Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 09.01.2013, 16:34   #1
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hallo Leute,
habe mir heute auch den GUV Virus eingefangen. Wie ich lesen konnte, haben sich den mehrere eingefangen. Ich komme in den abgesicherten Modus, kann aber keine Wiederherstellung nutzen, da dies deaktiviert war. Desweiteren habe ich noch 2 weitere Systeme auf unterschiedlichen Paritionen, die beide funktionieren.
Ich kann sogar das befallene Windows 7 64bit nutzen mit einem kleinen Trick, indem ich nach der Sperrung durch das Virus den TaskManager aufrufe und den Rechner runterfahre. Da im Hintergrund aber noch ein Programm läuft, möchte der TaskManager, das ich das herunterfahren erzwinge, welches ich abbreche.
Danach kann ich den PC ganz normal nutzen.
Könnt ihr mir helfen ?

Gruß

mpdreiforyou

Alt 09.01.2013, 16:35   #2
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hi
man nutzt auch keine Systemwiederherstellung bei Malware!
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die
    OTL.exe
    .
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die
    Textbox.
Code:
ATTFilter
activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread
__________________

__________________

Alt 09.01.2013, 17:15   #3
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hallo,

ich habe nur eine OTL.txt auf dem Desktop.

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 09.01.2013 17:05:05 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Uli\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,98 Gb Total Physical Memory | 5,89 Gb Available Physical Memory | 73,81% Memory free
15,96 Gb Paging File | 14,15 Gb Available in Paging File | 88,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 74,43 Gb Total Space | 1,29 Gb Free Space | 1,73% Space Free | Partition Type: NTFS
Drive D: | 1167,11 Gb Total Space | 367,48 Gb Free Space | 31,49% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 102,32 Gb Free Space | 21,97% Space Free | Partition Type: NTFS
Drive G: | 107,42 Gb Total Space | 64,29 Gb Free Space | 59,85% Space Free | Partition Type: NTFS
Drive H: | 97,66 Gb Total Space | 77,46 Gb Free Space | 79,32% Space Free | Partition Type: NTFS
 
Computer Name: KARLCHEN | User Name: Uli | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Uli\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Users\Uli\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Windows\jmesoft\Service.exe ()
PRC - C:\Programme\Lenovo\Power Dial\LitModeCtrl.exe (Lenovo)
PRC - C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()
PRC - C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)
PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (Intel(R) -- C:\Windows\SysNative\IPROSetMonitor.exe (Intel Corporation)
SRV:64bit: - (ftpsvc) -- C:\Windows\SysNative\inetsrv\ftpsvc.dll (Microsoft Corporation)
SRV:64bit: - (SNMP) -- C:\Windows\SysNative\snmp.exe (Microsoft Corporation)
SRV:64bit: - (NfsClnt) -- C:\Windows\SysNative\nfsclnt.exe (Microsoft Corporation)
SRV:64bit: - (MSMQTriggers) -- C:\Windows\SysNative\mqtgsvc.exe (Microsoft Corporation)
SRV:64bit: - (IISADMIN) -- C:\Windows\SysNative\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV:64bit: - (LPDSVC) -- C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (iprip) -- C:\Windows\SysNative\iprip.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WMSVC) -- C:\Windows\SysNative\inetsrv\WMSvc.exe (Microsoft Corporation)
SRV:64bit: - (TlntSvr) -- C:\Windows\SysNative\tlntsvr.exe (Microsoft Corporation)
SRV:64bit: - (simptcp) -- C:\Windows\SysNative\TCPSVCS.EXE (Microsoft Corporation)
SRV:64bit: - (MSMQ) -- C:\Windows\SysNative\mqsvc.exe (Microsoft Corporation)
SRV:64bit: - (CISVC) -- C:\Windows\SysNative\CISVC.EXE (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Intel(R) -- C:\Programme\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (JME Keyboard) -- C:\Windows\jmesoft\Service.exe ()
SRV - (SNMP) -- C:\Windows\SysWOW64\snmp.exe (Microsoft Corporation)
SRV - (WAS) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (LitModeCtrl) -- C:\Programme\Lenovo\Power Dial\LitModeCtrl.exe (Lenovo)
SRV - (CEEBC40A-FDED-4C59-B354-939132350B01) -- C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (LenovoCOMSvc) -- C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)
SRV - (simptcp) -- C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HauppaugeTVServer) -- C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (iaStorF) -- C:\Windows\SysNative\drivers\iaStorF.sys (Intel Corporation)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (RTL8192Ce) -- C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation                           )
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (e1cexpress) -- C:\Windows\SysNative\drivers\e1c62x64.sys (Intel Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Uim_IM) -- C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) -- C:\Windows\SysNative\drivers\uimx64.sys (Windows (R) 2000 DDK provider)
DRV:64bit: - (Uim_VIM) -- C:\Windows\SysNative\drivers\uim_vimx64.sys (Paragon)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (RpcXdr) -- C:\Windows\SysNative\drivers\rpcxdr.sys (Microsoft Corporation)
DRV:64bit: - (NfsRdr) -- C:\Windows\SysNative\drivers\nfsrdr.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RMCAST) -- C:\Windows\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (MQAC) -- C:\Windows\SysNative\drivers\mqac.sys (Microsoft Corporation)
DRV:64bit: - (PsxDrv) -- C:\Windows\SysNative\drivers\psxdrv.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hcw17bda) -- C:\Windows\SysNative\drivers\hcw17bda.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (adfs) -- C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (WinI2C-DDC) -- C:\Windows\SysNative\drivers\ddcdrv.sys (Nicomsoft Ltd.)
DRV:64bit: - (ElbyCDFL) -- C:\Windows\SysNative\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (UnlockerDriver5) -- C:\Program Files (x86)\Unlocker\UnlockerDriver5.sys ()
DRV - (WinI2C-DDC) -- C:\Windows\SysWOW64\drivers\ddcdrv.sys (Nicomsoft Ltd.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ElbyCDFL) -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys (SlySoft, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C1 D7 EE 6C 78 12 CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=109989&tt=050412_30b&babsrc=SP_ss&mntrId=0860bd63000000000000ac8112b43d50
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7LEND_deDE478
IE - HKCU\..\SearchScopes\{C08EBB1E-1D2A-4729-A061-A61E24C6DD94}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=IMB&o=15785&src=kw&q={searchTerms}&locale=&apn_ptnrs=HQ&apn_dtid=YYYYYYYYDE&apn_uid=14a5732e-886c-4681-86ab-a4b5c0d5a30b&apn_sauid=EFB679FF-3836-462C-B971-88DC4ACE33B0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.facebook.com/"
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.1.9
FF - prefs.js..extensions.enabledAddons: software%40loadtubes.com:1.01
FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:1.3
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7Be968fc70-8f95-4ab9-9e79-304de2a71ee1%7D:0.7.3
FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.145
FF - prefs.js..extensions.enabledAddons: leethax%40leethax.net:2013.01.03
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?affID=109989&tt=050412_30b&babsrc=KW_ss&mntrId=0860bd63000000000000ac8112b43d50&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPMPDRM: C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Users\Uli\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Uli\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Uli\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.04.10 15:04:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.07.31 20:01:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.20 16:22:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.04.10 15:04:08 | 000,000,000 | ---D | M]
 
[2012.04.04 16:41:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\Extensions
[2013.01.03 19:55:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\Firefox\Profiles\mt51ewtl.default\extensions
[2012.10.17 14:17:35 | 000,000,000 | ---D | M] (Charles Autoconfiguration) -- C:\Users\Uli\AppData\Roaming\mozilla\Firefox\Profiles\mt51ewtl.default\extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66}
[2012.04.06 19:28:08 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Uli\AppData\Roaming\mozilla\Firefox\Profiles\mt51ewtl.default\extensions\ffxtlbr@babylon.com
[2012.07.05 05:38:52 | 000,000,000 | ---D | M] (loadtbs) -- C:\Users\Uli\AppData\Roaming\mozilla\Firefox\Profiles\mt51ewtl.default\extensions\software@loadtubes.com
[2013.01.02 06:24:39 | 000,141,384 | ---- | M] () (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\extensions\jid0-nEKQbsVUhSe9FRuGEdAV8hAphDI@jetpack.xpi
[2013.01.03 19:55:18 | 000,021,513 | ---- | M] () (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\extensions\leethax@leethax.net.xpi
[2012.09.06 06:56:20 | 000,269,659 | ---- | M] () (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2012.08.25 07:09:31 | 000,270,021 | ---- | M] () (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.04.04 16:49:18 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
[2012.08.27 15:22:41 | 000,002,323 | ---- | M] () -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\searchplugins\askcom.xml
[2012.04.25 17:36:56 | 000,005,027 | ---- | M] () -- C:\Users\Uli\AppData\Roaming\mozilla\firefox\profiles\mt51ewtl.default\searchplugins\cannapower-user-uploads.xml
[2012.10.29 19:28:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.07.31 20:01:50 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012.12.20 16:22:15 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.01.05 17:04:02 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2012.12.20 16:22:14 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.06 14:38:54 | 000,002,353 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.12.20 16:22:14 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.12.20 16:22:14 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.12.20 16:22:14 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.12.20 16:22:14 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.12.20 16:22:14 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: 
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Uli\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Uli\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Uli\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - Extension: Wetter (Erweiterung) = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\beapnbfmjmjhhfpaoajfhjbbfnnlfpnc\0.9.0.7_0\
CHR - Extension: YouTube = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Lamborghini Sesto Elemento Theme = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\dappigdjllcnkkoacaoolciaolaaiemb\1.0_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Uli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2012.08.07 10:00:03 | 000,001,334 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 secure.tune-up.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Uli\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (loadtbs) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - C:\Users\Uli\AppData\Roaming\loadtbs\toolbar.dll (InfiniAd GmbH)
O4:64bit: - HKLM..\Run: [MsmqIntCert] C:\Windows\SysNative\mqrt.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [jmekey] C:\Windows\jmesoft\hotkey.exe (Lenovo)
O4 - HKLM..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe ()
O4 - HKLM..\Run: [Lenovo Dynamic Brightness System] C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe (Lenovo)
O4 - HKLM..\Run: [Lenovo Eye Distance System] C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe (Lenovo)
O4 - HKLM..\Run: [ModeSwitch] C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe (Lenovo)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Uli\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39759639-DEE9-4FFD-ABF8-DF03B8DB8006}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{501564E6-11A9-4628-8197-10B4DEA1149E}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\SysWow64\acaptuser32.dll (Adobe Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\PROGRA~3\dsgsdgdsgdsgw.bat) - C:\ProgramData\dsgsdgdsgdsgw.bat ()
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.01.09 11:32:17 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{13fdf555-7e66-11e1-b8d7-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{13fdf555-7e66-11e1-b8d7-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoLauncher.exe
O33 - MountPoints2\{75b174c7-7ee5-11e1-a9e8-40618675bd3a}\Shell - "" = AutoRun
O33 - MountPoints2\{75b174c7-7ee5-11e1-a9e8-40618675bd3a}\Shell\AutoRun\command - "" = L:\AUTORUN.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.01.09 16:40:25 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Uli\Desktop\OTL.exe
[2013.01.09 11:56:10 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\Macrovision
[2013.01.09 11:31:55 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2013.01.09 11:31:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013.01.09 11:26:20 | 000,256,000 | ---- | C] (Корпорация Майкрософт) -- C:\Users\Uli\wgsdgsdgdsgsd.dll
[2013.01.09 11:26:17 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2013.01.04 19:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP
[2013.01.04 19:04:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinSCP
[2013.01.04 18:39:25 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Local\Cranium_Consulting_and_Cu
[2013.01.04 18:39:13 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iPhoneBrowser
[2013.01.04 18:39:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iPhoneBrowser
[2013.01.01 15:12:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2013.01.01 15:08:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\2C0A
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0C0A
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0C04
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0816
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0804
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0424
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041F
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041E
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041D
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\041B
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0419
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0416
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0415
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0414
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0413
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0412
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0411
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0410
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040E
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040D
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040C
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040B
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\040A
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0409
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0408
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0406
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0405
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0404
[2013.01.01 14:41:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0401
[2013.01.01 14:31:59 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2013.01.01 14:31:59 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2013.01.01 14:31:59 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2013.01.01 14:31:59 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2013.01.01 14:31:58 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2013.01.01 14:31:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2013.01.01 14:31:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2013.01.01 14:31:58 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2013.01.01 14:31:58 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2013.01.01 14:31:58 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2013.01.01 14:31:57 | 002,075,712 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2013.01.01 14:28:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
[2013.01.01 14:28:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver-Soft
[2013.01.01 14:26:44 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2013.01.01 14:09:11 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012.12.26 19:25:39 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Local\{CA711E41-0539-4EEB-9562-C86AC7F0CC6C}
[2012.12.25 12:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012.12.24 12:16:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012.12.24 12:14:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2012.12.24 12:14:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2012.12.24 12:14:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012.12.24 12:13:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2012.12.24 12:12:23 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012.12.24 11:58:56 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.12.24 11:58:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012.12.22 21:18:42 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\MAGIX
[2012.12.22 21:18:02 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Local\Xara
[2012.12.22 21:18:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.12.22 21:17:53 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.12.22 21:17:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.12.18 16:25:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Backup & Recovery™ 2012 Free
[2012.12.17 13:56:54 | 000,444,928 | ---- | C] (Embarcadero Technologies, Inc.) -- C:\Windows\SysWow64\midas.dll
[2012.12.17 13:56:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ptv shared
[2012.12.17 13:56:50 | 000,000,000 | ---D | C] -- C:\ProgramData\PTV-AG
[2012.12.17 13:56:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PTV-AG
[2012.12.17 13:56:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\map&guide desktop 2012
[2012.12.15 11:33:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012.12.15 11:33:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012.12.12 14:53:37 | 000,000,000 | ---D | C] -- C:\Users\Uli\Documents\My Albums
[2012.12.12 14:30:51 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\Windows Live Writer
[2012.12.12 14:30:51 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Local\Windows Live Writer
[2012.12.11 21:15:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jAlbum
[2012.12.11 21:15:19 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\Jalbum AB
[2012.12.11 18:41:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.12.11 18:41:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012.12.11 06:34:56 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Roaming\dvdcss
[2012.12.10 22:23:52 | 000,000,000 | ---D | C] -- C:\Users\Uli\AppData\Local\{E6E23EE8-EC42-4FA7-BFA3-BA4FDE104813}
[2012.04.04 15:59:03 | 001,914,000 | ---- | C] (Adobe Systems Incorporated) -- C:\ProgramData\flashax10.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.01.09 17:04:03 | 000,004,049 | ---- | M] () -- C:\Windows\WINCMD.INI
[2013.01.09 17:02:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.01.09 16:19:05 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.09 16:19:04 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.09 16:19:04 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.09 16:18:15 | 001,841,962 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.09 16:18:15 | 000,787,782 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.09 16:18:15 | 000,726,226 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.09 16:18:15 | 000,180,072 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.09 16:18:15 | 000,147,006 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.09 16:12:23 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2013.01.09 16:12:21 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.09 16:11:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.09 16:11:53 | 2132,508,671 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.09 14:13:05 | 000,038,462 | ---- | M] () -- C:\Users\Uli\AppData\Roaming\Tabulatorgetrennte Werte (Windows).ADR
[2013.01.09 14:11:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000UA.job
[2013.01.09 13:34:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Uli\Desktop\OTL.exe
[2013.01.09 11:55:11 | 003,164,008 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.01.09 11:49:19 | 001,818,920 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.09 11:32:17 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2013.01.09 11:26:22 | 000,002,843 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2013.01.09 11:26:22 | 000,001,052 | ---- | M] () -- C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2013.01.09 11:26:22 | 000,000,159 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.reg
[2013.01.09 11:26:22 | 000,000,064 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.bat
[2013.01.09 11:26:20 | 000,256,000 | ---- | M] (Корпорация Майкрософт) -- C:\Users\Uli\wgsdgsdgdsgsd.dll
[2013.01.08 23:11:00 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000Core.job
[2013.01.07 14:49:52 | 000,140,678 | ---- | M] () -- C:\Users\Uli\Documents\737832_404812606269659_1365067866_o.jpg
[2013.01.06 13:50:44 | 000,027,632 | ---- | M] () -- C:\Users\Uli\Documents\Auto.jpg
[2013.01.04 20:36:50 | 000,000,600 | ---- | M] () -- C:\Users\Uli\AppData\Roaming\winscp.rnd
[2013.01.04 19:04:41 | 000,001,860 | ---- | M] () -- C:\Users\Uli\Desktop\WinSCP.lnk
[2013.01.04 19:03:16 | 000,003,019 | ---- | M] () -- C:\Users\Uli\Desktop\iPhoneBrowser.lnk
[2013.01.02 18:05:42 | 000,001,245 | ---- | M] () -- C:\Users\Uli\Desktop\Januar - Verknüpfung.lnk
[2013.01.01 14:48:58 | 000,001,713 | ---- | M] () -- C:\Users\Uli\Desktop\DriverGenius - Verknüpfung.lnk
[2012.12.30 14:12:27 | 000,000,017 | ---- | M] () -- C:\Users\Uli\AppData\Local\resmon.resmoncfg
[2012.12.24 12:22:18 | 000,002,703 | ---- | M] () -- C:\Users\Uli\Desktop\Microsoft Office Excel 2007.lnk
[2012.12.24 12:21:58 | 000,002,805 | ---- | M] () -- C:\Users\Uli\Desktop\Microsoft Office Groove 2007.lnk
[2012.12.22 21:18:01 | 000,001,142 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX Web Designer 7 Premium Download-Version.lnk
[2012.12.19 23:21:18 | 000,001,042 | ---- | M] () -- C:\Users\Uli\Desktop\PhotoScape.lnk
[2012.12.19 23:18:41 | 000,000,523 | -H-- | M] () -- C:\Windows\SysWow64\ws344069.ocx
[2012.12.19 23:18:41 | 000,000,463 | -H-- | M] () -- C:\os466477.bin
[2012.12.19 23:18:31 | 000,000,336 | ---- | M] () -- C:\Windows\ULEAD32.INI
[2012.12.17 13:57:25 | 000,002,103 | ---- | M] () -- C:\Users\Public\Desktop\map&guide desktop 2012.lnk
[2012.12.15 11:33:31 | 000,001,852 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012.12.13 04:12:44 | 000,002,485 | ---- | M] () -- C:\Users\Uli\Desktop\Google Chrome.lnk
[2012.12.12 20:01:52 | 000,266,615 | ---- | M] () -- C:\Windows\hpwins22.dat
[2012.12.11 21:15:39 | 000,001,034 | ---- | M] () -- C:\Users\Public\Desktop\jAlbum.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.01.09 14:13:05 | 000,038,462 | ---- | C] () -- C:\Users\Uli\AppData\Roaming\Tabulatorgetrennte Werte (Windows).ADR
[2013.01.09 11:32:17 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2013.01.09 11:26:22 | 000,002,843 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2013.01.09 11:26:22 | 000,001,052 | ---- | C] () -- C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2013.01.09 11:26:22 | 000,000,159 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.reg
[2013.01.09 11:26:22 | 000,000,064 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.bat
[2013.01.09 11:26:21 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2013.01.07 14:49:52 | 000,140,678 | ---- | C] () -- C:\Users\Uli\Documents\737832_404812606269659_1365067866_o.jpg
[2013.01.06 13:50:44 | 000,027,632 | ---- | C] () -- C:\Users\Uli\Documents\Auto.jpg
[2013.01.04 19:04:41 | 000,001,860 | ---- | C] () -- C:\Users\Uli\Desktop\WinSCP.lnk
[2013.01.04 19:04:41 | 000,000,600 | ---- | C] () -- C:\Users\Uli\AppData\Roaming\winscp.rnd
[2013.01.04 19:03:16 | 000,003,019 | ---- | C] () -- C:\Users\Uli\Desktop\iPhoneBrowser.lnk
[2013.01.02 18:05:42 | 000,001,245 | ---- | C] () -- C:\Users\Uli\Desktop\Januar - Verknüpfung.lnk
[2013.01.01 15:07:22 | 003,663,213 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2013.01.01 15:06:32 | 000,014,446 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2013.01.01 14:48:58 | 000,001,713 | ---- | C] () -- C:\Users\Uli\Desktop\DriverGenius - Verknüpfung.lnk
[2012.12.30 14:12:27 | 000,000,017 | ---- | C] () -- C:\Users\Uli\AppData\Local\resmon.resmoncfg
[2012.12.25 03:15:44 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.12.25 03:05:13 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.12.24 12:22:18 | 000,002,703 | ---- | C] () -- C:\Users\Uli\Desktop\Microsoft Office Excel 2007.lnk
[2012.12.24 12:21:58 | 000,002,805 | ---- | C] () -- C:\Users\Uli\Desktop\Microsoft Office Groove 2007.lnk
[2012.12.22 21:18:01 | 000,001,142 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX Web Designer 7 Premium Download-Version.lnk
[2012.12.17 13:57:25 | 000,002,115 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\map&guide desktop 2012.lnk
[2012.12.17 13:57:25 | 000,002,103 | ---- | C] () -- C:\Users\Public\Desktop\map&guide desktop 2012.lnk
[2012.12.15 11:33:31 | 000,001,852 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012.12.11 21:15:39 | 000,001,034 | ---- | C] () -- C:\Users\Public\Desktop\jAlbum.lnk
[2012.09.03 10:22:09 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\nnr.dll
[2012.08.07 10:48:01 | 000,000,336 | ---- | C] () -- C:\Windows\ULEAD32.INI
[2012.07.27 10:36:58 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2012.07.23 08:31:38 | 004,428,800 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2012.07.02 19:28:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.06.11 15:13:25 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012.06.09 18:21:56 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.05.21 17:28:58 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\mlc.dll
[2012.05.17 12:38:30 | 000,000,160 | ---- | C] () -- C:\Windows\wiso.ini
[2012.04.10 15:01:09 | 000,266,615 | ---- | C] () -- C:\Windows\hpwins22.dat
[2012.04.10 15:01:09 | 000,002,850 | ---- | C] () -- C:\Windows\hpwmdl22.dat
[2012.04.10 14:23:07 | 000,266,606 | ---- | C] () -- C:\Windows\hpwins22.dat.temp
[2012.04.10 14:23:07 | 000,002,850 | ---- | C] () -- C:\Windows\hpwmdl22.dat.temp
[2012.04.05 10:30:31 | 000,033,169 | ---- | C] () -- C:\Windows\Irremote.ini
[2012.04.05 10:29:39 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2012.04.05 10:29:39 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.04.05 10:29:29 | 000,142,337 | ---- | C] () -- C:\Windows\SysWow64\Wait.exe
[2012.04.05 10:28:48 | 000,006,198 | ---- | C] () -- C:\Windows\HCWPNP.INI
[2012.04.04 18:46:15 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.04.04 16:31:52 | 000,004,049 | ---- | C] () -- C:\Windows\WINCMD.INI
[2012.04.04 15:40:12 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2012.04.04 15:38:43 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012.04.04 15:31:07 | 001,818,920 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.12.07 22:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.04.19 12:35:15 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Arkadium
[2012.04.06 14:38:42 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Babylon
[2012.09.23 17:29:31 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Bigasoft MKV Converter
[2012.10.17 14:32:25 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Charles
[2012.07.04 20:29:44 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\convert
[2012.12.04 22:46:01 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\DATA BECKER Shared
[2012.04.09 13:35:33 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\FlashFXP
[2012.09.04 11:04:51 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\iFunbox_UserCache
[2012.08.27 15:30:43 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\ImgBurn
[2012.10.04 14:48:00 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\IrfanView
[2012.09.30 13:26:36 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\jAlbum
[2012.12.11 21:15:19 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Jalbum AB
[2012.10.21 18:35:30 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\LEGO Company
[2012.07.04 20:29:44 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\loadtbs
[2012.12.22 21:18:42 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\MAGIX
[2012.12.01 13:49:40 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\MAP&GUIDE
[2012.10.03 16:35:30 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\ObviousIdea
[2012.10.04 16:35:06 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\PhotoScape
[2012.12.04 22:27:25 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\ProtectDisc
[2012.10.27 16:57:37 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\TuneUp Software
[2013.01.09 14:41:15 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\uTorrent
[2012.07.31 19:58:58 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Win7codecs
[2012.12.12 14:30:51 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2012.12.01 14:39:33 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2012.04.04 15:53:30 | 000,000,000 | ---D | M] -- C:\25c30b0d196f4a262e3c485cb81a
[2012.10.24 18:29:02 | 000,000,000 | ---D | M] -- C:\archive_db
[2012.04.21 12:51:23 | 000,000,000 | ---D | M] -- C:\BigFishGamesCache
[2013.01.09 16:13:58 | 000,000,000 | -H-D | M] -- C:\Config.Msi
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2012.04.04 15:25:18 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.04.04 15:30:19 | 000,000,000 | ---D | M] -- C:\inetpub
[2012.12.24 12:12:23 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2013.01.09 11:31:55 | 000,000,000 | R--D | M] -- C:\Program Files
[2013.01.04 19:04:40 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2013.01.09 16:11:59 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2012.04.04 15:25:18 | 000,000,000 | -HSD | M] -- C:\Programme
[2012.04.04 15:25:18 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.09.24 16:49:35 | 000,000,000 | ---D | M] -- C:\SMNPROG
[2013.01.08 18:40:42 | 000,000,000 | ---D | M] -- C:\SMNPROGSE
[2013.01.09 17:05:56 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2013.01.01 15:07:14 | 000,000,000 | ---D | M] -- C:\TEMP
[2013.01.01 15:08:04 | 000,000,000 | R--D | M] -- C:\Users
[2013.01.09 12:11:16 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< C:\Windows\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.21 04:23:55 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU(39).TXT
[2009.07.14 06:08:49 | 000,032,640 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.04.04 15:59:42 | 000,001,100 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.04.04 15:59:42 | 000,001,104 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.04.04 16:53:00 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.09.20 16:51:00 | 000,001,060 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000Core.job
[2012.09.20 16:51:00 | 000,001,112 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000UA.job
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2010.09.13 17:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Users\Uli\Documents\DriverGenius\Backup\Driver Backup 4-28-2012-16323\Intel(R) Desktop Workstation Server Express Chipset SATA AHCI Controller\iastor.sys
[2010.09.13 17:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Users\Uli\Documents\DriverGenius\Backup\Driver Backup 4-28-2012-17358\Intel(R) Desktop Workstation Server Express Chipset SATA AHCI Controller\iastor.sys
[2010.09.13 17:24:26 | 000,437,272 | ---- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\drivers\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %USERPROFILE%\*.* >
[2013.01.09 17:12:27 | 003,932,160 | -HS- | M] () -- C:\Users\Uli\ntuser.dat
[2013.01.09 17:12:27 | 000,262,144 | -HS- | M] () -- C:\Users\Uli\ntuser.dat.LOG1
[2012.04.04 15:25:20 | 000,000,000 | -HS- | M] () -- C:\Users\Uli\ntuser.dat.LOG2
[2012.04.04 15:36:35 | 000,065,536 | -HS- | M] () -- C:\Users\Uli\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2012.04.04 15:36:35 | 000,524,288 | -HS- | M] () -- C:\Users\Uli\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2012.04.04 15:36:35 | 000,524,288 | -HS- | M] () -- C:\Users\Uli\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012.12.03 21:08:39 | 000,065,536 | -HS- | M] () -- C:\Users\Uli\ntuser.dat{36dc042d-3d81-11e2-82d6-40618675bd3a}.TM.blf
[2012.12.03 21:08:39 | 000,524,288 | -HS- | M] () -- C:\Users\Uli\ntuser.dat{36dc042d-3d81-11e2-82d6-40618675bd3a}.TMContainer00000000000000000001.regtrans-ms
[2012.12.03 21:08:39 | 000,524,288 | -HS- | M] () -- C:\Users\Uli\ntuser.dat{36dc042d-3d81-11e2-82d6-40618675bd3a}.TMContainer00000000000000000002.regtrans-ms
[2012.04.04 15:25:22 | 000,000,020 | -HS- | M] () -- C:\Users\Uli\ntuser.ini
[2013.01.09 11:26:20 | 000,256,000 | ---- | M] (Корпорация Майкрософт) -- C:\Users\Uli\wgsdgsdgdsgsd.dll
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Optional: Posix [binary data] [2010.11.21 04:24:41 | 000,089,088 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindowsPosix [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:EB333CFC
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:C8B8CEBD

