|
Log-Analyse und Auswertung: Virenbefall: Live Security Platinum VirusWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.08.2012, 09:52 | #1 | |
| Virenbefall: Live Security Platinum Virus Hallo zusammen, mein Laptop ist leider auch vom Live Security Platinum Virus befallen worden. Jeder Virenscanner sagt mir etwas anders, weshalb ich hoffe, dass Ihr mir weiterhelfen könnt. So sieht meine Malwarebytes-Logdatei aus. Zitat:
Viele Grüße Daniel Geändert von metaldakster (08.08.2012 um 10:13 Uhr) |
13.08.2012, 08:02 | #2 |
| Virenbefall: Live Security Platinum Virus Hallo zusammen,
__________________habe ich den Beitrag in ein falsches Forum kopiert? Bisher hat noch keiner darauf geantwortet. Es wäre klasse, wenn Ihr mir helfen könntet. Vielen Dank! |
17.08.2012, 16:24 | #3 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus Bitte erstmal routinemäßig einen neuen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
__________________Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Führ danach bitte auch nochmal ESET aus, danach sehen wir weiter. Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden. ESET Online Scanner Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
Code:
ATTFilter "%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt" Code:
ATTFilter "%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt" Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ |
20.08.2012, 10:22 | #4 |
| Virenbefall: Live Security Platinum Virus Hallo Cosinus, erstmal vielen Dank für Deine Antwort. Zusätzlich zu dem Scan im anderen Post habe ich nun noch einmal einen Scan über Malwarebytes gemacht. Hier das Log: Code:
ATTFilter Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.20.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 Daniel Kort :: DANIELKORTH-PC [Administrator] Schutz: Aktiviert 20.08.2012 09:36:54 mbam-log-2012-08-20 (09-36-54).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 363393 Laufzeit: 1 Stunde(n), 39 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Das ESET-Log sieht folgendermaßen aus: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=e0a8a27b9570884081792dfcd076eef1 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-14 01:27:17 # local_time=2012-08-14 03:27:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 15575013 15575013 0 0 # compatibility_mode=5893 16776573 100 94 20407 96578481 0 0 # compatibility_mode=8192 67108863 100 0 77 77 0 0 # scanned=160685 # found=0 # cleaned=0 # scan_time=3546 |
21.08.2012, 11:37 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
22.08.2012, 11:06 | #6 |
| Virenbefall: Live Security Platinum Virus Hallo Cosinus, dank Dir für die Antwort. Das Logfile sieht folgendermaßen aus: Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/22/2012 at 12:05:40 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (32 bits) # User : Daniel Kort - DANIELKORTH-PC # Boot Mode : Normal # Running from : C:\Users\Daniel Kort\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\DANIEL~1\AppData\Local\Temp\AskSearch Folder Found : C:\Users\Daniel Kort\AppData\LocalLow\facemoods.com Folder Found : C:\Program Files\facemoods.com File Found : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\searchplugins\Askcom.xml File Found : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml ***** [Registry] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 Key Found : HKLM\SOFTWARE\Description Key Found : HKLM\SOFTWARE\facemoods.com Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37} Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.facemoods.com/?a=make&f=2 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4 -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js Found : user_pref("browser.search.defaultengine", "Ask.com"); Found : user_pref("browser.search.order.1", "Ask.com"); Found : user_pref("extensions.facemoods._xpiupdate", true); Found : user_pref("extensions.facemoods.aflt", "_#wbst"); Found : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4"); Found : user_pref("extensions.facemoods.first_time", false); Found : user_pref("extensions.facemoods.id", "_#13a9eef6b57341769e747b0e659befae"); Found : user_pref("extensions.facemoods.instlDay", "_#15348"); Found : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com"); Found : user_pref("extensions.facemoods.sid", "_#13a9eef6b57341769e747b0e659befae"); Found : user_pref("extensions.facemoods.uninst", true); Found : user_pref("extensions.facemoods.update", "_#v1.4.0"); Found : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5"); -\\ Google Chrome v [Unable to get version] File : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences Found : "name" : "facemoods", Found : "search_url" : "hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4", Found : "homepage" : "hxxp://start.facemoods.com/?a=make", ************************* AdwCleaner[R1].txt - [7420 octets] - [22/08/2012 12:05:40] ########## EOF - C:\AdwCleaner[R1].txt - [7548 octets] ########## |
30.08.2012, 12:58 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
__________________ Logfiles bitte immer in CODE-Tags posten |
04.09.2012, 08:58 | #8 |
