %ProgramFiles% = I:\Program Files
Drive C: | 100.00 Mb Total Space | 75.86 Mb Free Space | 75.87% Space Free | Partition Type: NTFS
Drive D: | 232.83 Gb Total Space | 108.45 Gb Free Space | 46.58% Space Free | Partition Type: FAT32
Drive I: | 443.13 Gb Total Space | 315.39 Gb Free Space | 71.17% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011/05/25 11:29:48 | 001,336,712 | ---- | M] (LogMeIn Inc.) [Disabled] -- I:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011/05/01 17:00:36 | 000,136,360 | ---- | M] (Avira GmbH) [Auto] -- I:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/21 07:21:24 | 000,632,832 | ---- | M] (Nokia) [On_Demand] -- I:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/03/20 05:42:20 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- I:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/11/18 08:35:50 | 000,240,112 | ---- | M] (CyberLink) [Disabled] -- I:\Program Files\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_E92D8507)
SRV - [2010/07/04 05:44:03 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- I:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto] -- I:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/09/10 18:45:04 | 000,124,832 | ---- | M] () [Disabled] -- I:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2007/03/22 05:09:16 | 001,689,304 | ---- | M] ( ) [Auto] -- I:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe -- (AshampooDefragService)
SRV - [2005/11/17 09:18:52 | 001,527,900 | ---- | M] (MAGIX®) [Disabled] -- I:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005/03/04 06:42:08 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand] -- I:\Program Files\Common Files\AVM\De_serv.exe -- (de_serv)
SRV - [2005/03/04 05:50:00 | 000,118,784 | ---- | M] (AVM Berlin) [Auto] -- I:\Program Files\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (catchme)
DRV - [2011/06/28 16:31:30 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- I:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2011/03/20 05:42:20 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System] -- I:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/12/02 09:13:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- I:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/12/02 09:13:28 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- I:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/12/02 09:13:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- I:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/12/02 09:13:22 | 000,018,304 | ---- | M] (Nokia) [Kernel | On_Demand] -- I:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010/11/22 17:55:16 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto] -- I:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/10/13 16:49:42 | 000,022,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- I:\Windows\System32\drivers\usbsermpt.sys -- (usbsermpt)
DRV - [2010/08/14 11:59:32 | 000,281,760 | ---- | M] () [Kernel | Auto] -- I:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2010/08/14 11:59:32 | 000,025,888 | ---- | M] () [Kernel | Auto] -- I:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010/07/10 00:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- I:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/05/10 14:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- I:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- I:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/01/19 10:10:38 | 000,087,536 | ---- | M] (CyberLink Corp.) [2011/06/07 21:11:23] [Kernel | Auto] -- I:\Program Files\CyberLink\PowerDVD9\000.fcl -- ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2009/12/21 20:26:36 | 000,030,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- I:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009/11/20 07:15:18 | 000,137,728 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand] -- I:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2009/11/20 07:15:16 | 000,058,880 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand] -- I:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2009/10/07 08:48:58 | 000,163,368 | ---- | M] (CyberLink Corporation.) [File_System | Auto] -- I:\Windows\System32\drivers\CLBUDF.sys -- (CLBUDF)
DRV - [2009/10/07 08:48:58 | 000,015,784 | ---- | M] (Cyberlink Co.,Ltd.) [Kernel | System] -- I:\Windows\System32\drivers\CLBStor.sys -- (CLBStor)
DRV - [2009/07/13 21:19:10 | 000,245,328 | ---- | M] () [Kernel | Boot] -- I:\Windows\System32\drivers\volsnap.sys -- (volsnap)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- I:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/05/11 04:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- I:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/05/04 21:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot] -- I:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV - [2009/04/29 09:37:26 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand] -- I:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTERx86)
DRV - [2009/03/18 11:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- I:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- I:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/07/27 06:46:06 | 000,251,680 | ---- | M] (Protect Software GmbH) [Kernel | Auto] -- I:\Windows\System32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2007/07/27 04:13:08 | 000,330,144 | ---- | M] (Protect Software GmbH) [Kernel | Auto] -- I:\Windows\System32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007/05/11 10:17:25 | 000,221,184 | ---- | M] (TerraTec Electronic GmbH.) [Kernel | On_Demand] -- I:\Windows\System32\drivers\Cinergy_HT_PCI_MKII.sys -- (Cinergy_HT_PCI_MKII) Cinergy HT PCI (MKII)
DRV - [2004/07/14 06:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto] -- I:\Windows\System32\drivers\hardlock.sys -- (Hardlock)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
 
IE - HKU\.DEFAULT\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
IE - HKU\Melms_ON_I\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\Melms_ON_I\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Melms_ON_I\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 13 EE 64 48 11 CB 01  [binary data]
IE - HKU\Melms_ON_I\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\Melms_ON_I\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Melms_ON_I\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/05/22 10:36:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/05/22 10:36:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/06/18 16:02:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/22 12:08:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/15 06:43:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/06/18 16:02:35 | 000,000,000 | ---D | M]
 
