![]() |
Plagegeister aller Art und deren Bekämpfung: TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Hallo zusammen, ich mir wohl u.a. durch Anschluss einer externen HDD mit älteren Daten ein paar Plagegeister eingefangen. Da waren wohl in einigen "Jugendsünden" noch ein paar Überraschungen versteckt. MBAM OLT und ESET habe ich durchlaufen lassen, anbei die Logs. Ich habe eine Hand voll Pfade aus den Logs aus privaten Gründen gekürzt, falls diese benötigt werden reiche ich sie nach oder füge sie selbst in das Script ein. Vielen Dank für eure Hilfe! Patrick MBAM Durchlauf 1: Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2012.11.13.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 egal :: EGAL-PC [Administrator] 13.11.2012 19:56:47 mbam-log-2012-11-13 (19-56-47).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 375594 Laufzeit: 44 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) MBAM Durchlauf 2: Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2012.11.13.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 egal :: EGAL-PC [Administrator] 13.11.2012 19:56:47 mbam-log-2012-11-14 (00-03-39).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 375594 Laufzeit: 44 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Keine Aktion durchgeführt. C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Keine Aktion durchgeführt. (Ende) OLT: OTL logfile created on: 18.11.2012 15:11:17 - Run 2 OTL by OldTimer - Version Folder = C:\Users\egal\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,85 Gb Total Physical Memory | 0,95 Gb Available Physical Memory | 33,24% Memory free 5,71 Gb Paging File | 2,84 Gb Available in Paging File | 49,81% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 368,10 Gb Total Space | 298,23 Gb Free Space | 81,02% Space Free | Partition Type: NTFS Drive D: | 97,66 Gb Total Space | 96,20 Gb Free Space | 98,51% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: EGAL-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days ========== Processes (SafeList) ========== PRC - [2012.11.13 15:16:47 | 000,384,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.10.12 19:54:49 | 000,692,152 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe PRC - [2012.10.08 09:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe PRC - [2012.10.03 12:40:30 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\egal\Desktop\OTL.exe PRC - [2012.09.19 18:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2012.07.09 19:51:26 | 001,672,008 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyserver.exe PRC - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe PRC - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe PRC - [2012.07.09 19:50:56 | 000,594,760 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkytray.exe PRC - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe PRC - [2011.06.24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 22:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe ========== Modules (No Company Name) ========== MOD - [2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll ========== Services (SafeList) ========== SRV - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.10.14 18:35:23 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.10.12 19:54:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe -- (TwonkyProxy) SRV - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe -- (TwonkyWebDav) SRV - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe -- (TwonkyServer) SRV - [2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IntelCpHeciSvc.exe -- (cphs) SRV - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt) DRV - [2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.11.20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc) DRV - [2010.11.20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD) DRV - [2010.11.20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.10.19 22:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI) DRV - [2008.12.19 05:15:52 | 000,246,808 | ---- | M] (silex technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sxuptp.sys -- (sxuptp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 78 11 9F 0F B9 B9 CD 01 [binary data] IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EB DF 65 A1 12 C4 CD 01 [binary data] IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 14:05:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M] [2012.09.26 15:22:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2012.10.14 18:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.10.03 14:05:04 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT [2012.10.14 18:35:23 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.08.14 16:49:30 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004..\Run: [ICQ] C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.) O4 - Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D64C20E-EA5D-4AEE-88CD-9A5819240691}: DhcpNameServer = O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 360 Days ========== [2012.11.16 03:00:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012.11.16 03:00:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012.11.16 03:00:45 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012.11.16 03:00:44 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012.11.16 03:00:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012.11.16 03:00:44 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012.11.16 03:00:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012.11.16 03:00:43 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012.11.15 03:52:10 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll [2012.11.15 03:52:09 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2012.11.13 19:55:39 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.10.26 18:49:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Avira [2012.10.19 20:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.10.19 20:11:19 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.10.19 20:11:18 | 000,133,824 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2012.10.19 20:11:18 | 000,083,432 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2012.10.19 20:11:18 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.10.19 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\Handy [2012.10.17 19:09:02 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TeamViewer [2012.10.15 19:00:17 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2012.10.14 19:37:21 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\QuickPar [2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\UseNeXT [2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\UseNeXT [2012.10.14 18:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.10.10 