| Virenbefall: Live Security Platinum Virus Hallo Cosinus, anbei findest Du das Log-file. Facemoods wurde aus der Registry entfernt. Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 09/04/2012 at 09:53:20 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (32 bits) # User : Daniel Kort - DANIELKORTH-PC # Boot Mode : Normal # Running from : C:\Users\Daniel Kort\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\DANIEL~1\AppData\Local\Temp\AskSearch Folder Deleted : C:\Users\Daniel Kort\AppData\LocalLow\facemoods.com Folder Deleted : C:\Program Files\facemoods.com File Deleted : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\searchplugins\Askcom.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml ***** [Registry] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1 Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Description Key Deleted : HKLM\SOFTWARE\facemoods.com Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods] ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.facemoods.com/?a=make&f=2 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4 --> hxxp://www.google.com -\\ Mozilla Firefox v15.0 (de) Profile name : default File : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\user.js ... Deleted ! Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("extensions.facemoods._xpiupdate", true); Deleted : user_pref("extensions.facemoods.aflt", "_#wbst"); Deleted : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4"); Deleted : user_pref("extensions.facemoods.first_time", false); Deleted : user_pref("extensions.facemoods.id", "_#13a9eef6b57341769e747b0e659befae"); Deleted : user_pref("extensions.facemoods.instlDay", "_#15348"); Deleted : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com"); Deleted : user_pref("extensions.facemoods.sid", "_#13a9eef6b57341769e747b0e659befae"); Deleted : user_pref("extensions.facemoods.uninst", true); Deleted : user_pref("extensions.facemoods.update", "_#v1.4.0"); Deleted : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5"); -\\ Google Chrome v [Unable to get version] File : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "name" : "facemoods", Deleted : "search_url" : "hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4", Deleted : "homepage" : "hxxp://start.facemoods.com/?a=make", ************************* AdwCleaner[R1].txt - [7549 octets] - [22/08/2012 12:05:40] AdwCleaner[S1].txt - [7822 octets] - [04/09/2012 09:53:20] ########## EOF - C:\AdwCleaner[S1].txt - [7950 octets] ########## |
04.09.2012, 15:37 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus Bitte mal den aktuellen adwCleaner runterladen, also die alte adwcleaner löschen und neu runterladen adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
06.09.2012, 10:25 | #10 |
| Virenbefall: Live Security Platinum Virus Hallo Cosinus, die Suche mit dem neuen ADW Cleaner war sauber. Code:
ATTFilter # AdwCleaner v2.000 - Datei am 09/06/2012 um 11:24:21 erstellt # Aktualisiert am 30/08/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzer : Daniel Kort - DANIELKORTH-PC # Normaler Modus : Normal # Ausgeführt unter : C:\Users\Daniel Kort\Downloads\adwcleaner(1).exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKLM\Software\Description ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v15.0 (de) Profilname : default Datei : C:\Users\Daniel Kort\AppData\Roaming\Mozilla\Firefox\Profiles\powom3zm.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v [Version kann nicht ermittelt werden] Datei : C:\Users\Daniel Kort\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [7549 octets] - [22/08/2012 12:05:40] AdwCleaner[S1].txt - [7951 octets] - [04/09/2012 09:53:20] AdwCleaner[R2].txt - [1127 octets] - [06/09/2012 11:24:21] ########## EOF - C:\AdwCleaner[R2].txt - [1187 octets] ########## |
06.09.2012, 15:05 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus Hätte da mal zwei Fragen bevor es weiter geht 1.) Geht der normale Modus von Windows (wieder) uneingeschränkt? 2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
__________________ Logfiles bitte immer in CODE-Tags posten |
06.09.2012, 16:31 | #12 |
| Virenbefall: Live Security Platinum Virus Alles funktioniert und leere Ordner sind auch nicht vorhanden. In den vergangenen Wochen hat mich aber das JAVA-Update ständig genervt und ich vermute, dass hier der Virus auch etwas damit zu tun hatte. Den habe ich mittlerweile aber gelöscht. |
06.09.2012, 19:58 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
11.09.2012, 12:38 | #14 |
| Virenbefall: Live Security Platinum Virus Hallo Cosinus, anbei findest Du das OTL-Log: OTL Logfile: Code:
ATTFilter OTL logfile created on: 11.09.2012 13:19:21 - Run 1 OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Daniel Kort\Downloads Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,22 Gb Available Physical Memory | 40,61% Memory free 5,99 Gb Paging File | 3,85 Gb Available in Paging File | 64,34% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 283,40 Gb Total Space | 227,55 Gb Free Space | 80,29% Space Free | Partition Type: NTFS Computer Name: DANIELKORTH-PC | User Name: Daniel Kort | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.09.11 13:17:51 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Daniel Kort\Downloads\OTL.exe PRC - [2012.09.07 11:52:02 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012.08.15 09:31:06 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe PRC - [2012.08.10 08:48:16 