[2011/05/04 11:40:05 | 000,000,000 | ---D | M] (No name found) -- I:\Program Files\Mozilla Firefox\extensions
[2010/07/17 03:13:10 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/12 03:21:14 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/03 14:02:49 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/22 12:08:27 | 000,142,296 | ---- | M] (Mozilla Foundation) -- I:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/13 23:08:00 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- I:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/09 06:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- I:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010/01/01 04:00:00 | 000,001,392 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010/01/01 04:00:00 | 000,002,252 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 04:00:00 | 000,001,153 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2010/01/01 04:00:00 | 000,006,805 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010/01/01 04:00:00 | 000,001,178 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010/01/01 04:00:00 | 000,001,105 | ---- | M] () -- I:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011/05/08 09:58:58 | 000,000,027 | ---- | M]) - I:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - I:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - I:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - I:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - I:\Program Files\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O4 - HKLM..\Run: [Adobe Photo Downloader] I:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] I:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] I:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] I:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [InstantBurn] I:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [Name of App] I:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NokiaMServer] I:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NUSB3MON] I:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKU\Melms_ON_I..\Run: []  File not found
O4 - HKU\Melms_ON_I..\Run: [NokiaOviSuite2] I:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O4 - HKU\Melms_ON_I..\Run: [Remote Control Editor] I:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKU\Melms_ON_I..\Run: [SIDEBAR] I:\Program Files\Desktop Sidebar\dsidebar.exe (Idea2)
O4 - Startup: Error locating startup folders.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\Melms_ON_I\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - I:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - I:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - I:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - I:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - I:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - I:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - I:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - I:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/06/28 16:32:21 | 127,222,215 | ---- | C] (Igor Pavlov) -- I:\Users\Melms\Desktop\OTLPENet.exe
[2011/06/28 16:31:30 | 000,691,696 | ---- | C] (Duplex Secure Ltd.) -- I:\Windows\System32\drivers\sptd.sys
[2011/06/28 16:30:44 | 000,000,000 | ---D | C] -- I:\Program Files\LSoft Technologies
[2011/06/28 16:30:44 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2011/06/28 16:29:49 | 004,940,440 | ---- | C] (Macrovision Corporation) -- I:\Users\Melms\Desktop\IsoBurner-Setup.exe
[2011/06/26 10:04:31 | 000,000,000 | ---D | C] -- I:\Sierra
[2011/06/26 10:04:31 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2011/06/18 16:09:16 | 000,000,000 | ---D | C] -- I:\ProgramData\NokiaAccount
[2011/06/18 16:04:04 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Local\Nokia
[2011/06/18 16:03:44 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia
[2011/06/18 16:02:25 | 000,000,000 | ---D | C] -- I:\Program Files\PC Connectivity Solution
[2011/06/18 16:02:19 | 000,000,000 | -HSD | C] -- I:\Config.Msi
[2011/06/18 16:00:27 | 000,000,000 | ---D | C] -- I:\ProgramData\NokiaInstallerCache
[2011/06/16 13:48:59 | 000,161,792 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\d3d10_1.dll
[2011/06/16 13:48:52 | 000,599,552 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\msfeeds.dll
[2011/06/16 13:48:52 | 000,381,440 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\iedkcs32.dll
[2011/06/16 13:48:51 | 001,638,912 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\mshtml.tlb
[2011/06/16 13:48:51 | 000,606,208 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\mstime.dll
[2011/06/16 13:48:51 | 000,386,048 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\html.iec
[2011/06/16 13:48:51 | 000,185,856 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\iepeers.dll
[2011/06/16 13:48:51 | 000,176,640 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\ieui.dll
[2011/06/16 13:48:51 | 000,064,512 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\msfeedsbs.dll
[2011/06/16 13:48:51 | 000,048,128 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\jsproxy.dll
[2011/06/16 13:48:51 | 000,044,544 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\licmgr10.dll
[2011/06/16 13:48:51 | 000,012,800 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\msfeedssync.exe
[2011/06/11 11:14:31 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/06/11 11:13:31 | 000,000,000 | ---D | C] -- I:\Program Files\Activision
[2011/06/11 03:14:53 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- I:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/07 15:24:20 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Roaming\NVIDIA
[2011/06/07 15:24:06 | 000,000,000 | ---D | C] -- I:\Users\Melms\Documents\CyberLink
[2011/06/07 15:17:37 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Local\Power2Go
[2011/06/07 15:11:22 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2011/06/07 15:11:16 | 000,000,000 | ---D | C] -- I:\Program Files\Common Files\CyberLink
[2011/06/07 15:10:03 | 000,029,480 | ---- | C] (Microsoft Corporation) -- I:\Windows\System32\msxml3a.dll
[2011/06/07 15:08:03 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Roaming\CyberLink
[2011/06/07 15:08:00 | 000,000,000 | ---D | C] -- I:\Users\Melms\AppData\Local\Cyberlink
[2011/06/07 15:05:23 | 000,000,000 | R--D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2011/06/07 15:05:20 | 000,000,000 | ---D | C] -- I:\Program Files\Common Files\LightScribe
[2011/06/07 15:04:23 | 000,163,368 | ---- | C] (CyberLink Corporation.) -- I:\Windows\System32\drivers\CLBUDF.sys
[2011/06/07 15:04:23 | 000,015,784 | ---- | C] (Cyberlink Co.,Ltd.) -- I:\Windows\System32\drivers\CLBStor.sys
[2011/06/07 15:04:10 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2011/06/07 15:04:04 | 000,000,000 | ---D | C] -- I:\Program Files\CyberLink
[2011/06/07 15:03:59 | 000,000,000 | ---D | C] -- I:\ProgramData\CyberLink
[2011/06/07 15:02:37 | 000,000,000 | ---D | C] -- I:\ProgramData\Temp
[2011/06/07 13:52:10 | 001,531,392 | ---- | C] (Toshiba Samsung Storage Technology Corporation) -- I:\Users\Melms\AppData\Roaming\tsdnwin.dll
[2011/06/07 13:35:54 | 000,000,000 | ---D | C] -- I:\Program Files\SAMSUNG
[2011/06/07 13:35:54 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\ODD Firmware LiveUpdate
[2011/05/31 15:14:30 | 000,000,000 | ---D | C] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/05/31 15:14:29 | 000,000,000 | ---D | C] -- I:\Program Files\LogMeIn Hamachi
[2010/10/11 15:12:07 | 000,180,224 | ---- | C] ( ) -- I:\Windows\System32\rsnp2uvc.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011/06/29 02:16:36 | 000,067,584 | --S- | M] () -- I:\Windows\bootstat.dat
[2011/06/29 02:06:03 | 000,014,624 | ---- | M] () -- I:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/29 02:06:03 | 000,014,624 | ---- | M] () -- I:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/29 01:59:32 | 000,000,431 | ---- | M] () -- I:\Users\Melms\AppData\Roaming\SamsungLiveUpdateConfig.ini
[2011/06/29 01:58:50 | 000,001,092 | ---- | M] () -- I:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/29 01:58:35 | 1610,309,632 | -HS- | M] () -- I:\hiberfil.sys
[2011/06/28 17:29:00 | 000,001,096 | ---- | M] () -- I:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/28 16:38:01 | 127,222,215 | ---- | M] (Igor Pavlov) -- I:\Users\Melms\Desktop\OTLPENet.exe
[2011/06/28 16:30:44 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ ISO Burner
[2011/06/28 16:29:56 | 004,940,440 | ---- | M] (Macrovision Corporation) -- I:\Users\Melms\Desktop\IsoBurner-Setup.exe
[2011/06/28 16:04:39 | 000,031,137 | ---- | M] () -- I:\Users\Melms\Desktop\Bild3.png
[2011/06/27 02:29:09 | 000,668,302 | ---- | M] () -- I:\Windows\System32\perfh007.dat
[2011/06/27 02:29:09 | 000,619,894 | ---- | M] () -- I:\Windows\System32\perfh009.dat
[2011/06/27 02:29:09 | 000,134,150 | ---- | M] () -- I:\Windows\System32\perfc007.dat
[2011/06/27 02:29:09 | 000,110,082 | ---- | M] () -- I:\Windows\System32\perfc009.dat
[2011/06/26 15:30:42 | 000,046,186 | ---- | M] () -- I:\Users\Melms\Desktop\Bild2.png
[2011/06/26 11:11:53 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/26 10:13:37 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2011/06/26 10:13:34 | 000,000,403 | ---- | M] () -- I:\Windows\SIERRA.INI
[2011/06/18 16:03:44 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia
[2011/06/18 15:48:05 | 000,000,000 | -H-- | M] () -- I:\Windows\System32\drivers\Msft_User_wpdcomp_01_09_00.Wdf
[2011/06/18 15:47:48 | 000,000,000 | -H-- | M] () -- I:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/06/18 04:07:53 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- I:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/17 02:31:05 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/06/11 11:14:31 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/06/11 11:14:30 | 000,000,324 | ---- | M] () -- I:\Windows\game.ini
[2011/06/08 13:50:20 | 000,029,480 | ---- | M] (Microsoft Corporation) -- I:\Windows\System32\msxml3a.dll
[2011/06/07 15:17:26 | 000,344,400 | ---- | M] () -- I:\Windows\System32\FNTCACHE.DAT
[2011/06/07 15:09:48 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2011/06/07 15:05:23 | 000,000,000 | R--D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2011/06/07 13:52:26 | 001,531,392 | ---- | M] (Toshiba Samsung Storage Technology Corporation) -- I:\Users\Melms\AppData\Roaming\tsdnwin.dll
[2011/06/07 13:35:54 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\ODD Firmware LiveUpdate
[2011/06/05 15:07:52 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\sixteen tons entertainment
[2011/05/31 15:14:30 | 000,000,000 | ---D | M] -- I:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
 
