|
Log-Analyse und Auswertung: Virus/Trojaner "pl468q4scf.exe"Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.03.2013, 12:59 | #1 |
| Virus/Trojaner "pl468q4scf.exe" Der Computer meines Schwiegervaters macht probleme und braucht ca 10 min, um zu starten. Ich habe einen Systemscan mit "Avira Free Anitvirus" gemacht und dabei hat das Programm die Datei "pl468q4scf.exe" als Virus identifiziert. Ich habe schon einen anderen Thread durchgelesen und mal einen Scan mit Malwarebytes gemacht. Ich weiß nicht, ob das hilfreich ist, aber ich poste mal das Logfile. Code:
ATTFilter Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.03.23.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Alfred :: FAMILIE-5RMVRRM [Administrator] 23.03.2013 11:50:20 MBAM-log-2013-03-23 (12-26-16).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 257047 Laufzeit: 18 Minute(n), 6 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 2 HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Keine Aktion durchgeführt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Dokumente und Einstellungen\Alfred\pl468q4scf.exe (Trojan.Agent.H) -> Keine Aktion durchgeführt. (Ende) 1. Extras: Code:
ATTFilter OTL Extras logfile created on: 23.03.2013 12:30:41 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Alfred\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 511,23 Mb Total Physical Memory | 105,41 Mb Available Physical Memory | 20,62% Memory free 1,22 Gb Paging File | 0,83 Gb Available in Paging File | 67,85% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 68,36 Gb Total Space | 55,88 Gb Free Space | 81,74% Space Free | Partition Type: NTFS Drive D: | 80,68 Gb Total Space | 77,18 Gb Free Space | 95,66% Space Free | Partition Type: NTFS Computer Name: FAMILIE-5RMVRRM | User Name: Alfred | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* [HKEY_USERS\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\WINDOWS\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Programme\devolo\informer\devinf.exe" = C:\Programme\devolo\informer\devinf.exe:*:Enabled:devolo MicroLink Informer -- (devolo AG) "C:\Programme\aon\aonController\aonController.exe" = C:\Programme\aon\aonController\aonController.exe:*:Enabled:Controller -- (mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: office@mquadr.at) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\WINDOWS\temp\Installer.exe" = C:\WINDOWS\temp\Installer.exe:*:Enabled:Breitband-Internet-Installation -- (mquadr.at software engineering & consulting GmbH - Web: hxxp://www.mquadr.at - Mail: office@mquadr.at) "C:\Programme\aon\aonInstaller\Installer.exe" = C:\Programme\aon\aonInstaller\Installer.exe:*:Enabled:Installer -- (mquadr.at software engineering & consulting GmbH - Web: hxxp://www.mquadr.at - Mail: office@mquadr.at) "C:\WINDOWS\system32\svchost.exe" = C:\WINDOWS\system32\svchost.exe:*:Enabled:Microsoft Office -- (Microsoft Corporation) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel "{1ED31028-6D65-4CFD-AD03-8E484A052FE7}" = aonUpdate "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Ultra Edition "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6F7ECD56-E224-4263-9B7E-158E5CECC43B}" = HP Photo and Imaging 2.1 - Scanjet 2400 Series "{83ED1E80-A1B7-4236-BCF1-AC4A88151A6B}" = Microsoft AutoRoute 2006 "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{904B64C4-49D8-4941-A2B6-D13D06C5CD8B}" = Controller "{95120000-003F-0407-0000-0000000FF1CE}" = Microsoft Office Excel Viewer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch "{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Speicher-Disc "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager "{F4FEB66B-A7D7-42FC-8479-16C1E5C7DB73}" = Medisana BPA 3.0 German "{FFF5DEE7-8107-436B-9726-7573458FE6AE}" = ACE Mega CoDecS Pack "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software "aonUpdate" = aonUpdate "ATI Display Driver" = ATI Display Driver "AudioCatalyst" = AudioCatalyst "Avira AntiVir Desktop" = Avira Free Antivirus "CCleaner" = CCleaner "C-Media Audio" = C-Media 3D Audio "Controller" = Controller "dslmon" = devolo MicroLink Informer "hp deskjet 840c series" = hp deskjet 840c series (nur entfernen) "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{F4FEB66B-A7D7-42FC-8479-16C1E5C7DB73}" = Medisana BPA 3.0 German "LHTTSGED" = L&H TTS3000 Deutsch "Macromedia Shockwave Player" = Macromedia Shockwave Player "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "modemtest" = devolo Modemtest "MozBackup" = MozBackup 1.5.1 "Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de) "Mozilla Thunderbird 17.0.4 (x86 de)" = Mozilla Thunderbird 17.0.4 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "USB7554" = MicroLink 56k Fun USB "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR Archivierer ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 23.03.2013 04:52:38 | Computer Name = FAMILIE-5RMVRRM | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung firefox.exe, Version 19.0.2.4814, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.03.2013 04:54:49 | Computer Name = FAMILIE-5RMVRRM | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung firefox.exe, Version 19.0.2.4814, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.03.2013 04:57:39 | Computer Name = FAMILIE-5RMVRRM | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung firefox.exe, Version 19.0.2.4814, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.03.2013 05:01:52 | Computer Name = FAMILIE-5RMVRRM | Source = Avira Antivirus | ID = 4122 Description = Die Datei AVGDLL_Init(avgntflt) konnte nicht geladen werden. Fehlercode: 0xffffffff Error - 23.03.2013 05:11:58 | Computer Name = FAMILIE-5RMVRRM | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung avcenter.exe, Version 13.6.0.628, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.03.2013 05:22:11 | Computer Name = FAMILIE-5RMVRRM | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung firefox.exe, Version 19.0.2.4814, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.03.2013 05:29:45 | Computer Name = FAMILIE-5RMVRRM | Source = Avira Antivirus | ID = 4122 Description = Die Datei AVGDLL_Init(avgntflt) konnte nicht geladen werden. Fehlercode: 0xffffffff Error - 23.03.2013 06:03:34 | Computer Name = FAMILIE-5RMVRRM | Source = Avira Antivirus | ID = 4122 Description = Die Datei AVGDLL_Init(avgntflt) konnte nicht geladen werden. Fehlercode: 0xffffffff Error - 23.03.2013 06:34:00 | Computer Name = FAMILIE-5RMVRRM | Source = Avira Antivirus | ID = 4122 Description = Die Datei AVGDLL_Init(avgntflt) konnte