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.05.15 08:44:47 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2012.05.15 08:44:47 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.15 08:44:47 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.05.15 08:44:46 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe PRC - [2012.05.15 08:44:46 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.02.17 13:44:10 | 048,060,742 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.12.30 12:27:34 | 000,074,752 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe PRC - [2011.10.13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.04.08 14:50:02 | 000,542,264 | ---- | M] (Google) -- C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.02.23 22:19:22 | 000,371,200 | ---- | M] (shbox.de) -- C:\Program Files\FreePDF_XP\fpassist.exe PRC - [2010.12.06 14:09:22 | 011,229,976 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\Tracker Software\PDF Viewer\PDFXCview.exe PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.05.12 17:04:48 | 000,599,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\wfcrun32.exe PRC - [2010.05.12 17:03:22 | 000,300,472 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\concentr.exe PRC - [2010.01.15 14:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe PRC - [2009.11.12 02:55:30 | 000,203,776 | ---- | M] (Microsoft) -- C:\dell\DBRM\Reminder\DbrmTrayicon.exe PRC - [2009.07.17 06:57:36 | 004,562,944 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE PRC - [2009.07.17 06:57:36 | 000,026,112 | ---- | M] () -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE PRC - [2009.07.17 06:57:04 | 003,086,848 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE PRC - [2009.07.15 20:47:20 | 000,458,844 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe PRC - [2009.07.15 20:47:20 | 000,221,266 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe PRC - [2009.06.29 09:59:00 | 000,217,088 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe PRC - [2009.06.29 09:59:00 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe PRC - [2009.06.29 09:59:00 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe PRC - [2009.06.29 09:59:00 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe PRC - [2009.06.25 04:19:50 | 000,140,520 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe PRC - [2009.06.09 20:33:30 | 000,582,896 | ---- | M] (Dell, Inc.) -- C:\Program Files\Dell\Printer Software\ErrorApp\dkab1err.exe PRC - [2009.06.09 20:33:28 | 000,603,376 | ---- | M] ( ) -- C:\Windows\System32\dkabcoms.exe PRC - [2009.02.23 19:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2008.01.07 18:00:00 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM13Mon.exe PRC - [2007.02.12 10:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Windows\System32\drivers\o2flash.exe ========== Modules (No Company Name) ========== MOD - [2012.09.07 11:52:02 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012.08.15 09:31:06 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_271.dll MOD - [2012.06.14 11:17:35 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll MOD - [2012.06.14 11:16:10 | 000,391,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Iris.Mapi.MessageSt#\67a5a67d1c55617ff8b1e2b71c99f0b9\Iris.Mapi.MessageStore.ni.dll MOD - [2012.06.14 11:16:09 | 000,462,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\1b2a08ae2231112bb077a88e5a4737f3\Microsoft.BusinessSolutions.eCRM.DataSync.ni.dll MOD - [2012.06.14 11:16:04 | 003,826,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BusinessLayer\2af556542f02c884a5984e3180bf099a\BusinessLayer.ni.dll MOD - [2012.06.14 11:15:58 | 001,040,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\fbc0feb4b206da7eb439ef53f83d2520\Microsoft.Interop.Mapi.Impl.ni.dll MOD - [2012.06.14 11:15:57 | 001,526,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BCMRes\53fd79c2861c4e8a6e25872bea7d9641\BCMRes.ni.dll MOD - [2012.06.14 08:43:09 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll MOD - [2012.06.14 08:42:57 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll MOD - [2012.06.14 08:42:24 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll MOD - [2012.06.14 08:42:12 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll MOD - [2012.05.14 10:21:39 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll MOD - [2012.05.14 10:20:45 | 002,267,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\581c2fc3b9dffb23020955af33839b2a\Microsoft.Office.Interop.Outlook.ni.dll MOD - [2012.05.14 10:20:42 | 000,177,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\739c4b6df0732939cef67b3d9964f56a\Microsoft.Interop.Mapi.PropTags.ni.dll MOD - [2012.05.14 10:20:40 | 000,963,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\office\15c8640cbc8704d22e251f20389fc212\office.ni.dll MOD - [2012.05.14 10:20:40 | 000,062,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.e#\be6b273db7db07786b1776a2dbeaacf9\Microsoft.Interop.eCRM.Ole.ni.dll MOD - [2012.05.14 10:20:40 | 000,044,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll MOD - [2012.05.14 10:20:39 | 000,152,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\a4bf242f6258d04bd0570c5b7c79f35e\Microsoft.Interop.Mapi.Interfaces.ni.dll MOD - [2012.05.14 10:20:38 | 