========== Files Created - No Company Name ==========
 
[2011/06/28 16:04:39 | 000,031,137 | ---- | C] () -- I:\Users\Melms\Desktop\Bild3.png
[2011/06/26 15:30:41 | 000,046,186 | ---- | C] () -- I:\Users\Melms\Desktop\Bild2.png
[2011/06/26 10:04:31 | 000,000,403 | ---- | C] () -- I:\Windows\SIERRA.INI
[2011/06/18 15:48:05 | 000,000,000 | -H-- | C] () -- I:\Windows\System32\drivers\Msft_User_wpdcomp_01_09_00.Wdf
[2011/06/18 15:47:48 | 000,000,000 | -H-- | C] () -- I:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/06/11 11:14:30 | 000,000,324 | ---- | C] () -- I:\Windows\game.ini
[2011/06/07 13:35:58 | 000,000,431 | ---- | C] () -- I:\Users\Melms\AppData\Roaming\SamsungLiveUpdateConfig.ini
[2011/05/08 09:51:03 | 000,256,512 | ---- | C] () -- I:\Windows\PEV.exe
[2011/05/08 09:51:03 | 000,098,816 | ---- | C] () -- I:\Windows\sed.exe
[2011/05/08 09:51:03 | 000,089,088 | ---- | C] () -- I:\Windows\MBR.exe
[2011/05/08 09:51:03 | 000,080,412 | ---- | C] () -- I:\Windows\grep.exe
[2011/05/08 09:51:03 | 000,068,096 | ---- | C] () -- I:\Windows\zip.exe
[2011/03/20 14:48:15 | 000,043,520 | ---- | C] () -- I:\Windows\System32\CmdLineExt03.dll
[2011/02/26 19:45:09 | 000,000,381 | ---- | C] () -- I:\Windows\BeatBox.INI
[2011/02/26 19:45:09 | 000,000,028 | ---- | C] () -- I:\Windows\Robota.INI
[2011/02/26 18:58:31 | 000,124,596 | ---- | C] () -- I:\Windows\System32\mlfcache.dat
[2011/02/05 14:09:24 | 000,139,152 | ---- | C] () -- I:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/05 14:09:18 | 000,139,152 | ---- | C] () -- I:\Users\Melms\AppData\Roaming\PnkBstrK.sys
[2011/02/05 14:08:43 | 000,111,928 | ---- | C] () -- I:\Windows\System32\PnkBstrB.exe
[2011/02/05 14:08:40 | 000,794,408 | ---- | C] () -- I:\Windows\System32\pbsvc.exe
[2011/02/05 14:08:40 | 000,075,064 | ---- | C] () -- I:\Windows\System32\PnkBstrA.exe
[2011/02/03 15:56:57 | 000,000,019 | ---- | C] () -- I:\Windows\SoundConverter.INI
[2010/12/29 15:00:43 | 000,000,180 | ---- | C] () -- I:\Windows\System32\msftpd.exe
[2010/12/19 14:34:53 | 000,000,221 | ---- | C] () -- I:\Windows\SOFTEK.INI
[2010/10/19 11:18:19 | 000,002,464 | ---- | C] () -- I:\Windows\netdet.ini
[2010/10/15 15:00:00 | 000,007,168 | ---- | C] () -- I:\Users\Melms\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/11 15:12:07 | 000,237,568 | ---- | C] () -- I:\Windows\tsnp2uvc.exe
[2010/08/28 13:41:48 | 000,053,248 | ---- | C] () -- I:\Windows\System32\mgxasio2.dll
[2010/08/28 13:34:40 | 000,120,200 | ---- | C] () -- I:\Windows\System32\DLLDEV32i.dll
[2010/08/28 13:34:13 | 000,006,768 | ---- | C] () -- I:\Windows\mgxoschk.ini
[2010/08/14 11:26:47 | 000,007,597 | ---- | C] () -- I:\Users\Melms\AppData\Local\Resmon.ResmonCfg
[2010/08/14 11:14:19 | 000,281,760 | ---- | C] () -- I:\Windows\System32\drivers\atksgt.sys
[2010/08/14 11:14:14 | 000,025,888 | ---- | C] () -- I:\Windows\System32\drivers\lirsgt.sys
[2010/07/27 07:00:39 | 000,000,614 | ---- | C] () -- I:\Windows\eReg.dat
[2010/07/04 05:29:04 | 000,000,209 | ---- | C] () -- I:\Windows\ODBCINST.INI
[2009/08/02 18:21:54 | 000,197,912 | ---- | C] () -- I:\Windows\System32\physxcudart_20.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelSwedish.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelSpanish.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelPortugese.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelKorean.dll
[2009/08/02 18:21:54 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelJapanese.dll
[2009/08/02 18:21:52 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelGerman.dll
[2009/08/02 18:21:52 | 000,058,648 | ---- | C] () -- I:\Windows\System32\AgCPanelFrench.dll
[2009/07/14 04:47:43 | 000,668,302 | ---- | C] () -- I:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- I:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,134,150 | ---- | C] () -- I:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- I:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- I:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,344,400 | ---- | C] () -- I:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,619,894 | ---- | C] () -- I:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- I:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,110,082 | ---- | C] () -- I:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- I:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- I:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- I:\Windows\System32\dssec.dat
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- I:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- I:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- I:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- I:\Windows\System32\BWContextHandler.dll
[2009/07/13 19:11:34 | 000,245,328 | ---- | C] () -- I:\Windows\System32\drivers\volsnap.sys
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- I:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2010/07/20 09:35:21 | 000,000,000 | ---D | M] -- I:\ProgramData\#Company short name
[2010/06/21 09:45:55 | 000,000,000 | ---D | M] -- I:\ProgramData\Alwil Software
[2010/06/21 09:44:06 | 000,000,000 | -HSD | M] -- I:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Application Data
[2010/10/13 16:57:33 | 000,000,000 | ---D | M] -- I:\ProgramData\BVRP Software
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Documents
[2010/06/21 09:44:06 | 000,000,000 | -HSD | M] -- I:\ProgramData\Dokumente
[2010/11/20 09:51:33 | 000,000,000 | ---D | M] -- I:\ProgramData\EA Core
[2011/04/22 11:16:27 | 000,000,000 | ---D | M] -- I:\ProgramData\Electronic Arts
[2010/06/21 09:44:06 | 000,000,000 | -HSD | M] -- I:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Favorites
[2011/05/08 10:31:49 | 000,000,000 | ---D | M] -- I:\ProgramData\ICQ
[2011/05/06 16:00:19 | 000,000,000 | ---D | M] -- I:\ProgramData\Installations
[2010/08/28 13:40:04 | 000,000,000 | ---D | M] -- I:\ProgramData\MAGIX
[2010/06/26 12:58:11 | 000,000,000 | ---D | M] -- I:\ProgramData\Messenger Plus!
[2011/06/18 16:09:16 | 000,000,000 | ---D | M] -- I:\ProgramData\NokiaAccount
[2011/06/18 16:00:27 | 000,000,000 | ---D | M] -- I:\ProgramData\NokiaInstallerCache
[2011/05/06 16:20:27 | 000,000,000 | ---D | M] -- I:\ProgramData\PC Suite
[2010/12/20 10:12:08 | 000,000,000 | ---D | M] -- I:\ProgramData\Solidshield
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Start Menu
[2010/06/21 09:44:06 | 000,000,000 | -HSD | M] -- I:\ProgramData\Startmenü
[2011/06/08 13:50:49 | 000,000,000 | ---D | M] -- I:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- I:\ProgramData\Templates
[2010/06/26 13:05:50 | 000,000,000 | ---D | M] -- I:\ProgramData\TerraTec
[2010/06/21 09:44:06 | 000,000,000 | -HSD | M] -- I:\ProgramData\Vorlagen
[2010/10/01 01:59:29 | 000,000,000 | ---D | M] -- I:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/19 00:47:39 | 000,032,632 | ---- | M] () -- I:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >


cosinus 29.06.2011 21:47

Den TDSSKiller konntest du ja bisher nicht starten. Versuch das bitte nochmal:

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://www.trojaner-board.de/attachm...rnen-start.png


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Drummer_Shoo 29.06.2011 21:57

Code:

2011/06/29 22:57:04.0130 2444        TDSS rootkit removing tool 2.5.8.0 Jun 28 2011 19:12:16
2011/06/29 22:57:04.0333 2444        ================================================================================
2011/06/29 22:57:04.0333 2444        SystemInfo:
2011/06/29 22:57:04.0333 2444       
2011/06/29 22:57:04.0333 2444        OS Version: 6.1.7600 ServicePack: 0.0
2011/06/29 22:57:04.0333 2444        Product type: Workstation
2011/06/29 22:57:04.0333 2444        ComputerName: MELMS-PC
2011/06/29 22:57:04.0333 2444        UserName: Melms
2011/06/29 22:57:04.0333 2444        Windows directory: C:\Windows
2011/06/29 22:57:04.0333 2444        System windows directory: C:\Windows
2011/06/29 22:57:04.0333 2444        Processor architecture: Intel x86
2011/06/29 22:57:04.0333 2444        Number of processors: 2
2011/06/29 22:57:04.0333 2444        Page size: 0x1000
2011/06/29 22:57:04.0333 2444        Boot type: Normal boot
2011/06/29 22:57:04.0333 2444        ================================================================================
2011/06/29 22:57:06.0158 2444        Initialize success
2011/06/29 22:57:08.0966 1900        ================================================================================
2011/06/29 22:57:08.0966 1900        Scan started
2011/06/29 22:57:08.0966 1900        Mode: Manual;
2011/06/29 22:57:08.0966 1900        ================================================================================
2011/06/29 22:57:11.0415 1900        1394ohci        (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/06/29 22:57:11.0478 1900        acedrv10        (553ba53445795cbc0d4f9fa37eb855a6) C:\Windows\system32\drivers\acedrv10.sys
2011/06/29 22:57:11.0556 1900        acehlp10        (8ce00b6a46962a1808b19cd1dae5170c) C:\Windows\system32\drivers\acehlp10.sys
2011/06/29 22:57:11.0634 1900        ACPI            (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/06/29 22:57:11.0665 1900        AcpiPmi        (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/06/29 22:57:11.0712 1900        adp94xx        (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/06/29 22:57:11.0759 1900        adpahci        (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/06/29 22:57:11.0790 1900        adpu320        (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/06/29 22:57:11.0868 1900        AFD            (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys
2011/06/29 22:57:11.0883 1900        agp440          (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/06/29 22:57:11.0930 1900        aic78xx        (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/06/29 22:57:11.0977 1900        aliide          (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/06/29 22:57:12.0024 1900        amdagp          (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/06/29 22:57:12.0055 1900        amdide          (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/06/29 22:57:12.0086 1900        AmdK8          (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/06/29 22:57:12.0133 1900        AmdPPM          (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/06/29 22:57:12.0180 1900        amdsata        (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys
2011/06/29 22:57:12.0227 1900        amdsbs          (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/06/29 22:57:12.0273 1900        amdxata        (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys
2011/06/29 22:57:12.0367 1900        AppID          (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/06/29 22:57:12.0445 1900        arc            (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/06/29 22:57:12.0492 1900        arcsas          (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/06/29 22:57:12.0539 1900        AsyncMac        (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/29 22:57:12.0554 1900        atapi          (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/06/29 22:57:12.0585 1900        AtiPcie        (b73c832088dd54b55e04ff6f9646ad8c) C:\Windows\system32\DRIVERS\AtiPcie.sys
2011/06/29 22:57:12.0648 1900        atksgt          (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/06/29 22:57:12.0710 1900        avgntflt        (47b879406246ffdced59e18d331a0e7d) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/06/29 22:57:12.0741 1900        avipbb          (5fedef54757b34fb611b9ec8fb399364) C:\Windows\system32\DRIVERS\avipbb.sys
2011/06/29 22:57:12.0819 1900        b06bdrv        (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/06/29 22:57:12.0882 1900        b57nd60x        (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/06/29 22:57:12.0929 1900        Beep            (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/06/29 22:57:12.0991 1900        blbdrive        (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/06/29 22:57:13.0069 1900        bowser          (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/29 22:57:13.0100 1900        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/06/29 22:57:13.0131 1900        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/06/29 22:57:13.0178 1900        Brserid        (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/06/29 22:57:13.0225 1900        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/06/29 22:57:13.0272 1900        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/06/29 22:57:13.0303 1900        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/06/29 22:57:13.0365 1900        BTHMODEM        (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/06/29 22:57:13.0506 1900        cdfs            (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/29 22:57:13.0553 1900        cdrom          (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/06/29 22:57:13.0599 1900        Cinergy_HT_PCI_MKII (e55e0c3094bed534998e5ad88f9aacc2) C:\Windows\system32\DRIVERS\Cinergy_HT_PCI_MKII.sys
2011/06/29 22:57:13.0646 1900        circlass        (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/06/29 22:57:13.0740 1900        CLBStor        (f5c8f7a7d1a3f569bf77574a795cc19e) C:\Windows\system32\drivers\CLBStor.sys
2011/06/29 22:57:13.0802 1900        CLBUDF          (07b3e4fc5d4943ba802607ddf8f5d418) C:\Windows\system32\drivers\CLBUDF.sys
2011/06/29 22:57:13.0865 1900        CLFS            (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/06/29 22:57:13.0896 1900        CmBatt          (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/06/29 22:57:13.0927 1900        cmdide          (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/06/29 22:57:13.0943 1900        CNG            (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/06/29 22:57:13.0989 1900        Compbatt        (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/06/29 22:57:14.0036 1900        CompositeBus    (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/06/29 22:57:14.0083 1900        crcdisk        (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/06/29 22:57:14.0192 1900        DfsC            (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys
2011/06/29 22:57:14.0239 1900        discache        (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/06/29 22:57:14.0270 1900        Disk            (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/06/29 22:57:14.0317 1900        drmkaud        (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/06/29 22:57:14.0379 1900        DXGKrnl        (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/29 22:57:14.0489 1900        ebdrv          (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/06/29 22:57:14.0598 1900        ElbyCDIO        (44996a2addd2db7454f2ca40b67d8941) C:\Windows\system32\Drivers\ElbyCDIO.sys
2011/06/29 22:57:14.0629 1900        elxstor        (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/06/29 22:57:14.0676 1900        ErrDev          (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/06/29 22:57:14.0723 1900        exfat          (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/06/29 22:57:14.0769 1900        fastfat        (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/06/29 22:57:14.0816 1900        fdc            (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/29 22:57:14.0863 1900        FileInfo        (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/06/29 22:57:14.0894 1900        Filetrace      (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/06/29 22:57:14.0957 1900        flpydisk        (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/29 22:57:15.0003 1900        FltMgr          (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/06/29 22:57:15.0066 1900        FsDepends      (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/06/29 22:57:15.0097 1900        Fs_Rec          (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/29 22:57:15.0144 1900        fvevol          (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2011/06/29 22:57:15.0175 1900        gagp30kx        (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/06/29 22:57:15.0222 1900        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/06/29 22:57:15.0331 1900        hamachi        (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
2011/06/29 22:57:15.0409 1900        Hardlock        (ed32d389f8b0e74e400932e020bcfbdf) C:\Windows\system32\drivers\hardlock.sys
2011/06/29 22:57:15.0487 1900        hcw85cir        (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/06/29 22:57:15.0518 1900        HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/06/29 22:57:15.0549 1900        HDAudBus        (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/06/29 22:57:15.0565 1900        HidBatt        (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/06/29 22:57:15.0612 1900        HidBth          (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/06/29 22:57:15.0659 1900        HidIr          (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/06/29 22:57:15.0705 1900        HidUsb          (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/29 22:57:15.0752 1900        HpSAMD          (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/06/29 22:57:15.0830 1900        HTTP            (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/06/29 22:57:15.0846 1900        hwpolicy        (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/06/29 22:57:15.0861 1900        i8042prt        (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/06/29 22:57:15.0908 1900        iaStorV        (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys
2011/06/29 22:57:15.0955 1900        iirsp          (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/06/29 22:57:16.0064 1900        IntcAzAudAddService (0c36a7de2b4e6ec301b98ae300547701) C:\Windows\system32\drivers\RTKVHDA.sys
2011/06/29 22:57:16.0127 1900        intelide        (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/06/29 22:57:16.0189 1900        intelppm        (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/29 22:57:16.0251 1900        IPMIDRV        (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/06/29 22:57:16.0283 1900        IPNAT          (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/06/29 22:57:16.0329 1900        IRENUM          (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/06/29 22:57:16.0392 1900        isapnp          (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/06/29 22:57:16.0423 1900        iScsiPrt        (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/06/29 22:57:16.0470 1900        kbdclass        (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/06/29 22:57:16.0517 1900        kbdhid          (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/06/29 22:57:16.0595 1900        KMWDFILTERx86  (4476fe98aaf505acdcd3ee6360aabec1) C:\Windows\system32\DRIVERS\KMWDFILTER.sys
2011/06/29 22:57:16.0641 1900        KSecDD          (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/29 22:57:16.0719 1900        KSecPkg        (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/06/29 22:57:16.0813 1900        lirsgt          (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/06/29 22:57:16.0844 1900        lltdio          (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/29 22:57:16.0891 1900        LSI_FC          (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/06/29 22:57:16.0938 1900        LSI_SAS        (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/06/29 22:57:16.0985 1900        LSI_SAS2        (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/06/29 22:57:17.0016 1900        LSI_SCSI        (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/06/29 22:57:17.0047 1900        luafv          (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/06/29 22:57:17.0094 1900        megasas        (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/06/29 22:57:17.0141 1900        MegaSR          (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/06/29 22:57:17.0187 1900        Modem          (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/06/29 22:57:17.0219 1900        monitor        (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/29 22:57:17.0234 1900        mouclass        (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/06/29 22:57:17.0265 1900        mouhid          (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/29 22:57:17.0297 1900        mountmgr        (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/06/29 22:57:17.0312 1900        mpio            (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/06/29 22:57:17.0359 1900        mpsdrv          (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/29 22:57:17.0390 1900        MRxDAV          (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/06/29 22:57:17.0468 1900        mrxsmb          (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/29 22:57:17.0515 1900        mrxsmb10        (c108952d3660375dcb716b222912e868) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/29 22:57:17.0562 1900        mrxsmb20        (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/29 22:57:17.0593 1900        msahci          (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/06/29 22:57:17.0640 1900        msdsm          (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/06/29 22:57:17.0671 1900        Msfs            (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/06/29 22:57:17.0702 1900        mshidkmdf      (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/06/29 22:57:17.0749 1900        msisadrv        (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/06/29 22:57:17.0780 1900        MSKSSRV        (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/29 22:57:17.0827 1900        MSPCLOCK        (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/29 22:57:17.0874 1900        MSPQM          (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/06/29 22:57:17.0889 1900        MsRPC          (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/06/29 22:57:17.0921 1900        mssmbios        (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/29 22:57:17.0936 1900        MSTEE          (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/06/29 22:57:17.0983 1900        MTConfig        (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/06/29 22:57:18.0030 1900        Mup            (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/06/29 22:57:18.0077 1900        NativeWifiP    (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/29 22:57:18.0123 1900        NDIS            (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/06/29 22:57:18.0155 1900        NdisCap        (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/06/29 22:57:18.0201 1900        NdisTapi        (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/29 22:57:18.0248 1900        Ndisuio        (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/29 22:57:18.0264 1900        NdisWan        (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/29 22:57:18.0311 1900        NDProxy        (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/06/29 22:57:18.0342 1900        NetBIOS        (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/29 22:57:18.0373 1900        NetBT          (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/29 22:57:18.0404 1900        nfrd960        (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/06/29 22:57:18.0482 1900        nmwcd          (712bc0c22ba00b2ba324c6b8df668ee7) C:\Windows\system32\drivers\ccdcmb.sys
2011/06/29 22:57:18.0545 1900        nmwcdc          (7312987b6ccde6f6cee32c14bed1ca2e) C:\Windows\system32\drivers\ccdcmbo.sys
2011/06/29 22:57:18.0576 1900        Npfs            (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/06/29 22:57:18.0607 1900        nsiproxy        (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/29 22:57:18.0685 1900        Ntfs            (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys
2011/06/29 22:57:18.0747 1900        Null            (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/06/29 22:57:18.0794 1900        nusb3hub        (68c890ddb21028cb1ea5551b47b29e1b) C:\Windows\system32\DRIVERS\nusb3hub.sys
2011/06/29 22:57:18.0810 1900        nusb3xhc        (2cf970c1a9e05d3b91039c2dd4471c0e) C:\Windows\system32\DRIVERS\nusb3xhc.sys
2011/06/29 22:57:18.0997 1900        nvlddmkm        (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/06/29 22:57:19.0169 1900        nvraid          (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys
2011/06/29 22:57:19.0215 1900        nvstor          (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys
2011/06/29 22:57:19.0262 1900        nv_agp          (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/06/29 22:57:19.0309 1900        ohci1394        (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/06/29 22:57:19.0371 1900        Parport        (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/06/29 22:57:19.0403 1900        partmgr        (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/06/29 22:57:19.0434 1900        Parvdm          (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/06/29 22:57:19.0512 1900        pccsmcfd        (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2011/06/29 22:57:19.0559 1900        pci            (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/06/29 22:57:19.0605 1900        pciide          (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/06/29 22:57:19.0652 1900        pcmcia          (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/06/29 22:57:19.0683 1900        pcw            (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/06/29 22:57:19.0715 1900        PEAUTH          (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/06/29 22:57:19.0824 1900        PptpMiniport    (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/29 22:57:19.0855 1900        Processor      (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/06/29 22:57:19.0886 1900        Psched          (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/29 22:57:19.0949 1900        PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
2011/06/29 22:57:20.0011 1900        ql2300          (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/06/29 22:57:20.0058 1900        ql40xx          (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/06/29 22:57:20.0089 1900        QWAVEdrv        (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/29 22:57:20.0136 1900        RasAcd          (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/29 22:57:20.0183 1900        RasAgileVpn    (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/06/29 22:57:20.0214 1900        Rasl2tp        (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/29 22:57:20.0261 1900        RasPppoe        (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/29 22:57:20.0307 1900        RasSstp        (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/29 22:57:20.0339 1900        rdbss          (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/29 22:57:20.0385 1900        rdpbus          (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/06/29 22:57:20.0417 1900        RDPCDD          (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/29 22:57:20.0448 1900        RDPENCDD        (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/29 22:57:20.0463 1900        RDPREFMP        (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/06/29 22:57:20.0510 1900        RDPWD          (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/06/29 22:57:20.0541 1900        rdyboost        (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/06/29 22:57:20.0588 1900        rspndr          (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/29 22:57:20.0635 1900        RTL8167        (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