16:46:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2012.10.10 16:45:55 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2012.10.10 16:45:55 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2012.10.07 19:19:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TwonkyMedia [2012.10.07 08:04:14 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\vlc [2012.10.06 14:24:07 | 000,000,000 | ---D | C] -- C:\ProgramData\twonkyclient [2012.10.03 19:28:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer [2012.10.03 19:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\Tracker Software [2012.10.03 18:52:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Philips [2012.10.03 18:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\Philips [2012.10.03 18:50:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET [2012.10.03 18:49:38 | 000,000,000 | ---D | C] -- C:\ProgramData\TwonkyServer [2012.10.03 18:49:32 | 000,000,000 | ---D | C] -- C:\Program Files\Twonky [2012.10.03 13:51:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes [2012.10.03 13:49:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\GVU Logs [2012.10.03 12:46:18 | 000,000,000 | ---D | C] -- C:\_OTL [2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.10.03 10:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.09.26 17:34:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7M [2012.09.26 17:34:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\ICQ [2012.09.26 17:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7M [2012.09.26 15:23:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Macromedia [2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Mozilla [2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Mozilla [2012.09.24 21:24:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\ [2012.09.24 18:21:00 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Steganos [2012.09.24 18:15:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Adobe [2012.09.24 18:12:38 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TrueCrypt [2012.09.24 18:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt [2012.09.24 18:12:17 | 000,231,760 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys [2012.09.24 18:12:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt [2012.09.24 16:01:33 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Macromedia [2012.09.22 22:39:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited [2012.09.22 22:28:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited [2012.09.22 22:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP [2012.09.22 22:22:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner [2012.09.22 22:22:33 | 000,000,000 | ---D | C] -- C:\Program Files\Astonsoft [2012.09.22 22:03:53 | 000,000,000 | ---D | C] -- C:\Avis [2012.09.22 22:02:42 | 000,360,448 | ---- | C] (FLV.com) -- C:\Windows\System32\TubeFinder.exe [2012.09.22 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLV Converter [2012.09.22 22:02:41 | 001,081,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomctl.ocx [2012.09.22 22:02:41 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX [2012.09.22 22:02:41 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCFR.DLL [2012.09.22 22:02:41 | 000,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6FR.DLL [2012.09.22 22:02:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6STKIT.DLL [2012.09.22 22:02:41 | 000,084,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PICCLP32.OCX [2012.09.22 22:02:41 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGFR.DLL [2012.09.22 22:02:41 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PCCLPFR.DLL [2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\FreeFLVConverter [2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Free FLV Converter [2012.09.14 18:11:02 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys [2012.09.14 18:11:02 | 000,187,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar [2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar [2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Program Files\QuickPar [2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT [2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\Program Files\UseNeXT [2012.08.30 22:06:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Adobe [2012.08.30 22:05:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared [2012.08.30 22:05:31 | 000,198,864 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll [2012.08.30 22:05:28 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll [2012.08.30 22:05:28 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll [2012.08.30 22:05:27 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll [2012.08.30 22:05:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks [2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Real [2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\Program Files\Real [2012.08.30 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Real [2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Virtual Link [2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\Program Files\silex technology [2012.08.30 21:01:05 | 000,246,808 | ---- | C] (silex technology, Inc.) -- C:\Windows\System32\drivers\sxuptp.sys [2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\Searches [2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2012.08.26 18:50:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Identities [2012.08.26 18:50:24 | 000,000,000 | R--D | C] -- C:\Users\Admin\Contacts [2012.08.26 18:50:22 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\VirtualStore [2012.08.26 18:47:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics [2012.08.26 17:48:42 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys [2012.08.26 17:48:42 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys [2012.08.26 17:48:40 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys [2012.08.26 17:48:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe [2012.08.26 17:46:32 | 000,000,000 | --SD | C] -- C:\Users\Admin\AppData\Roaming\Microsoft [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Videos [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Saved Games [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Pictures [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Music [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Links [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Favorites [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Downloads [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Documents [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Desktop [2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Vorlagen [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Verlauf [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Temporary Internet Files [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Startmenü [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\SendTo [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Recent [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Netzwerkumgebung [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Lokale Einstellungen [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Videos [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Musik [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Eigene Dateien [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Bilder [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Druckumgebung [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Cookies [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Anwendungsdaten [2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Anwendungsdaten [2012.08.26 17:46:32 | 000,000,000 | -H-D | C] -- C:\Users\Admin\AppData [2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Temp [2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Microsoft [2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Media Center Programs [2012.08.26 17:36:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.08.26 17:36:14 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe [2012.08.26 17:36:11 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2012.08.26 17:36:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012.08.26 17:35:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Passwort-Manager Free [2012.08.26 17:35:25 | 000,000,000 | ---D | C] -- C:\Program Files\Steganos Password Manager Free 11 [2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Program Files\Intel [2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Intel [2012.08.26 17:30:29 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2012.08.26 17:30:28 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2012.08.26 17:30:28 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2012.08.26 17:30:28 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2012.08.26 17:30:28 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2012.08.26 17:30:28 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2012.08.26 17:30:28 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2012.08.26 17:30:28 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2012.08.26 17:30:28 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2012.08.26 17:30:28 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2012.08.26 17:30:28 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2012.08.26 17:30:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2012.08.26 17:30:28 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2012.08.26 17:30:28 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2012.08.26 17:30:28 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2012.08.26 17:30:28 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2012.08.26 17:30:28 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2012.08.26 17:30:28 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2012.08.26 17:30:28 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2012.08.26 17:30:28 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2012.08.26 17:30:28 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2012.08.26 17:30:28 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2012.08.26 17:30:28 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2012.08.26 17:30:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2012.08.26 17:30:28 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2012.08.26 17:30:28 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2012.08.26 17:30:28 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2012.08.26 17:30:28 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2012.08.26 17:30:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2012.08.26 17:27:41 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll [2012.08.26 17:27:40 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll [2012.08.26 17:27:40 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll [2012.08.26 17:27:40 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll [2012.08.26 17:27:40 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll [2012.08.26 17:27:40 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll [2012.08.26 17:27:40 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll [2012.08.26 17:27:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe [2012.08.26 17:27:31 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2012.08.26 17:27:31 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2012.08.26 17:27:26 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll [2012.08.26 17:27:25 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl [2012.08.26 17:27:24 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2012.08.26 17:27:24 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2012.08.26 17:27:21 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2012.08.26 17:27:21 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys [2012.08.26 17:25:43 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys [2012.08.26 17:25:00 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2012.08.26 17:25:00 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe [2012.08.26 17:24:59 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll [2012.08.26 17:24:59 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2012.08.26 17:24:55 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll [2012.08.26 17:24:55 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax [2012.08.26 17:24:44 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll [2012.08.26 17:24:43 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll [2012.08.26 17:24:33 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll [2012.08.26 17:24:32 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe [2012.08.26 17:24:30 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll [2012.08.26 17:24:23 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll [2012.08.26 17:24:23 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2012.08.26 17:24:23 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2012.08.26 17:24:22 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll [2012.08.26 17:24:22 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax [2012.08.26 17:24:20 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll [2012.08.26 17:24:16 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe [2012.08.26 17:24:16 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll [2012.08.26 17:24:15 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll [2012.08.26 17:24:15 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [2012.08.26 