< End of report >
         
--- --- ---

Wo finde ich denn die Extra.txt ?

Danke euch.
__________________

Alt 09.01.2013, 17:25   #4
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:
ATTFilter
:OTL
[2013.01.09 11:26:22 | 000,002,843 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2013.01.09 11:26:22 | 000,001,052 | ---- | C] () -- C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2013.01.09 11:26:22 | 000,000,159 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.reg
[2013.01.09 11:26:22 | 000,000,064 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.bat
[2013.01.09 11:26:21 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
 :Files
:Commands
[EMPTYFLASH] 
[emptytemp]
         


• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 09.01.2013, 17:35   #5
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Erst mal, super !

Der Rechner startet normal. Keine GUV mehr. Ich hoffe es war es mit ihm.

Hier das File:
PHP-Code:
All processes killed
========== OTL ==========
C:\ProgramData\dsgsdgdsgdsgw.js moved successfully.
C:\Users\Uli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk moved successfully.
C:\ProgramData\dsgsdgdsgdsgw.reg moved successfully.
C:\ProgramData\dsgsdgdsgdsgw.bat moved successfully.
C:\ProgramData\dsgsdgdsgdsgw.pad moved successfully.
========== 
COMMANDS ==========
 
[
EMPTYFLASH]
 
UserAll Users
 
User
Classic .NET AppPool
 
User
: Default
 
User: Default User
 
User
DefaultAppPool
 
User
Mcx1-KARLCHEN
 
User
: Public
 
UserUli
->Flash cache emptied2891 bytes
 
User
UpdatusUser
 
Total Flash Files Cleaned 
0,00 mb
 
 
[EMPTYTEMP]
 
UserAll Users
 
User
Classic .NET AppPool
->Temp folder emptied0 bytes
->Temporary Internet Files folder emptied0 bytes
 
User
: Default
->
Temp folder emptied0 bytes
->Temporary Internet Files folder emptied33170 bytes
 
User
: Default User
->Temp folder emptied0 bytes
->Temporary Internet Files folder emptied0 bytes
 
User
DefaultAppPool
->Temp folder emptied0 bytes
->Temporary Internet Files folder emptied33170 bytes
 
User
Mcx1-KARLCHEN
->Temp folder emptied516 bytes
->Temporary Internet Files folder emptied41733778 bytes
 
User
: Public
 
UserUli
->Temp folder emptied36058706 bytes
->Temporary Internet Files folder emptied2651979 bytes
->Java cache emptied266632 bytes
->FireFox cache emptied169354164 bytes
->Google Chrome cache emptied29724663 bytes
->Flash cache emptied0 bytes
 
User
UpdatusUser
->Temp folder emptied0 bytes
->Temporary Internet Files folder emptied33170 bytes
 
%systemdrive% .tmp files removed0 bytes
%systemroot% .tmp files removed1715858 bytes
%systemroot%\System32 .tmp files removed0 bytes
%systemroot%\System32 (64bit) .tmp files removed0 bytes
%systemroot%\System32\drivers .tmp files removed0 bytes
Windows Temp folder emptied
61290752 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied756674 bytes
RecycleBin emptied
166480 bytes
 
Total Files Cleaned 
328,00 mb
 
 
OTL by OldTimer 
Version 3.2.69.0 log created on 01092013_172851

Files
\Folders moved on Reboot...
C:\Users\Uli\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R16AE.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R16B0.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R16C2.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R16E3.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1714.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1725.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1727.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1739.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R175A.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R176C.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R177D.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R179E.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R17A0.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R17B2.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R17D3.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R17E5.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R17F6.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1818.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1829.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R182B.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R185C.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R185E.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R1870.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R280A.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R5EE4.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R5F05.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R5F46.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@R61E7.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@RA718.tmp moved successfully.
C:\Users\Uli\AppData\Local\Temp\Z@RA785.tmp moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot... 
Besten Dank noch einmal.


Alt 09.01.2013, 17:36   #6
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hi
download tdss killer:
http://www.trojaner-board.de/82358-t...entfernen.html
Klicke auf Change parameters
• Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system
• Klick auf OK und anschließend auf Start scan
- bei funden erst mal immer skip wählen, log posten
__________________
--> GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert

Alt 09.01.2013, 17:42   #7
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



OK.

Hier das Log.