000,484,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\BCMCommon\41a94b96546b49a19508e3c1d131bc77\BCMCommon.ni.dll MOD - [2012.05.14 10:17:33 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll MOD - [2012.05.14 10:17:31 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll MOD - [2012.05.14 10:17:30 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll MOD - [2012.05.14 10:16:34 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll MOD - [2012.05.14 10:16:30 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll MOD - [2012.05.14 10:16:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll MOD - [2012.05.14 10:16:21 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll MOD - [2012.02.17 20:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2012.02.17 13:44:10 | 048,060,742 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office.exe MOD - [2012.02.17 13:44:10 | 001,364,599 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\SSLSocket.dll MOD - [2012.02.17 13:44:10 | 000,405,504 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\XML.dll MOD - [2012.02.17 13:44:10 | 000,258,048 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\PostgreSQLPlugin.dll MOD - [2012.02.17 13:44:10 | 000,223,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHPng4101.dll MOD - [2012.02.17 13:44:10 | 000,151,552 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\RegEx.dll MOD - [2012.02.17 13:44:10 | 000,139,264 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Appearance Pak.dll MOD - [2012.02.17 13:44:10 | 000,120,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPicturePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Shell.dll MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MD5.dll MOD - [2012.02.17 13:44:10 | 000,098,304 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Browser Plugin.dll MOD - [2012.02.17 13:44:10 | 000,090,112 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHCalCtrl5121.dll MOD - [2012.02.17 13:44:10 | 000,084,992 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEffects7511.dll MOD - [2012.02.17 13:44:10 | 000,073,728 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\Internet Encodings.dll MOD - [2012.02.17 13:44:10 | 000,069,120 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHZStream10101.dll MOD - [2012.02.17 13:44:10 | 000,065,536 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSStringPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,065,024 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEffects37511.dll MOD - [2012.02.17 13:44:10 | 000,063,488 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHGFShared4101.dll MOD - [2012.02.17 13:44:10 | 000,059,904 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTypes6201.dll MOD - [2012.02.17 13:44:10 | 000,058,880 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPictureRotatePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,056,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMainPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,056,832 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTLStreams6201.dll MOD - [2012.02.17 13:44:10 | 000,056,320 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHTLEncryption6201.dll MOD - [2012.02.17 13:44:10 | 000,056,320 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHPEInterfaces7511.dll MOD - [2012.02.17 13:44:10 | 000,055,808 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWinPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,055,296 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHZComp10101.dll MOD - [2012.02.17 13:44:10 | 000,054,784 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCFPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,052,736 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSInternationalWinPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,050,176 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNotificationPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,048,640 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHAES10101.dll MOD - [2012.02.17 13:44:10 | 000,047,616 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSSystemInformationPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,046,080 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,045,056 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSProcessPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,043,520 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSABAddressbookPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,043,008 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHSha210101.dll MOD - [2012.02.17 13:44:10 | 000,043,008 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHEncrypt10101.dll MOD - [2012.02.17 13:44:10 | 000,041,984 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSPictureMacPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,040,960 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCallsPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,039,936 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSRegistrationPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,038,400 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSDateDifferencePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,037,376 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWinTransPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,035,840 