17:24:15 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [2012.08.26 17:24:14 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll [2012.08.26 17:24:14 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll [2012.08.26 17:24:13 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll [2012.08.26 17:24:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll [2012.08.26 17:24:13 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll [2012.08.26 17:24:13 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll [2012.08.26 17:24:13 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll [2012.08.26 17:24:13 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll [2012.08.26 17:24:13 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll [2012.08.26 17:24:13 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe [2012.08.26 17:24:08 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2012.08.26 17:24:07 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll [2012.08.26 17:24:07 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll [2012.08.26 17:21:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe [2012.08.26 17:21:07 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2012.08.26 17:19:48 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012.08.26 17:19:48 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012.08.26 17:19:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed [2012.08.26 17:18:19 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll [2012.08.26 17:15:23 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll [2012.08.26 17:15:23 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll [2012.08.26 17:15:20 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll [2012.08.26 17:15:20 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll [2012.08.26 17:15:20 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll [2012.08.26 17:15:18 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll [2012.08.26 17:15:18 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe [2012.08.26 17:14:22 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll [2012.08.26 17:14:04 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2012.08.26 17:14:02 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information [2012.08.26 17:11:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012.08.26 17:11:03 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2012.08.26 17:10:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2012.08.26 17:10:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2012.08.26 17:09:56 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll [2012.08.26 17:09:56 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll [2012.08.26 17:08:11 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2012.08.26 13:17:53 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2012.08.26 13:17:39 | 000,000,000 | -HSD | C] -- C:\Boot [2012.08.26 12:26:03 | 000,000,000 | -HSD | C] -- C:\Recovery [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Programme [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2012.08.26 12:26:00 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012.08.26 12:18:47 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2012.08.26 12:18:09 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2012.03.19 22:44:18 | 000,276,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe [2012.03.19 22:44:16 | 006,215,448 | ---- | C] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe [2012.03.19 22:40:34 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll [2012.03.19 22:26:56 | 006,120,960 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll [2012.03.19 22:11:38 | 007,795,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll [2012.03.19 21:12:30 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc [2012.03.19 21:12:28 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc [2012.03.19 21:12:28 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc [2012.03.19 21:12:28 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc [2012.03.19 21:12:28 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc [2012.03.19 21:12:28 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc [2012.03.19 21:12:26 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc [2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc [2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc [2012.03.19 21:12:26 | 000,430,080 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc [2012.03.19 21:12:26 | 000,428,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc [2012.03.19 21:12:24 | 000,438,272 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc [2012.03.19 21:12:24 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc [2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc [2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc [2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc [2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc [2012.03.19 21:12:24 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc [2012.03.19 21:12:24 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc [2012.03.19 21:12:22 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc [2012.03.19 21:12:22 | 000,427,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc [2012.03.19 21:12:22 | 000,426,496 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc [2012.03.19 21:12:08 | 000,313,344 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll [2012.03.19 21:12:08 | 000,286,208 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll [2012.03.19 21:12:08 | 000,120,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl [2012.03.19 21:12:06 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll [2012.03.19 21:11:52 | 000,059,392 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll [2012.03.19 21:11:36 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll [2012.03.19 21:11:30 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\Windows\System32\hccutils.dll [2012.03.19 21:11:22 | 000,172,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll [2012.03.19 21:10:56 | 009,023,488 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxress.dll [2012.03.19 21:10:56 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc [2012.03.19 21:09:08 | 002,321,408 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll [2012.03.19 21:09:08 | 000,519,680 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll [2012.03.19 21:09:08 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll [2012.03.19 21:09:08 | 000,237,056 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll [2012.03.19 21:09:08 | 000,177,152 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll ========== Files - Modified Within 360 Days ========== [2012.11.18 14:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.11.18 12:37:25 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.11.18 12:37:25 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.11.18 12:37:25 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.11.18 12:37:25 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.11.18 10:49:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.11.18 10:49:38 | 2298,261,504 | -HS- | M] () -- C:\hiberfil.sys [2012.11.16 03:21:41 | 000,265,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.11.13 19:56:12 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2012.10.18 18:59:05 | 002,345,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2012.10.17 19:20:34 | 000,000,232 | ---- | M] () -- C:\Users\Admin\Documents\Kundenliste.rtf [2012.10.15 20:36:49 | 000,000,420 | ---- | M] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf [2012.10.15 19:00:31 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.10.14 16:06:41 | 000,012,661 | ---- | M] () -- C:\Users\Admin\Desktop\ [2012.10.14 16:04:39 | 000,001,033 | ---- | M] () -- C:\Users\Admin\Desktop\ [2012.10.14 16:04:39 | 000,000,970 | ---- | M] () -- C:\Users\Admin\ [2012.10.12 19:54:49 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012.10.12 19:54:49 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012.10.08 08:56:24 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012.10.08 08:47:44 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012.10.08 08:46:32 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012.10.08 08:45:17 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012.10.08 08:44:05 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012.10.08 08:42:31 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012.10.08 08:40:56 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012.10.08 08:37:23 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012.10.07 16:27:34 | 000,539,738 | ---- | M] () -- C:\Users\Admin\Desktop\kinderkekse.xps [2012.10.07 16:27:11 | 000,718,181 | ---- | M] () -- C:\Users\Admin\Desktop\Pizzabrot.xps [2012.10.03 18:52:52 | 000,001,930 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk [2012.10.03 18:52:52 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\MediaManager.lnk [2012.10.03 12:41:28 | 001,820,575 | ---- | M] () -- C:\Users\Admin\Desktop\gvu anleitung.xps [2012.10.03 10:16:06 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.26 19:16:23 | 000,217,225 | ---- | M] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf [2012.09.25 23:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll [2012.09.24 21:24:42 | 000,159,468 | ---- | M] () -- C:\Users\Admin\ [2012.09.24 18:12:22 | 000,001,032 | ---- | M] () -- C:\Users\Public\Desktop\TrueCrypt.lnk [2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys [2012.09.22 22:28:15 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012.09.22 22:22:34 | 000,001,055 | ---- | M] () -- C:\Users\Admin\Desktop\DeepBurner.lnk [2012.09.22 22:02:42 | 000,001,079 | ---- | M] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk [2012.09.14 19:28:53 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2012.09.09 17:48:52 | 000,000,969 | ---- | M] () -- C:\Users\Admin\Desktop\QuickPar.lnk [2012.09.02 11:38:16 | 000,001,807 | ---- | M] () -- C:\Users\Admin\Desktop\ [2012.08.30 22:05:31 | 000,198,864 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll [2012.08.30 22:05:28 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll [2012.08.30 22:05:28 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll [2012.08.30 22:05:27 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll [2012.08.30 21:11:25 | 000,001,234 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk [2012.08.30 18:12:02 | 003,968,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2012.08.30 18:12:02 | 003,914,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.08.26 17:36:07 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll [2012.08.26 17:36:07 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll [2012.08.26 17:36:07 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe [2012.08.26 17:36:07 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2012.08.26 17:35:28 | 000,001,179 | ---- | M] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk [2012.08.26 17:30:29 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2012.08.26 17:30:28 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2012.08.26 17:30:28 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2012.08.26 17:30:28 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2012.08.26 17:30:28 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2012.08.26 17:30:28 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2012.08.26 17:30:28 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2012.08.26 17:30:28 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2012.08.26 17:30:28 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2012.08.26 17:30:28 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2012.08.26 17:30:28 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2012.08.26 17:30:28 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2012.08.26 17:30:28 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2012.08.26 17:30:28 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2012.08.26 17:30:28 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2012.08.26 17:30:28 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2012.08.26 17:30:28 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2012.08.26 17:30:28 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2012.08.26 17:30:28 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2012.08.26 17:30:28 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2012.08.26 17:30:28 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2012.08.26 17:30:28 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2012.08.26 17:30:28 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2012.08.26 17:30:28 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2012.08.26 17:30:28 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2012.08.26 17:30:28 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2012.08.26 17:30:28 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2012.08.26 17:30:28 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2012.08.26 17:30:28 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2012.08.26 17:30:28 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2012.08.26 13:17:41 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2012.08.26 12:21:31 | 000,177,271 | ---- | M] () -- C:\Windows\System32\license.rtf [2012.08.26 12:20:09 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf [2012.08.22 18:16:46 | 000,240,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys [2012.08.22 