nicht geladen werden. Fehlercode: 0xffffffff Error - 23.03.2013 06:34:22 | Computer Name = FAMILIE-5RMVRRM | Source = Avira Antivirus | ID = 4122 Description = Die Datei AVGDLL_Init(avgntflt) konnte nicht geladen werden. Fehlercode: 0xffffffff [ System Events ] Error - 23.03.2013 06:06:12 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Avira Echtzeit-Scanner" wurde mit folgendem dienstspezifischem Fehler beendet: 307 (0x133). Error - 23.03.2013 06:33:54 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "avipbb" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:34:16 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Avira Echtzeit-Scanner" wurde mit folgendem dienstspezifischem Fehler beendet: 307 (0x133). Error - 23.03.2013 06:34:16 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "avipbb" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:34:37 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Avira Echtzeit-Scanner" wurde mit folgendem dienstspezifischem Fehler beendet: 307 (0x133). Error - 23.03.2013 06:40:25 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "avipbb" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:48:40 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:49:02 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:49:24 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 Error - 23.03.2013 06:49:41 | Computer Name = FAMILIE-5RMVRRM | Source = Service Control Manager | ID = 7000 Description = Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet: %%31 < End of report > Code:
ATTFilter OTL logfile created on: 23.03.2013 12:30:41 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Alfred\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 511,23 Mb Total Physical Memory | 105,41 Mb Available Physical Memory | 20,62% Memory free 1,22 Gb Paging File | 0,83 Gb Available in Paging File | 67,85% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 68,36 Gb Total Space | 55,88 Gb Free Space | 81,74% Space Free | Partition Type: NTFS Drive D: | 80,68 Gb Total Space | 77,18 Gb Free Space | 95,66% Space Free | Partition Type: NTFS Computer Name: FAMILIE-5RMVRRM | User Name: Alfred | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\qttask.exe (Apple Computer, Inc.) PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG) PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation) PRC - C:\WINDOWS\system32\slserv.exe (Smart Link) PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP) ========== Modules (No Company Name) ========== MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll () MOD - C:\Programme\Mozilla Firefox\mozjs.dll () MOD - C:\WINDOWS\system32\msdmo.dll () MOD - C:\Programme\WinRAR\RarExt.dll () MOD - C:\WINDOWS\system32\ati2evxx.dll () MOD - C:\WINDOWS\system32\pdfcmnnt.dll () ========== Services (SafeList) ========== SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (SLService) -- C:\WINDOWS\System32\slserv.exe (Smart Link) SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found DRV - (PDRFRAME) -- File not found DRV - (PDRELI) -- File not found DRV - (PDFRAME) -- File not found DRV - (PDCOMP) -- File not found DRV - (PCIDump) -- File not found DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys File not found DRV - (lbrtfdc) -- File not found DRV - (i2omgmt) -- File not found DRV - (Changer) -- File not found DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation) DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation) DRV - (AFS2K) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.) DRV - (Mtlstrm) -- C:\WINDOWS\system32\drivers\mtlstrm.sys ( ) DRV - (Mtlmnt5) -- C:\WINDOWS\system32\drivers\mtlmnt5.sys ( ) DRV - (Slnt7554) -- C:\WINDOWS\system32\drivers\slnt7554.sys ( ) DRV - (SlNtHal) -- C:\WINDOWS\system32\drivers\slnthal.sys ( ) DRV - (RecAgent) -- C:\WINDOWS\system32\drivers\RecAgent.sys ( ) DRV - (SlWdmSup) -- C:\WINDOWS\system32\drivers\slwdmsup.sys ( ) DRV - (NtMtlFax) -- C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link) DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (PLCNDIS5) -- C:\WINDOWS\system32\plcndis5.sys (Intellon, Inc.) DRV - (viaagp1) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.) DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation) DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.utanet.at/ IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://suche.aon.at IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.telekom.at IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes,DefaultScope = {99968DBC-2B29-494F-A050-29B9BDB22FCF} IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{99968DBC-2B29-494F-A050-29B9BDB22FCF}: "URL" = hxxp://www.google.at/search?hl=de&q={searchTerms}&meta= IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.23 10:04:56 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.03.09 12:28:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.03.23 10:07:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions [2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.03.23 10:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.03.07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2013.03.07 16:45:15 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.07 16:45:15 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2013.03.07 16:45:15 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2013.03.07 16:45:15 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2013.03.07 16:45:15 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2013.03.07 16:45:15 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2001.08.23 11:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {147D6308-0614-4112-89B1-31402F9B82C4} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP) O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NWEReboot] File not found O4 - HKLM..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe (Apple Computer, Inc.) O4 - HKU\S-1-5-21-436374069-1614895754-839522115-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-436374069-1614895754-839522115-1003..