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSScreenshotPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,035,328 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCalendarStorePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,034,816 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSColorPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMemoryPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSFolderitemsPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,033,792 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGPDFPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,031,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMacOSXPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,031,744 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGGeometryPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,031,232 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSBasePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSImagePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSMathPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,030,720 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBlowf10101.dll MOD - [2012.02.17 13:44:10 | 000,029,184 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSWindowPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,028,160 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSNSAttributedStringPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,027,648 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGColorPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,027,136 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGImagePlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,026,624 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSAppleScriptPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,025,600 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSCGDataProviderPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,025,088 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHMacBinary10101.dll MOD - [2012.02.17 13:44:10 | 000,024,576 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\MBSScreenshotWindowPlugin16724.dll MOD - [2012.02.17 13:44:10 | 000,024,064 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBitFuncs6111.dll MOD - [2012.02.17 13:44:10 | 000,016,384 | ---- | M] () -- C:\Program Files\Revolver Office\Revolver Office Libs\EHBase6410101.dll MOD - [2011.10.05 04:52:30 | 000,756,048 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL MOD - [2011.06.22 12:46:12 | 000,434,016 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll MOD - [2010.11.13 02:02:22 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll MOD - [2010.11.13 02:02:21 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2010.11.05 03:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2010.11.05 03:57:39 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll MOD - [2010.02.16 15:21:49 | 002,440,144 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils\3.0.0.0__31bf3856ad364e35\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils.dll MOD - [2010.02.16 15:21:49 | 000,981,968 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.BusinessSolutions.eCRM.OutlookAddIn\3.0.0.0__31bf3856ad364e35\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.dll MOD - [2010.02.16 15:21:49 | 000,591,976 | ---- | M] () -- C:\Windows\assembly\GAC_32\Microsoft.Interop.Mapi.Impl\3.0.0.0__31bf3856ad364e35\Microsoft.Interop.Mapi.Impl.dll MOD - [2010.02.16 15:21:49 | 000,310,720 | ---- | M] () -- C:\Windows\assembly\GAC_32\BCMCommon\3.0.0.0__31bf3856ad364e35\BCMCommon.dll MOD - [2010.02.16 15:13:17 | 000,004,608 | ---- | M] () -- C:\Windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\Extensibility.dll MOD - [2009.07.17 06:57:02 | 000,055,808 | ---- | M] () -- C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll MOD - [2009.02.26 14:46:56 | 000,064,344 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll MOD - [2009.02.23 19:51:10 | 000,324,712 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\BCMRes.resources.dll MOD - [2008.03.17 17:14:56 | 000,012,112 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\Microsoft.Interop.Mapi.Interfaces.resources.dll MOD - [2008.03.17 17:14:38 | 000,068,432 | ---- | M] () -- C:\Program Files\Microsoft Small Business\Business Contact Manager\de-DE\BusinessLayer.resources.dll ========== Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService) SRV - [2012.09.07 11:52:02 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.08.15 09:31:09 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.05.15 08:44:47 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2012.05.15 08:44:47 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.15 08:44:46 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService) SRV - [2012.05.15 08:44:46 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.12.30 12:27:34 | 000,074,752 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver) SRV - [2011.10.21 16:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc) SRV - [2011.10.13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate) SRV - [2010.01.15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009.07.17 06:57:36 | 