PHP-Code:
17:38:57.0991 2016  TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17
:38:58.0085 2016  ============================================================
17:38:58.0085 2016  Current date time2013/01/09 17:38:58.0085
17
:38:58.0085 2016  SystemInfo:
17:38:58.0085 2016  
17
:38:58.0085 2016  OS Version6.1.7601 ServicePack1.0
17
:38:58.0085 2016  Product typeWorkstation
17
:38:58.0085 2016  ComputerNameKARLCHEN
17
:38:58.0085 2016  UserNameUli
17
:38:58.0085 2016  Windows directoryC:\Windows
17
:38:58.0085 2016  System windows directoryC:\Windows
17
:38:58.0085 2016  Running under WOW64
17
:38:58.0100 2016  Processor architectureIntel x64
17
:38:58.0100 2016  Number of processors8
17
:38:58.0100 2016  Page size0x1000
17
:38:58.0100 2016  Boot typeNormal boot
17
:38:58.0100 2016  ============================================================
17:38:58.0662 2016  Drive \Device\Harddisk0\DR0 Size0x12A1F16000 (74.53 Gb), SectorSize0x200Cylinders0x2601SectorsPerTrack0x3FTracksPerCylinder0xFFType 'K0'Flags 0x00000040
17
:38:58.0693 2016  Drive \Device\Harddisk1\DR1 Size0x15D50F66000 (1397.27 Gb), SectorSize0x200Cylinders0x2C881SectorsPerTrack0x3FTracksPerCylinder0xFFType 'K0'Flags 0x00000040
17
:38:58.0693 2016  Drive \Device\Harddisk2\DR2 Size0x7470C06000 (465.76 Gb), SectorSize0x200Cylinders0xED81SectorsPerTrack0x3FTracksPerCylinder0xFFType 'K0'Flags 0x00000040
17
:38:58.0709 2016  ============================================================
17:38:58.0709 2016  \Device\Harddisk0\DR0:
17:38:58.0709 2016  MBR partitions:
17:38:58.0709 2016  \Device\Harddisk0\DR0\Partition1MBRType 0x7StartLBA 0x800BlocksNum 0x32000
17
:38:58.0709 2016  \Device\Harddisk0\DR0\Partition2MBRType 0x7StartLBA 0x32800BlocksNum 0x94DC800
17
:38:58.0709 2016  \Device\Harddisk1\DR1:
17:38:58.0709 2016  MBR partitions:
17:38:58.0709 2016  \Device\Harddisk1\DR1\Partition1MBRType 0x7StartLBA 0x800BlocksNum 0x91E39800
17
:38:58.0724 2016  \Device\Harddisk1\DR1\Partition2MBRType 0x7StartLBA 0x91E3A800BlocksNum 0xC34F800
17
:38:58.0724 2016  \Device\Harddisk1\DR1\Partition3MBRType 0x7StartLBA 0x9E18A000BlocksNum 0xD6D7800
17
:38:58.0724 2016  \Device\Harddisk2\DR2:
17:38:58.0724 2016  MBR partitions:
17:38:58.0724 2016  \Device\Harddisk2\DR2\Partition1MBRType 0x7StartLBA 0x3FBlocksNum 0x3A384C02
17
:38:58.0724 2016  ============================================================
17:38:58.0724 2016  C: <-> \Device\Harddisk0\DR0\Partition2
17
:38:58.0787 2016  D: <-> \Device\Harddisk1\DR1\Partition1
17
:38:58.0802 2016  E: <-> \Device\Harddisk2\DR2\Partition1
17
:38:58.0849 2016  G: <-> \Device\Harddisk1\DR1\Partition3
17
:38:58.0896 2016  H: <-> \Device\Harddisk1\DR1\Partition2
17
:38:58.0896 2016  ============================================================
17:38:58.0896 2016  Initialize success
17
:38:58.0896 2016  ============================================================
17:39:31.0659 4812  ============================================================
17:39:31.0659 4812  Scan started
17
:39:31.0659 4812  ModeManualSigCheckTDLFS
17:39:31.0659 4812  ============================================================
17:39:31.0830 4812  ================ Scan system memory ========================
17:39:31.0830 4812  System memory ok
17
:39:31.0830 4812  ================ Scan services =============================
17:39:31.0846 4812  A87D604AEA360176311474C87A63BB88 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
17
:39:31.0877 4812  1394ohci ok
17
:39:31.0877 4812  A3769020F7E8A70FD3E824C050F33306 acedrv11        C:\Windows\system32\drivers\acedrv11.sys
17
:39:31.0893 4812  acedrv11 ok
17
:39:31.0893 4812  D81D9E70B8A6DD14D42D7B4EFA65D5F2 ACPI            C:\Windows\system32\drivers\ACPI.sys
17
:39:31.0908 4812  ACPI ok
17
:39:31.0908 4812  99F8E788246D495CE3794D7E7821D2CA AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
17
:39:31.0924 4812  AcpiPmi ok
17
:39:31.0924 4812  2F0683FD2DF1D92E891CACA14B45A8C1 adfs            C:\Windows\system32\drivers\adfs.sys
17
:39:31.0939 4812  adfs ok
17
:39:31.0955 4812  424877CB9D5517F980FF7BACA2EB379D AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
17
:39:31.0955 4812  AdobeFlashPlayerUpdateSvc ok
17
:39:31.0955 4812  2F6B34B83843F0C5118B63AC634F5BF4 adp94xx         C:\Windows\system32\drivers\adp94xx.sys
17
:39:31.0971 4812  adp94xx ok
17
:39:31.0986 4812  597F78224EE9224EA1A13D6350CED962 adpahci         C:\Windows\system32\drivers\adpahci.sys
17
:39:31.0986 4812  adpahci ok
17
:39:31.0986 4812  E109549C90F62FB570B9540C4B148E54 adpu320         C:\Windows\system32\drivers\adpu320.sys
17
:39:32.0002 4812  adpu320 ok
17
:39:32.0002 4812  4B78B431F225FD8624C5655CB1DE7B61 AeLookupSvc     C:\Windows\System32\aelupsvc.dll
17
:39:32.0049 4812  AeLookupSvc ok
17
:39:32.0049 4812  1C7857B62DE5994A75B054A9FD4C3825 AFD             C:\Windows\system32\drivers\afd.sys
17
:39:32.0064 4812  AFD ok
17
:39:32.0064 4812  608C14DBA7299D8CB6ED035A68A15799 agp440          C:\Windows\system32\drivers\agp440.sys
17
:39:32.0080 4812  agp440 ok
17
:39:32.0080 4812  3290D6946B5E30E70414990574883DDB ALG             C:\Windows\System32\alg.exe
17
:39:32.0095 4812  ALG ok
17
:39:32.0095 4812  5812713A477A3AD7363C7438CA2EE038 aliide          C:\Windows\system32\drivers\aliide.sys
17
:39:32.0095 4812  aliide ok
17
:39:32.0095 4812  1FF8B4431C353CE385C875F194924C0C amdide          C:\Windows\system32\drivers\amdide.sys
17
:39:32.0095 4812  amdide ok
17
:39:32.0111 4812  7024F087CFF1833A806193EF9D22CDA9 AmdK8           C:\Windows\system32\drivers\amdk8.sys
17
:39:32.0111 4812  AmdK8 ok
17
:39:32.0111 4812  1E56388B3FE0D031C44144EB8C4D6217 AmdPPM          C:\Windows\system32\drivers\amdppm.sys
17
:39:32.0127 4812  AmdPPM ok
17
:39:32.0127 4812  D4121AE6D0C0E7E13AA221AA57EF2D49 amdsata         C:\Windows\system32\drivers\amdsata.sys
17
:39:32.0127 4812  amdsata ok
17
:39:32.0142 4812  F67F933E79241ED32FF46A4F29B5120B amdsbs          C:\Windows\system32\drivers\amdsbs.sys
17
:39:32.0142 4812  amdsbs ok
17
:39:32.0142 4812  540DAF1CEA6094886D72126FD7C33048 amdxata         C:\Windows\system32\drivers\amdxata.sys
17
:39:32.0158 4812  amdxata ok
17
:39:32.0158 4812  59D01FA91962C9C1E9B4022B2D3B46DB AppHostSvc      C:\Windows\system32\inetsrv\apphostsvc.dll
17
:39:32.0158 4812  AppHostSvc ok
17
:39:32.0158 4812  89A69C3F2F319B43379399547526D952 AppID           C:\Windows\system32\drivers\appid.sys
17
:39:32.0220 4812  AppID ok
17
:39:32.0220 4812  0BC381A15355A3982216F7172F545DE1 AppIDSvc        C:\Windows\System32\appidsvc.dll
17
:39:32.0251 4812  AppIDSvc ok
17
:39:32.0251 4812  3977D4A871CA0D4F2ED1E7DB46829731 Appinfo         C:\Windows\System32\appinfo.dll
17
:39:32.0267 4812  Appinfo ok
17
:39:32.0267 4812  A5299D04ED225D64CF07A568A3E1BF8C Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17
:39:32.0283 4812  Apple Mobile Device ok
17
:39:32.0283 4812  4ABA3E75A76195A3E38ED2766C962899 AppMgmt         C:\Windows\System32\appmgmts.dll
17
:39:32.0298 4812  AppMgmt ok
17
:39:32.0298 4812  C484F8CEB1717C540242531DB7845C4E arc             C:\Windows\system32\drivers\arc.sys
17
:39:32.0298 4812  arc ok
17
:39:32.0298 4812  019AF6924AEFE7839F61C830227FE79C arcsas          C:\Windows\system32\drivers\arcsas.sys
17
:39:32.0314 4812  arcsas ok
17
:39:32.0329 4812  9217D874131AE6FF8F642F124F00A555 aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17
:39:32.0329 4812  aspnet_state ok
17
:39:32.0329 4812  769765CE2CC62867468CEA93969B2242 AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
17
:39:32.0345 4812  AsyncMac ok
17
:39:32.0345 4812  02062C0B390B7729EDC9E69C680A6F3C atapi           C:\Windows\system32\drivers\atapi.sys
17
:39:32.0361 4812  atapi ok
17
:39:32.0361 4812  F23FEF6D569FCE88671949894A8BECF1 AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17
:39:32.0392 4812  AudioEndpointBuilder ok
17
:39:32.0392 4812  F23FEF6D569FCE88671949894A8BECF1 AudioSrv        C:\Windows\System32\Audiosrv.dll
17
:39:32.0423 4812  AudioSrv ok
17
:39:32.0423 4812  A6BF31A71B409DFA8CAC83159E1E2AFF AxInstSV        C:\Windows\System32\AxInstSV.dll
17
:39:32.0439 4812  AxInstSV ok
17
:39:32.0439 4812  3E5B191307609F7514148C6832BB0842 b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
17
:39:32.0454 4812  b06bdrv ok
17
:39:32.0454 4812  B5ACE6968304A3900EEB1EBFD9622DF2 b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
17
:39:32.0470 4812  b57nd60a ok
17
:39:32.0470 4812  FDE360167101B4E45A96F939F388AEB0 BDESVC          C:\Windows\System32\bdesvc.dll
17
:39:32.0485 4812  BDESVC ok
17
:39:32.0485 4812  16A47CE2DECC9B099349A5F840654746 Beep            C:\Windows\system32\drivers\Beep.sys
17
:39:32.0501 4812  Beep ok
17
:39:32.0517 4812  82974D6A2FD19445CC5171FC378668A4 BFE             C:\Windows\System32\bfe.dll
17
:39:32.0532 4812  BFE ok
17
:39:32.0548 4812  1EA7969E3271CBC59E1730697DC74682 BITS            C:\Windows\System32\qmgr.dll
17
:39:32.0579 4812  BITS ok
17
:39:32.0579 4812  61583EE3C3A17003C4ACD0475646B4D3 blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
17
:39:32.0595 4812  blbdrive ok
17
:39:32.0595 4812  EBBCD5DFBB1DE70E8F4AF8FA59E401FD Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
17
:39:32.0610 4812  Bonjour Service ok
17
:39:32.0610 4812  6C02A83164F5CC0A262F4199F0871CF5 bowser          C:\Windows\system32\DRIVERS\bowser.sys
17
:39:32.0610 4812  bowser ok
17
:39:32.0610 4812  F09EEE9EDC320B5E1501F749FDE686C8 BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
17
:39:32.0626 4812  BrFiltLo ok
17
:39:32.0626 4812  B114D3098E9BDB8BEA8B053685831BE6 BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
17
:39:32.0626 4812  BrFiltUp ok
17
:39:32.0641 4812  05F5A0D14A2EE1D8255C2AA0E9E8E694 Browser         C:\Windows\System32\browser.dll
17
:39:32.0641 4812  Browser ok
17
:39:32.0641 4812  43BEA8D483BF1870F018E2D02E06A5BD Brserid         C:\Windows\System32\Drivers\Brserid.sys
17
:39:32.0657 4812  Brserid ok
17
:39:32.0657 4812  A6ECA2151B08A09CACECA35C07F05B42 BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
17
:39:32.0673 4812  BrSerWdm ok
17
:39:32.0673 4812  B79968002C277E869CF38BD22CD61524 BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
17
:39:32.0688 4812  BrUsbMdm ok
17
:39:32.0688 4812  A87528880231C54E75EA7A44943B38BF BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
17
:39:32.0688 4812  BrUsbSer ok
17
:39:32.0688 4812  9DA669F11D1F894AB4EB69BF546A42E8 BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
17
:39:32.0704 4812  BTHMODEM ok
17
:39:32.0704 4812  95F9C2976059462CBBF227F7AAB10DE9 bthserv         C:\Windows\system32\bthserv.dll
17
:39:32.0719 4812  bthserv ok
17
:39:32.0719 4812  B8BD2BB284668C84865658C77574381A cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
17
:39:32.0751 4812  cdfs ok
17
:39:32.0751 4812  F036CE71586E93D94DAB220D7BDF4416 cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
17
:39:32.0751 4812  cdrom ok
17
:39:32.0766 4812  CDCAD33F35DA17DB93BC844B02D9EDDF CEEBC40A-FDED-4C59-B354-939132350B01 C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe
17
:39:32.0766 4812  CEEBC40A-FDED-4C59-B354-939132350B01 ok
17
:39:32.0766 4812  F17D1D393BBC69C5322FBFAFACA28C7F CertPropSvc     C:\Windows\System32\certprop.dll
17
:39:32.0782 4812  CertPropSvc ok
17
:39:32.0797 4812  D7CD5C4E1B71FA62050515314CFB52CF circlass        C:\Windows\system32\drivers\circlass.sys
17
:39:32.0797 4812  circlass ok
17
:39:32.0797 4812  FF60401F1C659CA2ED4BAE85D3FD14DA CISVC           C:\Windows\system32\CISVC.EXE
17
:39:32.0813 4812  CISVC ok
17
:39:32.0813 4812  FE1EC06F2253F691FE36217C592A0206 CLFS            C:\Windows\system32\CLFS.sys
17
:39:32.0829 4812  CLFS ok
17
:39:32.0829 4812  D88040F816FDA31C3B466F0FA0918F29 clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17
:39:32.0829 4812  clr_optimization_v2.0.50727_32 ok
17
:39:32.0829 4812  D1CEEA2B47CB998321C579651CE3E4F8 clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17
:39:32.0844 4812  clr_optimization_v2.0.50727_64 ok
17
:39:32.0844 4812  C5A75EB48E2344ABDC162BDA79E16841 clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17
:39:32.0860 4812  clr_optimization_v4.0.30319_32 ok
17
:39:32.0860 4812  C6F9AF94DCD58122A4D7E89DB6BED29D clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17
:39:32.0860 4812  clr_optimization_v4.0.30319_64 ok
17
:39:32.0860 4812  0840155D0BDDF1190F84A663C284BD33 CmBatt          C:\Windows\system32\drivers\CmBatt.sys
17
:39:32.0875 4812  CmBatt ok
17
:39:32.0875 4812  E19D3F095812725D88F9001985B94EDD cmdide          C:\Windows\system32\drivers\cmdide.sys
17
:39:32.0875 4812  cmdide ok
17
:39:32.0891 4812  9AC4F97C2D3E93367E2148EA940CD2CD CNG             C:\Windows\system32\Drivers\cng.sys
17
:39:32.0907 4812  CNG ok
17
:39:32.0907 4812  102DE219C3F61415F964C88E9085AD14 Compbatt        C:\Windows\system32\drivers\compbatt.sys
17
:39:32.0907 4812  Compbatt ok
17
:39:32.0907 4812  03EDB043586CCEBA243D689BDDA370A8 CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
17
:39:32.0922 4812  CompositeBus ok
17
:39:32.0922 4812  COMSysApp ok
17
:39:32.0922 4812  1C827878A998C18847245FE1F34EE597 crcdisk         C:\Windows\system32\drivers\crcdisk.sys
17
:39:32.0938 4812  crcdisk ok
17
:39:32.0938 4812  9C01375BE382E834CC26D1B7EAF2C4FE CryptSvc        C:\Windows\system32\cryptsvc.dll
17
:39:32.0938 4812  CryptSvc ok
17
:39:32.0953 4812  54DA3DFD29ED9F1619B6F53F3CE55E49 CSC             C:\Windows\system32\drivers\csc.sys
17
:39:32.0969 4812  CSC ok
17
:39:32.0969 4812  3AB183AB4D2C79DCF459CD2C1266B043 CscService      C:\Windows\System32\cscsvc.dll
17
:39:32.0985 4812  CscService ok
17
:39:32.0985 4812  5C627D1B1138676C0A7AB2C2C190D123 DcomLaunch      C:\Windows\system32\rpcss.dll
17
:39:33.0016 4812  DcomLaunch ok
17
:39:33.0016 4812  3CEC7631A84943677AA8FA8EE5B6B43D defragsvc       C:\Windows\System32\defragsvc.dll
17
:39:33.0047 4812  defragsvc ok
17
:39:33.0047 4812  9BB2EF44EAA163B29C4A4587887A0FE4 DfsC            C:\Windows\system32\Drivers\dfsc.sys
17
:39:33.0063 4812  DfsC ok
17
:39:33.0078 4812  43D808F5D9E1A18E5EEB5EBC83969E4E Dhcp            C:\Windows\system32\dhcpcore.dll
17
:39:33.0078 4812  Dhcp ok
17
:39:33.0078 4812  13096B05847EC78F0977F2C0F79E9AB3 discache        C:\Windows\system32\drivers\discache.sys
17
:39:33.0109 4812  discache ok
17
:39:33.0109 4812  9819EEE8B5EA3784EC4AF3B137A5244C Disk            C:\Windows\system32\drivers\disk.sys
17
:39:33.0109 4812  Disk ok
17
:39:33.0109 4812  5DB085A8A6600BE6401F2B24EECB5415 dmvsc           C:\Windows\system32\drivers\dmvsc.sys
17
:39:33.0125 4812  dmvsc ok
17
:39:33.0125 4812  16835866AAA693C7D7FCEBA8FFF706E4 Dnscache        C:\Windows\System32\dnsrslvr.dll
17
:39:33.0141 4812  Dnscache ok
17
:39:33.0141 4812  B1FB3DDCA0FDF408750D5843591AFBC6 dot3svc         C:\Windows\System32\dot3svc.dll
17
:39:33.0156 4812  dot3svc ok
17
:39:33.0172 4812  B42ED0320C6E41102FDE0005154849BB Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
17
:39:33.0172 4812  Dot4 ok
17
:39:33.0172 4812  E9F5969233C5D89F3C35E3A66A52A361 Dot4Print       C:\Windows\system32\DRIVERS\Dot4Prt.sys
17
:39:33.0187 4812  Dot4Print ok
17
:39:33.0187 4812  FD05A02B0370BC3000F402E543CA5814 dot4usb         C:\Windows\system32\DRIVERS\dot4usb.sys
17
:39:33.0187 4812  dot4usb ok
17
:39:33.0203 4812  B26F4F737E8F9DF4F31AF6CF31D05820 DPS             C:\Windows\system32\dps.dll
17
:39:33.0219 4812  DPS ok
17
:39:33.0219 4812  9B19F34400D24DF84C858A421C205754 drmkaud         C:\Windows\system32\drivers\drmkaud.sys
17
:39:33.0234 4812  drmkaud ok
17
:39:33.0234 4812  F5BEE30450E18E6B83A5012C100616FD DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
17
:39:33.0250 4812  DXGKrnl ok
17
:39:33.0265 4812  1BEF2C2E229452EC49FFE5A27283341D e1cexpress      C:\Windows\system32\DRIVERS\e1c62x64.sys
17
:39:33.0265 4812  e1cexpress ok
17
:39:33.0265 4812  E2DDA8726DA9CB5B2C4000C9018A9633 EapHost         C:\Windows\System32\eapsvc.dll
17
:39:33.0297 4812  EapHost ok
17
:39:33.0312 4812  DC5D737F51BE844D8C82C695EB17372F ebdrv           C:\Windows\system32\drivers\evbda.sys
17
:39:33.0359 4812  ebdrv ok
17
:39:33.0359 4812  C118A82CD78818C29AB228366EBF81C3 EFS             C:\Windows\System32\lsass.exe
17
:39:33.0359 4812  EFS ok
17
:39:33.0375 4812  C4002B6B41975F057D98C439030CEA07 ehRecvr         C:\Windows\ehome\ehRecvr.exe
17
:39:33.0390 4812  ehRecvr ok
17
:39:33.0390 4812  4705E8EF9934482C5BB488CE28AFC681 ehSched         C:\Windows\ehome\ehsched.exe
17
:39:33.0406 4812  ehSched ok
17
:39:33.0406 4812  9387A484D31209D7FC3F795A787294DB ElbyCDFL        C:\Windows\system32\Drivers\ElbyCDFL.sys
17
:39:33.0406 4812  ElbyCDFL ok
17
:39:33.0406 4812  A05FC7ECA0966EBB70E4D17B855A853B ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
17
:39:33.0421 4812  ElbyCDIO ok
17
:39:33.0421 4812  0E5DA5369A0FCAEA12456DD852545184 elxstor         C:\Windows\system32\drivers\elxstor.sys
17
:39:33.0437 4812  elxstor ok
17
:39:33.0437 4812  34A3C54752046E79A126E15C51DB409B ErrDev          C:\Windows\system32\drivers\errdev.sys
17
:39:33.0437 4812  ErrDev ok
17
:39:33.0453 4812  esgiguard ok
17
:39:33.0453 4812  4166F82BE4D24938977DD1746BE9B8A0 EventSystem     C:\Windows\system32\es.dll
17
:39:33.0484 4812  EventSystem ok
17
:39:33.0484 4812  A510C654EC00C1E9BDD91EEB3A59823B exfat           C:\Windows\system32\drivers\exfat.sys
17
:39:33.0499 4812  exfat ok
17
:39:33.0499 4812  0ADC83218B66A6DB380C330836F3E36D fastfat         C:\Windows\system32\drivers\fastfat.sys
17
:39:33.0531 4812  fastfat ok
17
:39:33.0531 4812  DBEFD454F8318A0EF691FDD2EAAB44EB Fax             C:\Windows\system32\fxssvc.exe
17
:39:33.0546 4812  Fax ok
17
:39:33.0562 4812  D765D19CD8EF61F650C384F62FAC00AB fdc             C:\Windows\system32\drivers\fdc.sys
17
:39:33.0562 4812  fdc ok
17
:39:33.0562 4812  0438CAB2E03F4FB61455A7956026FE86 fdPHost         C:\Windows\system32\fdPHost.dll
17
:39:33.0577 4812  fdPHost ok
17
:39:33.0593 4812  802496CB59A30349F9A6DD22D6947644 FDResPub        C:\Windows\system32\fdrespub.dll
17
:39:33.0609 4812  FDResPub ok
17
:39:33.0609 4812  655661BE46B5F5F3FD454E2C3095B930 FileInfo        C:\Windows\system32\drivers\fileinfo.sys
17
:39:33.0609 4812  FileInfo ok
17
:39:33.0609 4812  5F671AB5BC87EEA04EC38A6CD5962A47 Filetrace       C:\Windows\system32\drivers\filetrace.sys
17
:39:33.0640 4812  Filetrace ok
17
:39:33.0640 4812  1F63900E2EB00101B9ACA2B7A870704E FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
17
:39:33.0655 4812  FLEXnet Licensing Service ok
17
:39:33.0655 4812  C172A0F53008EAEB8EA33FE10E177AF5 flpydisk        C:\Windows\system32\drivers\flpydisk.sys
17