\Run: [E06DXLRD_1476890] "C:\Programme\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE" -m File not found O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 O15 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..Trusted Domains: uni-graz.at ([]https in Vertrauenswürdige Sites) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1348999421515 (WUWebControl Class) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CD0B796-8D2C-433B-8D55-EB74130C2239}: DhcpNameServer = 195.34.133.21 195.34.133.22 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B10F9BE5-DA3F-4B17-9954-DED73D9F9628}: DhcpNameServer = 195.34.133.21 195.34.133.22 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D3D40258-515E-4126-B155-DCCACE2B1CF7}: DhcpNameServer = 10.0.0.138 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3A5CA91-A3DF-4D41-9D1D-F3B6AE8ADCEF}: DhcpNameServer = 195.34.133.21 195.34.133.22 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll () O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.02.13 17:03:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.03.23 12:28:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe [2013.03.23 12:26:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Desktop\LOGS [2013.03.23 11:48:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Malwarebytes [2013.03.23 11:48:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware [2013.03.23 11:48:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes [2013.03.23 11:48:15 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2013.03.23 11:48:15 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2013.03.23 10:16:16 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira [2013.03.09 12:28:08 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox [2009.06.20 10:44:29 | 053,634,800 | ---- | C] (Microsoft Corporation) -- C:\Programme\ExcelViewer.exe [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 d:\*.tmp files -> d:\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.03.23 12:33:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{92EA0041-BA85-4B6E-A2C1-892B498D1258}.job [2013.03.23 12:28:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe [2013.03.23 12:25:36 | 000,609,993 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe [2013.03.23 12:13:01 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013.03.23 11:48:18 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.23 10:17:56 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn [2013.03.23 10:17:54 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013.03.23 10:17:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013.03.23 10:16:16 | 000,001,677 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk [2013.03.23 10:07:36 | 000,001,638 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk [2013.03.23 10:05:01 | 000,000,702 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2013.03.23 09:52:22 | 000,002,509 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\Microsoft Office Word 2003.lnk [2013.03.17 17:53:34 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for [2013.03.15 20:00:00 | 000,000,610 | ---- | M] () -- C:\WINDOWS\tasks\Norton Internet Security - Vollständige Systemprüfung ausführen - Alfred.job [2013.03.06 17:56:09 | 000,000,278 | ---- | M] () -- C:\WINDOWS\hpqcopy.INI [2013.03.01 11:47:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 d:\*.tmp files -> d:\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.03.23 12:26:00 | 000,609,993 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe [2013.03.23 11:48:18 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.23 10:05:01 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2012.09.30 12:20:55 | 000,292,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.05.29 09:59:39 | 000,067,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\1f785d9b79d933f1.sys [2012.05.21 10:23:11 | 000,064,984 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\pl468q4scf.exe [2012.02.16 11:32:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010.03.09 17:01:04 | 000,000,082 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\default.pls [2006.07.09 10:13:00 | 000,038,451 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Microsoft Excel.ADR [2006.07.09 10:05:13 | 000,009,354 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Tabulatorgetrennte Werte (Windows).EML [2006.07.09 06:51:20 | 000,045,424 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\IMG_3054[2].jpg [2006.02.14 15:08:14 | 000,000,139 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2006.02.14 12:49:18 | 000,007,680 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.02.14 12:29:00 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\System32\shdocvw.dll -- [2008.04.14 03:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\System32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\System32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Dokumente und Einstellungen\Alfred\pl468q4scf.exe:SummaryInformation < End of report > Vielen Dank schon mal für eure Hilfe! |
23.03.2013, 14:47 | #2 |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Hallo und
__________________Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten. Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schliessen von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich. Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist. Arbeite daher in deinem eigenen Interesse solange mit, bis du das OK bekommst, dass alles erledigt ist. Hinweise zum Ablauf
Mal schauen: Schritt 1 Downloade dir bitte aswMBR.exe und speichere die Datei auf deinen Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung. Hinweis: Sollte der Scan Button ausgeblendet sein, schliesse das Tool und starte es erneut. Sollte es erneut nicht klappen, teile mir das bitte mit. Schritt 2 Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts löschen, sondern nur einen Scan-Report sehen. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ |
24.03.2013, 08:56 | #3 |
| Virus/Trojaner "pl468q4scf.exe" Hey! Danke für die schnelle Rückmeldung. Bin erst jetzt dazugekommen, die scans durchzuführen.
