|
Plagegeister aller Art und deren Bekämpfung: TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock PlusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.09.2012, 09:43 | #1 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus Hallo, bin völliger Anfänger, was die Bekämpfung von Viren, Trojs etc angeht. Jetzt spinnt firefox, glaub, ich hab Besuch. Könnte mir da jemand hier vielleicht weiterhelfen? Wie gesagt, ich hab null Ahnung. Hab jetzt HijackThis drüberlaufen lassen, hier der logfile. Spybot läuft auch nochmal, hat beim ersten Mal aber nix gefunden... Ich bin sehr dankbar für Unterstützung! Grüße an die Profis, Salenn Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:36:14, on 20.09.2012 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Intel\Wireless\Bin\EvtEng.exe C:\Programme\Intel\Wireless\Bin\S24EvMon.exe C:\Programme\Sygate\SPF\smc.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir Desktop\sched.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programme\Intel\Wireless\Bin\RegSrvc.exe C:\Programme\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Sony\VAIO Event Service\VESMgr.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\Explorer.EXE C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe C:\Programme\Apoint\Apoint.exe C:\Programme\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\wuauclt.exe C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Apoint\Apntex.exe C:\Programme\Spybot - Search & Destroy\TeaTimer.exe C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe C:\Programme\Spybot - Search & Destroy\SpybotSD.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\Mozilla Firefox\plugin-container.exe C:\Programme\Mozilla Firefox\plugin-container.exe C:\Dokumente und Einstellungen\sabina\Desktop\HiJackThis204.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com/de/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GoogleAFE.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [IntelWireless] "C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\QTTask.exe" -atboottime O4 - HKCU\..\Run: [swg] "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TrayBackup] "C:\Programme\TrayBackup\traybackup.exe" /AUTO O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Dropbox.lnk = C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe O8 - Extra context menu item: &Suche im Duden - res://C:\Programme\Duden-Suche Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=hxxp://www.club-vaio.com/de/ O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - hxxp://www3.snapfish.de/SnapfishActivia.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188477133421 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Update Service (gupdate1cae781c34ce778) (gupdate1cae781c34ce778) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Programme\Sony\Image Converter 2\IcVzMon.exe O23 - Service: iPod Service - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: MSCSPTISRV - Unknown owner - C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\MSCSPTISRV.exe (file missing) O23 - Service: Microsoft .NET Framework v1.1.4322 Update (NetFxUpdate_v1.1.4322) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\PACSPTISVR.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programme\Sygate\SPF\smc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\SPTISRV.exe (file missing) O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\SSScsiSV.exe O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Programme\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programme\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programme\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programme\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programme\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programme\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- End of file - 11990 bytes |
20.09.2012, 12:06 | #2 |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus hi
__________________nächstes mal, bitte einfach mal die foren regeln lesen, hjt logs wollen wir schon eine lange zeit nicht mehr sehen Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
20.09.2012, 12:36 | #3 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus OTL Logfile:
__________________Code:
ATTFilter OTL logfile created on: 20.09.2012 13:19:41 - Run 1 OTL by OldTimer - Version 3.2.64.0 Folder = C:\Dokumente und Einstellungen\sabina\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1022,04 Mb Total Physical Memory | 352,83 Mb Available Physical Memory | 34,52% Memory free 2,37 Gb Paging File | 1,52 Gb Available in Paging File | 64,27% Paging File free Paging file location(s): C:\pagefile.sys 8 8D:\pagefile.sys 1500 3000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 37,26 Gb Total Space | 10,98 Gb Free Space | 29,48% Space Free | Partition Type: NTFS Drive D: | 30,28 Gb Total Space | 19,13 Gb Free Space | 63,17% Space Free | Partition Type: NTFS Drive H: | 14,94 Gb Total Space | 5,12 Gb Free Space | 34,28% Space Free | Partition Type: NTFS Drive I: | 298,09 Gb Total Space | 194,04 Gb Free Space | 65,10% Space Free | Partition Type: NTFS Computer Name: PILATUS | User Name: sabina | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.09.20 13:16:19 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\sabina\Desktop\OTL.exe PRC - [2012.09.06 03:24:58 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe PRC - [2012.04.04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe PRC - [2012.01.17 11:07:58 | 000,505,736 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe PRC - [2012.01.17 11:07:54 | 000,252,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe PRC - [2011.07.11 20:31:45 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe PRC - [2011.04.28 11:24:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2010.11.23 15:15:34 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2010.01.14 23:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\TeaTimer.exe PRC - [2007.06.13 15:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006.02.28 14:25:48 | 000,602,182 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Wireless\Bin\iFrmewrk.exe PRC - [2006.02.28 14:22:50 | 000,397,381 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe PRC - [2005.11.28 14:39:32 | 000,118,784 | ---- | M] (Sony Corporation) -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe PRC - [2005.11.28 14:39:30 | 000,131,072 | ---- | M] (Sony Corporation) -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe PRC - [2005.11.28 14:39:22 | 000,270,336 | ---- | M] (Sony Corporation) -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe PRC - [2005.05.20 17:41:42 | 000,153,600 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\VAIO Event Service\VESMgr.exe PRC - [2004.11.17 13:47:16 | 000,118,784 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\Apoint\Apoint.exe PRC - [2004.08.19 02:40:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\Apoint\ApntEx.exe PRC - [2004.02.24 16:35:06 | 002,372,760 | ---- | M] (Sygate Technologies, Inc.) -- C:\Programme\Sygate\SPF\Smc.exe PRC - [2003.05.15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe ========== Modules (No Company Name) ========== MOD - [2012.09.06 03:25:12 | 002,244,064 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2010.01.28 14:57:53 | 000,355,688 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll MOD - [2009.02.27 17:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU MOD - [2008.03.25 06:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll MOD - [2006.02.28 14:39:02 | 000,876,544 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\Libeay32.dll MOD - [2006.02.28 14:39:02 | 000,208,965 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\iWMSProv.dll MOD - [2006.02.28 14:39:02 | 000,053,322 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\IntStngs.dll MOD - [2006.02.13 14:15:04 | 000,970,862 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\acAuth.dll MOD - [2005.05.20 17:42:20 | 000,010,752 | ---- | M] () -- C:\Programme\Sony\VAIO Event Service\VESBasePS.dll MOD - [2003.05.15 03:15:50 | 000,753,664 | ---- | M] () -- C:\Programme\Adobe\Acrobat 6.0\Distillr\AdistRes.DEU ========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\SPTISRV.exe -- (SPTISRV) SRV - File not found [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\PACSPTISVR.exe -- (PACSPTISVR) SRV - File not found [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe -- (NetFxUpdate_v1.1.4322) SRV - File not found [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\MSCSPTISRV.exe -- (MSCSPTISRV) SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe -- (de_serv) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012.09.06 03:25:06 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.08.23 10:16:34 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.04.04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2011.07.11 20:31:45 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService) SRV - [2011.04.28 11:24:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011.02.18 16:37:16 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2009.12.17 17:37:52 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programme\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) SRV - [2009.01.16 11:48:14 | 000,361,216 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag) SRV - [2008.05.29 10:28:54 | 000,028,416 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp) SRV - [2006.01.16 11:25:02 | 002,084,864 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Media Integrated Server\VMISrv.exe -- (VAIOMediaPlatform-IntegratedServer-AppServer) SRV - [2006.01.06 23:25:12 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\SSScsiSV.exe -- (SSScsiSV) SRV - [2005.12.21 11:06:28 | 000,155,648 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe -- (VAIOMediaPlatform-Mobile-Gateway) SRV - [2005.11.28 14:39:32 | 000,118,784 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- (VzFw) SRV - [2005.11.28 14:39:30 | 000,131,072 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc) SRV - [2005.11.28 14:39:22 | 000,270,336 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw) SRV - [2005.11.25 14:08:54 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service) SRV - [2005.10.11 13:07:50 | 000,770,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-IntegratedServer-UPnP) SRV - [2005.10.11 13:02:02 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-IntegratedServer-HTTP) SRV - [2005.07.14 20:10:16 | 000,032,768 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\Image Converter 2\IcVzMon.exe -- (Image Converter video recording monitor for VAIO Entertainment) SRV - [2005.05.20 17:41:42 | 000,153,600 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service) SRV - [2005.01.04 11:09:36 | 000,398,336 | ---- | M] (Sony Corporation) [Auto | Stopped] -- C:\Programme\Sony\VAIO Cooperated Initialisation\VCI_svc.exe -- (VCI) SRV - [2004.02.24 16:35:06 | 002,372,760 | ---- | M] (Sygate Technologies, Inc.) [Auto | Running] -- C:\Programme\Sygate\SPF\Smc.exe -- (SmcService) SRV - [2003.07.28 13:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2011.07.11 20:31:47 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.11 20:31:47 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009.05.11 11:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.02.13 12:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2006.11.28 22:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PDNMp50.sys -- (PDNMp50) DRV - [2006.11.28 22:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PDNSp50.sys -- (PDNSp50) DRV - [2006.02.28 15:35:56 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2006.02.26 04:43:00 | 001,428,480 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) DRV - [2006.02.21 11:32:32 | 000,226,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ti21sony.sys -- (ti21sony) DRV - [2005.12.27 08:22:00 | 000,029,184 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SonyImgF.sys -- (SonyImgF) DRV - [2005.11.21 07:06:02 | 000,009,216 | ---- | M] (Sony Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\shpf.sys -- (shpf) DRV - [2005.11.17 06:40:00 | 001,076,472 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2005.10.18 09:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2005.10.18 09:52:34 | 000,202,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2005.10.18 09:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2005.10.17 01:43:00 | 000,241,408 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp) DRV - [2004.11.22 06:31:10 | 000,108,767 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2004.02.02 10:53:28 | 000,018,518 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt) DRV - [2004.02.02 10:51:04 | 000,055,891 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\Teefer.sys -- (Teefer) DRV - [2004.02.02 10:37:32 | 000,011,914 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wg3n.sys -- (wg3n) DRV - [2002.08.20 04:59:32 | 000,071,961 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyPI.sys -- (SPI) DRV - [2002.07.17 09:05:10 | 000,016,512 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (ASPI) DRV - [2001.08.17 15:04:08 | 000,173,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\philcam2.sys -- (phil2vid) DRV - [2000.12.05 16:18:02 | 000,003,952 | ---- | M] (Sony Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DMICall.sys -- (DMICall) DRV - [2000.11.09 12:15:08 | 000,048,896 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyNC.sys -- (SNC) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Sony: Community: Welcome to the Sony Community for Computing IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Upgrade to Google Chrome IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Upgrade to Google Chrome IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Upgrade to Google Chrome IE - HKCU\..