:39:33.0671 4812  flpydisk ok
17
:39:33.0671 4812  DA6B67270FD9DB3697B20FCE94950741 FltMgr          C:\Windows\system32\drivers\fltmgr.sys
17
:39:33.0671 4812  FltMgr ok
17
:39:33.0687 4812  5C4CB4086FB83115B153E47ADD961A0C FontCache       C:\Windows\system32\FntCache.dll
17
:39:33.0702 4812  FontCache ok
17
:39:33.0718 4812  A8B7F3818AB65695E3A0BB3279F6DCE6 FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17
:39:33.0718 4812  FontCache3.0.0.0 ok
17
:39:33.0718 4812  D43703496149971890703B4B1B723EAC FsDepends       C:\Windows\system32\drivers\FsDepends.sys
17
:39:33.0718 4812  FsDepends ok
17
:39:33.0718 4812  6BD9295CC032DD3077C671FCCF579A7B Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
17
:39:33.0733 4812  Fs_Rec ok
17
:39:33.0733 4812  D225864F6FD96575A303A20BD42383ED ftpsvc          C:\Windows\system32\inetsrv\ftpsvc.dll
17
:39:33.0749 4812  ftpsvc ok
17
:39:33.0749 4812  1F7B25B858FA27015169FE95E54108ED fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
17
:39:33.0765 4812  fvevol ok
17
:39:33.0765 4812  8C778D335C9D272CFD3298AB02ABE3B6 gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
17
:39:33.0765 4812  gagp30kx ok
17
:39:33.0765 4812  8E98D21EE06192492A5671A6144D092F GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17
:39:33.0765 4812  GEARAspiWDM ok
17
:39:33.0780 4812  277BBC7E1AA1EE957F573A10ECA7EF3A gpsvc           C:\Windows\System32\gpsvc.dll
17
:39:33.0811 4812  gpsvc ok
17
:39:33.0811 4812  F02A533F517EB38333CB12A9E8963773 gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17
:39:33.0811 4812  gupdate ok
17
:39:33.0827 4812  F02A533F517EB38333CB12A9E8963773 gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17
:39:33.0827 4812  gupdatem ok
17
:39:33.0827 4812  5D4BC124FAAE6730AC002CDB67BF1A1C gusvc           C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
17
:39:33.0827 4812  gusvc ok
17
:39:33.0843 4812  593FA686FC0A5993784271F8EF6DB596 HauppaugeTVServer C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
17
:39:33.0843 4812  HauppaugeTVServer UnsignedFile.Multi.Generic ) - warning
17
:39:33.0843 4812  HauppaugeTVServer detected UnsignedFile.Multi.Generic (1)
17:39:33.0843 4812  D5D568E05D306C5E6EEDE22C89060C2F hcw17bda        C:\Windows\system32\drivers\hcw17bda.sys
17
:39:33.0858 4812  hcw17bda ok
17
:39:33.0858 4812  F2523EF6460FC42405B12248338AB2F0 hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
17
:39:33.0858 4812  hcw85cir ok
17
:39:33.0874 4812  975761C778E33CD22498059B91E7373A HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17
:39:33.0874 4812  HdAudAddService ok
17
:39:33.0889 4812  97BFED39B6B79EB12CDDBFEED51F56BB HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
17
:39:33.0889 4812  HDAudBus ok
17
:39:33.0889 4812  78E86380454A7B10A5EB255DC44A355F HidBatt         C:\Windows\system32\drivers\HidBatt.sys
17
:39:33.0905 4812  HidBatt ok
17
:39:33.0905 4812  7FD2A313F7AFE5C4DAB14798C48DD104 HidBth          C:\Windows\system32\drivers\hidbth.sys
17
:39:33.0921 4812  HidBth ok
17
:39:33.0921 4812  0A77D29F311B88CFAE3B13F9C1A73825 HidIr           C:\Windows\system32\drivers\hidir.sys
17
:39:33.0921 4812  HidIr ok
17
:39:33.0921 4812  BD9EB3958F213F96B97B1D897DEE006D hidserv         C:\Windows\system32\hidserv.dll
17
:39:33.0952 4812  hidserv ok
17
:39:33.0952 4812  9592090A7E2B61CD582B612B6DF70536 HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
17
:39:33.0952 4812  HidUsb ok
17
:39:33.0952 4812  387E72E739E15E3D37907A86D9FF98E2 hkmsvc          C:\Windows\system32\kmsvc.dll
17
:39:33.0983 4812  hkmsvc ok
17
:39:33.0983 4812  EFDFB3DD38A4376F93E7985173813ABD HomeGroupListener C:\Windows\system32\ListSvc.dll
17
:39:33.0983 4812  HomeGroupListener ok
17
:39:33.0999 4812  908ACB1F594274965A53926B10C81E89 HomeGroupProvider C:\Windows\system32\provsvc.dll
17
:39:33.0999 4812  HomeGroupProvider ok
17
:39:34.0014 4812  97AAC45A375168C6A2297BEEB9692E31 hpqcxs08        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
17
:39:34.0014 4812  hpqcxs08 ok
17
:39:34.0014 4812  19A4FB67B1C97EA18EDFF44340973CD9 hpqddsvc        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
17
:39:34.0030 4812  hpqddsvc ok
17
:39:34.0030 4812  39D2ABCD392F3D8A6DCE7B60AE7B8EFC HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
17
:39:34.0030 4812  HpSAMD ok
17
:39:34.0045 4812  F37882F128EFACEFE353E0BAE2766909 HPSLPSVC        C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
17
:39:34.0061 4812  HPSLPSVC UnsignedFile.Multi.Generic ) - warning
17
:39:34.0061 4812  HPSLPSVC detected UnsignedFile.Multi.Generic (1)
17:39:34.0061 4812  0EA7DE1ACB728DD5A369FD742D6EEE28 HTTP            C:\Windows\system32\drivers\HTTP.sys
17
:39:34.0092 4812  HTTP ok
17
:39:34.0092 4812  A5462BD6884960C9DC85ED49D34FF392 hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
17
:39:34.0092 4812  hwpolicy ok
17
:39:34.0108 4812  FA55C73D4AFFA7EE23AC4BE53B4592D3 i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
17
:39:34.0108 4812  i8042prt ok
17
:39:34.0108 4812  F7CE9BE72EDAC499B713ECA6DAE5D26F iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
17
:39:34.0123 4812  iaStor ok
17
:39:34.0139 4812  AE0C5DF7E7DA3E7AC29B64CFA8C4F044 iaStorA         C:\Windows\system32\DRIVERS\iaStorA.sys
17
:39:34.0139 4812  iaStorA ok
17
:39:34.0139 4812  777788D9B63CCEEEF2DB353BA4EDD454 IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(RRapid Storage Technology\IAStorDataMgrSvc.exe
17
:39:34.0155 4812  IAStorDataMgrSvc ok
17
:39:34.0155 4812  711241EA1BA9DB44F34D03D2AD00ED08 iaStorF         C:\Windows\system32\DRIVERS\iaStorF.sys
17
:39:34.0155 4812  iaStorF ok
17
:39:34.0155 4812  AAAF44DB3BD0B9D1FB6969B23ECC8366 iaStorV         C:\Windows\system32\drivers\iaStorV.sys
17
:39:34.0170 4812  iaStorV ok
17
:39:34.0201 4812  829EA5ECCAA623279D94EAEE3B5AD140 IconMan_R       C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
17
:39:34.0233 4812  IconMan_R ok
17
:39:34.0248 4812  5988FC40F8DB5B0739CD1E3A5D0D78BD idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17
:39:34.0264 4812  idsvc ok
17
:39:34.0264 4812  5C18831C61933628F5BB0EA2675B9D21 iirsp           C:\Windows\system32\drivers\iirsp.sys
17
:39:34.0264 4812  iirsp ok
17
:39:34.0264 4812  AB55B8A9B13130F638546881CE4425F8 IISADMIN        C:\Windows\system32\inetsrv\inetinfo.exe
17
:39:34.0279 4812  IISADMIN ok
17
:39:34.0295 4812  FCD84C381E0140AF901E58D48882D26B IKEEXT          C:\Windows\System32\ikeext.dll
17
:39:34.0311 4812  IKEEXT ok
17
:39:34.0342 4812  88798B4381FD58FAE2DA07880C177C5C IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
17
:39:34.0373 4812  IntcAzAudAddService ok
17
:39:34.0389 4812  C2712BF2D18C0D4214065A170E80C664 Intel(RCapability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
17
:39:34.0513 4812  Intel(RCapability Licensing Service Interface - ok
17
:39:34.0529 4812  8C90FA99363E2BC4938CCA3A487100E9 Intel(RPROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
17
:39:34.0545 4812  Intel(RPROSet Monitoring Service ok
17
:39:34.0545 4812  F00F20E70C6EC3AA366910083A0518AA intelide        C:\Windows\system32\drivers\intelide.sys
17
:39:34.0560 4812  intelide ok
17
:39:34.0560 4812  ADA036632C664CAA754079041CF1F8C1 intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
17
:39:34.0576 4812  intelppm ok
17
:39:34.0576 4812  098A91C54546A3B878DAD6A7E90A455B IPBusEnum       C:\Windows\system32\ipbusenum.dll
17
:39:34.0607 4812  IPBusEnum ok
17
:39:34.0607 4812  C9F0E1BD74365A8771590E9008D22AB6 IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
17
:39:34.0638 4812  IpFilterDriver ok
17
:39:34.0654 4812  08C2957BB30058E663720C5606885653 iphlpsvc        C:\Windows\System32\iphlpsvc.dll
17
:39:34.0669 4812  iphlpsvc ok
17
:39:34.0669 4812  0FC1AEA580957AA8817B8F305D18CA3A IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
17
:39:34.0685 4812  IPMIDRV ok
17
:39:34.0685 4812  AF9B39A7E7B6CAA203B3862582E9F2D0 IPNAT           C:\Windows\system32\drivers\ipnat.sys
17
:39:34.0701 4812  IPNAT ok
17
:39:34.0716 4812  6E50CFA46527B39015B750AAD161C5CC iPod Service    C:\Program Files\iPod\bin\iPodService.exe
17
:39:34.0732 4812  iPod Service ok
17
:39:34.0732 4812  11FE7637A49B67D9B1F895B2AD4D982F iprip           C:\Windows\System32\iprip.dll
17
:39:34.0747 4812  iprip ok
17
:39:34.0747 4812  3ABF5E7213EB28966D55D58B515D5CE9 IRENUM          C:\Windows\system32\drivers\irenum.sys
17
:39:34.0747 4812  IRENUM ok
17
:39:34.0763 4812  2F7B28DC3E1183E5EB418DF55C204F38 isapnp          C:\Windows\system32\drivers\isapnp.sys
17
:39:34.0763 4812  isapnp ok
17
:39:34.0763 4812  D931D7309DEB2317035B07C9F9E6B0BD iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
17
:39:34.0779 4812  iScsiPrt ok
17
:39:34.0779 4812  1DED0D0AA513E2A5862B20A520D3A1E1 JME Keyboard    C:\Windows\jmesoft\Service.exe
17
:39:34.0779 4812  JME Keyboard UnsignedFile.Multi.Generic ) - warning
17
:39:34.0779 4812  JME Keyboard detected UnsignedFile.Multi.Generic (1)
17:39:34.0779 4812  BC02336F1CBA7DCC7D1213BB588A68A5 kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
17
:39:34.0779 4812  kbdclass ok
17
:39:34.0794 4812  0705EFF5B42A9DB58548EEC3B26BB484 kbdhid          C:\Windows\system32\drivers\kbdhid.sys
17
:39:34.0794 4812  kbdhid ok
17
:39:34.0794 4812  C118A82CD78818C29AB228366EBF81C3 KeyIso          C:\Windows\system32\lsass.exe
17
:39:34.0810 4812  KeyIso ok
17
:39:34.0810 4812  97A7070AEA4C058B6418519E869A63B4 KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
17
:39:34.0810 4812  KSecDD ok
17
:39:34.0810 4812  26C43A7C2862447EC59DEDA188D1DA07 KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
17
:39:34.0825 4812  KSecPkg ok
17
:39:34.0825 4812  6869281E78CB31A43E969F06B57347C4 ksthunk         C:\Windows\system32\drivers\ksthunk.sys
17
:39:34.0841 4812  ksthunk ok
17
:39:34.0841 4812  6AB66E16AA859232F64DEB66887A8C9C KtmRm           C:\Windows\system32\msdtckrm.dll
17
:39:34.0872 4812  KtmRm ok
17
:39:34.0872 4812  D9F42719019740BAA6D1C6D536CBDAA6 LanmanServer    C:\Windows\system32\srvsvc.dll
17
:39:34.0903 4812  LanmanServer ok
17
:39:34.0903 4812  851A1382EED3E3A7476DB004F4EE3E1A LanmanWorkstation C:\Windows\System32\wkssvc.dll
17
:39:34.0919 4812  LanmanWorkstation ok
17
:39:34.0919 4812  57EAD1CA5C1FFC88905FD96B119BB286 LenovoCOMSvc    C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe
17
:39:34.0935 4812  LenovoCOMSvc UnsignedFile.Multi.Generic ) - warning
17
:39:34.0935 4812  LenovoCOMSvc detected UnsignedFile.Multi.Generic (1)
17:39:34.0935 4812  E5BEC70311434BA4BD87CD64F2B24356 LitModeCtrl     C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe
17
:39:34.0935 4812  LitModeCtrl UnsignedFile.Multi.Generic ) - warning
17
:39:34.0935 4812  LitModeCtrl detected UnsignedFile.Multi.Generic (1)
17:39:34.0935 4812  1538831CF8AD2979A04C423779465827 lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
17
:39:34.0950 4812  lltdio ok
17
:39:34.0966 4812  C1185803384AB3FEED115F79F109427F lltdsvc         C:\Windows\System32\lltdsvc.dll
17
:39:34.0981 4812  lltdsvc ok
17
:39:34.0981 4812  F993A32249B66C9D622EA5592A8B76B8 lmhosts         C:\Windows\System32\lmhsvc.dll
17
:39:35.0013 4812  lmhosts ok
17
:39:35.0013 4812  5DCD36FC4A6ECBF6E7F9B3BF7E0D0F55 LPDSVC          C:\Windows\system32\lpdsvc.dll
17
:39:35.0013 4812  LPDSVC ok
17
:39:35.0013 4812  1A93E54EB0ECE102495A51266DCDB6A6 LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
17
:39:35.0028 4812  LSI_FC ok
17
:39:35.0028 4812  1047184A9FDC8BDBFF857175875EE810 LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
17
:39:35.0028 4812  LSI_SAS ok
17
:39:35.0044 4812  30F5C0DE1EE8B5BC9306C1F0E4A75F93 LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
17
:39:35.0044 4812  LSI_SAS2 ok
17
:39:35.0044 4812  0504EACAFF0D3C8AED161C4B0D369D4A LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
17
:39:35.0059 4812  LSI_SCSI ok
17
:39:35.0059 4812  43D0F98E1D56CCDDB0D5254CFF7B356E luafv           C:\Windows\system32\drivers\luafv.sys
17
:39:35.0075 4812  luafv ok
17
:39:35.0075 4812  0BE09CD858ABF9DF6ED259D57A1A1663 Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
17
:39:35.0091 4812  Mcx2Svc ok
17
:39:35.0091 4812  A55805F747C6EDB6A9080D7C633BD0F4 megasas         C:\Windows\system32\drivers\megasas.sys
17
:39:35.0091 4812  megasas ok
17
:39:35.0106 4812  BAF74CE0072480C3B6B7C13B2A94D6B3 MegaSR          C:\Windows\system32\drivers\MegaSR.sys
17
:39:35.0106 4812  MegaSR ok
17
:39:35.0106 4812  D71FD7A4FDB01C554AE144037B688DF1 MEIx64          C:\Windows\system32\DRIVERS\HECIx64.sys
17
:39:35.0122 4812  MEIx64 ok
17
:39:35.0122 4812  123271BD5237AB991DC5C21FDF8835EB Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
17
:39:35.0122 4812  Microsoft Office Groove Audit Service ok
17
:39:35.0122 4812  E40E80D0304A73E8D269F7141D77250B MMCSS           C:\Windows\system32\mmcss.dll
17
:39:35.0153 4812  MMCSS ok
17
:39:35.0153 4812  800BA92F7010378B09F9ED9270F07137 Modem           C:\Windows\system32\drivers\modem.sys
17
:39:35.0169 4812  Modem ok
17
:39:35.0169 4812  B03D591DC7DA45ECE20B3B467E6AADAA monitor         C:\Windows\system32\DRIVERS\monitor.sys
17
:39:35.0184 4812  monitor ok
17
:39:35.0184 4812  7D27EA49F3C1F687D357E77A470AEA99 mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
17
:39:35.0184 4812  mouclass ok
17
:39:35.0184 4812  D3BF052C40B0C4166D9FD86A4288C1E6 mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
17
:39:35.0200 4812  mouhid ok
17
:39:35.0200 4812  32E7A3D591D671A6DF2DB515A5CBE0FA mountmgr        C:\Windows\system32\drivers\mountmgr.sys
17
:39:35.0200 4812  mountmgr ok
17
:39:35.0215 4812  8C7336950F1E69CDFD811CBBD9CF00A2 MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
17
:39:35.0215 4812  MozillaMaintenance ok
17
:39:35.0215 4812  A44B420D30BD56E145D6A2BC8768EC58 mpio            C:\Windows\system32\drivers\mpio.sys
17
:39:35.0231 4812  mpio ok
17
:39:35.0231 4812  6C38C9E45AE0EA2FA5E551F2ED5E978F mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
17
:39:35.0247 4812  mpsdrv ok
17
:39:35.0262 4812  54FFC9C8898113ACE189D4AA7199D2C1 MpsSvc          C:\Windows\system32\mpssvc.dll
17
:39:35.0278 4812  MpsSvc ok
17
:39:35.0293 4812  CD22D2563039DDA6793F7624719363A7 MQAC            C:\Windows\system32\drivers\mqac.sys
17
:39:35.0293 4812  MQAC ok
17
:39:35.0293 4812  DC722758B8261E1ABAFD31A3C0A66380 MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
17
:39:35.0309 4812  MRxDAV ok
17
:39:35.0309 4812  A5D9106A73DC88564C825D317CAC68AC mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
17
:39:35.0325 4812  mrxsmb ok
17
:39:35.0325 4812  D711B3C1D5F42C0C2415687BE09FC163 mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
17
:39:35.0340 4812  mrxsmb10 ok
17
:39:35.0340 4812  9423E9D355C8D303E76B8CFBD8A5C30C mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
17
:39:35.0340 4812  mrxsmb20 ok
17
:39:35.0340 4812  C25F0BAFA182CBCA2DD3C851C2E75796 msahci          C:\Windows\system32\drivers\msahci.sys
17
:39:35.0356 4812  msahci ok
17
:39:35.0356 4812  DB801A638D011B9633829EB6F663C900 msdsm           C:\Windows\system32\drivers\msdsm.sys
17
:39:35.0356 4812  msdsm ok
17
:39:35.0356 4812  DE0ECE52236CFA3ED2DBFC03F28253A8 MSDTC           C:\Windows\System32\msdtc.exe
17
:39:35.0371 4812  MSDTC ok
17
:39:35.0371 4812  AA3FB40E17CE1388FA1BEDAB50EA8F96 Msfs            C:\Windows\system32\drivers\Msfs.sys
17
:39:35.0403 4812  Msfs ok
17
:39:35.0403 4812  F9D215A46A8B9753F61767FA72A20326 mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
17
:39:35.0418 4812  mshidkmdf ok
17
:39:35.0418 4812  D916874BBD4F8B07BFB7FA9B3CCAE29D msisadrv        C:\Windows\system32\drivers\msisadrv.sys
17
:39:35.0418 4812  msisadrv ok
17
:39:35.0434 4812  808E98FF49B155C522E6400953177B08 MSiSCSI         C:\Windows\system32\iscsiexe.dll
17
:39:35.0449 4812  MSiSCSI ok
17
:39:35.0449 4812  msiserver ok
17
:39:35.0449 4812  49CCF2C4FEA34FFAD8B1B59D49439366 MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
17
:39:35.0481 4812  MSKSSRV ok
17
:39:35.0481 4812  FAAEAEF99E53561BEEE58F946CA56F0D MSMQ            C:\Windows\system32\mqsvc.exe
17
:39:35.0481 4812  MSMQ ok
17
:39:35.0481 4812  59ED174FD4314B0218DC91F9BFA6CD3D MSMQTriggers    C:\Windows\system32\mqtgsvc.exe
17
:39:35.0496 4812  MSMQTriggers ok
17
:39:35.0496 4812  BDD71ACE35A232104DDD349EE70E1AB3 MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
17
:39:35.0512 4812  MSPCLOCK ok
17
:39:35.0512 4812  4ED981241DB27C3383D72092B618A1D0 MSPQM           C:\Windows\system32\drivers\MSPQM.sys
17
:39:35.0543 4812  MSPQM ok
17
:39:35.0543 4812  759A9EEB0FA9ED79DA1FB7D4EF78866D MsRPC           C:\Windows\system32\drivers\MsRPC.sys
17
:39:35.0559 4812  MsRPC ok
17
:39:35.0559 4812  0EED230E37515A0EAEE3C2E1BC97B288 mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
17
:39:35.0559 4812  mssmbios ok
17
:39:35.0559 4812  2E66F9ECB30B4221A318C92AC2250779 MSTEE           C:\Windows\system32\drivers\MSTEE.sys
17
:39:35.0574 4812  MSTEE ok
17
:39:35.0590 4812  7EA404308934E675BFFDE8EDF0757BCD MTConfig        C:\Windows\system32\drivers\MTConfig.sys
17
:39:35.0590 4812  MTConfig ok
17
:39:35.0590 4812  F9A18612FD3526FE473C1BDA678D61C8 Mup             C:\Windows\system32\Drivers\mup.sys
17
:39:35.0590 4812  Mup ok
17
:39:35.0605 4812  582AC6D9873E31DFA28A4547270862DD napagent        C:\Windows\system32\qagentRT.dll
17
:39:35.0621 4812  napagent ok
17
:39:35.0637 4812  1EA3749C4114DB3E3161156FFFFA6B33 NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
17
:39:35.0652 4812  NativeWifiP ok
17
:39:35.0652 4812  760E38053BF56E501D562B70AD796B88 NDIS            C:\Windows\system32\drivers\ndis.sys
17
:39:35.0668 4812  NDIS ok
17
:39:35.0668 4812  9F9A1F53AAD7DA4D6FEF5BB73AB811AC NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
17
:39:35.0699 4812  NdisCap ok
17
:39:35.0699 4812  30639C932D9FEF22B31268FE25A1B6E5 NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
17
:39:35.0715 4812  NdisTapi ok
17
:39:35.0715 4812  136185F9FB2CC61E573E676AA5402356 Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
17
:39:35.0746 4812  Ndisuio ok
17
:39:35.0746 4812  53F7305169863F0A2BDDC49E116C2E11 NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
17
:39:35.0761 4812  NdisWan ok
17
:39:35.0761 4812  015C0D8E0E0421B4CFD48CFFE2825879 NDProxy         C:\Windows\system32\drivers\NDProxy.sys
17
:39:35.0777 4812  NDProxy ok
17
:39:35.0793 4812  2334DC48997BA203B794DF3EE70521DB Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
17
:39:35.0793 4812  Net Driver HPZ12 UnsignedFile.Multi.Generic ) - warning
17
:39:35.0793 4812  Net Driver HPZ12 detected UnsignedFile.Multi.Generic (1)