000,026,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc) SRV - [2009.07.15 20:47:20 | 000,221,266 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe -- (STacSV) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.06.09 20:33:28 | 000,603,376 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\dkabcoms.exe -- (dkab_device) SRV - [2009.02.23 19:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc) SRV - [2007.02.12 10:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Windows\System32\drivers\o2flash.exe -- (O2FLASH) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.05.15 08:44:47 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.15 08:44:47 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.04.16 16:22:04 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm) DRV - [2009.07.17 06:56:50 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY) DRV - [2009.07.15 20:47:20 | 000,409,088 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA) DRV - [2009.07.14 02:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.06.11 16:39:00 | 009,765,568 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.05.22 11:17:52 | 000,058,528 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2mdg.sys -- (O2MDGRDR) DRV - [2009.05.07 11:47:12 | 000,041,504 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2sdg.sys -- (O2SDGRDR) DRV - [2009.03.24 17:25:24 | 000,197,680 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2008.05.28 18:01:00 | 000,235,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM13Vid.sys -- (OEM13Vid) DRV - [2007.03.05 11:45:04 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM13Vfx.sys -- (OEM13Vfx) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com IE - HKLM\..\SearchScopes,DefaultScope = {0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7} IE - HKLM\..\SearchScopes\{0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8 IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\SearchScopes,DefaultScope = {0B7E6713-EB47-4ED9-AF4E-5E433AE4A9A7} IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\SearchScopes\{8CF8A38F-F1ED-4060-92CF-5FFBD20BA753}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} IE - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/ig" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2 FF - prefs.js..extensions.enabledItems: fmconverter@gmail.com:1.0.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@t-immersion.com/DFusionHomeWebPlugIn: C:\Program Files\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion) FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.01.09 16:13:26 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.07 11:52:02 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.07 11:52:00 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.07 11:52:02 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.09.07 11:52:00 | 000,000,000 | ---D | M] [2010.02.22 12:43:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Extensions [2012.08.30 17:56:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Firefox\Profiles\powom3zm.default\extensions [2012.08.30 17:56:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\Firefox\Profiles\powom3zm.default\extensions\trash [2012.08.30 17:56:36 | 000,199,396 | ---- | M] () (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\firefox\profiles\powom3zm.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2012.07.31 10:03:30 | 000,194,632 | ---- | M] () (No name found) -- C:\Users\Daniel Kort\AppData\Roaming\mozilla\firefox\profiles\powom3zm.default\extensions\trash\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2012.09.07 11:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012.09.07 11:51:57 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012.09.07 11:52:02 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.05.12 16:42:04 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll [2010.05.12 16:43:54 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll [2010.05.12 16:42:52 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll [2010.05.12 16:42:32 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll [2010.05.12 17:22:36 | 000,423,328 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll [1999.12.31 17:00:00 | 000,166,680 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2010.05.12 16:43:56 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll [2012.02.07 19:07:51 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.08.30 08:21:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.02.07 19:07:51 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.02.07 19:07:51 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.02.07 19:07:51 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.02.07 19:07:51 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found. O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) O4 - HKLM..\Run: [DBRMTray] C:\dell\DBRM\Reminder\DbrmTrayicon.exe (Microsoft) O4 - HKLM..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File not found O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation) O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.) O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [DKab1err] C:\Program Files\Dell\Printer Software\ErrorApp\dkab1err.exe (Dell, Inc.) O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [Remote Control Editor] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe" File not found O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) O4 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003..