\SearchScopes,DefaultScope = {9D685552-6E4A-4183-AA33-FA417237E2CA} IE - HKCU\..\SearchScopes\{9D685552-6E4A-4183-AA33-FA417237E2CA}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SNYK_de IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.update: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "paeng-coaching.de" FF - prefs.js..extensions.enabledAddons: ffxtlbra@softonic.com:1.5.0 FF - prefs.js..extensions.enabledAddons: optout@google.com:1.5 FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.4.4rc1 FF - prefs.js..extensions.enabledAddons: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5 FF - prefs.js..extensions.enabledAddons: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.60 FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5 FF - prefs.js..extensions.enabledItems: {d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}:1.0.5 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: C:\Programme\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.05.30 23:59:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.10 14:16:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.05.31 00:13:12 | 000,000,000 | ---D | M] [2008.09.12 12:53:50 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Extensions [2012.06.01 22:50:37 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions [2009.12.08 10:55:30 | 000,000,000 | ---D | M] (CookieSafe) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD} [2010.01.14 15:06:13 | 000,000,000 | ---D | M] (Ecosia (eco-friendly search engine)) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0} [2009.10.13 16:23:46 | 000,000,000 | ---D | M] (PageZoom) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\{eeb299da-31d8-4683-aad4-9c9a045e0351} [2012.06.01 22:50:37 | 000,000,000 | ---D | M] (softonic.com) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\ffxtlbra@softonic.com [2011.07.28 10:25:04 | 000,008,363 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\optout@google.com.xpi [2012.04.15 00:05:16 | 000,114,043 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\searchy@searchy.xpi [2012.05.30 23:34:17 | 000,524,730 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012.01.16 14:37:07 | 000,634,964 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2010.02.08 17:32:43 | 000,004,855 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\searchplugins\google-images.xml [2012.09.10 14:16:46 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.09.06 03:26:03 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2011.09.06 14:22:48 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2012.05.30 23:59:31 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Programme\mozilla firefox\plugins\nprpplugin.dll [2012.09.06 04:07:37 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.06 04:07:37 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2012.09.06 04:07:37 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2012.09.06 04:07:37 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2012.09.06 04:07:37 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2012.09.06 04:07:37 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.09.14 13:43:45 | 000,445,204 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 全讯网,åšå½©ä¼˜æƒ*,皇å†*æ*£ç½‘cr67com,皇å†*比分,皇å†*å³æ—¶æŒ‡æ•°,太阳城代ç†112scg,tt娱ä¹åŸŽ8bc8,网上真钱娱 O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 ²©²Êͨ,²©²ÊÍø,½ð±¦²©188,²©²ÊͨÆÀ¼¶,°Ù¼ÒÀÖ,°ÂÃî°Ù¼ÒÀÖ O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com - Informationen zum Thema Sex links. Diese Website steht zum Verkauf! O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 123haustiereundmehr.com O1 - Hosts: 127.0.0.1 123haustiereundmehr.com O1 - Hosts: 15292 more lines... O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programme\Google AFE\GoogleAFE.dll (Google) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O4 - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [APSDaemon] C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [IntelWireless] C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SmcService] C:\Programme\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [TrayBackup] C:\Programme\TrayBackup\traybackup.exe ((C) Michael Schiel) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk = C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.) O4 - Startup: C:\Dokumente und Einstellungen\sabina\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Suche im Duden - res://C:\Programme\Duden-Suche Toolbar\toolbar.dll/SEARCH.HTML File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) O15 - HKCU\..Trusted Domains: sony-europe.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: sonystyle-europe.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: vaio-link.com ([]* in Trusted sites) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} hxxp://www3.snapfish.de/SnapfishActivia.cab (Snapfish Activia) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188477133421 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E7916B6-F782-4C3E-8C12-4412838EC301}: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.03.31 10:49:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{3f673b38-c1d6-11dd-95d4-00014af5a31a}\Shell\verb1\command - "" = desktop.exe O33 - MountPoints2\{646fdcd6-4612-11df-977d-00014af5a31a}\Shell\AutoRun\command - "" = H:\9b9w3.exe O33 - MountPoints2\{646fdcd6-4612-11df-977d-00014af5a31a}\Shell\open\Command - "" = H:\9b9w3.exe O33 - MountPoints2\{b2f43f37-9b8b-11dd-9595-00014af5a31a}\Shell\AutoRun\command - "" = H:\System\Security\DriveGuard.exe -run O33 - MountPoints2\{b2f43f37-9b8b-11dd-9595-00014af5a31a}\Shell\Explore\Command - "" = H:\System\Security\DriveGuard.exe -run O33 - MountPoints2\{b2f43f37-9b8b-11dd-9595-00014af5a31a}\Shell\Open\Command - "" = H:\System\Security\DriveGuard.exe -run O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} - Security Update for Microsoft .NET Framework 2.0 (KB922770) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offlinebrowsingpaket ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer-Hilfe ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsererweiterungen ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - Zugang zu MSN Site ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} - Security Update for Microsoft .NET Framework 2.0 (KB928365) ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML-Datenbindung ActiveX: {967B098A-042D-4367-BAC9-8BC11684174F} - Security Update for Microsoft .NET Framework 2.0 (KB917283) ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer-Hauptschriftarten ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML-Hilfe ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE NetSvcs: 6to4 - File not found NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH) NetSvcs: WmdmPmSp - File not found MsConfig - Services: "McComponentHostService" MsConfig - Services: "helpsvc" MsConfig - Services: "gusvc" MsConfig - Services: "gupdatem" MsConfig - Services: "gupdate1cae781c34ce778" MsConfig - Services: "Bonjour Service" MsConfig - Services: "aspnet_state" MsConfig - Services: "Apple Mobile Device" MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Acrobat Assistant.lnk - C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe - (Adobe Systems Inc.) MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Gamma Loader.lnk - C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe - (Adobe Systems, Inc.) MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk - - File not found MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^ScanPanel.lnk - C:\ScanPanel\ScnPanel.exe - () MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^Dropbox.lnk - C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe - (Dropbox, Inc.) MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^OpenOffice.org 2.2.lnk - - File not found MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^OpenOffice.org 3.0.lnk - C:\Programme\OpenOffice\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpReg: Apoint - hkey= - key= - C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.) MsConfig - StartUpReg: CTFMON.EXE - hkey= - key= - File not found MsConfig - StartUpReg: igfxhkcmd - hkey= - key= - File not found MsConfig - StartUpReg: igfxpers - hkey= - key= - File not found MsConfig - StartUpReg: igfxtray - hkey= - key= - File not found MsConfig - StartUpReg: ISBMgr.exe - hkey= - key= - C:\Programme\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Programme\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= - File not found MsConfig - StartUpReg: Mouse Suite 98 Daemon - hkey= - key= - File not found MsConfig - StartUpReg: MSMSGS - hkey= - key= - File not found MsConfig - StartUpReg: NvCplDaemon - hkey= - key= - File not found MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Inc.) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Programme\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: SonyPowerCfg - hkey= - key= - C:\Programme\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation) MsConfig - StartUpReg: swg - hkey= - key= - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) MsConfig - StartUpReg: VAIO Update 2 - hkey= - key= - C:\Programme\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 2 MsConfig - State: "startup" - 2 CREATERESTOREPOINT Error creating restore point. ========== Files/Folders - Created Within 30 Days ========== [2012.09.20 13:16:17 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\sabina\Desktop\OTL.exe [2012.09.14 13:21:12 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Dokumente und Einstellungen\sabina\Desktop\HiJackThis204.exe [2012.09.14 12:46:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Spybot - Search & Destroy [2012.09.11 16:57:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Sun [2012.09.10 14:16:48 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service [2012.09.10 14:10:33 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.09.10 14:07:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\MSNInstaller [2012.09.01 21:35:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\sabina\Desktop\9_2012 [2012.08.23 11:43:12 | 000,000,000 | ---D | C] -- C:\Programme\Dropbox [2008.11.13 13:23:04 | 000,269,236 | ---- | C] (Thorsten Hoeppner) -- C:\Programme\DirSync_Setup.exe [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.09.20 13:17:18 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.09.20 13:16:19 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\sabina\Desktop\OTL.exe [2012.09.20 12:58:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012.09.20 09:37:31 | 000,045,378 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2012.09.20 09:37:22 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.09.20 09:37:22 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job [2012.09.20 09:34:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.09.20 09:34:12 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys [2012.09.17 22:18:05 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2012.09.16 12:28:37 | 000,465,967 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Desktop\FLT_3VOCYY9118_0.pdf [2012.09.16 09:56:14 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.09.14 13:43:45 | 000,445,204 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012.09.14 13:21:13 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Dokumente und Einstellungen\sabina\Desktop\HiJackThis204.exe [2012.09.13 00:04:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job [2012.09.10 14:16:49 | 000,000,700 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2012.09.05 19:22:16 | 061,605,428 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Desktop\Suesses_Gift.zip [2012.09.05 18:59:32 | 000,045,056 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.08.23 11:43:47 | 000,001,043 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Startmenü\Programme\Autostart\Dropbox.lnk [2012.08.23 11:42:43 | 000,001,037 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\Desktop\Dropbox.lnk [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.09.16 12:28:37 | 000,465,967 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Desktop\FLT_3VOCYY9118_0.pdf [2012.09.10 14:16:49 | 000,000,706 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk [2012.09.10 14:16:49 | 000,000,700 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2012.09.05 19:14:45 | 061,605,428 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Desktop\Suesses_Gift.zip [2012.08.23 11:43:47 | 000,001,043 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Startmenü\Programme\Autostart\Dropbox.lnk [2012.04.13 19:16:43 | 000,018,120 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\Artec48.sys [2012.04.13 19:15:34 | 000,167,936 | ---- | C] () -- C:\WINDOWS\A4.dll [2012.04.13 19:15:34 | 000,045,056 | ---- | C] () -- C:\WINDOWS\GetKey.dll [2012.02.13 14:14:38 | 000,038,496 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Kommagetrennte Werte (DOS).ADR [2012.02.03 11:49:15 | 000,000,082 | ---- | C] () -- C:\WINDOWS\odbc_merge.INI [2012.01.21 11:56:01 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\{9C22701C-6485-43A2-A1C3-E1AC2EC2A24B} [2011.06.18 00:20:14 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2009.01.28 15:44:13 | 000,037,929 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Kommagetrennte Werte (Windows).ADR [2007.10.29 20:58:13 | 112,441,538 | ---- | C] () -- C:\Programme\OOo_2.3.0_Win32Intel_install_de.exe [2007.08.06 22:05:05 | 000,045,056 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007.08.05 19:10:51 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html [2005.02.03 23:44:36 | 000,000,141 | ---- | C] () -- C:\Dokumente und Einstellungen\sabina\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat ========== ZeroAccess Check ========== [2006.03.31 10:58:58 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini ========== LOP Check ========== [2005.02.09 00:49:03 