17:39:35.0793 4812  86743D9F5D2B1048062B14B1D84501C4 NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
17
:39:35.0808 4812  NetBIOS ok
17
:39:35.0824 4812  09594D1089C523423B32A4229263F068 NetBT           C:\Windows\system32\DRIVERS\netbt.sys
17
:39:35.0839 4812  NetBT ok
17
:39:35.0839 4812  C118A82CD78818C29AB228366EBF81C3 Netlogon        C:\Windows\system32\lsass.exe
17
:39:35.0839 4812  Netlogon ok
17
:39:35.0855 4812  847D3AE376C0817161A14A82C8922A9E Netman          C:\Windows\System32\netman.dll
17
:39:35.0871 4812  Netman ok
17
:39:35.0871 4812  D22CD77D4F0D63D1169BB35911BFF12D NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17
:39:35.0886 4812  NetMsmqActivator ok
17
:39:35.0886 4812  D22CD77D4F0D63D1169BB35911BFF12D NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17
:39:35.0886 4812  NetPipeActivator ok
17
:39:35.0902 4812  5F28111C648F1E24F7DBC87CDEB091B8 netprofm        C:\Windows\System32\netprofm.dll
17
:39:35.0917 4812  netprofm ok
17
:39:35.0917 4812  D22CD77D4F0D63D1169BB35911BFF12D NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17
:39:35.0933 4812  NetTcpActivator ok
17
:39:35.0933 4812  D22CD77D4F0D63D1169BB35911BFF12D NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17
:39:35.0933 4812  NetTcpPortSharing ok
17
:39:35.0933 4812  77889813BE4D166CDAB78DDBA990DA92 nfrd960         C:\Windows\system32\drivers\nfrd960.sys
17
:39:35.0949 4812  nfrd960 ok
17
:39:35.0949 4812  311654EF177ACD01A2B16C34BA3F0960 NfsClnt         C:\Windows\system32\nfsclnt.exe
17
:39:35.0949 4812  NfsClnt ok
17
:39:35.0964 4812  255B989D47B063E00F89FF6446511DDB NfsRdr          C:\Windows\system32\drivers\nfsrdr.sys
17
:39:35.0964 4812  NfsRdr ok
17
:39:35.0964 4812  8AD77806D336673F270DB31645267293 NlaSvc          C:\Windows\System32\nlasvc.dll
17
:39:35.0980 4812  NlaSvc ok
17
:39:35.0980 4812  1E4C4AB5C9B8DD13179BBDC75A2A01F7 Npfs            C:\Windows\system32\drivers\Npfs.sys
17
:39:35.0995 4812  Npfs ok
17
:39:36.0011 4812  D54BFDF3E0C953F823B3D0BFE4732528 nsi             C:\Windows\system32\nsisvc.dll
17
:39:36.0027 4812  nsi ok
17
:39:36.0027 4812  E7F5AE18AF4168178A642A9247C63001 nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
17
:39:36.0042 4812  nsiproxy ok
17
:39:36.0058 4812  E453ACF4E7D44E5530B5D5F2B9CA8563 Ntfs            C:\Windows\system32\drivers\Ntfs.sys
17
:39:36.0089 4812  Ntfs ok
17
:39:36.0089 4812  9899284589F75FA8724FF3D16AED75C1 Null            C:\Windows\system32\drivers\Null.sys
17
:39:36.0105 4812  Null ok
17
:39:36.0105 4812  B01C1E6D7477961D6D1CBDCD44AF3E67 nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
17
:39:36.0120 4812  nusb3hub ok
17
:39:36.0120 4812  796BAE22DD827DB8AD7AE7C3F775E92F nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
17
:39:36.0120 4812  nusb3xhc ok
17
:39:36.0136 4812  1F07B814C0BB5AABA703ABFF1F31F2E8 NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
17
:39:36.0136 4812  NVHDA ok
17
:39:36.0245 4812  FE2909F7DFB12B9A20AD207FE23B7E96 nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
17
:39:36.0354 4812  nvlddmkm ok
17
:39:36.0354 4812  0A92CB65770442ED0DC44834632F66AD nvraid          C:\Windows\system32\drivers\nvraid.sys
17
:39:36.0370 4812  nvraid ok
17
:39:36.0370 4812  DAB0E87525C10052BF65F06152F37E4A nvstor          C:\Windows\system32\drivers\nvstor.sys
17
:39:36.0385 4812  nvstor ok
17
:39:36.0385 4812  3341D2C91989BC87C3C0BAA97C27253B NVSvc           C:\Windows\system32\nvvsvc.exe
17
:39:36.0401 4812  NVSvc ok
17
:39:36.0417 4812  551CE34DAD2DFF0A480781E68B286E4D nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17
:39:36.0432 4812  nvUpdatusService ok
17
:39:36.0448 4812  270D7CD42D6E3979F6DD0146650F0E05 nv_agp          C:\Windows\system32\drivers\nv_agp.sys
17
:39:36.0448 4812  nv_agp ok
17
:39:36.0463 4812  785F487A64950F3CB8E9F16253BA3B7B odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17
:39:36.0463 4812  odserv ok
17
:39:36.0463 4812  3589478E4B22CE21B41FA1BFC0B8B8A0 ohci1394        C:\Windows\system32\drivers\ohci1394.sys
17
:39:36.0479 4812  ohci1394 ok
17
:39:36.0479 4812  5A432A042DAE460ABE7199B758E8606C ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17
:39:36.0479 4812  ose ok
17
:39:36.0495 4812  3EAC4455472CC2C97107B5291E0DCAFE p2pimsvc        C:\Windows\system32\pnrpsvc.dll
17
:39:36.0495 4812  p2pimsvc ok
17
:39:36.0510 4812  927463ECB02179F88E4B9A17568C63C3 p2psvc          C:\Windows\system32\p2psvc.dll
17
:39:36.0526 4812  p2psvc ok
17
:39:36.0526 4812  0086431C29C35BE1DBC43F52CC273887 Parport         C:\Windows\system32\drivers\parport.sys
17
:39:36.0526 4812  Parport ok
17
:39:36.0526 4812  E9766131EEADE40A27DC27D2D68FBA9C partmgr         C:\Windows\system32\drivers\partmgr.sys
17
:39:36.0541 4812  partmgr ok
17
:39:36.0541 4812  3AEAA8B561E63452C655DC0584922257 PcaSvc          C:\Windows\System32\pcasvc.dll
17
:39:36.0557 4812  PcaSvc ok
17
:39:36.0557 4812  94575C0571D1462A0F70BDE6BD6EE6B3 pci             C:\Windows\system32\drivers\pci.sys
17
:39:36.0557 4812  pci ok
17
:39:36.0573 4812  B5B8B5EF2E5CB34DF8DCF8831E3534FA pciide          C:\Windows\system32\drivers\pciide.sys
17
:39:36.0573 4812  pciide ok
17
:39:36.0573 4812  B2E81D4E87CE48589F98CB8C05B01F2F pcmcia          C:\Windows\system32\drivers\pcmcia.sys
17
:39:36.0588 4812  pcmcia ok
17
:39:36.0588 4812  D6B9C2E1A11A3A4B26A182FFEF18F603 pcw             C:\Windows\system32\drivers\pcw.sys
17
:39:36.0588 4812  pcw ok
17
:39:36.0604 4812  68769C3356B3BE5D1C732C97B9A80D6E PEAUTH          C:\Windows\system32\drivers\peauth.sys
17
:39:36.0619 4812  PEAUTH ok
17
:39:36.0635 4812  B9B0A4299DD2D76A4243F75FD54DC680 PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
17
:39:36.0666 4812  PeerDistSvc ok
17
:39:36.0666 4812  E495E408C93141E8FC72DC0C6046DDFA PerfHost        C:\Windows\SysWow64\perfhost.exe
17
:39:36.0682 4812  PerfHost ok
17
:39:36.0697 4812  C7CF6A6E137463219E1259E3F0F0DD6C pla             C:\Windows\system32\pla.dll
17
:39:36.0729 4812  pla ok
17
:39:36.0729 4812  25FBDEF06C4D92815B353F6E792C8129 PlugPlay        C:\Windows\system32\umpnpmgr.dll
17
:39:36.0744 4812  PlugPlay ok
17
:39:36.0744 4812  AC78DF349F0E4CFB8B667C0CFFF83CCE Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
17
:39:36.0744 4812  Pml Driver HPZ12 UnsignedFile.Multi.Generic ) - warning
17
:39:36.0744 4812  Pml Driver HPZ12 detected UnsignedFile.Multi.Generic (1)
17:39:36.0760 4812  7195581CEC9BB7D12ABE54036ACC2E38 PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
17
:39:36.0760 4812  PNRPAutoReg ok
17
:39:36.0760 4812  3EAC4455472CC2C97107B5291E0DCAFE PNRPsvc         C:\Windows\system32\pnrpsvc.dll
17
:39:36.0775 4812  PNRPsvc ok
17
:39:36.0775 4812  4F15D75ADF6156BF56ECED6D4A55C389 PolicyAgent     C:\Windows\System32\ipsecsvc.dll
17
:39:36.0807 4812  PolicyAgent ok
17
:39:36.0807 4812  6BA9D927DDED70BD1A9CADED45F8B184 Power           C:\Windows\system32\umpo.dll
17
:39:36.0838 4812  Power ok
17
:39:36.0838 4812  F92A2C41117A11A00BE01CA01A7FCDE9 PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
17
:39:36.0853 4812  PptpMiniport ok
17
:39:36.0853 4812  0D922E23C041EFB1C3FAC2A6F943C9BF Processor       C:\Windows\system32\drivers\processr.sys
17
:39:36.0869 4812  Processor ok
17
:39:36.0869 4812  53E83F1F6CF9D62F32801CF66D8352A8 ProfSvc         C:\Windows\system32\profsvc.dll
17
:39:36.0885 4812  ProfSvc ok
17
:39:36.0885 4812  C118A82CD78818C29AB228366EBF81C3 ProtectedStorage C:\Windows\system32\lsass.exe
17
:39:36.0885 4812  ProtectedStorage ok
17
:39:36.0885 4812  0557CF5A2556BD58E26384169D72438D Psched          C:\Windows\system32\DRIVERS\pacer.sys
17
:39:36.0916 4812  Psched ok
17
:39:36.0916 4812  FDA6EFB7014E8C4524CB6B5B885E8A95 PsxDrv          C:\Windows\system32\drivers\psxdrv.sys
17
:39:36.0916 4812  PsxDrv ok
17
:39:36.0916 4812  87B04878A6D59D6C79251DC960C674C1 PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
17
:39:36.0931 4812  PxHlpa64 ok
17
:39:36.0931 4812  A53A15A11EBFD21077463EE2C7AFEEF0 ql2300          C:\Windows\system32\drivers\ql2300.sys
17
:39:36.0963 4812  ql2300 ok
17
:39:36.0963 4812  4F6D12B51DE1AAEFF7DC58C4D75423C8 ql40xx          C:\Windows\system32\drivers\ql40xx.sys
17
:39:36.0978 4812  ql40xx ok
17
:39:36.0978 4812  906191634E99AEA92C4816150BDA3732 QWAVE           C:\Windows\system32\qwave.dll
17
:39:36.0994 4812  QWAVE ok
17
:39:36.0994 4812  76707BB36430888D9CE9D705398ADB6C QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
17
:39:36.0994 4812  QWAVEdrv ok
17
:39:37.0009 4812  5A0DA8AD5762FA2D91678A8A01311704 RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
17
:39:37.0025 4812  RasAcd ok
17
:39:37.0025 4812  7ECFF9B22276B73F43A99A15A6094E90 RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
17
:39:37.0041 4812  RasAgileVpn ok
17
:39:37.0056 4812  8F26510C5383B8DBE976DE1CD00FC8C7 RasAuto         C:\Windows\System32\rasauto.dll
17
:39:37.0072 4812  RasAuto ok
17
:39:37.0072 4812  471815800AE33E6F1C32FB1B97C490CA Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
17
:39:37.0087 4812  Rasl2tp ok
17
:39:37.0103 4812  EE867A0870FC9E4972BA9EAAD35651E2 RasMan          C:\Windows\System32\rasmans.dll
17
:39:37.0119 4812  RasMan ok
17
:39:37.0119 4812  855C9B1CD4756C5E9A2AA58A15F58C25 RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
17
:39:37.0150 4812  RasPppoe ok
17
:39:37.0150 4812  E8B1E447B008D07FF47D016C2B0EEECB RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
17
:39:37.0165 4812  RasSstp ok
17
:39:37.0181 4812  77F665941019A1594D887A74F301FA2F rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
17
:39:37.0197 4812  rdbss ok
17
:39:37.0197 4812  302DA2A0539F2CF54D7C6CC30C1F2D8D rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
17
:39:37.0212 4812  rdpbus ok
17
:39:37.0212 4812  CEA6CC257FC9B7715F1C2B4849286D24 RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
17
:39:37.0228 4812  RDPCDD ok
17
:39:37.0228 4812  1B6163C503398B23FF8B939C67747683 RDPDR           C:\Windows\system32\drivers\rdpdr.sys
17
:39:37.0243 4812  RDPDR ok
17
:39:37.0243 4812  BB5971A4F00659529A5C44831AF22365 RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
17
:39:37.0259 4812  RDPENCDD ok
17
:39:37.0259 4812  216F3FA57533D98E1F74DED70113177A RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
17
:39:37.0290 4812  RDPREFMP ok
17
:39:37.0290 4812  70CBA1A0C98600A2AA1863479B35CB90 RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17
:39:37.0290 4812  RdpVideoMiniport ok
17
:39:37.0306 4812  E61608AA35E98999AF9AAEEEA6114B0A RDPWD           C:\Windows\system32\drivers\RDPWD.sys
17
:39:37.0306 4812  RDPWD ok
17
:39:37.0306 4812  34ED295FA0121C241BFEF24764FC4520 rdyboost        C:\Windows\system32\drivers\rdyboost.sys
17
:39:37.0321 4812  rdyboost ok
17
:39:37.0321 4812  254FB7A22D74E5511C73A3F6D802F192 RemoteAccess    C:\Windows\System32\mprdim.dll
17
:39:37.0337 4812  RemoteAccess ok
17
:39:37.0353 4812  E4D94F24081440B5FC5AA556C7C62702 RemoteRegistry  C:\Windows\system32\regsvc.dll
17
:39:37.0368 4812  RemoteRegistry ok
17
:39:37.0368 4812  CAF88D6573D21CD2AA27001DDBFDC74D RMCAST          C:\Windows\system32\DRIVERS\RMCAST.sys
17
:39:37.0399 4812  RMCAST ok
17
:39:37.0399 4812  E4DC58CF7B3EA515AE917FF0D402A7BB RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
17
:39:37.0415 4812  RpcEptMapper ok
17
:39:37.0415 4812  D5BA242D4CF8E384DB90E6A8ED850B8C RpcLocator      C:\Windows\system32\locator.exe
17
:39:37.0431 4812  RpcLocator ok
17
:39:37.0431 4812  5C627D1B1138676C0A7AB2C2C190D123 RpcSs           C:\Windows\system32\rpcss.dll
17
:39:37.0462 4812  RpcSs ok
17
:39:37.0462 4812  4AFDE1E8925A06BA253DAB6541701F5C RpcXdr          C:\Windows\system32\drivers\rpcxdr.sys
17
:39:37.0462 4812  RpcXdr ok
17
:39:37.0477 4812  DDC86E4F8E7456261E637E3552E804FF rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
17
:39:37.0493 4812  rspndr ok
17
:39:37.0493 4812  FC009873CBC12CC6D7045D803D8E8CD3 RSUSBSTOR       C:\Windows\system32\Drivers\RtsUStor.sys
17
:39:37.0509 4812  RSUSBSTOR ok
17
:39:37.0509 4812  E8D91B9BEBDBC0BB6BA60849F511FAA8 RTL8192Ce       C:\Windows\system32\DRIVERS\rtl8192Ce.sys
17
:39:37.0524 4812  RTL8192Ce ok
17
:39:37.0524 4812  E60C0A09F997826C7627B244195AB581 s3cap           C:\Windows\system32\drivers\vms3cap.sys
17
:39:37.0540 4812  s3cap ok
17
:39:37.0540 4812  C118A82CD78818C29AB228366EBF81C3 SamSs           C:\Windows\system32\lsass.exe
17
:39:37.0540 4812  SamSs ok
17
:39:37.0540 4812  AC03AF3329579FFFB455AA2DAABBE22B sbp2port        C:\Windows\system32\drivers\sbp2port.sys
17
:39:37.0555 4812  sbp2port ok
17
:39:37.0555 4812  9B7395789E3791A3B6D000FE6F8B131E SCardSvr        C:\Windows\System32\SCardSvr.dll
17
:39:37.0571 4812  SCardSvr ok
17
:39:37.0587 4812  253F38D0D7074C02FF8DEB9836C97D2B scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
17
:39:37.0602 4812  scfilter ok
17
:39:37.0618 4812  262F6592C3299C005FD6BEC90FC4463A Schedule        C:\Windows\system32\schedsvc.dll
17
:39:37.0649 4812  Schedule ok
17
:39:37.0649 4812  F17D1D393BBC69C5322FBFAFACA28C7F SCPolicySvc     C:\Windows\System32\certprop.dll
17
:39:37.0665 4812  SCPolicySvc ok
17
:39:37.0665 4812  6EA4234DC55346E0709560FE7C2C1972 SDRSVC          C:\Windows\System32\SDRSVC.dll
17
:39:37.0680 4812  SDRSVC ok
17
:39:37.0680 4812  3EA8A16169C26AFBEB544E0E48421186 secdrv          C:\Windows\system32\drivers\secdrv.sys
17
:39:37.0696 4812  secdrv ok
17
:39:37.0696 4812  BC617A4E1B4FA8DF523A061739A0BD87 seclogon        C:\Windows\system32\seclogon.dll
17
:39:37.0727 4812  seclogon ok
17
:39:37.0727 4812  C32AB8FA018EF34C0F113BD501436D21 SENS            C:\Windows\System32\sens.dll
17
:39:37.0743 4812  SENS ok
17
:39:37.0743 4812  0336CFFAFAAB87A11541F1CF1594B2B2 SensrSvc        C:\Windows\system32\sensrsvc.dll
17
:39:37.0758 4812  SensrSvc ok
17
:39:37.0758 4812  CB624C0035412AF0DEBEC78C41F5CA1B Serenum         C:\Windows\system32\DRIVERS\serenum.sys
17
:39:37.0758 4812  Serenum ok
17
:39:37.0774 4812  C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 Serial          C:\Windows\system32\DRIVERS\serial.sys
17
:39:37.0774 4812  Serial ok
17
:39:37.0774 4812  1C545A7D0691CC4A027396535691C3E3 sermouse        C:\Windows\system32\drivers\sermouse.sys
17
:39:37.0789 4812  sermouse ok
17
:39:37.0789 4812  0B6231BF38174A1628C4AC812CC75804 SessionEnv      C:\Windows\system32\sessenv.dll
17
:39:37.0805 4812  SessionEnv ok
17
:39:37.0821 4812  A554811BCD09279536440C964AE35BBF sffdisk         C:\Windows\system32\drivers\sffdisk.sys
17
:39:37.0821 4812  sffdisk ok
17
:39:37.0821 4812  FF414F0BAEFEBA59BC6C04B3DB0B87BF sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
17
:39:37.0836 4812  sffp_mmc ok
17
:39:37.0836 4812  DD85B78243A19B59F0637DCF284DA63C sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
17
:39:37.0836 4812  sffp_sd ok
17
:39:37.0852 4812  A9D601643A1647211A1EE2EC4E433FF4 sfloppy         C:\Windows\system32\drivers\sfloppy.sys
17
:39:37.0852 4812  sfloppy ok
17
:39:37.0852 4812  B95F6501A2F8B2E78C697FEC401970CE SharedAccess    C:\Windows\System32\ipnathlp.dll
17
:39:37.0883 4812  SharedAccess ok
17
:39:37.0883 4812  AAF932B4011D14052955D4B212A4DA8D ShellHWDetection C:\Windows\System32\shsvcs.dll
17
:39:37.0914 4812  ShellHWDetection ok
17
:39:37.0914 4812  E9E830D540EDEDED650F906628468548 simptcp         C:\Windows\System32\tcpsvcs.exe
17
:39:37.0914 4812  simptcp ok
17
:39:37.0930 4812  843CAF1E5FDE1FFD5FF768F23A51E2E1 SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
17
:39:37.0930 4812  SiSRaid2 ok
17
:39:37.0930 4812  6A6C106D42E9FFFF8B9FCB4F754F6DA4 SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
17
:39:37.0930 4812  SiSRaid4 ok
17
:39:37.0945 4812  548260A7B8654E024DC30BF8A7C5BAA4 Smb             C:\Windows\system32\DRIVERS\smb.sys
17
:39:37.0961 4812  Smb ok
17
:39:37.0961 4812  CA62AE004E98374BF7F082CD765EEA02 SNMP            C:\Windows\System32\snmp.exe
17
:39:37.0977 4812  SNMP ok
17
:39:37.0977 4812  6313F223E817CC09AA41811DAA7F541D SNMPTRAP        C:\Windows\System32\snmptrap.exe
17
:39:37.0977 4812  SNMPTRAP ok
17
:39:37.0992 4812  B9E31E5CACDFE584F34F730A677803F9 spldr           C:\Windows\system32\drivers\spldr.sys
17
:39:37.0992 4812  spldr ok
17
:39:37.0992 4812  85DAA09A98C9286D4EA2BA8D0E644377 Spooler         C:\Windows\System32\spoolsv.exe
17
:39:38.0008 4812  Spooler ok
17
:39:38.0039 4812  E17E0188BB90FAE42D83E98707EFA59C sppsvc          C:\Windows\system32\sppsvc.exe
17
:39:38.0101 4812  sppsvc ok
17
:39:38.0101 4812  93D7D61317F3D4BC4F4E9F8A96A7DE45 sppuinotify     C:\Windows\system32\sppuinotify.dll
17
:39:38.0117 4812  sppuinotify ok
17
:39:38.0117 4812  A15860E920B02C9A7CE8F3A6C2FF1E3A sptd            C:\Windows\System32\Drivers\sptd.sys
17
:39:38.0133 4812  sptd ok
17
:39:38.0148 4812  441FBA48BFF01FDB9D5969EBC1838F0B srv             C:\Windows\system32\DRIVERS\srv.sys
17
:39:38.0148 4812  srv ok
17
:39:38.0164 4812  B4ADEBBF5E3677CCE9651E0F01F7CC28 srv2            C:\Windows\system32\DRIVERS\srv2.sys
17
:39:38.0179 4812  srv2 ok
17
:39:38.0179 4812  27E461F0BE5BFF5FC737328F749538C3 srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
17
:39:38.0179 4812  srvnet ok
17
:39:38.0179 4812  51B52FBD583CDE8AA9BA62B8B4298F33 SSDPSRV         C:\Windows\System32\ssdpsrv.dll
17
:39:38.0211 4812  SSDPSRV ok
17
:39:38.0211 4812  AB7AEBF58DAD8DAAB7A6C45E6A8885CB SstpSvc         C:\Windows\system32\sstpsvc.dll
17
:39:38.0226 4812  SstpSvc ok
17
:39:38.0242 4812  0632004181860960CF6E10DE8DDEF78B Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17
:39:38.0242 4812  Stereo Service ok
17
:39:38.0242 4812  F3817967ED533D08327DC73BC4D5542A stexstor        C:\Windows\system32\drivers\stexstor.sys
17
:39:38.0257 4812  stexstor ok
17
:39:38.0257 4812  DECACB6921DED1A38642642685D77DAC StillCam        C:\Windows\system32\DRIVERS\serscan.sys
17
:39:38.0257 4812  StillCam ok
17
:39:38.0273 4812  8DD52E8E6128F4B2DA92CE27402871C1 stisvc          C:\Windows\System32\wiaservc.dll
17
:39:38.0289 4812  stisvc ok
17
:39:38.0289 4812  7785DC213270D2FC066538DAF94087E7 storflt         C:\Windows\system32\drivers\vmstorfl.sys
17
:39:38.0289 4812  storflt ok
17
:39:38.0304 4812  D34E4943D5AC096C8EDEEBFD80D76E23 storvsc         C:\Windows\system32\drivers\storvsc.sys
17
:39:38.0304 4812  storvsc ok
17
:39:38.0304 4812  D01EC09B6711A5F8E7E6564A4D0FBC90 swenum          C:\Windows\system32\DRIVERS\swenum.sys
17
:39:38.0304 4812  swenum ok
17
:39:38.0320 4812  E08E46FDD841B7184194011CA1955A0B swprv           C:\Windows\System32\swprv.dll
17
:39:38.0335 4812  swprv ok
17
:39:38.0351 4812  C3A39C4079305480972D29C44B868C78 Synth3dVsc      C:\Windows\system32\drivers\synth3dvsc.sys