2011/06/29 22:57:20.0729 1900        SASDIFSV        (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/06/29 22:57:20.0760 1900        SASKUTIL        (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/06/29 22:57:20.0791 1900        sbp2port        (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/06/29 22:57:20.0838 1900        scfilter        (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/06/29 22:57:20.0885 1900        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/06/29 22:57:20.0931 1900        Serenum        (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/29 22:57:20.0994 1900        Serial          (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/06/29 22:57:21.0025 1900        sermouse        (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/06/29 22:57:21.0087 1900        sffdisk        (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/06/29 22:57:21.0119 1900        sffp_mmc        (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/06/29 22:57:21.0150 1900        sffp_sd        (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/06/29 22:57:21.0165 1900        sfloppy        (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/06/29 22:57:21.0228 1900        sisagp          (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/06/29 22:57:21.0275 1900        SiSRaid2        (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/06/29 22:57:21.0290 1900        SiSRaid4        (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/06/29 22:57:21.0337 1900        Smb            (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/06/29 22:57:21.0368 1900        spldr          (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/06/29 22:57:21.0571 1900        sptd            (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/06/29 22:57:21.0571 1900        Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/06/29 22:57:21.0587 1900        sptd - detected LockedFile.Multi.Generic (1)
2011/06/29 22:57:21.0618 1900        srv            (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys
2011/06/29 22:57:21.0665 1900        srv2            (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/29 22:57:21.0727 1900        srvnet          (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/29 22:57:21.0774 1900        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/06/29 22:57:21.0821 1900        stexstor        (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/06/29 22:57:21.0852 1900        swenum          (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/06/29 22:57:21.0945 1900        Tcpip          (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\drivers\tcpip.sys
2011/06/29 22:57:22.0008 1900        TCPIP6          (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/29 22:57:22.0039 1900        tcpipreg        (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/29 22:57:22.0070 1900        TDPIPE          (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/06/29 22:57:22.0101 1900        TDTCP          (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/06/29 22:57:22.0133 1900        tdx            (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/29 22:57:22.0164 1900        TermDD          (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/06/29 22:57:22.0211 1900        tssecsrv        (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/29 22:57:22.0242 1900        tunnel          (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/29 22:57:22.0273 1900        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/06/29 22:57:22.0320 1900        udfs            (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/29 22:57:22.0382 1900        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/06/29 22:57:22.0413 1900        umbus          (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/06/29 22:57:22.0429 1900        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/06/29 22:57:22.0476 1900        upperdev        (7062ed67a10f1c83b2ab951736e24f11) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/06/29 22:57:22.0523 1900        usbaudio        (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys
2011/06/29 22:57:22.0569 1900        usbccgp        (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/29 22:57:22.0616 1900        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/06/29 22:57:22.0663 1900        usbehci        (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/06/29 22:57:22.0725 1900        usbfilter      (e5b14557793164db879ee56f5b59c3e2) C:\Windows\system32\DRIVERS\usbfilter.sys
2011/06/29 22:57:22.0772 1900        usbhub          (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/29 22:57:22.0835 1900        usbohci        (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/06/29 22:57:22.0866 1900        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/06/29 22:57:22.0913 1900        usbscan        (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/06/29 22:57:23.0006 1900        usbser          (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\DRIVERS\usbser.sys
2011/06/29 22:57:23.0069 1900        UsbserFilt      (b76d8039f5b595c4ca551b3d5dd15a98) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/06/29 22:57:23.0131 1900        usbsermpt      (caad3467fbfae8a380f67e9c7150a85e) C:\Windows\system32\DRIVERS\usbsermpt.sys
2011/06/29 22:57:23.0178 1900        USBSTOR        (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/29 22:57:23.0193 1900        usbuhci        (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/06/29 22:57:23.0225 1900        usbvideo        (b5f6a992d996282b7fae7048e50af83a) C:\Windows\system32\Drivers\usbvideo.sys
2011/06/29 22:57:23.0287 1900        VClone          (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys
2011/06/29 22:57:23.0334 1900        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/06/29 22:57:23.0381 1900        vga            (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/29 22:57:23.0396 1900        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/06/29 22:57:23.0427 1900        vhdmp          (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/06/29 22:57:23.0474 1900        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/06/29 22:57:23.0490 1900        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/06/29 22:57:23.0505 1900        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/06/29 22:57:23.0537 1900        volmgr          (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/06/29 22:57:23.0693 1900        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/06/29 22:57:23.0817 1900        volsnap        (7c28b63e4c9e5c3be7ffe53789593619) C:\Windows\system32\DRIVERS\volsnap.sys
2011/06/29 22:57:23.0864 1900        Suspicious file (Forged): C:\Windows\system32\DRIVERS\volsnap.sys. Real md5: 7c28b63e4c9e5c3be7ffe53789593619, Fake md5: 58df9d2481a56edde167e51b334d44fd
2011/06/29 22:57:23.0880 1900        volsnap - detected Rootkit.Win32.TDSS.tdl3 (0)
2011/06/29 22:57:23.0911 1900        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/06/29 22:57:23.0942 1900        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/06/29 22:57:24.0005 1900        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/06/29 22:57:24.0067 1900        WANARP          (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/29 22:57:24.0083 1900        Wanarpv6        (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/29 22:57:24.0129 1900        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/06/29 22:57:24.0145 1900        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/29 22:57:24.0207 1900        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/06/29 22:57:24.0223 1900        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/06/29 22:57:24.0317 1900        WinUsb          (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/06/29 22:57:24.0363 1900        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/06/29 22:57:24.0395 1900        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/29 22:57:24.0441 1900        WudfPf          (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/06/29 22:57:24.0473 1900        WUDFRd          (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/29 22:57:24.0675 1900        {B154377D-700F-42cc-9474-23858FBDF4BD} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\CyberLink\PowerDVD9\000.fcl
2011/06/29 22:57:24.0691 1900        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/06/29 22:57:24.0722 1900        MBR (0x1B8)    (feffdedea77250a6fcd92c304b49ace2) \Device\Harddisk5\DR5
2011/06/29 22:57:24.0738 1900        Boot (0x1200)  (52841af164ec66db5d00c7fcd90bb2d5) \Device\Harddisk0\DR0\Partition0
2011/06/29 22:57:24.0753 1900        Boot (0x1200)  (ff68da0c817c0fb993105e6fb741262c) \Device\Harddisk0\DR0\Partition1
2011/06/29 22:57:24.0769 1900        Boot (0x1200)  (94e401c5850a09e853a0d133aaa92edf) \Device\Harddisk5\DR5\Partition0
2011/06/29 22:57:24.0769 1900        ================================================================================
2011/06/29 22:57:24.0769 1900        Scan finished
2011/06/29 22:57:24.0769 1900        ================================================================================
2011/06/29 22:57:24.0785 5176        Detected object count: 2
2011/06/29 22:57:24.0785 5176        Actual detected object count: 2
2011/06/29 22:57:30.0837 5176        LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/06/29 22:57:30.0853 5176        volsnap        (7c28b63e4c9e5c3be7ffe53789593619) C:\Windows\system32\DRIVERS\volsnap.sys
2011/06/29 22:57:30.0853 5176        Suspicious file (Forged): C:\Windows\system32\DRIVERS\volsnap.sys. Real md5: 7c28b63e4c9e5c3be7ffe53789593619, Fake md5: 58df9d2481a56edde167e51b334d44fd
2011/06/29 22:57:32.0304 5176        Backup copy found, using it..
2011/06/29 22:57:32.0319 5176        C:\Windows\system32\DRIVERS\volsnap.sys - will be cured after reboot
2011/06/29 22:57:32.0319 5176        Rootkit.Win32.TDSS.tdl3(volsnap) - User select action: Cure