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ [2007.10.26 16:32:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ClipMemAdvanced [2008.11.03 13:27:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CounterPath [2012.04.10 17:27:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\elsterformular [2012.05.24 01:29:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tmp [2008.11.12 21:53:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2011.09.26 11:27:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} [2011.04.13 13:53:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2010.03.04 18:09:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009.08.15 20:43:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2007.10.26 16:32:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\ClipMemAdvanced [2012.05.23 20:09:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2012.09.20 12:25:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox [2012.04.10 17:38:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\elsterformular [2010.07.24 13:17:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\FRITZ! [2007.08.17 16:24:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\InterVideo [2008.08.11 16:43:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Leadertech [2010.03.11 19:46:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\MP3Find [2012.09.10 14:07:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\MSNInstaller [2008.12.30 18:07:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\OpenOffice.org [2008.10.15 17:40:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Opera [2012.05.30 23:32:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Oracle [2008.11.12 23:24:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\phonostar-Player [2008.10.09 13:58:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Snapfish [2005.02.09 00:58:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\sony [2007.08.09 12:17:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Thunderbird [2010.03.10 17:39:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Tobit [2008.11.12 23:09:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\TuneUp Software [2011.09.15 13:33:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Uniblue [2011.09.15 18:12:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Wise Registry Cleaner ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.06.06 12:37:34 | 000,000,000 | ---D | M] -- C:\backup [2012.09.10 21:38:51 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2006.03.31 14:09:39 | 000,000,000 | ---D | M] -- C:\Documentation [2007.08.06 21:35:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen [2008.08.18 17:22:10 | 000,000,000 | ---D | M] -- C:\Drivers [2007.08.04 16:51:31 | 000,000,000 | ---D | M] -- C:\PCWELT [2008.10.15 17:13:13 | 000,000,000 | ---D | M] -- C:\Program Files [2012.09.10 14:16:48 | 000,000,000 | R--D | M] -- C:\Programme [2005.02.04 00:13:48 | 000,000,000 | -HSD | M] -- C:\RECYCLER [2008.03.12 18:00:00 | 000,000,000 | ---D | M] -- C:\ringtoneexport [2012.04.13 19:16:44 | 000,000,000 | ---D | M] -- C:\ScanPanel [2012.09.20 13:22:51 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2007.10.29 21:38:13 | 000,000,000 | ---D | M] -- C:\Texte [2012.09.10 14:07:26 | 000,000,000 | ---D | M] -- C:\WINDOWS < %PROGRAMFILES%\*.exe > [2008.11.13 13:23:07 | 000,269,236 | ---- | M] (Thorsten Hoeppner) -- C:\Programme\DirSync_Setup.exe [2007.10.29 21:04:37 | 112,441,538 | ---- | M] () -- C:\Programme\OOo_2.3.0_Win32Intel_install_de.exe Invalid Environment Variable: LOCALAPPDATA < %systemroot%\*. /mp /s > < C:\Windows\system32\*.tsp > [2004.08.04 14:00:00 | 000,266,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\h323.tsp [2004.08.04 14:00:00 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp [2004.08.04 14:00:00 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ipconf.tsp [2004.08.04 14:00:00 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp [2004.08.04 14:00:00 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp [2005.07.08 18:28:23 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp [2004.08.04 14:00:00 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] [2006.03.31 03:35:49 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini [2006.03.31 10:52:06 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT [2007.08.04 17:04:52 | 000,000,276 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [2010.05.04 02:52:14 | 000,001,086 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [2010.05.04 02:52:15 | 000,001,090 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [2012.05.31 00:00:49 | 000,000,272 | ---- | C] () -- C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job [2012.05.31 00:00:49 | 000,000,280 | ---- | C] () -- C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job [2012.06.01 23:33:40 | 000,000,884 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job < MD5 for: AGP440.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2004.08.04 14:00:00 | 018,782,319 | R--- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys [2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\agp440.sys < MD5 for: ATAPI.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2004.08.04 14:00:00 | 018,782,319 | R--- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys [2004.08.04 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys < MD5 for: EVENTLOG.DLL > [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\eventlog.dll [2004.08.04 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2004.08.04 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe [2007.06.13 15:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\explorer.exe [2007.06.13 15:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\explorer.exe [2007.06.13 15:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: NETLOGON.DLL > [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\netlogon.dll [2004.08.04 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\system32\netlogon.dll [2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\SoftwareDistribution\Download\9a1182b50c9ecbd8bedf4c560755eafc\sp2qfe\netlogon.dll [2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\SoftwareDistribution\Download\c73c85abcd9580c46805ff94bb133fb8\sp2qfe\netlogon.dll < MD5 for: SCECLI.DLL > [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\scecli.dll [2004.08.04 14:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\system32\scecli.dll < MD5 for: USER32.DLL > [2005.03.02 20:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll [2007.03.08 17:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\system32\dllcache\user32.dll [2007.03.08 17:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\system32\user32.dll [2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll [2004.08.04 14:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll [2007.03.08 17:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll [2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\user32.dll < MD5 for: USERINIT.EXE > [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\userinit.exe [2004.08.04 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2004.08.04 14:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtUninstallKB307154$\winlogon.exe [2004.08.14 01:07:41 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=4C5B48AB9179DE15A7B6A48DC8E56121 -- C:\WINDOWS\system32\winlogon.exe [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\SoftwareDistribution\Download\a746b2abbbec3e139e29152ba22decd1\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2006.03.31 12:41:32 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2006.03.31 12:41:32 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2006.03.31 12:41:32 | 000,442,368 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\system32\*.dll /lockedfiles > [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %USERPROFILE%\*.* > [2007.08.04 16:48:54 | 000,000,100 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\LuResult.txt [2012.09.19 20:57:55 | 012,058,624 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\NTUSER.DAT [2012.09.20 13:23:36 | 000,001,024 | -H-- | M] () -- C:\Dokumente und Einstellungen\sabina\ntuser.dat.LOG [2007.08.30 14:02:39 | 003,407,872 | -H-- | M] () -- C:\Dokumente und Einstellungen\sabina\NTUSER.DAT_BAK_18468 [2008.11.12 23:16:32 | 005,242,880 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\NTUSER.DAT_BAK_37483 [2007.08.30 14:02:27 | 000,000,000 | -H-- | M] () -- C:\Dokumente und Einstellungen\sabina\NTUSER.DAT_TU_18468.LOG [2008.11.12 23:16:19 | 000,000,000 | -H-- | M] () -- C:\Dokumente und Einstellungen\sabina\NTUSER.DAT_TU_37483.LOG [2012.09.19 20:57:17 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\sabina\ntuser.ini [2011.01.26 12:38:22 | 000,003,651 | ---- | M] () -- C:\Dokumente und Einstellungen\sabina\_GEAREXT.WO_IDENT.TXT < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode: %SystemRoot%\system32\win32k.sys [2008.03.20 10:03:19 | 001,845,376 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 < End of report > EXTRA TEXT OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 20.09.2012 13:19:41 - Run 1 OTL by OldTimer - Version 3.2.64.0 Folder = C:\Dokumente und Einstellungen\sabina\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1022,04 Mb Total Physical Memory | 352,83 Mb Available Physical Memory | 34,52% Memory free 2,37 Gb Paging File | 1,52 Gb Available in Paging File | 64,27% Paging File free Paging file location(s): C:\pagefile.sys 8 8D:\pagefile.sys 1500 3000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 37,26 Gb Total Space | 10,98 Gb Free Space | 29,48% Space Free | Partition Type: NTFS Drive D: | 30,28 Gb Total Space | 19,13 Gb Free Space | 63,17% Space Free | Partition Type: NTFS Drive H: | 14,94 Gb Total Space | 5,12 Gb Free Space | 34,28% Space Free | Partition Type: NTFS Drive I: | 298,09 Gb Total Space | 194,04 Gb Free Space | 65,10% Space Free | Partition Type: NTFS Computer Name: PILATUS | User Name: sabina | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- Reg Error: Key error. File not found .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- Reg Error: Key error. exefile [open] -- "%1" %* http [open] -- Reg Error: Value error. https [open] -- Reg Error: Value error. InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [CEWE FOTOSCHAU] -- "C:\Programme\CeWe Color\Mein CEWE FOTOBUCH\CEWE FOTOSCHAU.exe" -d "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Fotoschau] -- "C:\Programme\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" () Directory [Mein CEWE FOTOBUCH] -- "C:\Programme\CeWe Color\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exe" "%1" () Directory [Pixum Fotobuch] -- "C:\Programme\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Programme\Sony\VAIO Media 5.0\Vc.exe" = C:\Programme\Sony\VAIO Media 5.0\Vc.exe:*:Disabled:[VAIO Media] VAIO Media -- (Sony Corporation) "F:\fsetup.exe" = F:\fsetup.exe:*:Enabled:AVM FSetup Application "C:\Programme\ClipMemAdvanced\clipmem.exe" = C:\Programme\ClipMemAdvanced\clipmem.exe:*:Enabled:clipmem -- () "C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation) "C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe" = C:\Dokumente und Einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.) "C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00F8608F-BA6A-4B32-843A-1A568ACD1198}" = VAIO Sea Wallpaper "{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset "{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library "{04B45310-A5FE-4425-BFCA-1A6D8920DE74}" = OpenOffice.org 3.0 "{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{11C98E1A-EC91-4B38-B44C-C562292D8453}" = Adobe Premiere Elements 2.0 "{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0 "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6 "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA "{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Google AFE "{3F5D066E-C946-A258-7634-533D350ED19C}" = myphotobook.de "{412033BC-44CF-48D9-B813-4B835101F4D3}" = Adobe Illustrator 10 "{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3 "{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0 "{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0 "{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008 "{58FCA730-74A6-49C0-95A7-696D78E689A3}" = e+ 48U "{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series "{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility "{61D6E4FB-1A62-4EB1-BE56-929B00C155CF}" = Wireless LAN Starter "{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus "{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VOR "{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp "{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer "{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0 "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VPS "{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO "{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML "{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management "{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data "{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.4 "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics "{AB467B85-4F52-48C2-AEED-0673D00417B0}" = SonicStage Mastering Studio Audio Filter "{ABBD2A2E-2424-4078-966F-F319A88D5F21}" = VAIO Starfish Wallpaper "{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0 Professional - English, Français, Deutsch "{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.0 - Deutsch "{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B502B428-3386-40A9-98DB-079AAB72E64F}" = mEoU "{B7C03E84-AF46-42F4-809D-D4127D9086D0}" = VAIO Edit Components 6.0 "{BBFFB027-7D53-4E1B-95BC-35A2216D1D60}" = VAIO Long Battery Life Wallpaper "{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library "{BF3B304B-8A18-452D-A19F-6012CA8418D7}" = SonicStage