17
:39:38.0351 4812  Synth3dVsc ok
17
:39:38.0367 4812  BF9CCC0BF39B418C8D0AE8B05CF95B7D SysMain         C:\Windows\system32\sysmain.dll
17
:39:38.0398 4812  SysMain ok
17
:39:38.0398 4812  E3C61FD7B7C2557E1F1B0B4CEC713585 TabletInputService C:\Windows\System32\TabSvc.dll
17
:39:38.0413 4812  TabletInputService ok
17
:39:38.0413 4812  40F0849F65D13EE87B9A9AE3C1DD6823 TapiSrv         C:\Windows\System32\tapisrv.dll
17
:39:38.0429 4812  TapiSrv ok
17
:39:38.0445 4812  1BE03AC720F4D302EA01D40F588162F6 TBS             C:\Windows\System32\tbssvc.dll
17
:39:38.0460 4812  TBS ok
17
:39:38.0476 4812  37608401DFDB388CAF66917F6B2D6FB0 Tcpip           C:\Windows\system32\drivers\tcpip.sys
17
:39:38.0507 4812  Tcpip ok
17
:39:38.0523 4812  37608401DFDB388CAF66917F6B2D6FB0 TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
17
:39:38.0538 4812  TCPIP6 ok
17
:39:38.0554 4812  1B16D0BD9841794A6E0CDE0CEF744ABC tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
17
:39:38.0554 4812  tcpipreg ok
17
:39:38.0554 4812  3371D21011695B16333A3934340C4E7C TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
17
:39:38.0569 4812  TDPIPE ok
17
:39:38.0569 4812  51C5ECEB1CDEE2468A1748BE550CFBC8 TDTCP           C:\Windows\system32\drivers\tdtcp.sys
17
:39:38.0569 4812  TDTCP ok
17
:39:38.0569 4812  DDAD5A7AB24D8B65F8D724F5C20FD806 tdx             C:\Windows\system32\DRIVERS\tdx.sys
17
:39:38.0601 4812  tdx ok
17
:39:38.0601 4812  561E7E1F06895D78DE991E01DD0FB6E5 TermDD          C:\Windows\system32\DRIVERS\termdd.sys
17
:39:38.0601 4812  TermDD ok
17
:39:38.0601 4812  2B5BDFF688EC9871D7EC5837833374E9 terminpt        C:\Windows\system32\drivers\terminpt.sys
17
:39:38.0616 4812  terminpt ok
17
:39:38.0616 4812  2E648163254233755035B46DD7B89123 TermService     C:\Windows\System32\termsrv.dll
17
:39:38.0647 4812  TermService ok
17
:39:38.0647 4812  F0344071948D1A1FA732231785A0664C Themes          C:\Windows\system32\themeservice.dll
17
:39:38.0663 4812  Themes ok
17
:39:38.0663 4812  E40E80D0304A73E8D269F7141D77250B THREADORDER     C:\Windows\system32\mmcss.dll
17
:39:38.0679 4812  THREADORDER ok
17
:39:38.0679 4812  519CB7D7F697F4BA47DE05845C20F158 TlntSvr         C:\Windows\System32\tlntsvr.exe
17
:39:38.0694 4812  TlntSvr ok
17
:39:38.0694 4812  7E7AFD841694F6AC397E99D75CEAD49D TrkWks          C:\Windows\System32\trkwks.dll
17
:39:38.0710 4812  TrkWks ok
17
:39:38.0725 4812  773212B2AAA24C1E31F10246B15B276C TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17
:39:38.0741 4812  TrustedInstaller ok
17
:39:38.0741 4812  CE18B2CDFC837C99E5FAE9CA6CBA5D30 tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
17
:39:38.0757 4812  tssecsrv ok
17
:39:38.0757 4812  D11C783E3EF9A3C52C0EBE83CC5000E9 TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
17
:39:38.0772 4812  TsUsbFlt ok
17
:39:38.0772 4812  9CC2CCAE8A84820EAECB886D477CBCB8 TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
17
:39:38.0772 4812  TsUsbGD ok
17
:39:38.0788 4812  E1748D04AE40118B62BC18AC86032192 tsusbhub        C:\Windows\system32\drivers\tsusbhub.sys
17
:39:38.0788 4812  tsusbhub ok
17
:39:38.0819 4812  D27430FD0EFD8CE745CCF6F179A5C4F2 TuneUp.UtilitiesSvc C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
17
:39:38.0850 4812  TuneUp.UtilitiesSvc ok
17
:39:38.0850 4812  7BC3381C0713F613B31ACDE38B71CB53 TuneUpUtilitiesDrv C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys
17
:39:38.0850 4812  TuneUpUtilitiesDrv ok
17
:39:38.0850 4812  3566A8DAAFA27AF944F5D705EAA64894 tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
17
:39:38.0881 4812  tunnel ok
17
:39:38.0881 4812  B4DD609BD7E282BFC683CEC7EAAAAD67 uagp35          C:\Windows\system32\drivers\uagp35.sys
17
:39:38.0881 4812  uagp35 ok
17
:39:38.0881 4812  FF4232A1A64012BAA1FD97C7B67DF593 udfs            C:\Windows\system32\DRIVERS\udfs.sys
17
:39:38.0913 4812  udfs ok
17
:39:38.0913 4812  3CBDEC8D06B9968ABA702EBA076364A1 UI0Detect       C:\Windows\system32\UI0Detect.exe
17
:39:38.0928 4812  UI0Detect ok
17
:39:38.0928 4812  34859D3801F4BD3DACFA131DD928455A UimBus          C:\Windows\system32\DRIVERS\uimx64.sys
17
:39:38.0928 4812  UimBus ok
17
:39:38.0944 4812  D3CE4776E7FFB25E6935B1C797F4650C Uim_IM          C:\Windows\system32\Drivers\Uim_IMx64.sys
17
:39:38.0944 4812  Uim_IM ok
17
:39:38.0944 4812  532E4BED5C7803B2EE5681818B2528B7 Uim_VIM         C:\Windows\system32\Drivers\uim_vimx64.sys
17
:39:38.0959 4812  Uim_VIM ok
17
:39:38.0959 4812  4BFE1BC28391222894CBF1E7D0E42320 uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
17
:39:38.0959 4812  uliagpkx ok
17
:39:38.0975 4812  DC54A574663A895C8763AF0FA1FF7561 umbus           C:\Windows\system32\DRIVERS\umbus.sys
17
:39:38.0975 4812  umbus ok
17
:39:38.0975 4812  B2E8E8CB557B156DA5493BBDDCC1474D UmPass          C:\Windows\system32\DRIVERS\umpass.sys
17
:39:38.0991 4812  UmPass ok
17
:39:38.0991 4812  A293DCD756D04D8492A750D03B9A297C UmRdpService    C:\Windows\System32\umrdp.dll
17
:39:38.0991 4812  UmRdpService ok
17
:39:39.0006 4812  BB879DCFD22926EFBEB3298129898CBB UnlockerDriver5 C:\Program Files (x86)\Unlocker\UnlockerDriver5.sys
17
:39:39.0006 4812  UnlockerDriver5 UnsignedFile.Multi.Generic ) - warning
17
:39:39.0006 4812  UnlockerDriver5 detected UnsignedFile.Multi.Generic (1)
17:39:39.0006 4812  D47EC6A8E81633DD18D2436B19BAF6DE upnphost        C:\Windows\System32\upnphost.dll
17
:39:39.0037 4812  upnphost ok
17
:39:39.0037 4812  AF1B9474D67897D0C2CFF58E0ACEACCC USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
17
:39:39.0037 4812  USBAAPL64 ok
17
:39:39.0037 4812  6F1A3157A1C89435352CEB543CDB359C usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
17
:39:39.0053 4812  usbccgp ok
17
:39:39.0053 4812  AF0892A803FDDA7492F595368E3B68E7 usbcir          C:\Windows\system32\drivers\usbcir.sys
17
:39:39.0069 4812  usbcir ok
17
:39:39.0069 4812  C025055FE7B87701EB042095DF1A2D7B usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
17
:39:39.0069 4812  usbehci ok
17
:39:39.0069 4812  287C6C9410B111B68B52CA298F7B8C24 usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
17
:39:39.0084 4812  usbhub ok
17
:39:39.0084 4812  9840FC418B4CBD632D3D0A667A725C31 usbohci         C:\Windows\system32\drivers\usbohci.sys
17
:39:39.0100 4812  usbohci ok
17
:39:39.0100 4812  73188F58FB384E75C4063D29413CEE3D usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
17
:39:39.0100 4812  usbprint ok
17
:39:39.0100 4812  AAA2513C8AED8B54B189FD0C6B1634C0 usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
17
:39:39.0115 4812  usbscan ok
17
:39:39.0115 4812  FED648B01349A3C8395A5169DB5FB7D6 USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
17
:39:39.0131 4812  USBSTOR ok
17
:39:39.0131 4812  62069A34518BCF9C1FD9E74B3F6DB7CD usbuhci         C:\Windows\system32\drivers\usbuhci.sys
17
:39:39.0131 4812  usbuhci ok
17
:39:39.0131 4812  EDBB23CBCF2CDF727D64FF9B51A6070E UxSms           C:\Windows\System32\uxsms.dll
17
:39:39.0162 4812  UxSms ok
17
:39:39.0162 4812  C118A82CD78818C29AB228366EBF81C3 VaultSvc        C:\Windows\system32\lsass.exe
17
:39:39.0162 4812  VaultSvc ok
17
:39:39.0162 4812  FD911873C0BB6945FA38C16E9A2B58F9 VClone          C:\Windows\system32\DRIVERS\VClone.sys
17
:39:39.0178 4812  VClone ok
17
:39:39.0178 4812  C5C876CCFC083FF3B128F933823E87BD vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
17
:39:39.0178 4812  vdrvroot ok
17
:39:39.0178 4812  8D6B481601D01A456E75C3210F1830BE vds             C:\Windows\System32\vds.exe
17
:39:39.0209 4812  vds ok
17
:39:39.0209 4812  DA4DA3F5E02943C2DC8C6ED875DE68DD vga             C:\Windows\system32\DRIVERS\vgapnp.sys
17
:39:39.0225 4812  vga ok
17
:39:39.0225 4812  53E92A310193CB3C03BEA963DE7D9CFC VgaSave         C:\Windows\System32\drivers\vga.sys
17
:39:39.0240 4812  VgaSave ok
17
:39:39.0240 4812  VGPU ok
17
:39:39.0256 4812  2CE2DF28C83AEAF30084E1B1EB253CBB vhdmp           C:\Windows\system32\drivers\vhdmp.sys
17
:39:39.0256 4812  vhdmp ok
17
:39:39.0256 4812  E5689D93FFE4E5D66C0178761240DD54 viaide          C:\Windows\system32\drivers\viaide.sys
17
:39:39.0271 4812  viaide ok
17
:39:39.0271 4812  86EA3E79AE350FEA5331A1303054005F vmbus           C:\Windows\system32\drivers\vmbus.sys
17
:39:39.0271 4812  vmbus ok
17
:39:39.0271 4812  7DE90B48F210D29649380545DB45A187 VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
17
:39:39.0287 4812  VMBusHID ok
17
:39:39.0287 4812  D2AAFD421940F640B407AEFAAEBD91B0 volmgr          C:\Windows\system32\drivers\volmgr.sys
17
:39:39.0287 4812  volmgr ok
17
:39:39.0303 4812  A255814907C89BE58B79EF2F189B843B volmgrx         C:\Windows\system32\drivers\volmgrx.sys
17
:39:39.0303 4812  volmgrx ok
17
:39:39.0303 4812  0D08D2F3B3FF84E433346669B5E0F639 volsnap         C:\Windows\system32\drivers\volsnap.sys
17
:39:39.0318 4812  volsnap ok
17
:39:39.0318 4812  5E2016EA6EBACA03C04FEAC5F330D997 vsmraid         C:\Windows\system32\drivers\vsmraid.sys
17
:39:39.0334 4812  vsmraid ok
17
:39:39.0349 4812  B60BA0BC31B0CB414593E169F6F21CC2 VSS             C:\Windows\system32\vssvc.exe
17
:39:39.0381 4812  VSS ok
17
:39:39.0381 4812  36D4720B72B5C5D9CB2B9C29E9DF67A1 vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
17
:39:39.0396 4812  vwifibus ok
17
:39:39.0396 4812  6A3D66263414FF0D6FA754C646612F3F vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
17
:39:39.0396 4812  vwififlt ok
17
:39:39.0412 4812  1C9D80CC3849B3788048078C26486E1A W32Time         C:\Windows\system32\w32time.dll
17
:39:39.0427 4812  W32Time ok
17
:39:39.0443 4812  B32009DB1972E7F2C227499289C4384A W3SVC           C:\Windows\system32\inetsrv\iisw3adm.dll
17
:39:39.0443 4812  W3SVC ok
17
:39:39.0459 4812  4E9440F4F152A7B944CB1663D3935A3E WacomPen        C:\Windows\system32\drivers\wacompen.sys
17
:39:39.0459 4812  WacomPen ok
17
:39:39.0459 4812  356AFD78A6ED4457169241AC3965230C WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
17
:39:39.0474 4812  WANARP ok
17
:39:39.0490 4812  356AFD78A6ED4457169241AC3965230C Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
17
:39:39.0505 4812  Wanarpv6 ok
17
:39:39.0505 4812  B32009DB1972E7F2C227499289C4384A WAS             C:\Windows\system32\inetsrv\iisw3adm.dll
17
:39:39.0521 4812  WAS ok
17
:39:39.0537 4812  78F4E7F5C56CB9716238EB57DA4B6A75 wbengine        C:\Windows\system32\wbengine.exe
17
:39:39.0552 4812  wbengine ok
17
:39:39.0552 4812  3AA101E8EDAB2DB4131333F4325C76A3 WbioSrvc        C:\Windows\System32\wbiosrvc.dll
17
:39:39.0568 4812  WbioSrvc ok
17
:39:39.0568 4812  7368A2AFD46E5A4481D1DE9D14848EDD wcncsvc         C:\Windows\System32\wcncsvc.dll
17
:39:39.0583 4812  wcncsvc ok
17
:39:39.0583 4812  20F7441334B18CEE52027661DF4A6129 WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17
:39:39.0599 4812  WcsPlugInService ok
17
:39:39.0599 4812  72889E16FF12BA0F235467D6091B17DC Wd              C:\Windows\system32\drivers\wd.sys
17
:39:39.0599 4812  Wd ok
17
:39:39.0615 4812  442783E2CB0DA19873B7A63833FF4CB4 Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
17
:39:39.0630 4812  Wdf01000 ok
17
:39:39.0630 4812  BF1FC3F79B863C914687A737C2F3D681 WdiServiceHost  C:\Windows\system32\wdi.dll
17
:39:39.0661 4812  WdiServiceHost ok
17
:39:39.0661 4812  BF1FC3F79B863C914687A737C2F3D681 WdiSystemHost   C:\Windows\system32\wdi.dll
17
:39:39.0661 4812  WdiSystemHost ok
17
:39:39.0677 4812  3DB6D04E1C64272F8B14EB8BC4616280 WebClient       C:\Windows\System32\webclnt.dll
17
:39:39.0677 4812  WebClient ok
17
:39:39.0693 4812  C749025A679C5103E575E3B48E092C43 Wecsvc          C:\Windows\system32\wecsvc.dll
17
:39:39.0708 4812  Wecsvc ok
17
:39:39.0708 4812  7E591867422DC788B9E5BD337A669A08 wercplsupport   C:\Windows\System32\wercplsupport.dll
17
:39:39.0739 4812  wercplsupport ok
17
:39:39.0739 4812  6D137963730144698CBD10F202E9F251 WerSvc          C:\Windows\System32\WerSvc.dll
17
:39:39.0755 4812  WerSvc ok
17
:39:39.0755 4812  611B23304BF067451A9FDEE01FBDD725 WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
17
:39:39.0786 4812  WfpLwf ok
17
:39:39.0786 4812  05ECAEC3E4529A7153B3136CEB49F0EC WIMMount        C:\Windows\system32\drivers\wimmount.sys
17
:39:39.0786 4812  WIMMount ok
17
:39:39.0786 4812  WinDefend ok
17
:39:39.0786 4812  WinHttpAutoProxySvc ok
17
:39:39.0786 4812  66C365B542195C1F6E2FF4A7D8F3827C WinI2C-DDC      C:\Windows\system32\drivers\DDCDrv.sys
17
:39:39.0802 4812  WinI2C-DDC ok
17
:39:39.0802 4812  19B07E7E8915D701225DA41CB3877306 Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
17
:39:39.0833 4812  Winmgmt ok
17
:39:39.0849 4812  BCB1310604AA415C4508708975B3931E WinRM           C:\Windows\system32\WsmSvc.dll
17
:39:39.0880 4812  WinRM ok
17
:39:39.0895 4812  FE88B288356E7B47B74B13372ADD906D WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
17
:39:39.0895 4812  WinUsb ok
17
:39:39.0911 4812  4FADA86E62F18A1B2F42BA18AE24E6AA Wlansvc         C:\Windows\System32\wlansvc.dll
17
:39:39.0927 4812  Wlansvc ok
17
:39:39.0927 4812  06C8FA1CF39DE6A735B54D906BA791C6 wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
17
:39:39.0927 4812  wlcrasvc ok
17
:39:39.0958 4812  7E47C328FC4768CB8BEAFBCFAFA70362 wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17
:39:39.0989 4812  wlidsvc ok
17
:39:39.0989 4812  F6FF8944478594D0E414D3F048F0D778 WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
17
:39:39.0989 4812  WmiAcpi ok
17
:39:40.0005 4812  38B84C94C5A8AF291ADFEA478AE54F93 wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
17
:39:40.0005 4812  wmiApSrv ok
17
:39:40.0005 4812  WMPNetworkSvc ok
17
:39:40.0020 4812  B5BD872122A2CE82D196ABF2D5D8D80A WMSVC           C:\Windows\system32\inetsrv\wmsvc.exe
17
:39:40.0020 4812  WMSVC ok
17
:39:40.0020 4812  96C6E7100D724C69FCF9E7BF590D1DCA WPCSvc          C:\Windows\System32\wpcsvc.dll
17
:39:40.0036 4812  WPCSvc ok
17
:39:40.0036 4812  93221146D4EBBF314C29B23CD6CC391D WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
17
:39:40.0036 4812  WPDBusEnum ok
17
:39:40.0051 4812  6BCC1D7D2FD2453957C5479A32364E52 ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
17
:39:40.0067 4812  ws2ifsl ok
17
:39:40.0067 4812  E8B1FE6669397D1772D8196DF0E57A9E wscsvc          C:\Windows\System32\wscsvc.dll
17
:39:40.0083 4812  wscsvc ok
17
:39:40.0083 4812  WSearch ok
17
:39:40.0083 4812  83575C43B2BFE9AB0661A7F957E843C0 wsvd            C:\Windows\system32\DRIVERS\wsvd.sys
17
:39:40.0083 4812  wsvd ok
17
:39:40.0114 4812  D9EF901DCA379CFE914E9FA13B73B4C4 wuauserv        C:\Windows\system32\wuaueng.dll
17
:39:40.0145 4812  wuauserv ok
17
:39:40.0145 4812  AB886378EEB55C6C75B4F2D14B6C869F WudfPf          C:\Windows\system32\drivers\WudfPf.sys
17
:39:40.0161 4812  WudfPf ok
17
:39:40.0161 4812  DDA4CAF29D8C0A297F886BFE561E6659 WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
17
:39:40.0176 4812  WUDFRd ok
17
:39:40.0176 4812  B20F051B03A966392364C83F009F7D17 wudfsvc         C:\Windows\System32\WUDFSvc.dll
17
:39:40.0176 4812  wudfsvc ok
17
:39:40.0176 4812  9A3452B3C2A46C073166C5CF49FAD1AE WwanSvc         C:\Windows\System32\wwansvc.dll
17
:39:40.0192 4812  WwanSvc ok
17
:39:40.0192 4812  ================ Scan global ===============================
17:39:40.0207 4812  BA0CD8C393E8C9F83354106093832C7B C:\Windows\system32\basesrv.dll
17
:39:40.0207 4812  9E479C2B605C25DA4971ABA36250FAEF C:\Windows\system32\winsrv.dll
17
:39:40.0207 4812  9E479C2B605C25DA4971ABA36250FAEF C:\Windows\system32\winsrv.dll
17
:39:40.0207 4812  D6160F9D869BA3AF0B787F971DB56368 C:\Windows\system32\sxssrv.dll
17
:39:40.0223 4812  24ACB7E5BE595468E3B9AA488B9B4FCB C:\Windows\system32\services.exe
17
:39:40.0223 4812  [Global] - ok
17
:39:40.0223 4812  ================ Scan MBR ==================================
17:39:40.0223 4812  A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17
:39:40.0395 4812  \Device\Harddisk0\DR0 ok
17
:39:40.0395 4812  A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
17
:39:40.0488 4812  \Device\Harddisk1\DR1 ok
17
:39:40.0488 4812  5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk2\DR2
17
:39:40.0566 4812  \Device\Harddisk2\DR2 ok
17
:39:40.0566 4812  ================ Scan VBR ==================================
17:39:40.0566 4812  72906609E6963D82553C82F8D5FC7D9C ] \Device\Harddisk0\DR0\Partition1
17
:39:40.0566 4812  \Device\Harddisk0\DR0\Partition1 ok
17
:39:40.0566 4812  DFFD4EE4883F952C5EF9E93903221A6B ] \Device\Harddisk0\DR0\Partition2
17
:39:40.0566 4812  \Device\Harddisk0\DR0\Partition2 ok
17
:39:40.0566 4812  FB13520DE538B692D73212B79C0A7051 ] \Device\Harddisk1\DR1\Partition1
17
:39:40.0566 4812  \Device\Harddisk1\DR1\Partition1 ok
17
:39:40.0582 4812  906D8527E166CB32C55ADD341CFB7292 ] \Device\Harddisk1\DR1\Partition2
17
:39:40.0582 4812  \Device\Harddisk1\DR1\Partition2 ok
17
:39:40.0582 4812  0EEAB56A0B33251B288B0E6576672BB0 ] \Device\Harddisk1\DR1\Partition3
17
:39:40.0582 4812  \Device\Harddisk1\DR1\Partition3 ok
17
:39:40.0582 4812  A1E160E72D09013A681B2C8C97253F34 ] \Device\Harddisk2\DR2\Partition1
17
:39:40.0582 4812  \Device\Harddisk2\DR2\Partition1 ok
17
:39:40.0582 4812  ============================================================
17:39:40.0582 4812  Scan finished
17
:39:40.0582 4812  ============================================================
17:39:40.0582 0164  Detected object count8
17
:39:40.0582 0164  Actual detected object count8
17
:40:20.0424 0164  HauppaugeTVServer UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  HauppaugeTVServer UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0424 0164  HPSLPSVC UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  HPSLPSVC UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0424 0164  JME Keyboard UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  JME Keyboard UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0424 0164  LenovoCOMSvc UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  LenovoCOMSvc UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0424 0164  LitModeCtrl UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  LitModeCtrl UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0424 0164  Net Driver HPZ12 UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0424 0164  Net Driver HPZ12 UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0440 0164  Pml Driver HPZ12 UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0440 0164  Pml Driver HPZ12 UnsignedFile.Multi.Generic ) - User select actionSkip 
17
:40:20.0440 0164  UnlockerDriver5 UnsignedFile.Multi.Generic ) - skipped by user
17
:40:20.0440 0164  UnlockerDriver5 UnsignedFile.Multi.Generic ) - User select actionSkip 
Gruß