__________________Hier die Logs: 1. aswMBR Code:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-03-24 08:40:27 ----------------------------- 08:40:27.484 OS Version: Windows 5.1.2600 Service Pack 3 08:40:27.484 Number of processors: 2 586 0x401 08:40:27.484 ComputerName: FAMILIE-5RMVRRM UserName: Alfred 08:40:28.015 Initialze error C0000001 - driver not loaded 08:43:56.593 AVAST engine defs: 13032302 08:44:17.140 Service scanning 08:44:17.515 Service 1f785d9b79d933f1 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys **HIDDEN** 08:44:33.328 Modules scanning 08:44:33.328 Disk 0 trace - called modules: 08:44:33.328 08:44:33.734 AVAST engine scan C:\WINDOWS 08:44:36.296 AVAST engine scan C:\WINDOWS\system32 08:46:32.062 AVAST engine scan C:\WINDOWS\system32\drivers 08:46:32.156 File: C:\WINDOWS\system32\drivers\1f785d9b79d933f1.sys **INFECTED** Win32:Malware-gen 08:46:43.328 AVAST engine scan C:\Dokumente und Einstellungen\Alfred 08:48:13.609 File: C:\Dokumente und Einstellungen\Alfred\pl468q4scf.exe **INFECTED** Win32:Kryptik-LFQ [Trj] 08:48:15.390 AVAST engine scan C:\Dokumente und Einstellungen\All Users 08:48:22.687 Scan finished successfully 08:49:13.265 The log file has been saved successfully to "C:\Dokumente und Einstellungen\Alfred\Desktop\LOGS\aswMBR.txt" 2. TDSSKiller: Code:
ATTFilter 08:49:50.0281 3504 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 08:49:50.0531 3504 ============================================================ 08:49:50.0531 3504 Current date / time: 2013/03/24 08:49:50.0531 08:49:50.0531 3504 SystemInfo: 08:49:50.0531 3504 08:49:50.0531 3504 OS Version: 5.1.2600 ServicePack: 3.0 08:49:50.0531 3504 Product type: Workstation 08:49:50.0531 3504 ComputerName: FAMILIE-5RMVRRM 08:49:50.0531 3504 UserName: Alfred 08:49:50.0531 3504 Windows directory: C:\WINDOWS 08:49:50.0531 3504 System windows directory: C:\WINDOWS 08:49:50.0546 3504 Processor architecture: Intel x86 08:49:50.0546 3504 Number of processors: 2 08:49:50.0546 3504 Page size: 0x1000 08:49:50.0546 3504 Boot type: Normal boot 08:49:50.0546 3504 ============================================================ 08:50:00.0578 3504 !crdlk 08:50:00.0625 3504 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A' 08:50:00.0640 3504 ============================================================ 08:50:00.0640 3504 \Device\Harddisk0\DR0: 08:50:00.0640 3504 MBR partitions: 08:50:00.0640 3504 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x88B8F9D 08:50:00.0656 3504 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x88B901B, BlocksNum 0xA15BBE5 08:50:00.0656 3504 ============================================================ 08:50:00.0671 3504 C: <-> \Device\Harddisk0\DR0\Partition1 08:50:00.0718 3504 D: <-> \Device\Harddisk0\DR0\Partition2 08:50:00.0734 3504 ============================================================ 08:50:00.0734 3504 Initialize success 08:50:00.0734 3504 ============================================================ 08:50:27.0578 1048 ============================================================ 08:50:27.0578 1048 Scan started 08:50:27.0578 1048 Mode: Manual; 08:50:27.0578 1048 ============================================================ 08:50:27.0859 1048 ================ Scan system memory ======================== 08:50:27.0859 1048 System memory - ok 08:50:27.0859 1048 ================ Scan services ============================= 08:50:27.0890 1048 Suspicious service (NoAccess): 1f785d9b79d933f1 08:50:28.0000 1048 [ CDAFD93CE777BABE4396781A5BAA2983 ] 1f785d9b79d933f1 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys 08:50:28.0000 1048 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys. md5: CDAFD93CE777BABE4396781A5BAA2983 08:50:29.0296 1048 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - infected 08:50:29.0296 1048 1f785d9b79d933f1 - detected Rootkit.Win32.Necurs.gen (0) 08:50:29.0343 1048 Abiosdsk - ok 08:50:29.0359 1048 abp480n5 - ok 08:50:29.0406 1048 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 08:50:29.0421 1048 ACPI - ok 08:50:29.0453 1048 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 08:50:29.0453 1048 ACPIEC - ok 08:50:29.0468 1048 adpu160m - ok 08:50:29.0515 1048 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 08:50:29.0515 1048 aec - ok 08:50:29.0562 1048 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 08:50:29.0562 1048 AFD - ok 08:50:29.0625 1048 [ B34B1AB0A7690A0E2301FEC6D17B2FC1 ] AFS2K C:\WINDOWS\system32\drivers\AFS2K.sys 08:50:29.0625 1048 AFS2K - ok 08:50:29.0640 1048 Aha154x - ok 08:50:29.0656 1048 aic78u2 - ok 08:50:29.0671 1048 aic78xx - ok 08:50:29.0718 1048 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WINDOWS\system32\alrsvc.dll 08:50:29.0734 1048 Alerter - ok 08:50:29.0781 1048 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WINDOWS\System32\alg.exe 08:50:29.0781 1048 ALG - ok 08:50:29.0796 1048 AliIde - ok 08:50:29.0812 1048 amsint - ok 08:50:29.0937 1048 [ 459465DA28E49B358ECFE0D788F328F4 ] AntiVirSchedulerService C:\Programme\Avira\AntiVir Desktop\sched.exe 08:50:29.0953 1048 AntiVirSchedulerService - ok 08:50:30.0031 1048 [ BCDD17E8469D647A71B347C4B6F86685 ] AntiVirService C:\Programme\Avira\AntiVir Desktop\avguard.exe 08:50:30.0031 1048 AntiVirService - ok 08:50:30.0078 1048 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 08:50:30.0093 1048 AppMgmt - ok 08:50:30.0125 1048 asc - ok 08:50:30.0156 1048 asc3350p - ok 08:50:30.0171 1048 asc3550 - ok 08:50:30.0265 1048 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 08:50:30.0265 1048 aspnet_state - ok 08:50:30.0328 1048 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 08:50:30.0328 1048 AsyncMac - ok 08:50:30.0375 1048 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 08:50:30.0375 1048 atapi - ok 08:50:30.0390 1048 Atdisk - ok 08:50:30.0437 1048 [ 89F6CB7B23111572C43F790D222C0415 ] Ati HotKey Poller C:\WINDOWS\System32\Ati2evxx.exe 08:50:30.0468 1048 Ati HotKey Poller - ok 08:50:30.0531 1048 [ B191D38D38E0ACC8CE22FA8E3D83B6B0 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe 08:50:30.0546 1048 ATI Smart - ok 08:50:30.0625 1048 [ 58F6F26083828FD18696F3592323BA21 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 08:50:30.0640 1048 ati2mtag - ok 08:50:30.0703 1048 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 08:50:30.0703 1048 Atmarpc - ok 08:50:30.0765 1048 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 08:50:30.0765 1048 AudioSrv - ok 08:50:30.0812 1048 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 08:50:30.0812 1048 audstub - ok 08:50:30.0875 1048 [ A5C175039B1D6D85D0E79F5855828E4D ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys 08:50:30.0875 1048 avgntflt - ok 08:50:30.0921 1048 [ 37B854C7D1F477E66C5B49C7700C47CC ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys 08:50:30.0921 1048 avipbb - ok 08:50:31.0000 1048 [ CC4EBA25D80DE42BBC2BF3E553219388 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys 08:50:31.0000 1048 avkmgr - ok 08:50:31.0062 1048 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 08:50:31.0062 1048 Beep - ok 08:50:31.0125 1048 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WINDOWS\system32\qmgr.dll 08:50:31.0140 1048 BITS - ok 08:50:31.0218 1048 [ B42057F06BBB98B31876C0B3F2B54E33 ] Browser C:\WINDOWS\System32\browser.dll 08:50:31.0234 1048 Browser - ok 08:50:31.0265 1048 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 08:50:31.0265 1048 cbidf2k - ok 08:50:31.0281 1048 cd20xrnt - ok 08:50:31.0328 1048 