Mastering Studio 2.2 "{C27BF761-C499-488D-A964-A3718BC6EC3E}" = DSD Direct "{C518C7BF-A345-4019-815B-FFDF32EBCAD9}" = VAIO HDD Protection "{C89EB8CD-675F-44F4-9729-4C9A8FAC2D4F}" = DSD Playback Plug-In 1.0 "{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E62952D9-52CC-4D65-B112-91DCD22856C5}_is1" = ClipMem Advanced "{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.20 "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support "{EE7EB179-5AA2-4B28-AC92-5CBAAF82BA7F}" = SonicStage Mastering Studio Plugins "{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL "{F0312AC6-988B-11DA-9C49-000476F770CC}" = CIB pdf brewer 2.5.22 "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service "{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi "{F860F390-78F4-4B45-8C1A-0489618E315B}" = Sygate Personal Firewall "{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171 "{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents "{FC37C108-821D-4EDE-8F40-D5B497586805}" = VAIO Control Center "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe InDesign 2.0" = Adobe InDesign 2.0 "Adobe Photoshop 7.0" = Adobe Photoshop 7.0 "Adobe SVG Viewer" = Adobe SVG Viewer 3.0 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "AVMFBox" = AVM FRITZ!Box Dokumentation "AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss "B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP "de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1" = myphotobook.de "DirSync" = DirSync 2.7d "Duden-Suche Toolbar_is1" = Duden-Suche Toolbar 1.0 "ElsterFormular 11.5.0.4546" = ElsterFormular Upgrade "ElsterFormular 13.1.1.8531u" = ElsterFormular "eyeBeam 1.5_is1" = eyeBeam 1.5.19.2 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "InstallShield_{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VAIO-Online-Registrierung (Deutsch) "InstallShield_{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VAIO Product Survey "InstallShield_{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00 "McAfee Security Scan" = McAfee Security Scan Plus "Mein CEWE FOTOBUCH" = Mein CEWE FOTOBUCH "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU "MouseSuite98" = Sony USB Mouse "Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NetCologne" = NetCologne-Installationsdateien entfernen "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Drivers" = NVIDIA Drivers "Pixum Fotobuch" = Pixum Fotobuch "PremElem20" = Adobe Premiere Elements 2.0 "ProInst" = Intel(R) PROSet/Wireless Software "RealPlayer 15.0" = RealPlayer "Revo Uninstaller" = Revo Uninstaller 1.71 "Softomate.SoftomateObjIEToolbar" = duden.de Toolbar "SWFPlayer_is1" = SWFPlayer 2.6.2.0 "VLC media player" = VideoLAN VLC media player 0.8.6d "Windows Media Format Runtime" = Windows Media Format Runtime "Windows Media Player" = Windows Media Player 10 "Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.14 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Move Media Player" = Move Media Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 01.09.2012 14:49:37 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 01.09.2012 14:52:42 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 01.09.2012 14:52:44 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Der angegebene Server kann den angeforderten Vorgang nicht ausführen. . Error - 09.09.2012 17:07:23 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 10.09.2012 03:59:16 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 10.09.2012 03:59:17 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Der angegebene Server kann den angeforderten Vorgang nicht ausführen. . Error - 14.09.2012 06:19:39 | Computer Name = PILATUS | Source = VSS | ID = 5013 Description = Volumeschattenkopie-Dienstfehler: Von Schattenkopieautor "RemovableStorageManager" aufgerufene Routine "OpenNtmsSessionW" ist mit Status "0x800708ca" (konvertiert in 0x800423f4) fehlgeschlagen. Error - 17.09.2012 04:25:38 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 17.09.2012 04:26:27 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . Error - 17.09.2012 04:27:52 | Computer Name = PILATUS | Source = crypt32 | ID = 131080 Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. . [ System Events ] Error - 17.09.2012 04:25:05 | Computer Name = PILATUS | Source = Service Control Manager | ID = 7011 Description = Zeitüberschreitung (30000 ms) beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache. Error - 17.09.2012 04:25:09 | Computer Name = PILATUS | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1058" aufgetreten, als der Dienst "gusvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8} Error - 17.09.2012 08:57:05 | Computer Name = PILATUS | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Microsoft .NET Framework v1.1.4322 Update" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 18.09.2012 07:52:58 | Computer Name = PILATUS | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Microsoft .NET Framework v1.1.4322 Update" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 18.09.2012 07:53:02 | Computer Name = PILATUS | Source = Dhcp | ID = 1002 Description = Die IP-Adresslease 192.168.0.198 für die Netzwerkkarte mit der Netzwerkadresse 00130255D148 wurde durch den DHCP-Server 0.0.0.0 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error - 18.09.2012 07:54:23 | Computer Name = PILATUS | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1058" aufgetreten, als der Dienst "gusvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8} Error - 18.09.2012 08:03:32 | Computer Name = PILATUS | Source = Windows Update Agent | ID = 16 Description = Verbindung nicht möglich: Es konnte keine Verbindung mit dem Dienst "Automatische Updates" hergestellt werden, daher können Updates nicht nach dem angegebenen Zeitplan heruntergeladen und installiert werden. Es wird weiterhin versucht, eine Verbindung herzustellen. Error - 19.09.2012 05:03:10 | Computer Name = PILATUS | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Microsoft .NET Framework v1.1.4322 Update" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 19.09.2012 08:15:56 | Computer Name = PILATUS | Source = DCOM | ID = 10005 Description = Bei DCOM ist der Fehler "%1058" aufgetreten, als der Dienst "gusvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8} Error - 20.09.2012 03:34:20 | Computer Name = PILATUS | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Microsoft .NET Framework v1.1.4322 Update" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 < End of report > |
20.09.2012, 18:22 | #4 |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus hi warum hat dein pc noch nie updates bekommen? servicepack 2, internet explorer 6 etc. aktuell ist seit jahren das servicepack 3. download tdss killer: http://www.trojaner-board.de/82358-t...entfernen.html Klicke auf Change parameters • Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system • Klick auf OK und anschließend auf Start scan - bei funden erst mal immer skip wählen, log posten
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
25.09.2012, 09:55 | #5 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus Gute Fragen! Keine Ahnung, wie gesagt... Werde ich einleiten. Scan läuft. 1000 Dank. Hier der REPORT: 10:53:40.0765 3320 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24 10:53:42.0781 3320 ============================================================ 10:53:42.0781 3320 Current date / time: 2012/09/25 10:53:42.0781 10:53:42.0781 3320 SystemInfo: 10:53:42.0781 3320 10:53:42.0781 3320 OS Version: 5.1.2600 ServicePack: 2.0 10:53:42.0781 3320 Product type: Workstation 10:53:42.0781 3320 ComputerName: PILATUS 10:53:42.0781 3320 UserName: sabina 10:53:42.0781 3320 Windows directory: C:\WINDOWS 10:53:42.0781 3320 System windows directory: C:\WINDOWS 10:53:42.0781 3320 Processor architecture: Intel x86 10:53:42.0781 3320 Number of processors: 2 10:53:42.0781 3320 Page size: 0x1000 10:53:42.0781 3320 Boot type: Normal boot 10:53:42.0781 3320 ============================================================ 10:53:46.0187 3320 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 10:53:46.0203 3320 Drive \Device\Harddisk3\DR12 - Size: 0x3BC000000 (14.94 Gb), SectorSize: 0x200, Cylinders: 0x79D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 10:53:46.0203 3320 Drive \Device\Harddisk4\DR13 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 10:53:46.0531 3320 ============================================================ 10:53:46.0531 3320 \Device\Harddisk0\DR0: 10:53:46.0562 3320 MBR partitions: 10:53:46.0562 3320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xDF8F90, BlocksNum 0x4A85300 10:53:46.0578 3320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x587E2CF, BlocksNum 0x3C901F2 10:53:46.0578 3320 \Device\Harddisk3\DR12: 10:53:46.0578 3320 MBR partitions: 10:53:46.0578 3320 \Device\Harddisk3\DR12\Partition1: MBR, Type 0x7, StartLBA 0x8A0, BlocksNum 0x1DDF760 10:53:46.0578 3320 \Device\Harddisk4\DR13: 10:53:46.0578 3320 MBR partitions: 10:53:46.0578 3320 \Device\Harddisk4\DR13\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D6C1 10:53:46.0578 3320 ============================================================ 10:53:46.0625 3320 C: <-> \Device\Harddisk0\DR0\Partition1 10:53:46.0671 3320 D: <-> \Device\Harddisk0\DR0\Partition2 10:53:46.0671 3320 I: <-> \Device\Harddisk4\DR13\Partition1 10:53:46.0671 3320 ============================================================ 10:53:46.0671 3320 Initialize success 10:53:46.0671 3320 ============================================================ 10:54:23.0281 0620 ============================================================ 10:54:23.0281 0620 Scan started 10:54:23.0281 0620 Mode: Manual; SigCheck; TDLFS; 10:54:23.0281 0620 ============================================================ 10:54:25.0406 0620 ================ Scan system memory ======================== 10:54:26.0500 0620 System memory - ok 10:54:26.0500 0620 ================ Scan services ============================= 10:54:26.0578 0620 Abiosdsk - ok 10:54:26.0578 0620 abp480n5 - ok 10:54:26.0609 0620 [ 94B4741D2CF9ED38140B831293D1601A ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:54:28.0531 0620 ACPI - ok 10:54:28.0671 0620 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 10:54:28.0937 0620 ACPIEC - ok 10:54:29.0000 0620 [ E12CFCF1DDBFC50948A75E6E38793225 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 10:54:29.0093 0620 AdobeFlashPlayerUpdateSvc - ok 10:54:29.0093 0620 adpu160m - ok 10:54:29.0125 0620 [ 1EE7B434BA961EF845DE136224C30FEC ] aec C:\WINDOWS\system32\drivers\aec.sys 10:54:29.0625 0620 aec - ok 10:54:29.0656 0620 [ 91F3DF93F40A74D222CD166FE95DB633 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys 10:54:29.0718 0620 AegisP ( UnsignedFile.Multi.Generic ) - warning 10:54:29.0718 0620 AegisP - detected UnsignedFile.Multi.Generic (1) 10:54:29.0734 0620 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys 10:54:29.0953 0620 AFD - ok 10:54:29.0953 0620 Aha154x - ok 10:54:29.0953 0620 aic78u2 - ok 10:54:29.0953 0620 aic78xx - ok 10:54:29.0984 0620 [ 1AAB6C5F8376357CB9B16C38C42C4076 ] Alerter C:\WINDOWS\system32\alrsvc.dll 10:54:30.0156 0620 Alerter - ok 10:54:30.0171 0620 [ 6596DD260FFDE1BDC994C1DF236307BB ] ALG C:\WINDOWS\System32\alg.exe 10:54:30.0265 0620 ALG - ok 10:54:30.0265 0620 AliIde - ok 10:54:30.0265 0620 amsint - ok 10:54:30.0375 0620 [ C27D46B06D340293670450FCE9DFB166 ] AntiVirSchedulerService C:\Programme\Avira\AntiVir Desktop\sched.exe 10:54:30.0437 0620 AntiVirSchedulerService - ok 10:54:30.0468 0620 [ 72D90E56563165984224493069C69ED4 ] AntiVirService C:\Programme\Avira\AntiVir Desktop\avguard.exe 10:54:30.0484 0620 AntiVirService - ok 10:54:30.0500 0620 [ B21FCBC58CB13BAC70F74B5AC5DA7409 ] ApfiltrService C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 10:54:30.0609 0620 ApfiltrService - ok 10:54:30.0671 0620 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe 10:54:30.0718 0620 Apple Mobile Device - ok 10:54:30.0718 0620 AppMgmt - ok 10:54:30.0765 0620 [ F0D692B0BFFB46E30EB3CEA168BBC49F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys 10:54:31.0015 0620 Arp1394 - ok 10:54:31.0015 0620 asc - ok 10:54:31.0015 0620 asc3350p - ok 10:54:31.0015 0620 asc3550 - ok 10:54:31.0046 0620 [ 54AB078660E536DA72B21A27F56B035B ] ASPI C:\WINDOWS\System32\DRIVERS\ASPI32.sys 10:54:31.0125 0620 ASPI ( UnsignedFile.Multi.Generic ) - warning 10:54:31.0125 0620 ASPI - detected UnsignedFile.Multi.Generic (1) 10:54:31.0218 0620 [ E1633440859F9A1B3CEAF73BA85225CA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 10:54:31.0390 0620 aspnet_state - ok 10:54:31.0406 0620 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:54:31.0593 0620 AsyncMac - ok 10:54:31.0625 0620 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 10:54:31.0781 0620 atapi - ok 10:54:31.0796 0620 Atdisk - ok 10:54:31.0796 0620 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:54:32.0000 0620 Atmarpc - ok 10:54:32.0031 0620 [ E98B8250398F6637B335A76BA8DFB602 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 10:54:32.0218 0620 AudioSrv - ok 10:54:32.0250 0620 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 10:54:32.0421 0620 audstub - ok 10:54:32.0453 0620 [ 0B497C79824F8E1BF22FA6AACD3DE3A0 ] avgio C:\Programme\Avira\AntiVir Desktop\avgio.sys 10:54:32.0515 0620 avgio - ok 10:54:32.0546 0620 [ 1E4114685DE1FFA9675E09C6A1FB3F4B ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys 10:54:32.0656 0620 avgntflt - ok 10:54:32.0671 0620 [ 0F78D3DAE6DEDD99AE54C9491C62ADF2 ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys 10:54:32.0734 0620 avipbb - ok 10:54:32.0765 0620 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 10:54:32.0984 0620 Beep - ok 10:54:33.0125 0620 [ 3A5E54A9AB96EF2D273B58136FB58EFE ] BITS C:\WINDOWS\system32\qmgr.dll 10:54:33.0671 0620 BITS - ok 10:54:33.0875 0620 [ F832F1505AD8B83474BD9A5B1B985E01 ] Bonjour Service C:\Programme\Bonjour\mDNSResponder.exe 10:54:34.0718 0620 Bonjour