\Run: [Unified Remote v2] C:\Program Files\Unified Remote\RemoteServer.exe File not found O4 - HKLM..\RunOnce: [DBRMTray] C:\dell\DBRM\Reminder\TrayApp.exe (Microsoft) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9DA7C255-C3DF-43F5-8E0B-BC2CBA7F9518}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.) Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.09.07 11:51:57 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.08.29 14:31:09 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\SLS PS [2012.08.29 09:37:06 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\Nachhaltigkeit [2012.08.22 10:47:34 | 000,000,000 | ---D | C] -- C:\Users\Daniel Kort\Desktop\SAP_Ebook Schweiz_online.pdf [2012.08.14 14:26:53 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2 C:\Users\Daniel Kort\Desktop\*.tmp files -> C:\Users\Daniel Kort\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.09.11 12:31:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.09.11 11:58:54 | 000,711,370 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.09.11 11:58:54 | 000,662,950 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.09.11 11:58:54 | 000,153,766 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.09.11 11:58:54 | 000,124,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.09.11 08:18:12 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.09.11 08:18:12 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.09.11 08:09:58 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2012.09.11 08:09:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.09.11 08:09:46 | 2411,950,080 | -HS- | M] () -- C:\hiberfil.sys [2012.09.10 16:33:41 | 000,049,787 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1682 Blogstory Vega.pdf [2012.09.10 12:49:40 | 000,087,123 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\12244_120904_Schild_SAP.pdf [2012.09.06 10:34:39 | 000,050,384 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1675 Editing SAP HANA Partner Race (1).pdf [2012.09.05 16:51:55 | 000,049,082 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver (2).pdf [2012.09.05 16:10:15 | 000,050,504 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver (1).pdf [2012.09.05 15:43:56 | 000,048,630 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\Revolver.pdf [2012.09.05 15:37:57 | 000,051,268 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\SAPD-1574 Entwicklung und Programmierung Nachhaltigkeitskampagne.pdf [2012.08.31 11:30:05 | 001,145,499 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\2012-08-13_10-46-24_578.jpg [2012.08.24 13:58:52 | 000,688,694 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\952_SAP_E-Book-Mobility_inhalt.pdf [2012.08.23 09:45:42 | 001,777,486 | ---- | M] () -- C:\Users\Daniel Kort\Desktop\xing_mediadata_20120719_de.pdf [2012.08.16 08:48:16 | 000,580,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2 C:\Users\Daniel Kort\Desktop\*.tmp files -> C:\Users\Daniel Kort\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.09.10 16:33:41 | 000,049,787 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1682 Blogstory Vega.pdf [2012.09.10 12:49:40 | 000,087,123 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\12244_120904_Schild_SAP.pdf [2012.09.06 10:34:39 | 000,050,384 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1675 Editing SAP HANA Partner Race (1).pdf [2012.09.05 16:51:54 | 000,049,082 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver (2).pdf [2012.09.05 16:10:15 | 000,050,504 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver (1).pdf [2012.09.05 15:43:56 | 000,048,630 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\Revolver.pdf [2012.09.05 15:37:57 | 000,051,268 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\SAPD-1574 Entwicklung und Programmierung Nachhaltigkeitskampagne.pdf [2012.08.31 11:30:05 | 001,145,499 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\2012-08-13_10-46-24_578.jpg [2012.08.24 13:58:51 | 000,688,694 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\952_SAP_E-Book-Mobility_inhalt.pdf [2012.08.23 09:45:42 | 001,777,486 | ---- | C] () -- C:\Users\Daniel Kort\Desktop\xing_mediadata_20120719_de.pdf [2012.05.07 09:40:00 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2012.05.07 09:40:00 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe [2012.01.11 12:17:32 | 000,002,048 | -HS- | C] () -- C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998}\@ [2011.09.08 14:46:59 | 000,072,080 | ---- | C] () -- C:\Users\Daniel Kort\g2mdlhlpx.exe [2011.07.13 16:00:59 | 000,015,418 | ---- | C] () -- C:\Users\Daniel Kort\.TransferManager.db [2011.06.22 09:02:50 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2010.11.17 12:22:55 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE [2010.10.28 10:01:06 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2010.04.01 11:54:19 | 000,006,144 | ---- | C] () -- C:\Users\Daniel Kort\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.02.22 12:52:07 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat ========== LOP Check ========== [2011.06.10 