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 08:50:31.0328 1048 Cdaudio - ok 08:50:31.0375 1048 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 08:50:31.0375 1048 Cdfs - ok 08:50:31.0406 1048 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 08:50:31.0406 1048 Cdrom - ok 08:50:31.0421 1048 Changer - ok 08:50:31.0468 1048 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WINDOWS\system32\cisvc.exe 08:50:31.0468 1048 CiSvc - ok 08:50:31.0515 1048 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 08:50:31.0515 1048 ClipSrv - ok 08:50:31.0531 1048 CmdIde - ok 08:50:31.0609 1048 [ E5ADEEF2C0DB43964223F408F1FCC97E ] cmuda C:\WINDOWS\system32\drivers\cmuda.sys 08:50:31.0640 1048 cmuda - ok 08:50:31.0687 1048 COMSysApp - ok 08:50:31.0718 1048 Cpqarray - ok 08:50:31.0765 1048 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 08:50:31.0781 1048 CryptSvc - ok 08:50:31.0796 1048 dac2w2k - ok 08:50:31.0812 1048 dac960nt - ok 08:50:31.0875 1048 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 08:50:31.0890 1048 DcomLaunch - ok 08:50:31.0953 1048 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 08:50:31.0953 1048 Dhcp - ok 08:50:32.0000 1048 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 08:50:32.0000 1048 Disk - ok 08:50:32.0015 1048 dmadmin - ok 08:50:32.0062 1048 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 08:50:32.0093 1048 dmboot - ok 08:50:32.0156 1048 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WINDOWS\system32\drivers\dmio.sys 08:50:32.0156 1048 dmio - ok 08:50:32.0203 1048 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 08:50:32.0203 1048 dmload - ok 08:50:32.0250 1048 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WINDOWS\System32\dmserver.dll 08:50:32.0250 1048 dmserver - ok 08:50:32.0265 1048 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 08:50:32.0265 1048 DMusic - ok 08:50:32.0328 1048 [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 08:50:32.0343 1048 Dnscache - ok 08:50:32.0406 1048 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 08:50:32.0406 1048 Dot3svc - ok 08:50:32.0437 1048 dpti2o - ok 08:50:32.0468 1048 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 08:50:32.0468 1048 drmkaud - ok 08:50:32.0531 1048 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WINDOWS\System32\eapsvc.dll 08:50:32.0531 1048 EapHost - ok 08:50:32.0578 1048 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WINDOWS\System32\ersvc.dll 08:50:32.0578 1048 ERSvc - ok 08:50:32.0640 1048 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WINDOWS\system32\services.exe 08:50:32.0640 1048 Eventlog - ok 08:50:32.0687 1048 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WINDOWS\System32\es.dll 08:50:32.0687 1048 EventSystem - ok 08:50:32.0718 1048 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 08:50:32.0734 1048 Fastfat - ok 08:50:32.0796 1048 [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 08:50:32.0796 1048 FastUserSwitchingCompatibility - ok 08:50:32.0828 1048 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 08:50:32.0828 1048 Fdc - ok 08:50:32.0859 1048 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys 08:50:32.0859 1048 FETNDIS - ok 08:50:32.0921 1048 [ B7186B33B6CF3A23841015531E6E7D68 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys 08:50:32.0921 1048 FETNDISB - ok 08:50:32.0937 1048 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 08:50:32.0953 1048 Fips - ok 08:50:33.0000 1048 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 08:50:33.0000 1048 Flpydisk - ok 08:50:33.0046 1048 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 08:50:33.0046 1048 FltMgr - ok 08:50:33.0078 1048 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 08:50:33.0078 1048 Fs_Rec - ok 08:50:33.0109 1048 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 08:50:33.0109 1048 Ftdisk - ok 08:50:33.0140 1048 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys 08:50:33.0140 1048 gameenum - ok 08:50:33.0171 1048 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 08:50:33.0171 1048 Gpc - ok 08:50:33.0265 1048 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Programme\Google\Update\GoogleUpdate.exe 08:50:33.0265 1048 gupdate - ok 08:50:33.0296 1048 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Programme\Google\Update\GoogleUpdate.exe 08:50:33.0312 1048 gupdatem - ok 08:50:33.0375 1048 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 08:50:33.0375 1048 helpsvc - ok 08:50:33.0406 1048 HidServ - ok 08:50:33.0453 1048 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 08:50:33.0453 1048 HidUsb - ok 08:50:33.0515 1048 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 08:50:33.0515 1048 hkmsvc - ok 08:50:33.0546 1048 hpn - ok 08:50:33.0593 1048 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 08:50:33.0593 1048 HTTP - ok 08:50:33.0671 1048 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 08:50:33.0671 1048 HTTPFilter - ok 08:50:33.0703 1048 i2omgmt - ok 08:50:33.0718 1048 i2omp - ok 08:50:33.0765 1048 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 08:50:33.0765 1048 i8042prt - ok 08:50:33.0796 1048 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 08:50:33.0796 1048 Imapi - ok 08:50:33.0843 1048 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WINDOWS\System32\imapi.exe 08:50:33.0859 1048 ImapiService - ok 08:50:33.0953 1048 ini910u - ok 08:50:33.0984 1048 IntelIde - ok 08:50:34.0031 1048 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 08:50:34.0031 1048 intelppm - ok 08:50:34.0062 1048 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys 08:50:34.0062 1048 ip6fw - ok 08:50:34.0109 1048 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 08:50:34.0109 1048 IpFilterDriver - ok 08:50:34.0156 1048 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 08:50:34.0156 1048 IpInIp - ok 08:50:34.0187 1048 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 08:50:34.0187 1048 IpNat - ok 08:50:34.0234 1048 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 08:50:34.0234 1048 IPSec - ok 08:50:34.0265 1048 [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda C:\WINDOWS\system32\DRIVERS\irda.sys 08:50:34.0265 1048 irda - ok 08:50:34.0312 1048 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 08:50:34.0312 1048 IRENUM - ok 08:50:34.0343 1048 [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon C:\WINDOWS\System32\irmon.dll 08:50:34.0359 1048 Irmon - ok 08:50:34.0390 1048 [ 0501F0B9AB08425F8C0EACBDCC04AA32 ] irsir C:\WINDOWS\system32\DRIVERS\irsir.sys 08:50:34.0390 1048 irsir - ok 08:50:34.0421 