mpdreiforyou

Alt 09.01.2013, 17:53   #8
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hi
combofix:
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 09.01.2013, 18:05   #9
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hier ist das Log File von Combofix

Combofix Logfile:
Code:
ATTFilter
ComboFix 13-01-08.01 - Uli 09.01.2013  17:57:35.1.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.8173.6315 [GMT 1:00]
ausgeführt von:: c:\users\Uli\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\smartdl
c:\program files (x86)\smartdl\dler.exe
c:\program files (x86)\smartdl\gunzip.exe
c:\program files (x86)\smartdl\header.bmp
c:\program files (x86)\smartdl\header2.bmp
c:\program files (x86)\smartdl\header3.bmp
c:\program files (x86)\smartdl\next.bmp
c:\program files (x86)\smartdl\skip.bmp
c:\program files (x86)\smartdl\status-o
C:\torrent.exe
c:\users\Public\sdelevURL.tmp
c:\users\Uli\AppData\Roaming\convert\convert.exe
c:\users\Uli\wgsdgsdgdsgsd.dll
c:\windows\IsUn0407.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-12-09 bis 2013-01-09  ))))))))))))))))))))))))))))))
.
.
2013-01-09 16:41 . 2013-01-09 16:41	76232	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{D85777CF-4F71-4364-A0E9-4A855025B43B}\offreg.dll
2013-01-09 16:28 . 2013-01-09 16:28	--------	d-----w-	C:\_OTL
2013-01-09 10:56 . 2013-01-09 10:56	--------	d-----w-	c:\users\Uli\AppData\Roaming\Macrovision
2013-01-09 10:31 . 2013-01-09 10:31	--------	d-----w-	c:\program files\Enigma Software Group
2013-01-09 10:31 . 2013-01-09 10:31	--------	d-----w-	c:\program files (x86)\Common Files\Wise Installation Wizard
2013-01-09 10:26 . 2013-01-09 10:26	--------	d-----w-	c:\windows\Sun
2013-01-09 02:26 . 2012-11-08 17:24	9125352	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{D85777CF-4F71-4364-A0E9-4A855025B43B}\mpengine.dll
2013-01-04 18:04 . 2013-01-04 18:04	--------	d-----w-	c:\program files (x86)\WinSCP
2013-01-04 17:39 . 2013-01-04 17:39	--------	d-----w-	c:\users\Uli\AppData\Local\Cranium_Consulting_and_Cu
2013-01-04 17:39 . 2013-01-04 17:39	--------	d-----w-	c:\program files (x86)\iPhoneBrowser
2013-01-01 14:13 . 2011-11-28 18:30	584704	----a-w-	c:\windows\system32\Rtlihvs.dll
2013-01-01 14:12 . 2013-01-01 14:12	--------	d-----w-	c:\programdata\Intel
2013-01-01 14:12 . 2012-07-12 18:56	62784	----a-w-	c:\windows\system32\drivers\HECIx64.sys
2013-01-01 14:11 . 2010-10-29 15:11	422504	----a-w-	c:\windows\system32\RtsUStor.dll
2013-01-01 14:11 . 2012-11-19 11:10	652344	----a-w-	c:\windows\system32\drivers\iaStorA.sys
2013-01-01 14:11 . 2012-11-19 11:10	28216	----a-w-	c:\windows\system32\drivers\iaStorF.sys
2013-01-01 14:08 . 2013-01-01 14:08	--------	d-----w-	c:\program files (x86)\AGEIA Technologies
2013-01-01 14:08 . 2013-01-01 14:08	--------	d-----w-	c:\users\UpdatusUser
2013-01-01 14:07 . 2012-12-01 05:49	3663213	----a-w-	c:\windows\system32\nvcoproc.bin
2013-01-01 13:41 . 2013-01-01 13:41	--------	d-----w-	c:\windows\system32\2C0A
2013-01-01 13:31 . 2011-04-06 14:33	2826984	----a-w-	c:\windows\system32\drivers\RTKVHD64.sys
2013-01-01 13:28 . 2013-01-01 13:28	--------	d-----w-	c:\program files (x86)\Driver-Soft
2013-01-01 13:26 . 2013-01-09 16:31	--------	d-----w-	c:\programdata\NVIDIA
2013-01-01 13:09 . 2013-01-01 13:09	--------	d-----w-	c:\programdata\NVIDIA Corporation
2012-12-31 14:50 . 2011-11-10 15:54	9882112	----a-w-	c:\windows\SysWow64\RtsUStoricon.dll
2012-12-25 02:15 . 2012-07-26 07:46	2560	----a-w-	c:\windows\system32\drivers\de-DE\wdf01000.sys.mui
2012-12-25 02:15 . 2012-07-26 04:55	785512	----a-w-	c:\windows\system32\drivers\Wdf01000.sys
2012-12-25 02:15 . 2012-07-26 04:55	54376	----a-w-	c:\windows\system32\drivers\WdfLdr.sys
2012-12-25 02:15 . 2012-07-26 02:36	9728	----a-w-	c:\windows\system32\Wdfres.dll
2012-12-25 02:12 . 2010-02-23 08:16	294912	----a-w-	c:\windows\system32\browserchoice.exe
2012-12-25 02:05 . 2012-12-16 17:11	46080	----a-w-	c:\windows\system32\atmlib.dll
2012-12-25 02:05 . 2012-12-16 14:45	367616	----a-w-	c:\windows\system32\atmfd.dll
2012-12-25 02:05 . 2012-12-16 14:13	295424	----a-w-	c:\windows\SysWow64\atmfd.dll
2012-12-25 02:05 . 2012-12-16 14:13	34304	----a-w-	c:\windows\SysWow64\atmlib.dll
2012-12-25 02:05 . 2012-07-26 03:08	229888	----a-w-	c:\windows\system32\WUDFHost.exe
2012-12-25 02:05 . 2012-07-26 03:08	84992	----a-w-	c:\windows\system32\WUDFSvc.dll
2012-12-25 02:05 . 2012-07-26 03:08	744448	----a-w-	c:\windows\system32\WUDFx.dll
2012-12-25 02:05 . 2012-07-26 03:08	45056	----a-w-	c:\windows\system32\WUDFCoinstaller.dll
2012-12-25 02:05 . 2012-07-26 03:08	194048	----a-w-	c:\windows\system32\WUDFPlatform.dll
2012-12-25 02:05 . 2012-07-26 02:26	87040	----a-w-	c:\windows\system32\drivers\WUDFPf.sys
2012-12-25 02:05 . 2012-07-26 02:26	198656	----a-w-	c:\windows\system32\drivers\WUDFRd.sys
2012-12-25 02:02 . 2012-03-01 06:46	23408	----a-w-	c:\windows\system32\drivers\fs_rec.sys
2012-12-25 02:02 . 2012-03-01 06:33	81408	----a-w-	c:\windows\system32\imagehlp.dll
2012-12-25 02:02 . 2012-03-01 06:28	5120	----a-w-	c:\windows\system32\wmi.dll
2012-12-25 02:02 . 2012-03-01 05:33	159232	----a-w-	c:\windows\SysWow64\imagehlp.dll
2012-12-25 02:02 . 2012-03-01 05:29	5120	----a-w-	c:\windows\SysWow64\wmi.dll
2012-12-24 11:13 . 2012-06-02 05:50	458704	----a-w-	c:\windows\system32\drivers\cng.sys
2012-12-24 11:12 . 2012-05-14 05:26	956928	----a-w-	c:\windows\system32\localspl.dll
2012-12-24 10:58 . 2012-12-24 10:58	--------	d-----w-	c:\windows\PCHEALTH
2012-12-24 10:58 . 2012-12-24 11:13	--------	d-----w-	c:\program files\Microsoft Office
2012-12-22 20:18 . 2012-12-22 20:18	--------	d-----w-	c:\users\Uli\AppData\Roaming\MAGIX
2012-12-22 20:18 . 2012-12-22 20:18	--------	d-----w-	c:\users\Uli\AppData\Local\Xara
2012-12-22 20:17 . 2012-12-22 20:18	--------	d-----w-	c:\programdata\MAGIX
2012-12-22 20:17 . 2012-12-22 20:17	--------	d-----w-	c:\program files (x86)\MAGIX
2012-12-17 12:56 . 2011-09-14 10:23	444928	----a-w-	c:\windows\SysWow64\midas.dll
2012-12-17 12:56 . 2012-12-17 12:56	--------	d-----w-	c:\program files (x86)\Common Files\ptv shared
2012-12-17 12:56 . 2012-12-17 12:56	--------	d-----w-	c:\programdata\PTV-AG
2012-12-17 12:56 . 2012-12-17 12:56	--------	d-----w-	c:\program files (x86)\PTV-AG
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-12-15 10:33 . 2012-12-15 10:33	159744	----a-w-	c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-12-15 10:33 . 2012-12-15 10:33	--------	d-----w-	c:\program files (x86)\QuickTime
2012-12-12 13:30 . 2012-12-12 13:30	--------	d-----w-	c:\users\Uli\AppData\Local\Windows Live Writer
2012-12-12 13:30 . 2012-12-12 13:30	--------	d-----w-	c:\users\Uli\AppData\Roaming\Windows Live Writer
2012-12-11 20:15 . 2012-12-11 20:15	--------	d-----w-	c:\users\Uli\AppData\Roaming\Jalbum AB
2012-12-11 17:41 . 2012-12-11 17:41	--------	d-----w-	c:\program files (x86)\Common Files\Java
2012-12-11 17:41 . 2012-12-11 17:41	95208	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-12-11 17:41 . 2012-12-11 17:41	--------	d-----w-	c:\program files (x86)\Java
2012-12-11 05:34 . 2012-12-11 05:34	--------	d-----w-	c:\users\Uli\AppData\Roaming\dvdcss
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 16:31 . 2012-04-04 14:30	4194304	----a-w-	c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2013-01-09 10:46 . 2012-04-06 16:30	67599240	----a-w-	c:\windows\system32\MRT.exe
2013-01-08 21:02 . 2012-04-04 15:52	74248	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-08 21:02 . 2012-04-04 15:52	697864	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-11 17:41 . 2012-09-28 14:46	821736	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2012-12-11 17:41 . 2012-09-28 14:46	746984	----a-w-	c:\windows\SysWow64\deployJava1.dll
2012-12-03 15:47 . 2012-04-04 14:38	2816824	----a-w-	c:\windows\system32\nvapi64.dll
2012-12-03 15:47 . 2012-04-04 14:38	15016256	----a-w-	c:\windows\system32\nvwgf2umx.dll
2012-12-03 15:47 . 2012-04-04 14:38	12603960	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2012-12-01 05:49 . 2011-04-07 19:37	2557800	----a-w-	c:\windows\system32\nvsvcr.dll
2012-12-01 05:49 . 2011-04-07 19:37	63336	----a-w-	c:\windows\system32\nvshext.dll
2012-12-01 05:49 . 2011-04-07 19:37	118120	----a-w-	c:\windows\system32\nvmctray.dll
2012-12-01 05:49 . 2011-04-07 19:37	890216	----a-w-	c:\windows\system32\nvvsvc.exe
2012-12-01 05:48 . 2011-04-07 19:36	6223208	----a-w-	c:\windows\system32\nvcpl.dll
2012-12-01 05:48 . 2011-04-07 19:35	3311464	----a-w-	c:\windows\system32\nvsvc64.dll
2012-11-30 21:43 . 2012-11-30 21:43	438632	----a-w-	c:\windows\SysWow64\nvStreaming.exe
2012-11-30 04:45 . 2013-01-09 04:18	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2012-11-08 10:29 . 2012-11-08 10:29	1402312	----a-w-	c:\windows\SysWow64\msxml4.dll
2012-11-03 01:41 . 2012-04-04 14:38	53248	----a-w-	c:\windows\SysWow64\CSVer.dll
2012-10-28 17:48 . 2012-10-28 17:48	560184	----a-w-	c:\windows\system32\drivers\sptd.sys
2012-10-25 02:12 . 2012-10-25 02:12	94208	----a-w-	c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 02:12 . 2012-10-25 02:12	69632	----a-w-	c:\windows\SysWow64\QuickTime.qts
2012-10-17 13:16 . 2012-10-17 13:16	916456	----a-w-	c:\windows\system32\deployJava1.dll
2012-10-17 13:16 . 2012-10-17 13:16	289768	----a-w-	c:\windows\system32\javaws.exe
2012-10-17 13:16 . 2012-10-17 13:16	1034216	----a-w-	c:\windows\system32\npDeployJava1.dll
2012-10-17 13:16 . 2012-10-17 13:16	189416	----a-w-	c:\windows\system32\javaw.exe
2012-10-17 13:16 . 2012-10-17 13:16	188904	----a-w-	c:\windows\system32\java.exe
2012-10-17 13:16 . 2012-10-17 13:16	108008	----a-w-	c:\windows\system32\WindowsAccessBridge-64.dll
2012-10-16 08:38 . 2012-12-24 11:13	135168	----a-w-	c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-12-24 11:13	350208	----a-w-	c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-12-24 11:13	561664	----a-w-	c:\windows\apppatch\AcLayers.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{DFEFCDEE-CF1A-4FC8-88AD-129872198372}"= "c:\users\Uli\AppData\Roaming\loadtbs\toolbar.dll" [2012-06-20 614912]
.
[HKEY_CLASSES_ROOT\clsid\{dfefcdee-cf1a-4fc8-88ad-129872198372}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-04-04 39408]
"Akamai NetSession Interface"="c:\users\Uli\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-11-30 56128]
"jmekey"="c:\windows\jmesoft\hotkey.exe" [2011-03-21 118784]
"jmesoft"="c:\windows\jmesoft\ServiceLoader.exe" [2011-03-15 28672]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048]
"ModeSwitch"="c:\program files\Lenovo\Power Dial\LitModeSwitch.exe" [2010-09-26 163840]
"Lenovo Dynamic Brightness System"="c:\program files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe" [2010-10-08 285696]
"Lenovo Eye Distance System"="c:\program files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe" [2010-09-09 265216]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"UnlockerAssistant"="c:\program files (x86)\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AutoStart IR.lnk - c:\program files (x86)\WinTV\Ir.exe [2012-4-5 110647]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
WinTV Recording Status..lnk - c:\program files (x86)\WinTV\WinTV7\WinTVTray.exe [2012-4-5 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="c:\progra~3\dsgsdgdsgdsgw.bat"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R1 Uim_VIM;UIM Virtual Image Plugin;c:\windows\system32\Drivers\uim_vimx64.sys [2011-11-17 352816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 JME Keyboard;JME Keyboard Driver;c:\windows\jmesoft\Service.exe [2011-03-15 32768]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17bda.sys [2008-12-11 57344]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WMSVC;Webverwaltungsdienst;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys [2012-11-19 652344]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys [2012-11-19 28216]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-29 55856]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\DDCDrv.sys [2008-04-08 20832]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-29 96752]
S2 ftpsvc;Microsoft-FTP-Dienst;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 HauppaugeTVServer;HauppaugeTVServer;c:\program files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [2009-04-01 442368]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage-Technologie;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-11-19 14904]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-09-07 2464400]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-07-27 636952]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2012-09-06 170824]
S2 iprip;RIP-Überwachung;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 LenovoCOMSvc;LenovoCOMService;c:\program files\Lenovo\Power Dial\LenovoCOMSvc.exe [2009-09-30 49152]
S2 NfsClnt;Client für NFS;c:\windows\system32\nfsclnt.exe [2010-11-21 65536]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2012-09-14 2365792]
S3 LitModeCtrl;LitModeCtrl;c:\program files\Lenovo\Power Dial\LitModeCtrl.exe [2010-09-09 81920]
S3 NfsRdr;Client für NFS-Redirector;c:\windows\system32\drivers\nfsrdr.sys [2010-11-21 246272]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2012-08-27 107912]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2012-08-27 226696]
S3 PsxDrv;PsxDrv;c:\windows\system32\drivers\psxdrv.sys [2009-07-13 10240]
S3 RpcXdr;Server für NFS Open RPC (ONCRPC);c:\windows\system32\drivers\rpcxdr.sys [2010-11-21 104960]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2012-08-29 243712]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [2012-09-13 879760]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [2012-08-28 11880]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 89067630
*Deregistered* - 89067630
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs	REG_MULTI_SZ   	w3svc was
apphost	REG_MULTI_SZ   	apphostsvc
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2013-01-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 21:02]
.
2013-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 14:59]
.
2013-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 14:59]
.
2013-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000Core.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-20 15:51]
.
2013-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3780310404-1495567817-1753761354-1000UA.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-20 15:51]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2010-11-21 247808]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-03-28 11786344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
IE: An vorhandenes PDF anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: Verknüpfungsziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\mt51ewtl.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxps://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109989&tt=050412_30b&babsrc=KW_ss&mntrId=0860bd63000000000000ac8112b43d50&q=
FF - ExtSQL: 2012-12-28 22:29; leethax@leethax.net; c:\users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\mt51ewtl.default\extensions\leethax@leethax.net.xpi
FF - ExtSQL: 2013-01-02 06:24; jid0-nEKQbsVUhSe9FRuGEdAV8hAphDI@jetpack; c:\users\Uli\AppData\Roaming\Mozilla\Firefox\Profiles\mt51ewtl.default\extensions\jid0-nEKQbsVUhSe9FRuGEdAV8hAphDI@jetpack.xpi
FF - ExtSQL: !HIDDEN! 2012-04-10 16:04; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109989&tt=050412_30b
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 0860bd63000000000000ac8112b43d50
FF - user.js: extensions.BabylonToolbar_i.hardId - 0860bd63000000000000ac8112b43d50
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15436
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:39
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
------- Dateityp-Verknüpfung -------
.
.txt=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
WebBrowser-{DFEFCDEE-CF1A-4FC8-88AD-129872198372} - (no file)
AddRemove-HijackThis - l:\bootcd\wintools\HijackThis.exe
AddRemove-{3966711E-1F98-4C9F-AE0B-6AD28137FE64} - c:\programdata\{802DB52C-80D7-4701-8846-73B3AEA244E6}\Mir4Installer.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90,
   43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87
"{DFEFCDEE-CF1A-4FC8-88AD-129872198372}"=hex:51,66,7a,6c,4c,1d,38,12,80,ce,fc,
   db,28,81,a6,0a,f7,bb,51,d8,77,47,c7,66
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
   27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,
   07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
   36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
   76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
   ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f,
   aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04
"{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84,
   f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63
"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,
   fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
   2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,
   51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
   fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
   b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:1d,2d,61,05,5f,d2,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,48,b5,ff,7f,44,0b,d2,4b,a1,e9,4c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,48,b5,ff,7f,44,0b,d2,4b,a1,e9,4c,\
.
[HKEY_USERS\S-1-5-21-3780310404-1495567817-1753761354-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-3780310404-1495567817-1753761354-1000)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.eml.14"
.
[HKEY_USERS\S-1-5-21-3780310404-1495567817-1753761354-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-3780310404-1495567817-1753761354-1000)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.vcf"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-01-09  18:03:09
ComboFix-quarantined-files.txt  2013-01-09 17:03
.
Vor Suchlauf: 1.208.143.872 Bytes frei
Nach Suchlauf: 778.375.168 Bytes frei
.
- - End Of File - - BEBD39D62402DE4BE2F4C98DA1A1460D
         
--- --- ---


Danke euch.

Kurze Frage.
Der Rechner läuft wieder. War es das jetzt oder kommt da noch was ?

Ihr habt sicherlich viel zu tun und euer Service ist echt klasse.

Danke euch vielmals.

Alt 09.01.2013, 19:03   #10
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hi,
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 09.01.2013, 21:03   #11
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



So, hier ist dann das Ergebniss.

PHP-Code:
Malwarebytes Anti-Malware (Test1.70.0.1100
www
.malwarebytes.org

Datenbank Version
v2013.01.09.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Uli 
:: KARLCHEN [Administrator]

SchutzAktiviert

09.01.2013 20
:02:37
mbam
-log-2013-01-09 (20-02-37).txt

Art des Suchlaufs
Vollständiger Suchlauf (C:\|G:\|H:\|)
Aktivierte SuchlaufeinstellungenSpeicher Autostart Registrierung Dateisystem Heuristiks/Extra HeuristiKs/Shuriken PUP PUM
Deaktivierte Suchlaufeinstellungen
P2P
Durchsuchte Objekte
949676
Laufzeit
41 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel4
HKCR
\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372} (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\loadtbs-3.0 (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte2
HKCU
\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{DFEFCDEE-CF1A-4FC8-88AD-129872198372} (PUP.LoadTubes) -> DatenîÍïßÏÈOˆ*˜rƒr -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{DFEFCDEE-CF1A-4FC8-88AD-129872198372} (PUP.LoadTubes) -> Daten:  -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse3
C
:\Users\Uli\AppData\Roaming\loadtbs (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien21
C
:\Program Files (x86)\Mahjongg Dimensions Deluxe\BFG_Games_Loader_v2.0.exe (PUP.Hacktool.Patcher) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Qoobox\Quarantine\C\Users\Uli\wgsdgsdgdsgsd.dll.vir (Trojan.FakeMS) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Local\Temp\ww6YPuJP.exe.part (PUP.PSWTool.Finder) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\toolbar.dll (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\ytdl.exe (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\keyHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\config.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\domHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\evHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\license.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\uninstall.exe (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\updateHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com\background.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com\background.js (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com\download.js (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com\fire.js (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\chrome@loadtubes.com\manifest.json (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\html\dimensions.ini (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\html\install.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\html\uninstall.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Uli\AppData\Roaming\loadtbs\html\uninstallComplete.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(
Ende
Gruß

mpdreiforyou

Alt 09.01.2013, 21:05   #12
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hi,

lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 09.01.2013, 21:54   #13
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Hier die Liste.