Service - ok 10:54:34.0812 0620 [ D8653DCD80CF2EBB333FC4FCC43A7DEF ] Browser C:\WINDOWS\System32\browser.dll 10:54:35.0265 0620 Browser - ok 10:54:35.0312 0620 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 10:54:35.0593 0620 cbidf2k - ok 10:54:35.0656 0620 [ 6163ED60B684BAB19D3352AB22FC48B2 ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 10:54:37.0312 0620 CCDECODE - ok 10:54:37.0312 0620 cd20xrnt - ok 10:54:37.0343 0620 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 10:54:37.0515 0620 Cdaudio - ok 10:54:37.0546 0620 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 10:54:37.0718 0620 Cdfs - ok 10:54:37.0750 0620 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:54:37.0937 0620 Cdrom - ok 10:54:37.0953 0620 Changer - ok 10:54:37.0968 0620 [ 234D52C63C67A8CF4AF9BECCE43BFB4A ] CiSvc C:\WINDOWS\system32\cisvc.exe 10:54:38.0171 0620 CiSvc - ok 10:54:38.0203 0620 [ 0461868578D29DC18FB1C79933C5158A ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 10:54:38.0406 0620 ClipSrv - ok 10:54:38.0437 0620 [ 3D560AF01BDC50B4A1E1BFB5CDC06D63 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:54:38.0578 0620 clr_optimization_v2.0.50727_32 - ok 10:54:38.0609 0620 [ 4266BE808F85826AEDF3C64C1E240203 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 10:54:38.0781 0620 CmBatt - ok 10:54:38.0781 0620 CmdIde - ok 10:54:38.0796 0620 [ DF1B1A24BF52D0EBC01ED4ECE8979F50 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 10:54:38.0984 0620 Compbatt - ok 10:54:39.0000 0620 COMSysApp - ok 10:54:39.0000 0620 Cpqarray - ok 10:54:39.0031 0620 [ 1A5F9DB98DF7955B4C7CBDBF2C638238 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 10:54:39.0250 0620 CryptSvc - ok 10:54:39.0250 0620 dac2w2k - ok 10:54:39.0250 0620 dac960nt - ok 10:54:39.0296 0620 [ 891E3E4537C6DFCAE475073FC49CE9CB ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 10:54:39.0703 0620 DcomLaunch - ok 10:54:39.0703 0620 de_serv - ok 10:54:39.0734 0620 [ 7C4D218F9017725589ADACAB82BEB0F8 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 10:54:40.0125 0620 Dhcp - ok 10:54:40.0171 0620 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 10:54:40.0328 0620 Disk - ok 10:54:40.0328 0620 dmadmin - ok 10:54:40.0375 0620 [ 5789B83BA87FC84C3568CF86CACEF8CE ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 10:54:40.0578 0620 dmboot - ok 10:54:40.0609 0620 [ 526192BF7696F72E29777BF4A180513A ] DMICall C:\WINDOWS\system32\DRIVERS\DMICall.sys 10:54:40.0781 0620 DMICall - ok 10:54:40.0796 0620 [ 084EB0A50A4F7B4705C8A57F234E5291 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 10:54:40.0984 0620 dmio - ok 10:54:41.0015 0620 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 10:54:41.0187 0620 dmload - ok 10:54:41.0187 0620 [ FA2D9D1A9F6B5A88D01E1685CE2378BA ] dmserver C:\WINDOWS\System32\dmserver.dll 10:54:41.0359 0620 dmserver - ok 10:54:41.0390 0620 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 10:54:41.0578 0620 DMusic - ok 10:54:41.0609 0620 [ D20C5B5F0D8AC53FFEC17FF9B1658A6E ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 10:54:42.0046 0620 Dnscache - ok 10:54:42.0046 0620 dpti2o - ok 10:54:42.0078 0620 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 10:54:42.0234 0620 drmkaud - ok 10:54:42.0265 0620 [ 877A4512CC9074D6954776AF47021766 ] ERSvc C:\WINDOWS\System32\ersvc.dll 10:54:42.0437 0620 ERSvc - ok 10:54:42.0453 0620 [ EDB6B81761BD60F32F740BBC40AFB676 ] Eventlog C:\WINDOWS\system32\services.exe 10:54:42.0640 0620 Eventlog - ok 10:54:42.0671 0620 [ BEBC63622BDC30053A3145EBD90AF450 ] EventSystem C:\WINDOWS\system32\es.dll 10:54:43.0093 0620 EventSystem - ok 10:54:43.0171 0620 [ A346E25E3ACB4AEF81BFD49BF82112C9 ] EvtEng C:\Programme\Intel\Wireless\Bin\EvtEng.exe 10:54:43.0218 0620 EvtEng ( UnsignedFile.Multi.Generic ) - warning 10:54:43.0218 0620 EvtEng - detected UnsignedFile.Multi.Generic (1) 10:54:43.0265 0620 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 10:54:43.0437 0620 Fastfat - ok 10:54:43.0453 0620 [ 521A4CB71CC419FDF60DB83E7308AE2B ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 10:54:43.0937 0620 FastUserSwitchingCompatibility - ok 10:54:43.0968 0620 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 10:54:44.0140 0620 Fdc - ok 10:54:44.0171 0620 [ 9E9AF89F9B14AA6249065C309CE73BD8 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 10:54:44.0343 0620 Fips - ok 10:54:44.0359 0620 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 10:54:44.0546 0620 Flpydisk - ok 10:54:44.0578 0620 [ 3D234FB6D6EE875EB009864A299BEA29 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 10:54:45.0031 0620 FltMgr - ok 10:54:45.0062 0620 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:54:45.0234 0620 Fs_Rec - ok 10:54:45.0250 0620 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:54:45.0437 0620 Ftdisk - ok 10:54:45.0468 0620 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GearAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 10:54:45.0500 0620 GearAspiWDM - ok 10:54:45.0546 0620 [ 9599A713E1776B8F69300FC9008F33C1 ] getPlusHelper C:\Programme\NOS\bin\getPlus_Helper.dll 10:54:45.0656 0620 getPlusHelper - ok 10:54:45.0703 0620 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:54:45.0906 0620 Gpc - ok 10:54:45.0968 0620 [ 626A24ED1228580B9518C01930936DF9 ] gupdate1cae781c34ce778 C:\Programme\Google\Update\GoogleUpdate.exe 10:54:46.0015 0620 gupdate1cae781c34ce778 - ok 10:54:46.0015 0620 [ 626A24ED1228580B9518C01930936DF9 ] gupdatem C:\Programme\Google\Update\GoogleUpdate.exe 10:54:46.0031 0620 gupdatem - ok 10:54:46.0093 0620 [ 5467F1FF0AF264566740F67E8B810735 ] gusvc C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe 10:54:46.0156 0620 gusvc - ok 10:54:46.0187 0620 [ E31363D186B3E1D7C4E9117884A6AEE5 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 10:54:46.0265 0620 HDAudBus - ok 10:54:46.0328 0620 [ BA85BCF1A2BCF927C3600574173403E0 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 10:54:46.0531 0620 helpsvc - ok 10:54:46.0531 0620 HidServ - ok 10:54:46.0562 0620 [ 1DE6783B918F540149AA69943BDFEBA8 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:54:46.0765 0620 HidUsb - ok 10:54:46.0765 0620 hpn - ok 10:54:46.0796 0620 [ ACC46DDA7FECE95A253AE88CEA172E12 ] HSFHWAZL C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 10:54:46.0875 0620 HSFHWAZL - ok 10:54:46.0937 0620 [ C9F4E7DA78A02623ABF78A4A34CE79B1 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 10:54:47.0125 0620 HSF_DPV - ok 10:54:47.0171 0620 [ CB77BB47E67E84DEB17BA29632501730 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 10:54:47.0640 0620 HTTP - ok 10:54:47.0671 0620 [ 9EC7E866BBDBF3ECC0E67F4E0A838EB2 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 10:54:47.0859 0620 HTTPFilter - ok 10:54:47.0859 0620 i2omgmt - ok 10:54:47.0859 0620 i2omp - ok 10:54:47.0890 0620 [ 7C575018D0413440D75432A78B88C899 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:54:48.0078 0620 i8042prt - ok 10:54:48.0156 0620 [ BC1F1FF8D5800398937966CDB0A97FDC ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 10:54:48.0359 0620 ialm - ok 10:54:48.0468 0620 [ A16DEDF58C40D8236578F0FBB520EA6D ] Image Converter video recording monitor for VAIO Entertainment C:\Programme\Sony\Image Converter 2\IcVzMon.exe 10:54:48.0531 0620 Image Converter video recording monitor for VAIO Entertainment ( UnsignedFile.Multi.Generic ) - warning 10:54:48.0531 0620 Image Converter video recording monitor for VAIO Entertainment - detected UnsignedFile.Multi.Generic (1) 10:54:48.0546 0620 [ F8AA320C6A0409C0380E5D8A99D76EC6 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 10:54:48.0718 0620 Imapi - ok 10:54:48.0750 0620 [ 57D7267A9ED91ECAF4336B08C9628FCA ] ImapiService C:\WINDOWS\system32\imapi.exe 10:54:48.0937 0620 ImapiService - ok 10:54:48.0937 0620 ini910u - ok 10:54:48.0937 0620 IntelIde - ok 10:54:48.0968 0620 [ AE7511ADA0D951D50CEF95D7ECBACE99 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 10:54:49.0390 0620 intelppm - ok 10:54:49.0421 0620 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 10:54:49.0593 0620 Ip6Fw - ok 10:54:49.0625 0620 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:54:49.0812 0620 IpFilterDriver - ok 10:54:49.0812 0620 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:54:50.0031 0620 IpInIp - ok 10:54:50.0125 0620 [ E2168CBC7098FFE963C6F23F472A3593 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:54:50.0578 0620 IpNat - ok 10:54:50.0625 0620 [ 9033D67B7112D23EDED6789BACDED128 ] iPod Service C:\Programme\iPod\bin\iPodService.exe 10:54:50.0687 0620 iPod Service - ok 10:54:50.0734 0620 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:54:50.0890 0620 IPSec - ok 10:54:50.0906 0620 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 10:54:51.0015 0620 IRENUM - ok 10:54:51.0062 0620 [ CE9B7AFDF0A3D7DD8D1487262316B959 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:54:51.0265 0620 isapnp - ok 10:54:51.0343 0620 [ 5472D771C0197355C1D347F20392B982 ] JavaQuickStarterService C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe 10:54:51.0375 0620 JavaQuickStarterService - ok 10:54:51.0390 0620 [ B128FC0A5CD83F669D5DE4B58F77C7D6 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:54:51.0562 0620 Kbdclass - ok 10:54:51.0593 0620 [ BA5DEDA4D934E6288C2F66CAF58D2562 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 10:54:52.0031 0620 kmixer - ok 10:54:52.0062 0620 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 10:54:52.0218 0620 KSecDD - ok 10:54:52.0265 0620 [ 2865FA4ED4471929881C053A6E5A85F6 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 10:54:52.0703 0620 lanmanserver - ok 10:54:52.0734 0620 [ 65C7AC9213A805C389F09B5BAAA9A30C ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 10:54:53.0156 0620 lanmanworkstation - ok 10:54:53.0156 0620 lbrtfdc - ok 10:54:53.0187 0620 [ 4C25FADD7FE1D5BD779B20D3D0EB8D7C ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 10:54:53.0359 0620 LmHosts - ok 10:54:53.0421 0620 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe 10:54:53.0484 0620 McComponentHostService - ok 10:54:53.0500 0620 [ E246A32C445056996074A397DA56E815 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 10:54:53.0546 0620 mdmxsdk - ok 10:54:53.0578 0620 [ E5215AB942C5AC5F7EB0E54871D7A27C ] Messenger C:\WINDOWS\System32\msgsvc.dll 10:54:53.0765 0620 Messenger - ok 10:54:53.0796 0620 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 10:54:53.0937 0620 mnmdd - ok 10:54:53.0968 0620 [ BB2470D20405B272EA47CA5E18F1C58E ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 10:54:54.0125 0620 mnmsrvc - ok 10:54:54.0140 0620 [ 91A3DA4B12F6F1D760463A7F7857F748 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 10:54:54.0312 0620 Modem - ok 10:54:54.0328 0620 [ 71E15CA47FD947552054AFB28536268F ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:54:54.0500 0620 Mouclass - ok 10:54:54.0515 0620 [ 66A6F73C74E1791464160A7065CE711A ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:54:54.0687 0620 mouhid - ok 10:54:54.0703 0620 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 10:54:54.0890 0620 MountMgr - ok 10:54:54.0937 0620 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 10:54:55.0000 0620 MozillaMaintenance - ok 10:54:55.0000 0620 mraid35x - ok 10:54:55.0062 0620 [ 29414447EB5BDE2F8397DC965DBB3156 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:54:55.0484 0620 MRxDAV - ok 10:54:55.0546 0620 [ 025AF03CE51645C62F3B6907A7E2BE5E ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:54:56.0000 0620 MRxSmb - ok 10:54:56.0046 0620 MSCSPTISRV - ok 10:54:56.0078 0620 [ D059F9C7752EF461476E83180DAA5C62 ] MSDTC C:\WINDOWS\system32\msdtc.exe 10:54:56.0234 0620 MSDTC - ok 10:54:56.0281 0620 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 10:54:56.0453 0620 Msfs - ok 10:54:56.0453 0620 MSIServer - ok 10:54:56.0484 0620 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:54:56.0625 0620 MSKSSRV - ok 10:54:56.0640 0620 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:54:56.0812 0620 MSPCLOCK - ok 10:54:56.0843 0620 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 10:54:57.0000 0620 MSPQM - ok 10:54:57.0031 0620 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:54:57.0203 0620 mssmbios - ok 10:54:57.0234 0620 [ BF13612142995096AB084F2DB7F40F77 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 10:54:57.0390 0620 MSTEE - ok 10:54:57.0437 0620 [ F66B6B1CDDEE6CA87CEFC016EB7A0D8E ] Mup C:\WINDOWS\system32\drivers\Mup.sys 10:54:57.0859 0620 Mup - ok 10:54:57.0890 0620 [ 5C8DC6429C43DC6177C1FA5B76290D1A ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 10:54:58.0046 0620 NABTSFEC - ok 10:54:58.0093 0620 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 10:54:58.0265 0620 NDIS - ok 10:54:58.0281 0620 [ 520CE427A8B298F54112857BCF6BDE15 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 10:54:58.0453 0620 NdisIP - ok 10:54:58.0468 0620 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:54:58.0625 0620 NdisTapi - ok 10:54:58.0656 0620 [ 8D3CE6B579CDE8D37ACC690B67DC2106 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:54:59.0046 0620 Ndisuio - ok 10:54:59.0093 0620 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:54:59.0265 0620 NdisWan - ok 10:54:59.0281 0620 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 10:54:59.0453 0620 NDProxy - ok 10:54:59.0484 0620 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 10:54:59.0656 0620 NetBIOS - ok 10:54:59.0703 0620 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 10:54:59.0875 0620 NetBT - ok 10:54:59.0937 0620 [ F4EFF57254F565F39B6029150414A0D5 ] NetDDE C:\WINDOWS\system32\netdde.exe 10:55:00.0109 0620 NetDDE - ok 10:55:00.0109 0620 [ F4EFF57254F565F39B6029150414A0D5 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 10:55:00.0234 0620 NetDDEdsdm - ok 10:55:00.0265 0620 NetFxUpdate_v1.1.4322 - ok 10:55:00.0296 0620 [ 183805EB05BCA5A1E4AAAED4D2BE3690 ] Netlogon C:\WINDOWS\system32\lsass.exe 10:55:00.0421 0620 Netlogon - ok 10:55:00.0468 0620 [ 