1048 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 08:50:34.0421 1048 isapnp - ok 08:50:34.0484 1048 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 08:50:34.0484 1048 Kbdclass - ok 08:50:34.0500 1048 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 08:50:34.0500 1048 kmixer - ok 08:50:34.0531 1048 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 08:50:34.0546 1048 KSecDD - ok 08:50:34.0593 1048 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 08:50:34.0609 1048 lanmanserver - ok 08:50:34.0656 1048 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 08:50:34.0671 1048 lanmanworkstation - ok 08:50:34.0687 1048 lbrtfdc - ok 08:50:34.0734 1048 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 08:50:34.0734 1048 LmHosts - ok 08:50:34.0812 1048 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE 08:50:34.0828 1048 MDM - ok 08:50:34.0890 1048 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WINDOWS\System32\msgsvc.dll 08:50:34.0906 1048 Messenger - ok 08:50:34.0937 1048 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 08:50:34.0937 1048 mnmdd - ok 08:50:34.0984 1048 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe 08:50:34.0984 1048 mnmsrvc - ok 08:50:35.0031 1048 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 08:50:35.0031 1048 Modem - ok 08:50:35.0093 1048 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys 08:50:35.0093 1048 MODEMCSA - ok 08:50:35.0125 1048 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 08:50:35.0125 1048 Mouclass - ok 08:50:35.0171 1048 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 08:50:35.0171 1048 MountMgr - ok 08:50:35.0265 1048 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 08:50:35.0265 1048 MozillaMaintenance - ok 08:50:35.0296 1048 mraid35x - ok 08:50:35.0359 1048 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 08:50:35.0359 1048 MRxDAV - ok 08:50:35.0406 1048 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 08:50:35.0421 1048 MRxSmb - ok 08:50:35.0484 1048 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WINDOWS\System32\msdtc.exe 08:50:35.0484 1048 MSDTC - ok 08:50:35.0500 1048 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 08:50:35.0500 1048 Msfs - ok 08:50:35.0531 1048 MSIServer - ok 08:50:35.0546 1048 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 08:50:35.0546 1048 MSKSSRV - ok 08:50:35.0578 1048 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 08:50:35.0578 1048 MSPCLOCK - ok 08:50:35.0625 1048 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 08:50:35.0625 1048 MSPQM - ok 08:50:35.0703 1048 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 08:50:35.0703 1048 mssmbios - ok 08:50:35.0734 1048 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys 08:50:35.0734 1048 ms_mpu401 - ok 08:50:35.0781 1048 [ 6433EC4BCE450447C7947F6181A9E268 ] Mtlmnt5 C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys 08:50:35.0796 1048 Mtlmnt5 - ok 08:50:35.0875 1048 [ 30B87862B93574A20D78E1FF63C88694 ] Mtlstrm C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys 08:50:35.0906 1048 Mtlstrm - ok 08:50:35.0984 1048 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 08:50:36.0000 1048 Mup - ok 08:50:36.0046 1048 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WINDOWS\System32\qagentrt.dll 08:50:36.0062 1048 napagent - ok 08:50:36.0125 1048 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 08:50:36.0125 1048 NDIS - ok 08:50:36.0156 1048 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 08:50:36.0156 1048 NdisTapi - ok 08:50:36.0187 1048 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 08:50:36.0187 1048 Ndisuio - ok 08:50:36.0234 1048 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 08:50:36.0234 1048 NdisWan - ok 08:50:36.0296 1048 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 08:50:36.0296 1048 NDProxy - ok 08:50:36.0328 1048 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 08:50:36.0328 1048 NetBIOS - ok 08:50:36.0343 1048 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 08:50:36.0343 1048 NetBT - ok 08:50:36.0390 1048 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WINDOWS\system32\netdde.exe 08:50:36.0406 1048 NetDDE - ok 08:50:36.0437 1048 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 08:50:36.0437 1048 NetDDEdsdm - ok 08:50:36.0484 1048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WINDOWS\System32\lsass.exe 08:50:36.0484 1048 Netlogon - ok 08:50:36.0546 1048 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WINDOWS\System32\netman.dll 08:50:36.0546 1048 Netman - ok 08:50:36.0593 1048 [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla C:\WINDOWS\System32\mswsock.dll 08:50:36.0609 1048 Nla - ok 08:50:36.0671 1048 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 08:50:36.0671 1048 Npfs - ok 08:50:36.0703 1048 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 08:50:36.0718 1048 Ntfs - ok 08:50:36.0750 1048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WINDOWS\System32\lsass.exe 08:50:36.0750 1048 NtLmSsp - ok 08:50:36.0812 1048 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 08:50:36.0828 1048 NtmsSvc - ok 08:50:36.0921 1048 [ 576B34CEAE5B7E5D9FD2775E93B3DB53 ] NtMtlFax C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys 08:50:36.0921 1048 NtMtlFax - ok 08:50:36.0968 1048 [ A568B9A9FFE2D9387222A5C90F86D731 ] NTSIM C:\WINDOWS\System32\ntsim.sys 08:50:36.0984 1048 NTSIM - ok 08:50:37.0015 1048 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 08:50:37.0015 1048 Null - ok 08:50:37.0078 1048 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 08:50:37.0078 1048 NwlnkFlt - ok 08:50:37.0093 1048 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 08:50:37.0093 1048 NwlnkFwd - ok 08:50:37.0156 1048 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 08:50:37.0171 1048 ose - ok 08:50:37.0250 1048 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 08:50:37.0250 1048 Parport - ok 08:50:37.0296 1048 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 08:50:37.0296 1048 PartMgr - ok 08:50:37.0328 1048 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 08:50:37.0328 1048 ParVdm - ok 08:50:37.0390 1048 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 08:50:37.0390 1048 PCI - ok 08:50:37.0406 1048 PCIDump - ok 08:50:37.0437 1048 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 08:50:37.0453 1048 PCIIde - ok 08:50:37.0484 1048 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 08:50:37.0484 1048 Pcmcia - ok 08:50:37.0500 1048 PDCOMP - ok 08:50:37.0515 1048 PDFRAME - ok 08:50:37.0531 1048 PDRELI - ok 