PHP-Code:
Acrobat.com    Adobe Systems Incorporated    07.08.2012        1.2.443                    Notwendig
Adobe Acrobat 9 Pro Extended 
EnglishFrançaisDeutsch    Adobe Systems    04.04.2012        9.0.0   Notwendig
Adobe Acrobat 9 Pro Extended 64
-bit Add-On    Adobe Systems Incorporated    04.04.2012    38,0KB    9.0.0   Notwendig
Adobe AIR    Adobe Systems Inc
.    07.08.2012        1.1.0.5790                        Notwendig
Adobe Flash Player 10 ActiveX    Adobe Systems
Inc.    07.08.2012    1,96MB    10.0.2.54               Notwendig
Adobe Flash Player 10 ActiveX    Adobe Systems Incorporated    04.04.2012        10.0.22.87             Notwendig
Adobe Flash Player 11 Plugin    Adobe Systems Incorporated    08.01.2013    6
,00MB    11.5.502.146        Notwendig
Adobe Media Player    Adobe Systems Incorporated    07.08.2012        1.1                 Notwendig
Akamai NetSession 
Interface    Akamai TechnologiesInc    20.06.2012                     unbekannt    
Apple Application Support    Apple Inc
.    15.12.2012    65,0MB    2.3                     Notwendig
Apple Mobile Device Support    Apple Inc
.    11.10.2012    23,7MB    6.0.0.59                   Notwendig
Apple Software Update    Apple Inc
.    29.07.2012    2,38MB    2.1.3.127                        Notwendig
AudioShell 1.3.5    Softpointer Inc    06.04.2012        1.3.5                           unbekannt
Bigasoft MKV Converter 3.6.18.4499    Bigasoft Corporation    23.09.2012                        Notwendig        
Bildschutz Pro 3.01    K
-Lab Development    08.10.2012                             Notwendig    
Bonjour    Apple Inc
.    29.07.2012    2,00MB    3.0.0.10                                 Notwendig
Canon Inkjet Printer Driver Add
-On Module        05.04.2012                          Notwendig    
Canon iP4800 series Printer Driver        05.04.2012                            Notwendig
Canon MP Navigator 1.0        05.04.2012                                     Notwendig
Canon ScanGear Starter        05.04.2012                                    Notwendig
Canon Utilities Easy
-PhotoPrint EX        05.04.2012                            Notwendig        
CCleaner    Piriform    22.08.2012        3.22                            Notwendig
Cheat Engine 6.2    Dark Byte    05.09.2012    27
,5MB                            unnötig
Cisco EAP
-FAST Module    Cisco SystemsInc.    04.04.2012    1,55MB    2.2.14                    unbekannt
Cisco LEAP Module    Cisco Systems
Inc.    04.04.2012    644KB    1.0.19                    unbekannt
Cisco PEAP Module    Cisco Systems
Inc.    04.04.2012    1,23MB    1.1.6                    unbekannt
CloneCD    SlySoft    11.06.2012                                            Notwendig                                                
DivX
-Setup    DivXLLC    31.07.2012        2.6.1.9                            Notwendig
Driver Genius Professional Edition    Driver
-Soft Inc.    01.01.2013    15,4MB    10.0            unnötig
Easy GIF Animator 5.02    Karlis Blumentals    07.08.2012        Easy GIF Animator 5.0            unnötig
EasyBCD 2.1.2    NeoSmart Technologies    22.04.2012        2.1.2                        Notwendig
G DATA Logox4 Speechengine    G DATA Software AG    07.09.2012                        unnötig        
Google Chrome    Google Inc
.    07.09.2012        23.0.1271.97                        Notwendig
Google Toolbar 
for Internet Explorer    Google Inc.    24.09.2012        7.4.3230.2052              unnötig
Hauppauge Signal Monitor Utility        05.04.2012                            unnötig    
Hauppauge Software MPEG
-2 Decoder Installer        05.04.2012                           unnötig        
Hauppauge WinTV Infrared Remote        05.04.2012                                   unnötig        
HijackThis 2.0.2    TrendMicro    27.08.2012       2.0.2                            unbekannt
HP Customer Participation Program 14.0    HP    10.04.2012        14.0                       notwendig
HP Document Manager 2.0    HP    10.04.2012        2.0                             notwendig
HP Imaging Device Functions 14.0    HP    10.04.2012        14.0                    notwendig
HP Officejet Pro 8500 A909 Series    HP    10.04.2012        14.0                     Notwendig
HP Smart Web Printing 4.60    HP    10.04.2012        4.60                            Notwendig
HP Solution Center 14.0    HP    10.04.2012        14.0                            Notwendig
HP Update    Hewlett
-Packard    30.04.2012    3,98MB    5.003.001.001                        Notwendig
iCloud    Apple Inc
.    11.10.2012    80,2MB    2.0.2.187                            unnötig
iFunbox 
(v1.99.958.697), iFunbox DevTeam        04.09.2012    37,6MB    v1.99.958.697            unbekannt
Image Resizer Powertoy 
Clone for Windows (64 bit)    Brice Lambson    24.04.2012    303KB    2.1.1        unnötig
ImgBurn    LIGHTNING UK
!    27.08.2012        2.5.7.0                                unnötig
Intel
(RManagement Engine Components    Intel Corporation    01.01.2013        8.1.20.1337        Notwendig
Intel
(RNetwork Connections 17.4.95.0    Intel    01.01.2013    16,3MB    17.4.95.0                Notwendig
Intel
(RRapid Storage Technology    Intel Corporation    01.01.2013        11.7.0.1013        Notwendig
iPhoneBrowser    Cranium Consulting 
and Custom Software    04.01.2013    424KB    1.9.3                unnötig
IrfanView 
(remove only)    Irfan Skiljan    04.10.2012    1,50MB    4.32                        unnötig
iTunes    Apple Inc
.    11.10.2012    182MB    10.7.0.21                            Notwendig
jAlbum    Jalbum AB    11.12.2012    141MB    10.10.8                                Notwendig
Java 7 Update 9    Oracle    11.12.2012    128MB    7.0.90                                Notwendig
Java 7 Update 9 
(64-bit)    Oracle    17.10.2012    127MB    7.0.90                        Notwendig
JDownloader 0.9    AppWork GmbH    06.04.2012        0.9                            Notwendig
L0phtCrack 6    L0pht Holdings
LLC    06.07.2012        6.0                        unbekannt
LEGO Digital Designer    LEGO A
/S    21.10.2012                                unnötig        
Lenovo Dynamic Brightness System    Lenovo    04.04.2012        4.0.00.22080                Notwendig
Lenovo Eye Distance System    Lenovo    04.04.2012        4.0.00.21090                    Notwendig
Lenovo Power2Go    CyberLink Corp
.    04.04.2012    150MB    6.0.3720                        Notwendig
Lenovo Rescue System    CyberLink Corp
.    04.04.2012        3.0.2431                    Notwendig
Lenovo Tinian Fn PS
/2 Keyboard Driver    Lenovo    04.04.2012        V1.0.11.0321                Notwendig
Lenovo Treiber
und Anwendungsinstallation    Lenovo    04.04.2012        5.10.2918            Notwendig
LVT    Lenovo    04.04.2012        4.1.2.0919                                Notwendig
MAGIX Web Designer 7 Premium Download
-Version    MAGIX AG    22.12.2012        7.0.4.16490        unnötig
Malwarebytes Anti
-Malware Version 1.70.0.1100    Malwarebytes Corporation    09.01.2013    18,4MB    1.70.0.1100  Notwendig
map
&guide desktop 2012    PTV-AG    17.12.2012        18.0.0.226                        Notwendig
Microsoft 
.NET Framework 4 Client Profile    Microsoft Corporation    05.04.2012    38,8MB    4.0.30319    Notwendig
Microsoft 
.NET Framework 4 Client Profile DEU Language Pack    Microsoft Corporation    05.04.2012    2,93MB    4.0.30319   Notwendig
Microsoft 
.NET Framework 4 Extended    Microsoft Corporation    14.06.2012    51,9MB    4.0.30319        Notwendig
Microsoft Office Enterprise 2007    Microsoft Corporation    26.12.2012        12.0.6612.1000        Notwendig
Microsoft Office File Validation Add
-In    Microsoft Corporation    25.12.2012    7,95MB    14.0.5130.5003        Notwendig
Microsoft Silverlight    Microsoft Corporation    25.12.2012    60
,3MB    4.1.10329.0                Notwendig
Microsoft SQL Server 2005 Compact Edition 
[ENU]    Microsoft Corporation    04.04.2012    1,69MB    3.1.0000    Notwendig
Microsoft Visual C
++ 2005 Redistributable    Microsoft Corporation    06.04.2012    300KB    8.0.61001    Notwendig
Microsoft Visual C
++ 2008 Redistributable x86 9.0.21022    Microsoft Corporation    04.04.2012    4,96MB    9.0.21022    Notwendig
Microsoft Visual C
++ 2008 Redistributable x86 9.0.30729.17    Microsoft Corporation    06.07.2012    232KB    9.0.30729    Notwendig
Microsoft Visual C
++ 2008 Redistributable x86 9.0.30729.4148    Microsoft Corporation    17.05.2012    228KB    9.0.30729.4148    Notwendig
Microsoft Visual C
++ 2008 Redistributable x86 9.0.30729.6161    Microsoft Corporation    04.04.2012    600KB    9.0.30729.6161    Notwendig
Microsoft Visual C
++ 2010  x64 Redistributable 10.0.40219    Microsoft Corporation    01.01.2013    13,8MB    10.0.40219    Notwendig
Microsoft Visual C
++ 2010  x86 Redistributable 10.0.40219    Microsoft Corporation    01.01.2013    11,1MB    10.0.40219    Notwendig
Mozilla Firefox 17.0.1 
(x86 de)    Mozilla    20.12.2012    71,3MB    17.0.1                        Notwendig
Mozilla Maintenance Service    Mozilla    20.12.2012    329KB    17.0.1                        Notwendig
MP3
-Info extension V3.4.23    Michael Mutschler    06.04.2012        3.4.23                Notwendig
MPM    Hewlett
-Packard    10.04.2012    300KB    1.00.0000                            Notwendig
MSXML 4.0 SP2 
(KB954430)    Microsoft Corporation    06.04.2012    1,27MB    4.20.9870.0            Notwendig
MSXML 4.0 SP2 
(KB973688)    Microsoft Corporation    06.04.2012    1,33MB    4.20.9876.0            Notwendig
MSXML 4.0 SP3 Parser    Microsoft Corporation    22.12.2012    1
,47MB    4.30.2100.0                Notwendig
MSXML 4.0 SP3 Parser 
(KB2721691)    Microsoft Corporation    26.12.2012    1,53MB    4.30.2114.0        Notwendig
MSXML 4.0 SP3 Parser 
(KB2758694)    Microsoft Corporation    09.01.2013    1,54MB    4.30.2117.0        Notwendig
NetObjects Fusion 11.0        03.09.2012        11 German                        Notwendig
NVIDIA 3D Vision Controller
-Treiber 310.70    NVIDIA Corporation    01.01.2013        310.70        Notwendig
NVIDIA 3D Vision Treiber 310.70    NVIDIA Corporation    01.01.2013        310.70                Notwendig
NVIDIA Grafiktreiber 310.70    NVIDIA Corporation    01.01.2013        310.70                Notwendig
NVIDIA HD
-Audiotreiber 1.3.18.0    NVIDIA Corporation    01.01.2013        1.3.18.0            Notwendig
NVIDIA PhysX
-Systemsoftware 9.12.1031    NVIDIA Corporation    01.01.2013        9.12.1031        Notwendig
NVIDIA Update 1.11.3    NVIDIA Corporation    01.01.2013        1.11.3                    Notwendig
OCR Software by I
.R.I.S14.0    HP    10.04.2012        14.0                        Notwendig
OneKey Recovery    CyberLink Corp
.    04.04.2012        3.0.2431                        unnötig
Ontrack EasyRecovery Professional    Kroll Ontrack Inc
.    24.10.2012    79,9MB    6.21.03            unnötig
PantsOff 2.0    Christoph Bünger Software    09.01.2013                            unnötig
Paragon Backup 
Recovery™ 2012 Free    Paragon Software    24.10.2012    145MB    90.00.0003        unnötig
phase5    Hans
-Dieter Berretz    22.09.2012        09.09.2003                        Notwendig
PhotoScape        04.07.2012                                        unnötig    
PlayReady PC Runtime amd64    Microsoft Corporation    05.04.2012    2
,05MB    1.3.0                unbekannt
Power Dial    Lenovo    04.04.2012        3.0.1.2126                            Notwendig
Protect Disc License Helper 1.0.125 
(IE)    Protect Disc    04.12.2012        1.0.125            Notwendig
ProtectDisc Driver
Version 11    ProtectDisc Software GmbH    04.12.2012        11.0.0.14        Notwendig
PS3 Media Server    PS3 Media Server    31.07.2012    94
,4MB    1.60.0                    unnötig
PTV Europe 
DOM City Map Premium 2012.1N (C:\ProgramData\PTV-AG\map&guide desktop\18\maps\EuropePremium.geo)    Notwendig
PTV Europe 
DOM City Map Premium 2012.1N (D:\ProgramData\PTV-AG\map&guide desktop\18\maps\EuropePremium.geo)    Notwendig
QuickTime    Apple Inc
.    15.12.2012    73,1MB    7.73.80.64                        Notwendig
Realtek High Definition Audio Driver    Realtek Semiconductor Corp
.    01.01.2013        6.0.1.6343    Notwendig
Realtek USB 2.0 Card Reader    Realtek Semiconductor Corp
.    01.01.2013        6.2.8400.30143        Notwendig
REALTEK Wireless LAN Driver        01.01.2013        1.00.0187                    Notwendig
Renesas Electronics USB 3.0 Host Controller Driver    Renesas Electronics Corporation    01.01.2013    1
,22MB    2.1.39.0    Notwendig
Roxio BackOnTrack    Roxio    04.04.2012    86
,9MB    1.3.1                            Notwendig
Shop 
for HP Supplies    HP    10.04.2012        14.0                            unnötig
ThemeWallpaper    Lenovo    04.04.2012        1.2.0.101108                            unnötig
TuneUp Utilities 2013    TuneUp Software    27.10.2012        13.0.2013.181                    Notwendig
Ulead GIF Animator 5 Test        07.08.2012                                unnötig    
Unlocker 1.9.1    Cedrick Collomb    17.05.2012        1.9.1                            unnötig
VirtualCloneDrive    Elaborate Bytes    04.04.2012                                Notwendig        
VirtualDJ PRO Full    Atomix Productions    04.04.2012    48
,6MB    7.0.4                    Notwendig
VLC media player 2.0.2    VideoLAN    23.07.2012        2.0.2                        Notwendig
Win7codecs    Shark007    31.07.2012    68
,7MB    3.7.3                            Notwendig
Win7codecs    Shark007    31.07.2012        3.7.3                            Notwendig
Windows 7 USB
/DVD Download Tool    Microsoft Corporation    22.04.2012    2,71MB    1.0.30                Notwendig
Windows Live Essentials    Microsoft Corporation    04.04.2012        15.4.3508.1109                unbekannt
Windows Live Mesh ActiveX control 
for remote connections    Microsoft Corporation    04.04.2012    5,57MB    15.4.5722.2    unbekannt
WinRAR 4.10 
(64-bit)    win.rar GmbH    14.06.2012        4.10.0                        Notwendig
WinSCP 4.3.9    Martin Prikryl    04.01.2013    8
,83MB    4.3.9                            Notwendig
WISO Steuer
-Sparbuch 2012    Buhl Data Service GmbH    17.05.2012        19.00.7303            Notwendig
µTorrent        04.04.2012        1.8.3                                Notwendig 

Alt 10.01.2013, 00:35   #14
markusg
/// Malware-holic
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
deinstaliere:
Driver*Genius*
Easy*GIF*
G*DATA*
Google*Toolbar*
Hauppauge*: alle
HijackThis*
iFunbox*
Image*
ImgBurn****
iPhoneBrowser****
IrfanView*
Java*: beide
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
LEGO*
MAGIX*
Ontrack*
PantsOff*
Paragon*
PhotoScape********
PS3*
Shop*
ThemeWallpaper****
TuneUp*: verzichte auf solchen Unsinn, viele Funktionen bringen nichts, andere können dem System schaden.
du musst dein System nur sauber halten, wenig im autostart, unnützes deinstalieren.
Ulead*
Unlocker*
Win7codecs****: braucht man eig auch nicht unbedingt, vlc spielt ja alles ab
Windows*Live*: alle die, die du nicht nutzt.

Öffne CCleaner, analysieren, starten, pc neustarten.

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste
    mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 10.01.2013, 06:08   #15
mpdreiforyou
 
GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Standard

GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert



Dient das ganze jetzt nur noch, um das system geringer zu halten oder wie man sagt sauber.

Werde mich nach der Arbeit mal dran setzen.

Ist denn der Trojaner jetzt runter ?

Antwort

Themen zu GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert
64bit, abgesicherte, abgesicherten, abgesicherter, aufrufe, deaktiviert, guv virus, herunterfahren, heute, hintergrund, kleine, kleinen, konnte, leute, modus, nutze, nutzen, programm, rechner, sperrung, systeme, taskmanager, trick, unterschiedliche, virus, wiederherstellung, windows, windows 7




Ähnliche Themen: GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert


  1. Windows 7 32 Bit: Kein abgesicherter Modus, Kein Avast möglich, WIN-Update streikt USW.
    Plagegeister aller Art und deren Bekämpfung - 30.06.2015 (16)
  2. Win7-64bit: GVU Trojaner - Abgesicherter Modus/Wiederherstellungspunkt gehen nicht
    Log-Analyse und Auswertung - 22.06.2015 (9)
  3. Interpol Trojaner auf Windows 7 64 bit Rechner, Abgesicherter Modus geht nicht
    Log-Analyse und Auswertung - 29.05.2014 (8)
  4. GVU/BKA Trojaner auf XP-Rechner, kein abgesicherter Modus möglich
    Plagegeister aller Art und deren Bekämpfung - 05.05.2014 (10)
  5. GVU Trojaner - Kein abgesicherter Modus geht nicht
    Plagegeister aller Art und deren Bekämpfung - 20.10.2013 (3)
  6. Weißer Bildschirm nach Anmeldung, kein abgesicherter Modus, kein Taskmanager
    Log-Analyse und Auswertung - 09.07.2013 (13)
  7. Bundespolizei, Trojaner, Windows XP, Kein Taskmanager, kein abgesicherter Modus
    Log-Analyse und Auswertung - 14.04.2013 (20)
  8. GemaTrojaner auf Mini Compaq mit XP, kein CD Rom Laufwerk, kein abgesicherter Modus
    Log-Analyse und Auswertung - 17.03.2013 (33)
  9. Trojaner blockiert Windows Vista Rechner, abgesicherter Modus geht auch nicht
    Plagegeister aller Art und deren Bekämpfung - 31.01.2013 (4)
  10. GVU Trojaner blockiert Windows Vista Rechner, abgesicherter Modus geht auch nicht
    Plagegeister aller Art und deren Bekämpfung - 30.01.2013 (1)
  11. GVU Trojaner, Abgesicherter Modus ebenfalls gespeerter Bildschirm, kein Wiederherstellungspunkt
    Plagegeister aller Art und deren Bekämpfung - 15.01.2013 (8)
  12. BKA-Virus: Kein Internet, kein abgesicherter Modus, keine Systemwiederherstellung möglich
    Plagegeister aller Art und deren Bekämpfung - 14.11.2012 (40)
  13. BKA-Virus - abgesicherter Modus funktioniert nicht; Wiederherstellungspunkt nicht vorhanden
    Plagegeister aller Art und deren Bekämpfung - 25.07.2012 (9)
  14. gema virus und abgesicherter modus geht nicht, vorerst kein zweit pc
    Plagegeister aller Art und deren Bekämpfung - 21.02.2012 (12)
  15. Bundespolizei Trojaner Hilfe gesucht, kein abgesicherter Modus, kein CD Laufwerk...
    Plagegeister aller Art und deren Bekämpfung - 14.12.2011 (1)
  16. abgesicherter Modus deaktiviert
    Alles rund um Windows - 04.06.2007 (2)
  17. Kein Antiviren-Programm und auch kein abgesicherter Modus mehr möglich
    Log-Analyse und Auswertung - 12.02.2007 (1)

Zum Thema GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert - Hallo Leute, habe mir heute auch den GUV Virus eingefangen. Wie ich lesen konnte, haben sich den mehrere eingefangen. Ich komme in den abgesicherten Modus, kann aber keine Wiederherstellung nutzen, - GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert...
Archiv
Du betrachtest: GVU auf dem Rechner, abgesicherter Modus geht, jedoch kein Wiederherstellungspunkt, da deaktiviert auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.