cosinus 29.06.2011 22:05

TDSS wurde erkannt und entfernt. Bitte Windows neu starten und zur Kontrolle ein neues Log mit dem Kaspersky-TDSS-Killer machen.

Drummer_Shoo 29.06.2011 22:07

Code:

2011/06/29 23:07:53.0322 3356        TDSS rootkit removing tool 2.5.8.0 Jun 28 2011 19:12:16
2011/06/29 23:07:53.0464 3356        ================================================================================
2011/06/29 23:07:53.0464 3356        SystemInfo:
2011/06/29 23:07:53.0464 3356       
2011/06/29 23:07:53.0464 3356        OS Version: 6.1.7600 ServicePack: 0.0
2011/06/29 23:07:53.0464 3356        Product type: Workstation
2011/06/29 23:07:53.0464 3356        ComputerName: MELMS-PC
2011/06/29 23:07:53.0464 3356        UserName: Melms
2011/06/29 23:07:53.0464 3356        Windows directory: C:\Windows
2011/06/29 23:07:53.0464 3356        System windows directory: C:\Windows
2011/06/29 23:07:53.0464 3356        Processor architecture: Intel x86
2011/06/29 23:07:53.0464 3356        Number of processors: 2
2011/06/29 23:07:53.0464 3356        Page size: 0x1000
2011/06/29 23:07:53.0464 3356        Boot type: Normal boot
2011/06/29 23:07:53.0464 3356        ================================================================================
2011/06/29 23:07:54.0541 3356        Initialize success
2011/06/29 23:07:58.0775 4024        ================================================================================
2011/06/29 23:07:58.0775 4024        Scan started
2011/06/29 23:07:58.0775 4024        Mode: Manual;
2011/06/29 23:07:58.0775 4024        ================================================================================
2011/06/29 23:08:00.0488 4024        1394ohci        (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/06/29 23:08:00.0550 4024        acedrv10        (553ba53445795cbc0d4f9fa37eb855a6) C:\Windows\system32\drivers\acedrv10.sys
2011/06/29 23:08:00.0604 4024        acehlp10        (8ce00b6a46962a1808b19cd1dae5170c) C:\Windows\system32\drivers\acehlp10.sys
2011/06/29 23:08:00.0664 4024        ACPI            (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/06/29 23:08:00.0688 4024        AcpiPmi        (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/06/29 23:08:00.0727 4024        adp94xx        (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/06/29 23:08:00.0750 4024        adpahci        (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/06/29 23:08:00.0769 4024        adpu320        (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/06/29 23:08:00.0830 4024        AFD            (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys
2011/06/29 23:08:00.0853 4024        agp440          (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/06/29 23:08:00.0877 4024        aic78xx        (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/06/29 23:08:00.0906 4024        aliide          (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/06/29 23:08:00.0940 4024        amdagp          (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/06/29 23:08:00.0965 4024        amdide          (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/06/29 23:08:00.0989 4024        AmdK8          (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/06/29 23:08:01.0021 4024        AmdPPM          (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/06/29 23:08:01.0065 4024        amdsata        (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys
2011/06/29 23:08:01.0093 4024        amdsbs          (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/06/29 23:08:01.0116 4024        amdxata        (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys
2011/06/29 23:08:01.0169 4024        AppID          (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/06/29 23:08:01.0216 4024        arc            (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/06/29 23:08:01.0239 4024        arcsas          (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/06/29 23:08:01.0281 4024        AsyncMac        (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/29 23:08:01.0303 4024        atapi          (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/06/29 23:08:01.0336 4024        AtiPcie        (b73c832088dd54b55e04ff6f9646ad8c) C:\Windows\system32\DRIVERS\AtiPcie.sys
2011/06/29 23:08:01.0391 4024        atksgt          (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/06/29 23:08:01.0447 4024        avgntflt        (47b879406246ffdced59e18d331a0e7d) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/06/29 23:08:01.0470 4024        avipbb          (5fedef54757b34fb611b9ec8fb399364) C:\Windows\system32\DRIVERS\avipbb.sys
2011/06/29 23:08:01.0524 4024        b06bdrv        (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/06/29 23:08:01.0573 4024        b57nd60x        (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/06/29 23:08:01.0641 4024        Beep            (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/06/29 23:08:01.0669 4024        blbdrive        (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/06/29 23:08:01.0718 4024        bowser          (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/29 23:08:01.0748 4024        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/06/29 23:08:01.0769 4024        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/06/29 23:08:01.0804 4024        Brserid        (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/06/29 23:08:01.0838 4024        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/06/29 23:08:01.0853 4024        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/06/29 23:08:01.0871 4024        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/06/29 23:08:01.0897 4024        BTHMODEM        (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/06/29 23:08:02.0023 4024        cdfs            (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/29 23:08:02.0055 4024        cdrom          (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/06/29 23:08:02.0106 4024        Cinergy_HT_PCI_MKII (e55e0c3094bed534998e5ad88f9aacc2) C:\Windows\system32\DRIVERS\Cinergy_HT_PCI_MKII.sys
2011/06/29 23:08:02.0136 4024        circlass        (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/06/29 23:08:02.0199 4024        CLBStor        (f5c8f7a7d1a3f569bf77574a795cc19e) C:\Windows\system32\drivers\CLBStor.sys
2011/06/29 23:08:02.0233 4024        CLBUDF          (07b3e4fc5d4943ba802607ddf8f5d418) C:\Windows\system32\drivers\CLBUDF.sys
2011/06/29 23:08:02.0275 4024        CLFS            (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/06/29 23:08:02.0335 4024        CmBatt          (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/06/29 23:08:02.0355 4024        cmdide          (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/06/29 23:08:02.0386 4024        CNG            (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/06/29 23:08:02.0415 4024        Compbatt        (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/06/29 23:08:02.0441 4024        CompositeBus    (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/06/29 23:08:02.0468 4024        crcdisk        (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/06/29 23:08:02.0541 4024        DfsC            (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys
2011/06/29 23:08:02.0576 4024        discache        (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/06/29 23:08:02.0605 4024        Disk            (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/06/29 23:08:02.0677 4024        drmkaud        (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/06/29 23:08:02.0726 4024        DXGKrnl        (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/29 23:08:02.0829 4024        ebdrv          (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/06/29 23:08:02.0934 4024        ElbyCDIO        (44996a2addd2db7454f2ca40b67d8941) C:\Windows\system32\Drivers\ElbyCDIO.sys
2011/06/29 23:08:02.0966 4024        elxstor        (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/06/29 23:08:02.0997 4024        ErrDev          (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/06/29 23:08:03.0044 4024        exfat          (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/06/29 23:08:03.0079 4024        fastfat        (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/06/29 23:08:03.0123 4024        fdc            (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/29 23:08:03.0156 4024        FileInfo        (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/06/29 23:08:03.0185 4024        Filetrace      (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/06/29 23:08:03.0235 4024        flpydisk        (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/29 23:08:03.0269 4024        FltMgr          (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/06/29 23:08:03.0303 4024        FsDepends      (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/06/29 23:08:03.0325 4024        Fs_Rec          (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/29 23:08:03.0366 4024        fvevol          (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2011/06/29 23:08:03.0391 4024        gagp30kx        (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/06/29 23:08:03.0444 4024        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/06/29 23:08:03.0522 4024        hamachi        (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
2011/06/29 23:08:03.0606 4024        Hardlock        (ed32d389f8b0e74e400932e020bcfbdf) C:\Windows\system32\drivers\hardlock.sys
2011/06/29 23:08:03.0671 4024        hcw85cir        (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/06/29 23:08:03.0710 4024        HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/06/29 23:08:03.0749 4024        HDAudBus        (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/06/29 23:08:03.0761 4024        HidBatt        (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/06/29 23:08:03.0791 4024        HidBth          (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/06/29 23:08:03.0835 4024        HidIr          (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/06/29 23:08:03.0861 4024        HidUsb          (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/29 23:08:03.0908 4024        HpSAMD          (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/06/29 23:08:03.0942 4024        HTTP            (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/06/29 23:08:03.0972 4024        hwpolicy        (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/06/29 23:08:03.0994 4024        i8042prt        (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/06/29 23:08:04.0043 4024        iaStorV        (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys
2011/06/29 23:08:04.0070 4024        iirsp          (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/06/29 23:08:04.0151 4024        IntcAzAudAddService (0c36a7de2b4e6ec301b98ae300547701) C:\Windows\system32\drivers\RTKVHDA.sys
2011/06/29 23:08:04.0202 4024        intelide        (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/06/29 23:08:04.0227 4024        intelppm        (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/29 23:08:04.0255 4024        IPMIDRV        (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/06/29 23:08:04.0288 4024        IPNAT          (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/06/29 23:08:04.0329 4024        IRENUM          (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/06/29 23:08:04.0350 4024        isapnp          (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/06/29 23:08:04.0377 4024        iScsiPrt        (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/06/29 23:08:04.0415 4024        kbdclass        (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/06/29 23:08:04.0438 4024        kbdhid          (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/06/29 23:08:04.0507 4024        KMWDFILTERx86  (4476fe98aaf505acdcd3ee6360aabec1) C:\Windows\system32\DRIVERS\KMWDFILTER.sys
2011/06/29 23:08:04.0527 4024        KSecDD          (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/29 23:08:04.0568 4024        KSecPkg        (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/06/29 23:08:04.0664 4024        lirsgt          (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/06/29 23:08:04.0691 4024        lltdio          (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/29 23:08:04.0734 4024        LSI_FC          (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/06/29 23:08:04.0753 4024        LSI_SAS        (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/06/29 23:08:04.0775 4024        LSI_SAS2        (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/06/29 23:08:04.0799 4024        LSI_SCSI        (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/06/29 23:08:04.0824 4024        luafv          (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/06/29 23:08:04.0850 4024        megasas        (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/06/29 23:08:04.0880 4024        MegaSR          (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/06/29 23:08:04.0915 4024        Modem          (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/06/29 23:08:04.0952 4024        monitor        (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/29 23:08:04.0967 4024        mouclass        (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/06/29 23:08:04.0992 4024        mouhid          (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/29 23:08:05.0013 4024        mountmgr        (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/06/29 23:08:05.0036 4024        mpio            (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/06/29 23:08:05.0063 4024        mpsdrv          (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/29 23:08:05.0093 4024        MRxDAV          (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/06/29 23:08:05.0146 4024        mrxsmb          (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/29 23:08:05.0188 4024        mrxsmb10        (c108952d3660375dcb716b222912e868) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/29 23:08:05.0231 4024        mrxsmb20        (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/29 23:08:05.0259 4024        msahci          (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/06/29 23:08:05.0306 4024        msdsm          (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/06/29 23:08:05.0352 4024        Msfs            (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/06/29 23:08:05.0371 4024        mshidkmdf      (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/06/29 23:08:05.0389 4024        msisadrv        (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/06/29 23:08:05.0431 4024        MSKSSRV        (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/29 23:08:05.0459 4024        MSPCLOCK        (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/29 23:08:05.0473 4024        MSPQM          (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/06/29 23:08:05.0497 4024        MsRPC          (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/06/29 23:08:05.0522 4024        mssmbios        (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/29 23:08:05.0545 4024        MSTEE          (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/06/29 23:08:05.0563 4024        MTConfig        (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/06/29 23:08:05.0585 4024        Mup            (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/06/29 23:08:05.0643 4024        NativeWifiP    (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/29 23:08:05.0677 4024        NDIS            (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/06/29 23:08:05.0703 4024        NdisCap        (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/06/29 23:08:05.0731 4024        NdisTapi        (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/29 23:08:05.0764 4024        Ndisuio        (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/29 23:08:05.0786 4024        NdisWan        (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/29 23:08:05.0825 4024        NDProxy        (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/06/29 23:08:05.0840 4024        NetBIOS        (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/29 23:08:05.0861 4024        NetBT          (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/29 23:08:05.0909 4024        nfrd960        (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/06/29 23:08:05.0966 4024        nmwcd          (712bc0c22ba00b2ba324c6b8df668ee7) C:\Windows\system32\drivers\ccdcmb.sys