08:50:37.0546 1048 PDRFRAME - ok 08:50:37.0578 1048 perc2 - ok 08:50:37.0593 1048 perc2hib - ok 08:50:37.0703 1048 [ 2ABA2F545B35F9C6CC2CFC4E1D539A80 ] PLCNDIS5 C:\WINDOWS\system32\plcndis5.sys 08:50:37.0703 1048 PLCNDIS5 - ok 08:50:37.0734 1048 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WINDOWS\system32\services.exe 08:50:37.0734 1048 PlugPlay - ok 08:50:37.0765 1048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WINDOWS\System32\lsass.exe 08:50:37.0765 1048 PolicyAgent - ok 08:50:37.0812 1048 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 08:50:37.0812 1048 PptpMiniport - ok 08:50:37.0843 1048 [ 2CB55427C58679F49AD600FCCBA76360 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys 08:50:37.0859 1048 Processor - ok 08:50:37.0875 1048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 08:50:37.0890 1048 ProtectedStorage - ok 08:50:37.0906 1048 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 08:50:37.0921 1048 PSched - ok 08:50:37.0953 1048 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 08:50:37.0968 1048 Ptilink - ok 08:50:37.0984 1048 ql1080 - ok 08:50:38.0000 1048 Ql10wnt - ok 08:50:38.0015 1048 ql12160 - ok 08:50:38.0031 1048 ql1240 - ok 08:50:38.0062 1048 ql1280 - ok 08:50:38.0078 1048 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 08:50:38.0078 1048 RasAcd - ok 08:50:38.0156 1048 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WINDOWS\System32\rasauto.dll 08:50:38.0156 1048 RasAuto - ok 08:50:38.0203 1048 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys 08:50:38.0203 1048 Rasirda - ok 08:50:38.0218 1048 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 08:50:38.0218 1048 Rasl2tp - ok 08:50:38.0281 1048 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WINDOWS\System32\rasmans.dll 08:50:38.0296 1048 RasMan - ok 08:50:38.0328 1048 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 08:50:38.0328 1048 RasPppoe - ok 08:50:38.0343 1048 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 08:50:38.0343 1048 Raspti - ok 08:50:38.0390 1048 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 08:50:38.0390 1048 Rdbss - ok 08:50:38.0421 1048 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 08:50:38.0421 1048 RDPCDD - ok 08:50:38.0453 1048 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 08:50:38.0453 1048 rdpdr - ok 08:50:38.0515 1048 [ 5B3055DAA788BD688594D2F5981F2A83 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 08:50:38.0515 1048 RDPWD - ok 08:50:38.0578 1048 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 08:50:38.0578 1048 RDSessMgr - ok 08:50:38.0640 1048 [ 41315D97BB319BD5B5E1B367570E7B3C ] RecAgent C:\WINDOWS\system32\DRIVERS\RecAgent.sys 08:50:38.0640 1048 RecAgent - ok 08:50:38.0703 1048 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 08:50:38.0703 1048 redbook - ok 08:50:38.0750 1048 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 08:50:38.0750 1048 RemoteAccess - ok 08:50:38.0796 1048 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 08:50:38.0812 1048 RemoteRegistry - ok 08:50:38.0859 1048 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WINDOWS\System32\locator.exe 08:50:38.0859 1048 RpcLocator - ok 08:50:38.0906 1048 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WINDOWS\system32\rpcss.dll 08:50:38.0921 1048 RpcSs - ok 08:50:38.0953 1048 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\System32\rsvp.exe 08:50:38.0968 1048 RSVP - ok 08:50:39.0015 1048 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WINDOWS\system32\lsass.exe 08:50:39.0015 1048 SamSs - ok 08:50:39.0062 1048 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 08:50:39.0062 1048 SCardSvr - ok 08:50:39.0125 1048 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WINDOWS\system32\schedsvc.dll 08:50:39.0125 1048 Schedule - ok 08:50:39.0218 1048 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 08:50:39.0218 1048 Secdrv - ok 08:50:39.0265 1048 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WINDOWS\System32\seclogon.dll 08:50:39.0265 1048 seclogon - ok 08:50:39.0328 1048 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WINDOWS\system32\sens.dll 08:50:39.0328 1048 SENS - ok 08:50:39.0375 1048 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 08:50:39.0375 1048 serenum - ok 08:50:39.0421 1048 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 08:50:39.0421 1048 Serial - ok 08:50:39.0453 1048 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 08:50:39.0453 1048 Sfloppy - ok 08:50:39.0500 1048 [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 08:50:39.0515 1048 SharedAccess - ok 08:50:39.0562 1048 [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 08:50:39.0562 1048 ShellHWDetection - ok 08:50:39.0578 1048 Simbad - ok 08:50:39.0640 1048 [ F3A4AB7230646941D41A9E2E754F047A ] Slnt7554 C:\WINDOWS\system32\DRIVERS\slnt7554.sys 08:50:39.0656 1048 Slnt7554 - ok 08:50:39.0687 1048 [ F06507086FF9BFDBCF3C5098A4848B5D ] SlNtHal C:\WINDOWS\system32\DRIVERS\Slnthal.sys 08:50:39.0687 1048 SlNtHal - ok 08:50:39.0718 1048 SLService - ok 08:50:39.0750 1048 [ CD4F4CEE4481E11BDA806A9366785A1D ] SlWdmSup C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys 08:50:39.0765 1048 SlWdmSup - ok 08:50:39.0781 1048 Sparrow - ok 08:50:39.0828 1048 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 08:50:39.0828 1048 splitter - ok 08:50:39.0890 1048 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 08:50:39.0890 1048 Spooler - ok 08:50:39.0906 1048 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 08:50:39.0921 1048 sr - ok 08:50:39.0968 1048 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WINDOWS\System32\srsvc.dll 08:50:39.0984 1048 srservice - ok 08:50:40.0031 1048 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 08:50:40.0046 1048 Srv - ok 08:50:40.0093 1048 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 08:50:40.0093 1048 SSDPSRV - ok 08:50:40.0171 1048 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 08:50:40.0171 1048 ssmdrv - ok 08:50:40.0234 1048 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WINDOWS\system32\wiaservc.dll 08:50:40.0250 1048 stisvc - ok 08:50:40.0312 1048 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 08:50:40.0312 1048 swenum - ok 08:50:40.0328 1048 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 08:50:40.0328 1048 swmidi - ok 08:50:40.0343 1048 SwPrv - ok 08:50:40.0390 1048 symc810 - ok 08:50:40.0406 1048 symc8xx - ok 08:50:40.0437 1048 sym_hi - ok 08:50:40.0453 1048 sym_u3 - ok 08:50:40.0500 1048 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 08:50:40.0500 1048 