1E5218FBE323C375B488318950E10FB4 ] Netman C:\WINDOWS\System32\netman.dll 10:55:00.0875 0620 Netman - ok 10:55:00.0906 0620 [ 5C5C53DB4FEF16CF87B9911C7E8C6FBC ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys 10:55:01.0062 0620 NIC1394 - ok 10:55:01.0109 0620 [ B36E08F680BAE4DFC5C24D00A2DFC9E7 ] Nla C:\WINDOWS\System32\mswsock.dll 10:55:01.0250 0620 Nla - ok 10:55:01.0265 0620 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 10:55:01.0437 0620 Npfs - ok 10:55:01.0484 0620 [ 19A811EF5F1ED5C926A028CE107FF1AF ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 10:55:01.0968 0620 Ntfs - ok 10:55:02.0000 0620 [ 183805EB05BCA5A1E4AAAED4D2BE3690 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 10:55:02.0109 0620 NtLmSsp - ok 10:55:02.0156 0620 [ 428AA946A8D9F32DBB4260C8E6E13377 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 10:55:02.0359 0620 NtmsSvc - ok 10:55:02.0390 0620 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 10:55:02.0562 0620 Null - ok 10:55:02.0687 0620 [ E5851A969D6B63866BD2B8B2A16087AC ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 10:55:02.0953 0620 nv - ok 10:55:02.0984 0620 [ 2F1DB86B3B9158910EB7C7647EA80259 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 10:55:03.0015 0620 NVSvc - ok 10:55:03.0062 0620 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 10:55:03.0234 0620 NwlnkFlt - ok 10:55:03.0234 0620 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 10:55:03.0390 0620 NwlnkFwd - ok 10:55:03.0406 0620 [ 0951DB8E5823EA366B0E408D71E1BA2A ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys 10:55:03.0578 0620 ohci1394 - ok 10:55:03.0625 0620 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 10:55:03.0671 0620 ose - ok 10:55:03.0671 0620 PACSPTISVR - ok 10:55:03.0687 0620 [ B2F17A2EDB5450E61973A037F63A595B ] Parport C:\WINDOWS\system32\drivers\Parport.sys 10:55:03.0875 0620 Parport - ok 10:55:03.0890 0620 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 10:55:04.0062 0620 PartMgr - ok 10:55:04.0078 0620 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 10:55:04.0250 0620 ParVdm - ok 10:55:04.0281 0620 [ 6FB463E5B243FBD6F3D3C83F914D94FB ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 10:55:04.0453 0620 PCI - ok 10:55:04.0453 0620 PCIDump - ok 10:55:04.0468 0620 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 10:55:04.0640 0620 PCIIde - ok 10:55:04.0687 0620 [ E2363F4C1DAFF89ABEE5F593E13D8A05 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 10:55:04.0859 0620 Pcmcia - ok 10:55:04.0859 0620 PDCOMP - ok 10:55:04.0859 0620 PDFRAME - ok 10:55:04.0890 0620 [ 1BF91F352D746AD7469FA71783B5FAE8 ] PDNMp50 C:\WINDOWS\system32\drivers\PDNMp50.sys 10:55:04.0937 0620 PDNMp50 - ok 10:55:04.0937 0620 [ 1961590AA191B6B7DCF18A6A693AF7B8 ] PDNSp50 C:\WINDOWS\system32\drivers\PDNSp50.sys 10:55:04.0984 0620 PDNSp50 - ok 10:55:04.0984 0620 PDRELI - ok 10:55:04.0984 0620 PDRFRAME - ok 10:55:04.0984 0620 perc2 - ok 10:55:04.0984 0620 perc2hib - ok 10:55:05.0078 0620 [ 3BD216DE6A56190C19C951ED2E19087A ] phil2vid C:\WINDOWS\system32\DRIVERS\philcam2.sys 10:55:05.0265 0620 phil2vid - ok 10:55:05.0281 0620 [ EDB6B81761BD60F32F740BBC40AFB676 ] PlugPlay C:\WINDOWS\system32\services.exe 10:55:05.0421 0620 PlugPlay - ok 10:55:05.0437 0620 [ 183805EB05BCA5A1E4AAAED4D2BE3690 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 10:55:05.0562 0620 PolicyAgent - ok 10:55:05.0578 0620 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:55:05.0734 0620 PptpMiniport - ok 10:55:05.0734 0620 [ 183805EB05BCA5A1E4AAAED4D2BE3690 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 10:55:05.0859 0620 ProtectedStorage - ok 10:55:05.0890 0620 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 10:55:06.0046 0620 PSched - ok 10:55:06.0093 0620 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:55:06.0250 0620 Ptilink - ok 10:55:06.0281 0620 [ F91D5CBFC43E61D80C347B2EA1ECC9E7 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:55:06.0328 0620 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning 10:55:06.0328 0620 PxHelp20 - detected UnsignedFile.Multi.Generic (1) 10:55:06.0328 0620 ql1080 - ok 10:55:06.0328 0620 Ql10wnt - ok 10:55:06.0328 0620 ql12160 - ok 10:55:06.0343 0620 ql1240 - ok 10:55:06.0343 0620 ql1280 - ok 10:55:06.0375 0620 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:55:06.0531 0620 RasAcd - ok 10:55:06.0562 0620 [ E3C6E87C1F84584A773D7C3DD205DBFF ] RasAuto C:\WINDOWS\System32\rasauto.dll 10:55:06.0718 0620 RasAuto - ok 10:55:06.0734 0620 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:55:06.0906 0620 Rasl2tp - ok 10:55:06.0937 0620 [ FFC8343B35FB2DF01A5767748EFA5B58 ] RasMan C:\WINDOWS\System32\rasmans.dll 10:55:07.0421 0620 RasMan - ok 10:55:07.0453 0620 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:55:07.0609 0620 RasPppoe - ok 10:55:07.0625 0620 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 10:55:07.0796 0620 Raspti - ok 10:55:07.0812 0620 [ 03B965B1CA47F6EF60EB5E51CB50E0AF ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:55:08.0265 0620 Rdbss - ok 10:55:08.0296 0620 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:55:08.0484 0620 RDPCDD - ok 10:55:08.0500 0620 [ B54CD38A9EBFBF2B3561426E3FE26F62 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 10:55:08.0953 0620 RDPWD - ok 10:55:08.0984 0620 [ AEC159942DF64A9890072D7BB1797762 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 10:55:09.0156 0620 RDSessMgr - ok 10:55:09.0171 0620 [ AA56702E230860565CB8D43680F57F33 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 10:55:09.0359 0620 redbook - ok 10:55:09.0375 0620 [ D9B85D3E8F7347166A64915AEBCF6AC5 ] RegSrvc C:\Programme\Intel\Wireless\Bin\RegSrvc.exe 10:55:09.0421 0620 RegSrvc ( UnsignedFile.Multi.Generic ) - warning 10:55:09.0421 0620 RegSrvc - detected UnsignedFile.Multi.Generic (1) 10:55:09.0453 0620 [ EBA80CDF25E02084857957E820004934 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 10:55:09.0640 0620 RemoteAccess - ok 10:55:09.0671 0620 [ DA23F9F3F1B1871120F980A6879581AC ] RpcLocator C:\WINDOWS\system32\locator.exe 10:55:09.0875 0620 RpcLocator - ok 10:55:09.0921 0620 [ 891E3E4537C6DFCAE475073FC49CE9CB ] RpcSs C:\WINDOWS\system32\rpcss.dll 10:55:10.0359 0620 RpcSs - ok 10:55:10.0390 0620 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\system32\rsvp.exe 10:55:10.0562 0620 RSVP - ok 10:55:10.0609 0620 [ A30C30D53671468BA727326B4FABCC46 ] S24EventMonitor C:\Programme\Intel\Wireless\Bin\S24EvMon.exe 10:55:10.0703 0620 S24EventMonitor ( UnsignedFile.Multi.Generic ) - warning 10:55:10.0703 0620 S24EventMonitor - detected UnsignedFile.Multi.Generic (1) 10:55:10.0718 0620 [ 078EBA5670FDAA041552CD86B984F2DE ] s24trans C:\WINDOWS\system32\DRIVERS\s24trans.sys 10:55:10.0750 0620 s24trans ( UnsignedFile.Multi.Generic ) - warning 10:55:10.0750 0620 s24trans - detected UnsignedFile.Multi.Generic (1) 10:55:10.0750 0620 [ 183805EB05BCA5A1E4AAAED4D2BE3690 ] SamSs C:\WINDOWS\system32\lsass.exe 10:55:10.0875 0620 SamSs - ok 10:55:10.0921 0620 [ B4CF7B42DE6CFA6FDE7D6AF4DAA55F57 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 10:55:11.0093 0620 SCardSvr - ok 10:55:11.0140 0620 [ D5E73842F38E24457C63FEF8CEFFBE19 ] Schedule C:\WINDOWS\system32\schedsvc.dll 10:55:11.0312 0620 Schedule - ok 10:55:11.0343 0620 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:55:11.0812 0620 Secdrv - ok 10:55:11.0859 0620 [ FED544B43903FB801B106F062110358A ] seclogon C:\WINDOWS\System32\seclogon.dll 10:55:12.0015 0620 seclogon - ok 10:55:12.0031 0620 [ AB74D986C1DD0D0C95B6AD37EC1E9F4F ] SENS C:\WINDOWS\system32\sens.dll 10:55:12.0203 0620 SENS - ok 10:55:12.0218 0620 [ CD5B9995AFCDB466C9EFC048D167E3BE ] Serial C:\WINDOWS\system32\drivers\Serial.sys 10:55:12.0421 0620 Serial - ok 10:55:12.0453 0620 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 10:55:12.0578 0620 Sfloppy - ok 10:55:12.0625 0620 [ 9245420422E409A25C1410ACB4244060 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 10:55:12.0843 0620 SharedAccess - ok 10:55:12.0859 0620 [ 521A4CB71CC419FDF60DB83E7308AE2B ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 10:55:13.0250 0620 ShellHWDetection - ok 10:55:13.0281 0620 [ B8E1AC2CDAD522572BFC73781D0E37E2 ] shpf C:\WINDOWS\system32\DRIVERS\shpf.sys 10:55:13.0343 0620 shpf ( UnsignedFile.Multi.Generic ) - warning 10:55:13.0343 0620 shpf - detected UnsignedFile.Multi.Generic (1) 10:55:13.0343 0620 Simbad - ok 10:55:13.0390 0620 [ 5CAEED86821FA2C6139E32E9E05CCDC9 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 10:55:13.0531 0620 SLIP - ok 10:55:13.0671 0620 [ F3CC67EBBD33EC8D87BE51169B5ADD6D ] SmcService C:\Programme\Sygate\SPF\smc.exe 10:55:13.0843 0620 SmcService - ok 10:55:13.0859 0620 [ BE6038E0A7D2E2FE69107E41A0265831 ] SNC C:\WINDOWS\system32\Drivers\SonyNC.sys 10:55:13.0937 0620 SNC - ok 10:55:13.0968 0620 [ FB77021110EAA16EA6E0961C844EF0D2 ] SonyImgF C:\WINDOWS\system32\DRIVERS\SonyImgF.sys 10:55:14.0031 0620 SonyImgF ( UnsignedFile.Multi.Generic ) - warning 10:55:14.0031 0620 SonyImgF - detected UnsignedFile.Multi.Generic (1) 10:55:14.0062 0620 [ A1ECEEAA5C5E74B2499EB51D38185B84 ] SONYPVU1 C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 10:55:14.0250 0620 SONYPVU1 - ok 10:55:14.0250 0620 Sparrow - ok 10:55:14.0296 0620 [ AD9436C46C10222B8F03405628A8CD86 ] SPI C:\WINDOWS\system32\DRIVERS\SonyPI.sys 10:55:14.0375 0620 SPI - ok 10:55:14.0375 0620 [ 0CE218578FFF5F4F7E4201539C45C78F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 10:55:14.0828 0620 splitter - ok 10:55:14.0859 0620 [ DA81EC57ACD4CDC3D4C51CF3D409AF9F ] Spooler C:\WINDOWS\system32\spoolsv.exe 10:55:15.0328 0620 Spooler - ok 10:55:15.0328 0620 SPTISRV - ok 10:55:15.0359 0620 [ E4200CB2F418D8FC4ACDD7E38C419D6A ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 10:55:15.0468 0620 sr - ok 10:55:15.0500 0620 [ E150E7618328562598F4CE0B5851B5CD ] srservice C:\WINDOWS\system32\srsvc.dll 10:55:15.0953 0620 srservice - ok 10:55:16.0000 0620 [ EA554A3FFC3F536FE8320EB38F5E4843 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 10:55:16.0468 0620 Srv - ok 10:55:16.0484 0620 [ 6FA03B462B2FFFE2627171B7FE73EE29 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 10:55:16.0609 0620 SSDPSRV - ok 10:55:16.0640 0620 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 10:55:16.0671 0620 ssmdrv - ok 10:55:16.0718 0620 [ F05B8D10BD6AD4CBB561E29D5BE2C674 ] SSScsiSV C:\Programme\Gemeinsame Dateien\Sony Shared\Avlib\SSScsiSV.exe 10:55:16.0781 0620 SSScsiSV ( UnsignedFile.Multi.Generic ) - warning 10:55:16.0781 0620 SSScsiSV - detected UnsignedFile.Multi.Generic (1) 10:55:16.0859 0620 [ BBBC5BF9A5F1FB5D57E91B944D2E51A5 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys 10:55:16.0984 0620 STHDA - ok 10:55:17.0031 0620 [ 25E9B30AF1FA1B9AF1853577F39FF20B ] stisvc C:\WINDOWS\system32\wiaservc.dll 10:55:17.0515 0620 stisvc - ok 10:55:17.0531 0620 [ 284C57DF5DC7ABCA656BC2B96A667AFB ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 10:55:17.0687 0620 streamip - ok 10:55:17.0718 0620 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 10:55:17.0875 0620 swenum - ok 10:55:17.0906 0620 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 10:55:18.0062 0620 swmidi - ok 10:55:18.0062 0620 SwPrv - ok 10:55:18.0062 0620 symc810 - ok 10:55:18.0078 0620 symc8xx - ok 10:55:18.0078 0620 sym_hi - ok 10:55:18.0078 0620 sym_u3 - ok 10:55:18.0109 0620 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 10:55:18.0265 0620 sysaudio - ok 10:55:18.0281 0620 [ 6D0C43DF9D3A7C5A9B4F94772CBD5DDC ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 10:55:18.0453 0620 SysmonLog - ok 10:55:18.0484 0620 [ 427D7EB3B453347082C8F4B370065D60 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 10:55:18.0953 0620 TapiSrv - ok 10:55:19.0015 0620 [ 64798ECFA43D78C7178375FCDD16D8C8 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:55:19.0500 0620 Tcpip - ok 10:55:19.0531 0620 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 10:55:19.0703 0620 TDPIPE - ok 10:55:19.0718 0620 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 10:55:19.0875 0620 TDTCP - ok 10:55:19.0906 0620 [ 64E59FCF5F81F55442E8476CE8E54CA0 ] Teefer C:\WINDOWS\system32\Drivers\Teefer.sys 10:55:19.0953 0620 Teefer ( UnsignedFile.Multi.Generic ) - warning 10:55:19.0953 0620 Teefer - detected UnsignedFile.Multi.Generic (1) 10:55:20.0000 0620 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 10:55:20.0234 0620 TermDD - ok 10:55:20.0265 0620 [ 1850BC10DE5DCCCEDE063FC2D0F2CEDA ] TermService C:\WINDOWS\System32\termsrv.dll 10:55:20.0468 0620 TermService - ok 10:55:20.0500 0620 [ 521A4CB71CC419FDF60DB83E7308AE2B ] Themes C:\WINDOWS\System32\shsvcs.dll 10:55:20.0921 0620 Themes - ok 10:55:20.0953 0620 [ 26587CE8E6C6F16B8B4E7E2C16FA00BF ] ti21sony C:\WINDOWS\system32\drivers\ti21sony.sys 10:55:21.0031 0620 ti21sony - ok 10:55:21.0031 0620 TosIde - ok 10:55:21.0062 0620 [ A34E894201D66E380E1FA96FE11B587E ] TrkWks C:\WINDOWS\system32\trkwks.dll 10:55:21.0234 0620 TrkWks - ok 10:55:21.0265 0620 [ 77D14696D77D2A6F04A466DDD49026BE ] TuneUp.Defrag C:\WINDOWS\System32\TuneUpDefragService.exe 10:55:21.0328 0620 TuneUp.Defrag - ok 10:55:21.0375 0620 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 10:55:21.0546 0620 Udfs - ok 10:55:21.0546 0620 ultra - ok 10:55:21.0578 0620 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe 10:55:21.0656 0620 UMWdf - ok 10:55:21.0703 0620 [ CED744117E91BDC0BEB810F7D8608183 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 10:55:22.0203 0620 Update - ok 10:55:22.0234 0620 [ 855790C1BACED245A6B210AF430ED17B ] upnphost C:\WINDOWS\System32\upnphost.dll 10:55:22.0703 0620 upnphost - ok 10:55:22.0718 0620 [ A99F867E76CFDAA28EE305B93F70E84F ] UPS C:\WINDOWS\System32\ups.exe 10:55:22.0890 0620 UPS - ok 10:55:22.0921 0620 [ 1DF89C499BF45D878B87EBD4421D462D ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys 10:55:22.0953 0620 USBAAPL ( UnsignedFile.Multi.Generic ) - warning 10:55:22.0953 0620 USBAAPL - detected UnsignedFile.Multi.Generic (1) 10:55:22.0984 