15:12:58 | 000,000,000 | ---D | M] -- C:\Users\Bewerber\AppData\Roaming\ICAClient [2012.05.07 09:39:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FreePDF [2011.06.03 15:56:47 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\ICAClient [2011.03.10 17:35:41 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\PixelPlanet [2011.09.01 16:57:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Revolver Preferences [2010.04.14 11:01:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TerraTec [2011.07.07 15:21:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Total Immersion [2010.05.04 13:15:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TuneUp Software [2011.10.21 18:49:44 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Unified Remote [2012.05.10 08:38:17 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2011.09.27 14:45:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Adobe [2012.06.06 08:39:56 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Apple Computer [2012.02.16 09:10:48 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Avira [2010.02.23 09:40:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\CyberLink [2010.07.01 13:20:39 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\DivX [2010.09.22 08:55:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FastStone [2012.05.07 09:39:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\FreePDF [2011.06.03 15:56:47 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\ICAClient [2010.02.22 11:44:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Identities [2012.02.10 18:37:17 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\InstallShield [2010.02.22 11:58:33 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Macromedia [2012.07.03 13:45:45 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Malwarebytes [2009.07.14 10:56:56 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Media Center Programs [2012.05.18 12:42:28 | 000,000,000 | --SD | M] -- C:\Users\Daniel Kort\AppData\Roaming\Microsoft [2010.02.22 12:43:16 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Mozilla [2011.03.10 17:35:41 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\PixelPlanet [2011.09.01 16:57:24 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Revolver Preferences [2010.04.01 20:50:12 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Roxio [2012.09.11 13:20:25 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Skype [2011.07.11 08:38:59 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\skypePM [2010.04.14 11:01:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TerraTec [2011.07.07 15:21:35 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Total Immersion [2010.05.04 13:15:08 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\TuneUp Software [2011.10.21 18:49:44 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\Unified Remote [2012.03.07 16:42:11 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\vlc [2012.06.08 10:21:54 | 000,000,000 | ---D | M] -- C:\Users\Daniel Kort\AppData\Roaming\WinRAR < %APPDATA%\*.exe /s > [2011.11.15 15:02:18 | 005,147,880 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Daniel Kort\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: IASTOR.SYS > [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Drivers\storage\R229669\IaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\drivers\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_4f144d6467fc7c22\iaStor.sys [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_10aa509d6843c6fc\iaStor.sys < MD5 for: IASTORV.SYS > [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys [2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys [2010.11.20 14:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys [2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll [2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys [2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys [2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys [2010.11.20 14:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll [2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll [2010.11.20 14:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010.11.20 14:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < End of report > [/code] |
11.09.2012, 16:58 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Virenbefall: Live Security Platinum Virus Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL FF - user.js - File not found O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-413260923-1584583347-2878145964-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun O33 - MountPoints2\{e925371b-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell - "" = AutoRun O33 - MountPoints2\{e925372a-f804-11df-b546-904ce5e0a042}\Shell\AutoRun\command - "" = E:\AutoRun.exe :Files C:\Users\Daniel Kort\AppData\Local\{7c9c6958-a65d-e6bc-5848-15b770ab5998} ipconfig /flushdns /c :Commands [purity] [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Virenbefall: Live Security Platinum Virus |
administrator, anti-malware, appdata, autostart, befall, befallen, dateien, explorer, gen, hallo zusammen, inprocserver32, laptop, live, microsoft, platinum, scan, scanner, security, service, software, speicher, version, virenscan, virenscanner, virus |