18:16:36 | 000,187,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [2012.07.04 22:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll [2012.06.06 06:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll [2012.06.02 23:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll [2012.06.02 23:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups.dll [2012.06.02 23:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll [2012.06.02 23:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll [2012.06.02 23:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll [2012.06.02 14:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll [2012.06.02 14:12:20 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe [2012.06.02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll [2012.05.31 11:25:14 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2012.05.05 08:46:52 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll [2012.04.26 05:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll [2012.04.26 05:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll [2012.04.26 05:41:16 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe [2012.03.19 22:58:28 | 000,080,208 | ---- | M] () -- C:\Windows\System32\iglhxs32.vp [2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe [2012.03.19 22:44:16 | 006,215,448 | ---- | M] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe [2012.03.19 22:40:34 | 000,081,920 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll [2012.03.19 22:26:56 | 006,120,960 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll [2012.03.19 22:26:08 | 000,145,804 | ---- | M] () -- C:\Windows\System32\igcompkrng600.bin [2012.03.19 22:26:06 | 000,963,912 | ---- | M] () -- C:\Windows\System32\igkrng600.bin [2012.03.19 22:26:06 | 000,261,208 | ---- | M] () -- C:\Windows\System32\igfcg600m.bin [2012.03.19 22:25:58 | 000,058,880 | ---- | M] () -- C:\Windows\System32\igdde32.dll [2012.03.19 22:11:38 | 007,795,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll [2012.03.19 21:21:14 | 013,212,672 | ---- | M] () -- C:\Windows\System32\ig4icd32.dll [2012.03.19 21:12:48 | 000,144,790 | ---- | M] () -- C:\Windows\System32\Gfxres.ro-RO.resources [2012.03.19 21:12:46 | 000,139,901 | ---- | M] () -- C:\Windows\System32\Gfxres.hr-HR.resources [2012.03.19 21:12:46 | 000,125,306 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-TW.resources [2012.03.19 21:12:46 | 000,123,778 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-CN.resources [2012.03.19 21:12:44 | 000,221,877 | ---- | M] () -- C:\Windows\System32\Gfxres.th-TH.resources [2012.03.19 21:12:44 | 000,143,564 | ---- | M] () -- C:\Windows\System32\Gfxres.tr-TR.resources [2012.03.19 21:12:44 | 000,141,854 | ---- | M] () -- C:\Windows\System32\Gfxres.sv-SE.resources [2012.03.19 21:12:42 | 000,192,378 | ---- | M] () -- C:\Windows\System32\Gfxres.ru-RU.resources [2012.03.19 21:12:42 | 000,140,548 | ---- | M] () -- C:\Windows\System32\Gfxres.sk-SK.resources [2012.03.19 21:12:42 | 000,136,850 | ---- | M] () -- C:\Windows\System32\Gfxres.sl-SI.resources [2012.03.19 21:12:40 | 000,143,112 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-BR.resources [2012.03.19 21:12:40 | 000,142,079 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-PT.resources [2012.03.19 21:12:40 | 000,141,421 | ---- | M] () -- C:\Windows\System32\Gfxres.pl-PL.resources [2012.03.19 21:12:38 | 000,147,116 | ---- | M] () -- C:\Windows\System32\Gfxres.ko-KR.resources [2012.03.19 21:12:38 | 000,142,797 | ---- | M] () -- C:\Windows\System32\Gfxres.nl-NL.resources [2012.03.19 21:12:38 | 000,136,778 | ---- | M] () -- C:\Windows\System32\Gfxres.nb-NO.resources [2012.03.19 21:12:36 | 000,162,150 | ---- | M] () -- C:\Windows\System32\Gfxres.ja-JP.resources [2012.03.19 21:12:36 | 000,148,461 | ---- | M] () -- C:\Windows\System32\Gfxres.it-IT.resources [2012.03.19 21:12:36 | 000,142,606 | ---- | M] () -- C:\Windows\System32\Gfxres.hu-HU.resources [2012.03.19 21:12:34 | 000,157,713 | ---- | M] () -- C:\Windows\System32\Gfxres.he-IL.resources [2012.03.19 21:12:34 | 000,144,267 | ---- | M] () -- C:\Windows\System32\Gfxres.fr-FR.resources [2012.03.19 21:12:34 | 000,140,949 | ---- | M] () -- C:\Windows\System32\Gfxres.fi-FI.resources [2012.03.19 21:12:32 | 000,208,522 | ---- | M] () -- C:\Windows\System32\Gfxres.el-GR.resources [2012.03.19 21:12:32 | 000,146,125 | ---- | M] () -- C:\Windows\System32\Gfxres.es-ES.resources [2012.03.19 21:12:32 | 000,146,008 | ---- | M] () -- C:\Windows\System32\Gfxres.de-DE.resources [2012.03.19 21:12:30 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc [2012.03.19 21:12:30 | 000,164,821 | ---- | M] () -- C:\Windows\System32\Gfxres.ar-SA.resources [2012.03.19 21:12:30 | 000,141,297 | ---- | M] () -- C:\Windows\System32\Gfxres.cs-CZ.resources [2012.03.19 21:12:30 | 000,136,261 | ---- | M] () -- C:\Windows\System32\Gfxres.da-DK.resources [2012.03.19 21:12:28 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc [2012.03.19 21:12:28 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc [2012.03.19 21:12:28 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc [2012.03.19 21:12:28 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc [2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc [2012.03.19 21:12:28 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc [2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc [2012.03.19 21:12:26 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc [2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc [2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc [2012.03.19 21:12:26 | 000,430,080 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc [2012.03.19 21:12:26 | 000,428,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc [2012.03.19 21:12:24 | 000,438,272 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc [2012.03.19 21:12:24 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc [2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc [2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc [2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc [2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc [2012.03.19 21:12:24 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc [2012.03.19 21:12:24 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc [2012.03.19 21:12:22 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc [2012.03.19 21:12:22 | 000,427,008 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc [2012.03.19 21:12:22 | 000,426,496 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc [2012.03.19 21:12:22 | 000,131,674 | ---- | M] () -- C:\Windows\System32\Gfxres.en-US.resources [2012.03.19 21:12:08 | 000,313,344 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll [2012.03.19 21:12:08 | 000,286,208 