0620 [ 45A0D14B26C35497AD93BCE7E15C9941 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 10:55:23.0156 0620 usbaudio - ok 10:55:23.0187 0620 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 10:55:23.0328 0620 usbccgp - ok 10:55:23.0375 0620 [ 15E993BA2F6946B2BFBBFCD30398621E ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:55:23.0531 0620 usbehci - ok 10:55:23.0562 0620 [ C72F40947F92CEA56A8FB532EDF025F1 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:55:23.0734 0620 usbhub - ok 10:55:23.0750 0620 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 10:55:23.0937 0620 usbprint - ok 10:55:23.0968 0620 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 10:55:24.0140 0620 usbscan - ok 10:55:24.0171 0620 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:55:24.0328 0620 USBSTOR - ok 10:55:24.0359 0620 [ F8FD1400092E23C8F2F31406EF06167B ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 10:55:24.0531 0620 usbuhci - ok 10:55:24.0562 0620 [ 838C97B3D28BFEBDD11D12ADFE957004 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll 10:55:24.0609 0620 UxTuneUp - ok 10:55:24.0656 0620 [ FB1A8F8CBD361FC1F0D144D5018C97F3 ] VAIO Entertainment TV Device Arbitration Service C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe 10:55:24.0703 0620 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - warning 10:55:24.0703 0620 VAIO Entertainment TV Device Arbitration Service - detected UnsignedFile.Multi.Generic (1) 10:55:24.0765 0620 [ 2B0EAC2B6E5F1C5E007DABAE101028B0 ] VAIO Event Service C:\Programme\Sony\VAIO Event Service\VESMgr.exe 10:55:24.0812 0620 VAIO Event Service ( UnsignedFile.Multi.Generic ) - warning 10:55:24.0812 0620 VAIO Event Service - detected UnsignedFile.Multi.Generic (1) 10:55:24.0937 0620 [ 8A851EE335A459440B69A44C1CD50BDB ] VAIOMediaPlatform-IntegratedServer-AppServer C:\Programme\Sony\VAIO Media Integrated Server\VMISrv.exe 10:55:25.0203 0620 VAIOMediaPlatform-IntegratedServer-AppServer ( UnsignedFile.Multi.Generic ) - warning 10:55:25.0203 0620 VAIOMediaPlatform-IntegratedServer-AppServer - detected UnsignedFile.Multi.Generic (1) 10:55:25.0265 0620 [ B74A27540B0B7FE393A882B94B0D2188 ] VAIOMediaPlatform-IntegratedServer-HTTP C:\Programme\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe 10:55:25.0312 0620 VAIOMediaPlatform-IntegratedServer-HTTP ( UnsignedFile.Multi.Generic ) - warning 10:55:25.0312 0620 VAIOMediaPlatform-IntegratedServer-HTTP - detected UnsignedFile.Multi.Generic (1) 10:55:25.0343 0620 [ 4914B65DCCF68CB95C2D1303C7264C8C ] VAIOMediaPlatform-IntegratedServer-UPnP C:\Programme\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe 10:55:25.0546 0620 VAIOMediaPlatform-IntegratedServer-UPnP ( UnsignedFile.Multi.Generic ) - warning 10:55:25.0546 0620 VAIOMediaPlatform-IntegratedServer-UPnP - detected UnsignedFile.Multi.Generic (1) 10:55:25.0562 0620 [ C5AFCD27DFE4D1501406B9AD40F85750 ] VAIOMediaPlatform-Mobile-Gateway C:\Programme\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe 10:55:25.0656 0620 VAIOMediaPlatform-Mobile-Gateway ( UnsignedFile.Multi.Generic ) - warning 10:55:25.0656 0620 VAIOMediaPlatform-Mobile-Gateway - detected UnsignedFile.Multi.Generic (1) 10:55:25.0718 0620 [ 55A47A048E5FD13977CA47DF39CBA5FF ] VCI C:\Programme\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe 10:55:25.0843 0620 VCI ( UnsignedFile.Multi.Generic ) - warning 10:55:25.0843 0620 VCI - detected UnsignedFile.Multi.Generic (1) 10:55:25.0843 0620 Vcsw - ok 10:55:25.0859 0620 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 10:55:26.0109 0620 VgaSave - ok 10:55:26.0109 0620 ViaIde - ok 10:55:26.0156 0620 [ D6888520FF56D72A50437E371CA25FC9 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 10:55:26.0296 0620 VolSnap - ok 10:55:26.0343 0620 [ 6635ECBF0D8090DC3A452D0D072B5D5B ] VSS C:\WINDOWS\System32\vssvc.exe 10:55:26.0468 0620 VSS - ok 10:55:26.0515 0620 [ AF9EBC7CF22A18E2369346067F555953 ] VzCdbSvc C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 10:55:26.0578 0620 VzCdbSvc ( UnsignedFile.Multi.Generic ) - warning 10:55:26.0578 0620 VzCdbSvc - detected UnsignedFile.Multi.Generic (1) 10:55:26.0609 0620 [ 37D04941A5B52027EE32D2685F0F72BA ] VzFw C:\Programme\Gemeinsame Dateien\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe 10:55:26.0656 0620 VzFw ( UnsignedFile.Multi.Generic ) - warning 10:55:26.0656 0620 VzFw - detected UnsignedFile.Multi.Generic (1) 10:55:26.0703 0620 [ C6D874CD2A5B83CD11CDEBD28A638584 ] W32Time C:\WINDOWS\system32\w32time.dll 10:55:26.0875 0620 W32Time - ok 10:55:26.0953 0620 [ 4E7B07653F4F9937CF62AD2869FBA520 ] w39n51 C:\WINDOWS\system32\DRIVERS\w39n51.sys 10:55:27.0171 0620 w39n51 - ok 10:55:27.0218 0620 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:55:27.0406 0620 Wanarp - ok 10:55:27.0421 0620 WDICA - ok 10:55:27.0437 0620 [ EFD235CA22B57C81118C1AEB4798F1C1 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 10:55:27.0953 0620 wdmaud - ok 10:55:27.0984 0620 [ 879ECB9A5F14A03960B84EDB7207A051 ] WebClient C:\WINDOWS\System32\webclnt.dll 10:55:28.0468 0620 WebClient - ok 10:55:28.0484 0620 [ 8E95E30E9031C3AC25EC2455DA19831F ] wg3n C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys 10:55:28.0531 0620 wg3n ( UnsignedFile.Multi.Generic ) - warning 10:55:28.0531 0620 wg3n - detected UnsignedFile.Multi.Generic (1) 10:55:28.0578 0620 [ C1D5CBD8AA0D674DA1BA1BB189696396 ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 10:55:28.0734 0620 winachsf - ok 10:55:28.0796 0620 [ DA2DADB42916E59C6E4BBA593BCCDA73 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 10:55:28.0937 0620 winmgmt - ok 10:55:29.0000 0620 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 10:55:29.0062 0620 WmdmPmSN - ok 10:55:29.0078 0620 [ 042A78FCD1ADFB0FBA9865D55C6F5CC1 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 10:55:29.0281 0620 WmiApSrv - ok 10:55:29.0312 0620 [ 1385E5AA9C9821790D33A9563B8D2DD0 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys 10:55:29.0375 0620 WpdUsb - ok 10:55:29.0375 0620 [ F62A090F00C5B4E597E8AA4B1048CE05 ] wpsdrvnt C:\WINDOWS\system32\drivers\wpsdrvnt.sys 10:55:29.0421 0620 wpsdrvnt ( UnsignedFile.Multi.Generic ) - warning 10:55:29.0421 0620 wpsdrvnt - detected UnsignedFile.Multi.Generic (1) 10:55:29.0453 0620 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys 10:55:29.0609 0620 WS2IFSL - ok 10:55:29.0625 0620 [ BD3561AAE748150CF51C2CA876449EA7 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 10:55:29.0812 0620 wscsvc - ok 10:55:29.0843 0620 [ D5842484F05E12121C511AA93F6439EC ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 10:55:30.0015 0620 WSTCODEC - ok 10:55:30.0046 0620 [ 1EDDD5C0ECF3FA6EDFD8A25B2B4E7DF6 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 10:55:30.0218 0620 wuauserv - ok 10:55:30.0250 0620 [ EB52B74A5DAADC2CCA68B3E7D81007E6 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 10:55:30.0718 0620 WZCSVC - ok 10:55:30.0734 0620 [ 8302DE1C64618D72346DD0034DBC5D9B ] xmlprov C:\WINDOWS\System32\xmlprov.dll 10:55:30.0921 0620 xmlprov - ok 10:55:30.0984 0620 [ 96982CB3611BD4DB9ED7A5FF2C29219F ] yukonwxp C:\WINDOWS\system32\DRIVERS\yk51x86.sys 10:55:31.0046 0620 yukonwxp - ok 10:55:31.0046 0620 ================ Scan global =============================== 10:55:31.0078 0620 [ 1B91BAC6996731EE8925F58205DCB016 ] C:\WINDOWS\system32\basesrv.dll 10:55:31.0156 0620 [ 317DF8980138FB91AE03E95757F4D0E9 ] C:\WINDOWS\system32\winsrv.dll 10:55:31.0218 0620 [ 317DF8980138FB91AE03E95757F4D0E9 ] C:\WINDOWS\system32\winsrv.dll 10:55:31.0250 0620 [ EDB6B81761BD60F32F740BBC40AFB676 ] C:\WINDOWS\system32\services.exe 10:55:31.0250 0620 [Global] - ok 10:55:31.0250 0620 ================ Scan MBR ================================== 10:55:31.0265 0620 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 10:55:31.0578 0620 \Device\Harddisk0\DR0 - ok 10:55:31.0578 0620 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk3\DR12 10:55:35.0781 0620 \Device\Harddisk3\DR12 - ok 10:55:35.0781 0620 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk4\DR13 10:55:36.0218 0620 \Device\Harddisk4\DR13 - ok 10:55:36.0218 0620 ================ Scan VBR ================================== 10:55:36.0218 0620 [ 85C47202E47E294D253FC3A15B956822 ] \Device\Harddisk0\DR0\Partition1 10:55:36.0218 0620 \Device\Harddisk0\DR0\Partition1 - ok 10:55:36.0234 0620 [ 635B51F0357B5FD29E87C1E21F67F593 ] \Device\Harddisk0\DR0\Partition2 10:55:36.0234 0620 \Device\Harddisk0\DR0\Partition2 - ok 10:55:36.0234 0620 [ D25E3C7510E8F359BC38E8CF9748D10A ] \Device\Harddisk3\DR12\Partition1 10:55:36.0234 0620 \Device\Harddisk3\DR12\Partition1 - ok 10:55:36.0250 0620 [ 7D8775ABE083072FDA96AA83FEC0EE02 ] \Device\Harddisk4\DR13\Partition1 10:55:36.0250 0620 \Device\Harddisk4\DR13\Partition1 - ok 10:55:36.0250 0620 ============================================================ 10:55:36.0250 0620 Scan finished 10:55:36.0250 0620 ============================================================ 10:55:36.0359 2420 Detected object count: 24 10:55:36.0359 2420 Actual detected object count: 24 10:55:54.0890 2420 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 ASPI ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 ASPI ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 EvtEng ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 Image Converter video recording monitor for VAIO Entertainment ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 Image Converter video recording monitor for VAIO Entertainment ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 S24EventMonitor ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 S24EventMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 s24trans ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 s24trans ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 shpf ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 shpf ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 SonyImgF ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 SonyImgF ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 SSScsiSV ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 SSScsiSV ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 Teefer ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 Teefer ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 USBAAPL ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIO Entertainment TV Device Arbitration Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIO Event Service ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIO Event Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-AppServer ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-AppServer ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-HTTP ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-HTTP ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-UPnP ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIOMediaPlatform-IntegratedServer-UPnP ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0890 2420 VAIOMediaPlatform-Mobile-Gateway ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0890 2420 VAIOMediaPlatform-Mobile-Gateway ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0906 2420 VCI ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0906 2420 VCI ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0906 2420 VzCdbSvc ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0906 2420 VzCdbSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0906 2420 VzFw ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0906 2420 VzFw ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0906 2420 wg3n ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0906 2420 wg3n ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:55:54.0906 2420 wpsdrvnt ( UnsignedFile.Multi.Generic ) - skipped by user 10:55:54.0906 2420 wpsdrvnt ( UnsignedFile.Multi.Generic ) - User select action: Skip |
25.09.2012, 12:37 | #6 | |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus nu wird noch nichts geupdatet, erst am ende Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!Downloade dir bitte Combofix von einem dieser Downloadspiegel Link 1 Link 2 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus |
25.09.2012, 13:15 | #7 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus HIer der logfile von Combofix: Combofix Logfile: Code:
ATTFilter ComboFix 12-09-24.03 - sabina 25.09.2012 14:02:55.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.49.1031.18.1022.287 [GMT 2:00] ausgeführt von:: c:\dokumente und einstellungen\sabina\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\IsUn0407.exe c:\windows\system32\rnaph.dll c:\windows\system32\URTTemp c:\windows\system32\URTTemp\fusion.dll c:\windows\system32\URTTemp\mscoree.dll c:\windows\system32\URTTemp\mscoree.dll.local c:\windows\system32\URTTemp\mscorsn.dll c:\windows\system32\URTTemp\mscorwks.dll c:\windows\system32\URTTemp\msvcr71.dll . . ((((((((((((((((((((((( Dateien erstellt von 2012-08-25 bis 2012-09-25 )))))))))))))))))))))))))))))) . . 2012-09-25 10:17 . 2012-09-25 10:17 -------- d-----w- c:\windows\LastGood 2012-09-11 14:57 . 2012-09-11 14:57 -------- d-----w- c:\dokumente und einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Sun 2012-09-10 12:07 . 2012-09-10 12:07 -------- d-----w- c:\dokumente und einstellungen\sabina\Anwendungsdaten\MSNInstaller . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-24 14:58 . 2012-06-01 21:33 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-24 14:58 . 2012-06-01 21:33 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2008-11-13 11:23 . 2008-11-13 11:23 269236 -c--a-w- c:\programme\DirSync_Setup.exe 2007-10-29 19:04 . 2007-10-29 18:58 112441538 -c--a-w- c:\programme\OOo_2.3.0_Win32Intel_install_de.exe 2012-09-06 01:26 . 2012-09-10 12:16 266720 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\dokumente und einstellungen\sabina\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\dokumente und einstellungen\sabina\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\dokumente und einstellungen\sabina\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\dokumente und einstellungen\sabina\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-08 68856] "TrayBackup"="c:\programme\TrayBackup\traybackup.exe" [2009-01-12 354304] "SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelWireless"="c:\programme\Intel\Wireless\Bin\ifrmewrk.exe" [2006-02-28 602182] "SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-02-24 2372760] "Apoint"="c:\programme\Apoint\Apoint.exe" [2004-11-17 118784] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-07 7557120] "avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-11-23 281768] "SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2012-01-17 252296] "APSDaemon"="c:\programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2012-04-18 421888] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] . c:\dokumente und einstellungen\sabina\Startmenü\Programme\Autostart\ Dropbox.lnk - c:\dokumente und einstellungen\sabina\Anwendungsdaten\Dropbox\bin\Dropbox.exe [2012-5-24 27112840] . c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\ Acrobat Assistant.lnk - c:\programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] McAfee Security Scan Plus.lnk - c:\programme\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2005-05-20 15:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Acrobat Assistant.lnk] path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Gamma Loader.lnk] path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk] path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Reader - Schnellstart.lnk backup=c:\windows\pss\Adobe Reader - Schnellstart.lnkCommon Startup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^ScanPanel.lnk] path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\ScanPanel.lnk backup=c:\windows\pss\ScanPanel.lnkCommon Startup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^Dropbox.lnk] path=c:\dokumente und einstellungen\sabina\Startmenü\Programme\Autostart\Dropbox.lnk backup=c:\windows\pss\Dropbox.lnkStartup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^OpenOffice.org 2.2.lnk] path=c:\dokumente und einstellungen\sabina\Startmenü\Programme\Autostart\OpenOffice.org 2.2.lnk backup=c:\windows\pss\OpenOffice.org 2.2.lnkStartup . [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^sabina^Startmenü^Programme^Autostart^OpenOffice.org 3.0.lnk] path=c:\dokumente und einstellungen\sabina\Startmenü\Programme\Autostart\OpenOffice.org 3.0.lnk backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] c:\windows\system32\dumprep 0 -k [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 2004-11-17 11:47 118784 ----a-w- c:\programme\Apoint\Apoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd] 2005-12-17 02:08 77824 ----a-w- c:\windows\system32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers] 2005-12-17 02:08 118784 ----a-w- c:\windows\system32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray] 2005-12-17 02:08 98304 ----a-w- c:\windows\system32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe] 2004-02-20 12:12 32768 -c--a-w- c:\programme\Sony\ISB Utility\ISBMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-03-07 13:33 421160 ----a-w- c:\programme\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon] 2002-03-14 14:46 45056 ----a-w- c:\windows\system32\ico.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2006-03-07 12:26 7557120 ----a-w- c:\windows\system32\nvcpl.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-04-18 18:56 421888 ----a-w- c:\programme\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2011-04-18 15:30 15146376 ----a-r- c:\programme\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonyPowerCfg] 2006-01-26 00:28 212992 ----a-w- c:\programme\Sony\VAIO Power Management\SPMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2007-08-08 08:46 68856 ----a-w- c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2] 2005-10-11 19:36 151552 ----a-w- c:\programme\Sony\VAIO Update 2\VAIOUpdt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "McComponentHostService"=3 (0x3) "helpsvc"=2 (0x2) "gusvc"=3 (0x3) "gupdatem"=3 (0x3) "gupdate1cae781c34ce778"=2 (0x2) "Bonjour Service"=2 (0x2) "aspnet_state"=3 (0x3) "Apple Mobile Device"=2 (0x2) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Programme\\Sony\\VAIO Media 5.0\\Vc.exe"= "c:\\Programme\\ClipMemAdvanced\\clipmem.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Programme\\Bonjour\\mDNSResponder.exe"= "c:\\Programme\\iTunes\\iTunes.exe"= "c:\\Dokumente und Einstellungen\\sabina\\Anwendungsdaten\\Dropbox\\bin\\Dropbox.exe"= "c:\\Programme\\Skype\\Phone\\Skype.exe"= "c:\\Programme\\Gemeinsame Dateien\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= . R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [31.03.2006 03:36 9216] R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [23.08.2009 22:35 136360] R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [31.03.2006 03:36 71961] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [31.03.2006 03:36 226304] S2 gupdate1cae781c34ce778;Google Update Service (gupdate1cae781c34ce778);c:\programme\Google\Update\GoogleUpdate.exe [29.04.2010 11:48 133104] S2 NetFxUpdate_v1.1.4322;Microsoft .NET Framework v1.1.4322 Update;c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe --> c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe [?] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [01.06.2012 22:19 250288] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [24.08.2007 20:55 16512] S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [29.04.2010 11:48 133104] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programme\McAfee Security Scan\3.0.207\McCHSvc.exe [17.06.2011 19:33 237008] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [10.09.2012 14:16 114144] S3 PDNMp50;PDNMp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNMp50.sys [28.11.2006 22:46 28224] S3 PDNSp50;PDNSp50 NDIS Protocol Driver;c:\windows\system32\drivers\PDNSp50.sys [28.11.2006 22:46 27072] S3 phil2vid;Philips VGA-Kamera (USB);c:\windows\system32\drivers\philcam2.sys [20.01.2008 23:43 173696] S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [31.03.2006 03:36 29184] . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 02712736 *Deregistered* - 02712736 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Inhalt des "geplante Tasks" Ordners . 2012-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 14:58] . 2012-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\programme\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57] . 2012-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\programme\Google\Update\GoogleUpdate.exe [2010-04-29 09:47] . 2012-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\programme\Google\Update\GoogleUpdate.exe [2010-04-29 09:47] . 2012-09-24 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job - c:\programme\Real\RealUpgrade\realupgrade.exe [2012-04-30 16:21] . 2012-09-12 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1914860865-1393117939-1139308094-1007.job - c:\programme\Real\RealUpgrade\realupgrade.exe [2012-04-30 16:21] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:blank uSearch Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Suche im Duden - c:\programme\Duden-Suche Toolbar\toolbar.dll/SEARCH.HTML IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 Trusted Zone: sony-europe.com Trusted Zone: sonystyle-europe.com Trusted Zone: vaio-link.com TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\dokumente und einstellungen\sabina\Anwendungsdaten\Mozilla\Firefox\Profiles\2oojj84h.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.startup.homepage - paeng-coaching.de FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings FF - user.js: extensions.Softonic.autoRvrt - false FF - user.js: extensions.Softonic_i.newTab - false FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1&cc=&q= FF - user.js: extensions.Softonic.id - 54a58ef000000000000000130255d148 FF - user.js: extensions.Softonic.instlDay - 15492 FF - user.js: extensions.Softonic.vrsn - 1.5.24.3 FF - user.js: extensions.Softonic.vrsni - 1.5.24.3 FF - user.js: extensions.Softonic_i.vrsnTs - 1.5.24.322:45 FF - user.js: extensions.Softonic.prtnrId - softonic FF - user.js: extensions.Softonic.prdct - Softonic FF - user.js: extensions.Softonic.aflt - SD FF - user.js: extensions.Softonic_i.smplGrp - none FF - user.js: extensions.Softonic.tlbrId - base FF - user.js: extensions.Softonic.instlRef - MON00015 FF - user.js: extensions.Softonic.dfltLng - de FF - user.js: extensions.Softonic.excTlbr - false FF - user.js: extensions.Softonic.admin - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-MSMSGS - c:\programme\Messenger\msmsgs.exe AddRemove-Adobe InDesign 2.0 - c:\windows\ISUN0407.EXE AddRemove-Adobe Photoshop 7.0 - c:\windows\ISUN0407.EXE AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\dokumente und einstellungen\All Users\Anwendungsdaten\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-09-25 14:08 Windows 5.1.2600 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1914860865-1393117939-1139308094-1007\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'winlogon.exe'(864) c:\windows\system32\VESWinlogon.dll . Zeit der Fertigstellung: 2012-09-25 14:11:09 ComboFix-quarantined-files.txt 2012-09-25 12:11 . Vor Suchlauf: 12 Verzeichnis(se), 11.577.012.224 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 13.523.898.368 Bytes frei . WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut . - - End Of File - - 36E5FB9727041B47CB50A7C100F110EB |
26.09.2012, 18:10 | #8 |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus hi malwarebytes: Downloade Dir bitte Malwarebytes
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
28.09.2012, 20:45 | #9 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus Malwarebytes Anti-Malware (Test) 1.65.0.1400 Malwarebytes : Free Anti-Malware download Datenbank Version: v2012.09.27.02 Windows XP Service Pack 2 x86 NTFS Internet Explorer 6.0.2900.2180 sabina :: PILATUS [Administrator] Schutz: Aktiviert 28.09.2012 12:55:43 mbam-log-2012-09-28 (12-55-43).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 303426 Laufzeit: 1 Stunde(n), 11 Minute(n), 9 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Programme\Sony\VAIO Cooperated Initialisation\Automatic.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Programme\Sony\VAIO Cooperated Initialisation\Manual.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Programme\Sony\VAIO Cooperated Initialisation\UnInstall.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Was meinsst Du? Alles bereinigt? Irgendwie läuft Firefox immer noch nicht rund... |
29.09.2012, 18:56 | #10 |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus wie läuft das gerät jetzt?
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
01.10.2012, 11:00 | #11 |
| TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus Tja, wie gesagt...vielleicht ein bissl besser... Ein Pop UP geht noch immer auf. Einfach so. Auf diversen Seiten. Es ist blau..heißt wizard...oder so ähnlich. Die Filter bei ADblock plus helfen nicht. Schiebt sich wie eine "Leiste" immer wieder ins Bild. Wie interpretierst Du den Logfile? Alles sauber? DANKE DIR auf jeden FAll schon mal für die großartige Hilfe! Bekomme beim Start jetzt immer diese Meldung von Sygate Firewall: Die EXE-Datei wurde seit der letzten Verwendung von C:\WINDOWS\system32\ntoskrnl.exe geändert. Dateiversion : 5.1.2600.3670 (xpsp_sp2_qfe.100216-2016) Dateibeschreibung : NT-Kernel und -System Dateipfad : C:\WINDOWS\system32\ntoskrnl.exe Prozess-ID : 4 (Heximal) 4 (Dezimal) Verbindungsursprung : lokal initiert Protokoll : UDP Lokale Adresse : 192.168.178.35 Lokaler Port : 137 Remote-Name : Remote-Adresse : 192.168.178.255 Remote-Port : 137 (NETBIOS-NS - Browsing requests of NetBIOS over TCP/IP) Ethernet-Paket-Details: Ethernet II (Packet Length: 124) Destination: ff-ff-ff-ff-ff-ff Source: 00-13-02-55-d1-48 Type: IP (0x0800) Internet Protocol Version: 4 Header Length: 20 bytes Flags: .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset:0 Time to live: 128 Protocol: 0x11 (UDP - User Datagram Protocol) Header checksum: 0xb54 (Correct) Source: 192.168.178.35 Destination: 192.168.178.255 User Datagram Protocol Source port: 137 Destination port: 137 Length: 8 Checksum: 0x62c6 (Correct) Data (76 Bytes) Binäres Abbild des Pakets: 0000: FF FF FF FF FF FF 00 13 : 02 55 D1 48 08 00 45 00 | .........U.H..E. 0010: 00 60 00 0E 00 00 80 11 : 54 0B C0 A8 B2 23 C0 A8 | .`......T....#.. 0020: B2 FF 00 89 00 89 00 4C : C6 62 80 01 29 10 00 01 | .......L.b..)... 0030: 00 00 00 00 00 01 20 45 : 42 46 43 45 43 45 46 45 | ...... EBFCECEFE 0040: 4A 46 45 46 44 45 48 46 : 43 46 46 46 41 46 41 45 | JFEFDEHFCFFFAFAE 0050: 46 43 41 43 41 41 41 00 : 00 20 00 01 C0 0C 00 20 | FCACAAA.. ..... 0060: 00 01 00 04 93 E0 00 06 : 80 00 C0 A8 B2 23 00 00 | .............#.. 0070: 00 00 00 00 00 00 00 00 : 00 00 00 00 | ............ Firefox hakt die ganze Zeit...braucht ewig zum Öffnen neuer Seiten. MAcht selbstständig Taps zu, etc. NOch IDeen? |
03.10.2012, 17:53 | #12 |
/// Malware-holic | TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus dann machen wir neu. firewalls brauchst du übrigens nicht extra, die windows eigene reicht. 1. Datenrettung:
ich werde außerdem noch weitere punkte dazu posten. 4. alle Passwörter ändern! 5. nach PC Absicherung, die gesicherten Daten prüfen und falls sauber: zurückspielen. 6. werde ich dann noch was zum absichern von Onlinebanking mit Chip Card Reader + Star Money sagen.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus |
adblock, antivir, antivir guard, avira, bho, converter, desktop, excel, firefox, flash player, google, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, mozilla, plug-in, registry, security, server, software, system, trojaner, trojaner?, viren, windows, windows xp |