2011/06/29 23:08:06.0003 4024        nmwcdc          (7312987b6ccde6f6cee32c14bed1ca2e) C:\Windows\system32\drivers\ccdcmbo.sys
2011/06/29 23:08:06.0031 4024        Npfs            (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/06/29 23:08:06.0052 4024        nsiproxy        (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/29 23:08:06.0104 4024        Ntfs            (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys
2011/06/29 23:08:06.0146 4024        Null            (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/06/29 23:08:06.0184 4024        nusb3hub        (68c890ddb21028cb1ea5551b47b29e1b) C:\Windows\system32\DRIVERS\nusb3hub.sys
2011/06/29 23:08:06.0207 4024        nusb3xhc        (2cf970c1a9e05d3b91039c2dd4471c0e) C:\Windows\system32\DRIVERS\nusb3xhc.sys
2011/06/29 23:08:06.0386 4024        nvlddmkm        (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/06/29 23:08:06.0513 4024        nvraid          (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys
2011/06/29 23:08:06.0544 4024        nvstor          (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys
2011/06/29 23:08:06.0583 4024        nv_agp          (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/06/29 23:08:06.0630 4024        ohci1394        (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/06/29 23:08:06.0658 4024        Parport        (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/06/29 23:08:06.0687 4024        partmgr        (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/06/29 23:08:06.0707 4024        Parvdm          (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/06/29 23:08:06.0769 4024        pccsmcfd        (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2011/06/29 23:08:06.0804 4024        pci            (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/06/29 23:08:06.0832 4024        pciide          (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/06/29 23:08:06.0874 4024        pcmcia          (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/06/29 23:08:06.0924 4024        pcw            (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/06/29 23:08:06.0954 4024        PEAUTH          (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/06/29 23:08:07.0083 4024        PptpMiniport    (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/29 23:08:07.0106 4024        Processor      (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/06/29 23:08:07.0156 4024        Psched          (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/29 23:08:07.0209 4024        PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
2011/06/29 23:08:07.0270 4024        ql2300          (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/06/29 23:08:07.0311 4024        ql40xx          (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/06/29 23:08:07.0342 4024        QWAVEdrv        (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/29 23:08:07.0377 4024        RasAcd          (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/29 23:08:07.0401 4024        RasAgileVpn    (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/06/29 23:08:07.0428 4024        Rasl2tp        (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/29 23:08:07.0468 4024        RasPppoe        (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/29 23:08:07.0493 4024        RasSstp        (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/29 23:08:07.0518 4024        rdbss          (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/29 23:08:07.0545 4024        rdpbus          (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/06/29 23:08:07.0565 4024        RDPCDD          (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/29 23:08:07.0597 4024        RDPENCDD        (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/29 23:08:07.0614 4024        RDPREFMP        (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/06/29 23:08:07.0662 4024        RDPWD          (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/06/29 23:08:07.0694 4024        rdyboost        (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/06/29 23:08:07.0740 4024        rspndr          (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/29 23:08:07.0781 4024        RTL8167        (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
2011/06/29 23:08:07.0893 4024        SASDIFSV        (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/06/29 23:08:07.0930 4024        SASKUTIL        (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/06/29 23:08:07.0972 4024        sbp2port        (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/06/29 23:08:08.0001 4024        scfilter        (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/06/29 23:08:08.0039 4024        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/06/29 23:08:08.0076 4024        Serenum        (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/29 23:08:08.0117 4024        Serial          (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/06/29 23:08:08.0146 4024        sermouse        (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/06/29 23:08:08.0196 4024        sffdisk        (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/06/29 23:08:08.0231 4024        sffp_mmc        (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/06/29 23:08:08.0251 4024        sffp_sd        (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/06/29 23:08:08.0274 4024        sfloppy        (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/06/29 23:08:08.0319 4024        sisagp          (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/06/29 23:08:08.0343 4024        SiSRaid2        (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/06/29 23:08:08.0364 4024        SiSRaid4        (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/06/29 23:08:08.0380 4024        Smb            (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/06/29 23:08:08.0412 4024        spldr          (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/06/29 23:08:08.0489 4024        sptd            (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/06/29 23:08:08.0489 4024        Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/06/29 23:08:08.0499 4024        sptd - detected LockedFile.Multi.Generic (1)
2011/06/29 23:08:08.0540 4024        srv            (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys
2011/06/29 23:08:08.0578 4024        srv2            (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/29 23:08:08.0633 4024        srvnet          (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/29 23:08:08.0675 4024        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/06/29 23:08:08.0705 4024        stexstor        (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/06/29 23:08:08.0736 4024        swenum          (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/06/29 23:08:08.0825 4024        Tcpip          (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\drivers\tcpip.sys
2011/06/29 23:08:08.0881 4024        TCPIP6          (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/29 23:08:08.0912 4024        tcpipreg        (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/29 23:08:08.0937 4024        TDPIPE          (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/06/29 23:08:08.0951 4024        TDTCP          (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/06/29 23:08:08.0973 4024        tdx            (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/29 23:08:08.0993 4024        TermDD          (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/06/29 23:08:09.0039 4024        tssecsrv        (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/29 23:08:09.0073 4024        tunnel          (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/29 23:08:09.0104 4024        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/06/29 23:08:09.0132 4024        udfs            (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/29 23:08:09.0178 4024        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/06/29 23:08:09.0209 4024        umbus          (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/06/29 23:08:09.0238 4024        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/06/29 23:08:09.0280 4024        upperdev        (7062ed67a10f1c83b2ab951736e24f11) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/06/29 23:08:09.0327 4024        usbaudio        (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys
2011/06/29 23:08:09.0351 4024        usbccgp        (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/29 23:08:09.0401 4024        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/06/29 23:08:09.0432 4024        usbehci        (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/06/29 23:08:09.0471 4024        usbfilter      (e5b14557793164db879ee56f5b59c3e2) C:\Windows\system32\DRIVERS\usbfilter.sys
2011/06/29 23:08:09.0495 4024        usbhub          (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/29 23:08:09.0515 4024        usbohci        (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/06/29 23:08:09.0533 4024        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/06/29 23:08:09.0572 4024        usbscan        (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/06/29 23:08:09.0629 4024        usbser          (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\DRIVERS\usbser.sys
2011/06/29 23:08:09.0691 4024        UsbserFilt      (b76d8039f5b595c4ca551b3d5dd15a98) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/06/29 23:08:09.0743 4024        usbsermpt      (caad3467fbfae8a380f67e9c7150a85e) C:\Windows\system32\DRIVERS\usbsermpt.sys
2011/06/29 23:08:09.0778 4024        USBSTOR        (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/29 23:08:09.0811 4024        usbuhci        (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/06/29 23:08:09.0852 4024        usbvideo        (b5f6a992d996282b7fae7048e50af83a) C:\Windows\system32\Drivers\usbvideo.sys
2011/06/29 23:08:09.0899 4024        VClone          (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys
2011/06/29 23:08:09.0932 4024        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/06/29 23:08:09.0974 4024        vga            (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/29 23:08:09.0996 4024        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/06/29 23:08:10.0020 4024        vhdmp          (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/06/29 23:08:10.0047 4024        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/06/29 23:08:10.0067 4024        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/06/29 23:08:10.0083 4024        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/06/29 23:08:10.0107 4024        volmgr          (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/06/29 23:08:10.0133 4024        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/06/29 23:08:10.0162 4024        volsnap        (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/06/29 23:08:10.0214 4024        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/06/29 23:08:10.0244 4024        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/06/29 23:08:10.0266 4024        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/06/29 23:08:10.0297 4024        WANARP          (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/29 23:08:10.0310 4024        Wanarpv6        (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/29 23:08:10.0356 4024        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/06/29 23:08:10.0382 4024        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/29 23:08:10.0439 4024        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/06/29 23:08:10.0453 4024        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/06/29 23:08:10.0527 4024        WinUsb          (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/06/29 23:08:10.0561 4024        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/06/29 23:08:10.0598 4024        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/29 23:08:10.0654 4024        WudfPf          (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/06/29 23:08:10.0682 4024        WUDFRd          (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/29 23:08:10.0809 4024        {B154377D-700F-42cc-9474-23858FBDF4BD} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\CyberLink\PowerDVD9\000.fcl
2011/06/29 23:08:10.0831 4024        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/06/29 23:08:10.0864 4024        MBR (0x1B8)    (feffdedea77250a6fcd92c304b49ace2) \Device\Harddisk5\DR5
2011/06/29 23:08:10.0875 4024        Boot (0x1200)  (52841af164ec66db5d00c7fcd90bb2d5) \Device\Harddisk0\DR0\Partition0
2011/06/29 23:08:10.0890 4024        Boot (0x1200)  (ff68da0c817c0fb993105e6fb741262c) \Device\Harddisk0\DR0\Partition1
2011/06/29 23:08:10.0899 4024        Boot (0x1200)  (94e401c5850a09e853a0d133aaa92edf) \Device\Harddisk5\DR5\Partition0
2011/06/29 23:08:10.0906 4024        ================================================================================
2011/06/29 23:08:10.0906 4024        Scan finished
2011/06/29 23:08:10.0906 4024        ================================================================================
2011/06/29 23:08:10.0915 6008        Detected object count: 1
2011/06/29 23:08:10.0915 6008        Actual detected object count: 1
2011/06/29 23:08:16.0472 6008        LockedFile.Multi.Generic(sptd) - User select action: Skip


cosinus 29.06.2011 22:10

Wir sollten den MBR manuell fixen, auch wenn das letzte Log von mbrcheck sagte es wär alles ok. Andere Idee hab ich aufgrund der Unauffälligkeiten der Logs nicht mehr. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Win7 (32-Bit) installiert?
Wenn nicht: Schau mal hier => RescueDisc-Win7-32-Bit

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten)

Falls Du eine normale Win7-Installations-DVD (32-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:11 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131