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll [2012.03.19 21:12:08 | 000,120,320 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl [2012.03.19 21:12:06 | 000,025,088 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll [2012.03.19 21:11:52 | 000,059,392 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll [2012.03.19 21:11:36 | 000,130,048 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll [2012.03.19 21:11:30 | 000,096,256 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hccutils.dll [2012.03.19 21:11:22 | 000,172,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll [2012.03.19 21:11:22 | 000,009,216 | ---- | M] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2012.03.19 21:10:56 | 009,023,488 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxress.dll [2012.03.19 21:10:56 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc [2012.03.19 21:09:28 | 000,000,264 | ---- | M] () -- C:\Windows\System32\GfxUI.exe.config [2012.03.19 21:09:08 | 002,321,408 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll [2012.03.19 21:09:08 | 001,921,265 | ---- | M] () -- C:\Windows\System32\iglhxa32.cpa [2012.03.19 21:09:08 | 000,519,680 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll [2012.03.19 21:09:08 | 000,452,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll [2012.03.19 21:09:08 | 000,237,056 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll [2012.03.19 21:09:08 | 000,177,152 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll [2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll [2012.03.19 21:09:08 | 000,059,594 | ---- | M] () -- C:\Windows\System32\iglhxc32.vp [2012.03.19 21:09:08 | 000,059,384 | ---- | M] () -- C:\Windows\System32\iglhxc32_dev.vp [2012.03.19 21:09:08 | 000,059,328 | ---- | M] () -- C:\Windows\System32\iglhxg32_dev.vp [2012.03.19 21:09:08 | 000,059,215 | ---- | M] () -- C:\Windows\System32\iglhxo32_dev.vp [2012.03.19 21:09:08 | 000,058,781 | ---- | M] () -- C:\Windows\System32\iglhxo32.vp [2012.03.19 21:09:08 | 000,058,684 | ---- | M] () -- C:\Windows\System32\iglhxg32.vp [2012.03.19 21:09:08 | 000,001,074 | ---- | M] () -- C:\Windows\System32\iglhxa32.vp [2012.03.03 06:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2012.02.17 06:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll [2012.02.15 13:51:56 | 000,360,448 | ---- | M] (FLV.com) -- C:\Windows\System32\TubeFinder.exe [2011.12.30 06:27:56 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl ========== Files Created - No Company Name ========== [2012.11.13 19:55:41 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.17 19:20:33 | 000,000,232 | ---- | C] () -- C:\Users\Admin\Documents\Kundenliste.rtf [2012.10.15 20:36:49 | 000,000,420 | ---- | C] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf [2012.10.15 19:00:31 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk [2012.10.15 19:00:31 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.10.14 16:06:41 | 000,012,661 | ---- | C] () -- C:\Users\Admin\Desktop\ [2012.10.14 16:04:39 | 000,001,033 | ---- | C] () -- C:\Users\Admin\Desktop\ [2012.10.14 16:04:39 | 000,000,970 | ---- | C] () -- C:\Users\Admin\ [2012.10.07 16:27:34 | 000,539,738 | ---- | C] () -- C:\Users\Admin\Desktop\kinderkekse.xps [2012.10.07 16:27:10 | 000,718,181 | ---- | C] () -- C:\Users\Admin\Desktop\Pizzabrot.xps [2012.10.03 18:52:52 | 000,001,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk [2012.10.03 18:52:52 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\MediaManager.lnk [2012.10.03 12:42:14 | 001,820,575 | ---- | C] () -- C:\Users\Admin\Desktop\gvu anleitung.xps [2012.10.03 10:05:31 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.09.26 19:16:22 | 000,217,225 | ---- | C] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf [2012.09.24 21:24:40 | 000,159,468 | ---- | C] () -- [2012.09.24 18:12:22 | 000,001,032 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk [2012.09.22 22:28:15 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012.09.22 22:28:15 | 000,001,849 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk [2012.09.22 22:22:34 | 000,001,055 | ---- | C] () -- C:\Users\Admin\Desktop\DeepBurner.lnk [2012.09.22 22:02:42 | 000,001,079 | ---- | C] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk [2012.09.22 22:02:41 | 000,364,544 | ---- | C] () -- C:\Windows\System32\PropertyGrid.ocx [2012.09.22 22:02:41 | 000,208,500 | ---- | C] () -- C:\Windows\System32\ReyXpBasics.tlb [2012.09.22 22:02:41 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ControlSubX.ocx [2012.09.09 17:48:52 | 000,000,969 | ---- | C] () -- C:\Users\Admin\Desktop\QuickPar.lnk [2012.09.02 11:38:16 | 000,001,807 | ---- | C] () -- C:\Users\Admin\Desktop\UseNeXT.lnk [2012.08.30 21:01:31 | 000,001,234 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk [2012.08.26 18:50:33 | 000,001,413 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012.08.26 17:35:28 | 000,001,179 | ---- | C] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk [2012.08.26 17:30:28 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012.08.26 17:19:50 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.08.26 17:14:22 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2012.08.26 17:10:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk [2012.08.26 13:17:41 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK [2012.08.26 13:17:39 | 000,383,786 | RHS- | C] () -- C:\bootmgr [2012.08.26 12:21:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2012.08.26 12:21:15 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2012.08.26 12:20:09 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf [2012.08.26 12:18:10 | 2298,261,504 | -HS- | C] () -- C:\hiberfil.sys [2012.03.19 22:58:28 | 000,080,208 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp [2012.03.19 22:26:08 | 000,145,804 | ---- | C] () -- C:\Windows\System32\igcompkrng600.bin [2012.03.19 22:26:06 | 000,963,912 | ---- | C] () -- C:\Windows\System32\igkrng600.bin [2012.03.19 22:26:06 | 000,261,208 | ---- | C] () -- C:\Windows\System32\igfcg600m.bin [2012.03.19 22:25:58 | 000,058,880 | ---- | C] () -- C:\Windows\System32\igdde32.dll [2012.03.19 21:21:14 | 013,212,672 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll [2012.03.19 21:12:48 | 000,144,790 | ---- | C] () -- C:\Windows\System32\Gfxres.ro-RO.resources [2012.03.19 21:12:46 | 000,139,901 | ---- | C] () -- C:\Windows\System32\Gfxres.hr-HR.resources [2012.03.19 21:12:46 | 000,125,306 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-TW.resources [2012.03.19 21:12:46 | 000,123,778 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-CN.resources [2012.03.19 21:12:44 | 000,221,877 | ---- | C] () -- C:\Windows\System32\Gfxres.th-TH.resources [2012.03.19 21:12:44 | 000,143,564 | ---- | C] () -- C:\Windows\System32\Gfxres.tr-TR.resources [2012.03.19 21:12:44 | 000,141,854 | ---- | C] () -- C:\Windows\System32\Gfxres.sv-SE.resources [2012.03.19 21:12:42 | 000,192,378 | ---- | C] () -- C:\Windows\System32\Gfxres.ru-RU.resources [2012.03.19 21:12:42 | 000,140,548 | ---- | C] () -- C:\Windows\System32\Gfxres.sk-SK.resources [2012.03.19 21:12:42 | 000,136,850 | ---- | C] () -- C:\Windows\System32\Gfxres.sl-SI.resources [2012.03.19 21:12:40 | 000,143,112 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-BR.resources [2012.03.19 21:12:40 | 000,142,079 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-PT.resources [2012.03.19 21:12:40 | 000,141,421 | ---- | C] () -- C:\Windows\System32\Gfxres.pl-PL.resources [2012.03.19 21:12:38 | 000,147,116 | ---- | C] () -- C:\Windows\System32\Gfxres.ko-KR.resources [2012.03.19 21:12:38 | 000,142,797 | ---- | C] () -- C:\Windows\System32\Gfxres.nl-NL.resources [2012.03.19 21:12:38 | 000,136,778 | ---- | C] () -- C:\Windows\System32\Gfxres.nb-NO.resources [2012.03.19 21:12:36 | 000,162,150 | ---- | C] () -- C:\Windows\System32\Gfxres.ja-JP.resources [2012.03.19 21:12:36 | 000,148,461 | ---- | C] () -- C:\Windows\System32\Gfxres.it-IT.resources [2012.03.19 21:12:36 | 000,142,606 | ---- | C] () -- C:\Windows\System32\Gfxres.hu-HU.resources [2012.03.19 21:12:34 | 000,157,713 | ---- | C] () -- C:\Windows\System32\Gfxres.he-IL.resources [2012.03.19 21:12:34 | 000,144,267 | ---- | C] () -- C:\Windows\System32\Gfxres.fr-FR.resources [2012.03.19 21:12:34 | 000,140,949 | ---- | C] () -- C:\Windows\System32\Gfxres.fi-FI.resources [2012.03.19 21:12:32 | 000,208,522 | ---- | C] () -- C:\Windows\System32\Gfxres.el-GR.resources [2012.03.19 21:12:32 | 000,146,125 | ---- | C] () -- C:\Windows\System32\Gfxres.es-ES.resources [2012.03.19 21:12:32 | 000,146,008 | ---- | C] () -- C:\Windows\System32\Gfxres.de-DE.resources [2012.03.19 21:12:30 | 000,164,821 | ---- | C] () -- C:\Windows\System32\Gfxres.ar-SA.resources [2012.03.19 21:12:30 | 000,141,297 | ---- | C] () -- C:\Windows\System32\Gfxres.cs-CZ.resources [2012.03.19 21:12:30 | 000,136,261 | ---- | C] () -- C:\Windows\System32\Gfxres.da-DK.resources [2012.03.19 21:12:22 | 000,131,674 | ---- | C] () -- C:\Windows\System32\Gfxres.en-US.resources [2012.03.19 21:11:22 | 000,009,216 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2012.03.19 21:09:28 | 000,000,264 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2012.03.19 21:09:08 | 001,921,265 | ---- | C] () -- C:\Windows\System32\iglhxa32.cpa [2012.03.19 21:09:08 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll [2012.03.19 21:09:08 | 000,059,594 | ---- | C] () -- C:\Windows\System32\iglhxc32.vp [2012.03.19 21:09:08 | 000,059,384 | ---- | C] () -- C:\Windows\System32\iglhxc32_dev.vp [2012.03.19 21:09:08 | 000,059,328 | ---- | C] () -- C:\Windows\System32\iglhxg32_dev.vp [2012.03.19 21:09:08 | 000,059,215 | ---- | C] () -- C:\Windows\System32\iglhxo32_dev.vp [2012.03.19 21:09:08 | 000,058,781 | ---- | C] () -- C:\Windows\System32\iglhxo32.vp [2012.03.19 21:09:08 | 000,058,684 | ---- | C] () -- C:\Windows\System32\iglhxg32.vp [2012.03.19 21:09:08 | 000,001,074 | ---- | C] () -- C:\Windows\System32\iglhxa32.vp [2010.11.21 01:46:14 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2010.11.21 01:46:14 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2010.11.21 01:46:14 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2010.11.21 01:46:14 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2010.11.20 22:29:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe ========== ZeroAccess Check ========== [2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report > ESET Log: ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=12 # version=7 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=97206b8cac1e69449988079e3006b1e2 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-11-18 09:52:51 # local_time=2012-11-18 10:52:51 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 2597649 2597649 0 0 # compatibility_mode=5893 16776573 100 94 42720 104902715 0 0 # compatibility_mode=8192 67108863 100 0 4647 4647 0 0 # scanned=142556 # found=6 # cleaned=0 # scan_time=4068 C:\Users\Patrick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\738cd4bb-675ba20a a variant of Win32/Kryptik.AOPO trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Patrick\AppData\Roaming\AcroIEHelpe231.dll Win32/Spy.Banker.YRG trojan (unable to clean) 00000000000000000000000000000000 I F:\Filme\Filmchen\arkanum\Magma swingt im Lustschloss Arkanum.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I F:\Filme\Filmchen\gr\Magma swingt im Lustschloss Arkanum gr.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I F:\Wichtige Dokumente\p\Software\Babylon_Uebersetzer\Babylon8_setup.exe a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I F:\Wichtige Dokumente\p\Software\pdf\PDF-Creator\PDFCreator-1_2_1_setup.exe Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I |
![]() | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Hallo und
__________________![]() Zitat:
__________________ |
![]() | #3 |
| ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Hallo,
__________________ich habe aus dem OLT-Log, im Abschnitt " Files/Folders - Created Within 360 Days" und im Abschnitt " Files - Modified Within 360 Days" ein paar Pfade gekürzt. Beispiel: [2012.09.24 21:24:40 | 000,159,468 | ---- | C] () -- !!!Hier fehlt der Pfad zu einer persönlichen Datei !!! Gruß Patrick |
![]() | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Derartige Zensuraktionen sind kontraproduktiv, du solltest nur private Infos wie komplette Vor- und Nachnamen unkenntlich machen
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
| ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Ok, das nächste mal werde ich anders vorgehen. Im Endeffekt macht es an der Stelle ja keinen Unterschied ob ich einen Pfad aus xxxe oder ihn Lösche, ungültig ist er in jedem Fall. Egal, ich werde das zukünftig beachten ![]() |
![]() | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 Bitte nun Logs mit GMER (<<< klick für Anleitung) und aswMBR (Anleitung etwas weiter unten) erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim zweiten Mal nicht will, lass es einfach weg und führ nur aswMBR aus. aswMBR-Download => aswMBR.exe - speichere die Datei auf deinem Desktop.
Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________ --> TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 |
![]() |
Themen zu TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 |
administrator, adobe, antivir, application/pdf:, autorun, avg, avira, bho, defender, downloader, explorer, firefox, flash player, format, helper, installation, logfile, mozilla, opera, plug-in, programme, realtek, registry, scan, software, tracker, trojan |