sysaudio - ok 08:50:40.0546 1048 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 08:50:40.0546 1048 SysmonLog - ok 08:50:40.0625 1048 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 08:50:40.0640 1048 TapiSrv - ok 08:50:40.0687 1048 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 08:50:40.0703 1048 Tcpip - ok 08:50:40.0765 1048 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 08:50:40.0765 1048 TDPIPE - ok 08:50:40.0796 1048 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 08:50:40.0796 1048 TDTCP - ok 08:50:40.0843 1048 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 08:50:40.0843 1048 TermDD - ok 08:50:40.0921 1048 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WINDOWS\System32\termsrv.dll 08:50:40.0953 1048 TermService - ok 08:50:41.0000 1048 [ 2DB7D303C36DDD055215052F118E8E75 ] Themes C:\WINDOWS\System32\shsvcs.dll 08:50:41.0000 1048 Themes - ok 08:50:41.0046 1048 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe 08:50:41.0046 1048 TlntSvr - ok 08:50:41.0093 1048 TosIde - ok 08:50:41.0156 1048 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WINDOWS\system32\trkwks.dll 08:50:41.0171 1048 TrkWks - ok 08:50:41.0203 1048 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 08:50:41.0203 1048 Udfs - ok 08:50:41.0218 1048 ultra - ok 08:50:41.0281 1048 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 08:50:41.0296 1048 Update - ok 08:50:41.0359 1048 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WINDOWS\System32\upnphost.dll 08:50:41.0375 1048 upnphost - ok 08:50:41.0406 1048 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WINDOWS\System32\ups.exe 08:50:41.0406 1048 UPS - ok 08:50:41.0468 1048 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 08:50:41.0468 1048 usbccgp - ok 08:50:41.0500 1048 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 08:50:41.0515 1048 usbehci - ok 08:50:41.0546 1048 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 08:50:41.0546 1048 usbhub - ok 08:50:41.0609 1048 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 08:50:41.0625 1048 usbscan - ok 08:50:41.0656 1048 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 08:50:41.0656 1048 USBSTOR - ok 08:50:41.0718 1048 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 08:50:41.0718 1048 usbuhci - ok 08:50:41.0781 1048 [ BEE793D4A059CAEA55D6AC20E19B3A8F ] USB_RNDIS C:\WINDOWS\system32\DRIVERS\usb8023.sys 08:50:41.0781 1048 USB_RNDIS - ok 08:50:41.0812 1048 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 08:50:41.0828 1048 VgaSave - ok 08:50:41.0875 1048 [ 4B039BBD037B01F5DB5A144C837F283A ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys 08:50:41.0875 1048 viaagp1 - ok 08:50:41.0921 1048 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 08:50:41.0921 1048 ViaIde - ok 08:50:41.0968 1048 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 08:50:41.0968 1048 VolSnap - ok 08:50:42.0015 1048 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WINDOWS\System32\vssvc.exe 08:50:42.0046 1048 VSS - ok 08:50:42.0109 1048 [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time C:\WINDOWS\System32\w32time.dll 08:50:42.0109 1048 W32Time - ok 08:50:42.0156 1048 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 08:50:42.0156 1048 Wanarp - ok 08:50:42.0171 1048 WDICA - ok 08:50:42.0203 1048 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 08:50:42.0203 1048 wdmaud - ok 08:50:42.0265 1048 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WINDOWS\System32\webclnt.dll 08:50:42.0265 1048 WebClient - ok 08:50:42.0359 1048 [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 08:50:42.0359 1048 winmgmt - ok 08:50:42.0453 1048 [ 6E18978B749F0696A774DE3F2CB142DD ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 08:50:42.0453 1048 WmdmPmSN - ok 08:50:42.0531 1048 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WINDOWS\System32\advapi32.dll 08:50:42.0562 1048 Wmi - ok 08:50:42.0625 1048 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe 08:50:42.0625 1048 WmiApSrv - ok 08:50:42.0703 1048 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WINDOWS\system32\wscsvc.dll 08:50:42.0703 1048 wscsvc - ok 08:50:42.0765 1048 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 08:50:42.0781 1048 wuauserv - ok 08:50:42.0828 1048 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 08:50:42.0843 1048 WZCSVC - ok 08:50:42.0906 1048 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 08:50:42.0906 1048 xmlprov - ok 08:50:42.0968 1048 ================ Scan global =============================== 08:50:43.0015 1048 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll 08:50:43.0062 1048 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 08:50:43.0093 1048 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 08:50:43.0109 1048 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe 08:50:43.0109 1048 [Global] - ok 08:50:43.0109 1048 ================ Scan MBR ================================== 08:50:43.0140 1048 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 08:50:43.0453 1048 \Device\Harddisk0\DR0 - ok 08:50:43.0453 1048 ================ Scan VBR ================================== 08:50:43.0453 1048 [ 419E0E86CCAEA9B1007E36922D127ADB ] \Device\Harddisk0\DR0\Partition1 08:50:43.0468 1048 \Device\Harddisk0\DR0\Partition1 - ok 08:50:43.0484 1048 [ 3A078522B2D615653713BB15F22B968C ] \Device\Harddisk0\DR0\Partition2 08:50:43.0484 1048 \Device\Harddisk0\DR0\Partition2 - ok 08:50:43.0484 1048 ============================================================ 08:50:43.0484 1048 Scan finished 08:50:43.0484 1048 ============================================================ 08:50:43.0609 1424 Detected object count: 1 08:50:43.0609 1424 Actual detected object count: 1 08:51:02.0250 1424 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - skipped by user 08:51:02.0250 1424 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - User select action: Skip 08:52:22.0000 3476 Deinitialize success |
24.03.2013, 13:39 | #4 | |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Hey, sieh an, wie vermutet der Kollege Necurs.. Schritt 1 Starte bitte TDSSkiller.exe. Vista und Win7 User mit Rechtsklick "als Administrator ausführen".
Schritt 2 Warnung für Mitleser: Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix.
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
Schritt 3 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.03.2013, 21:17 | #5 |
| Virus/Trojaner "pl468q4scf.exe" Hey! Ich habe die Anweisungen schön befolgt... ;-) 2 abweichungen: * die Option "cure" bei TDSSKiller stand nicht zur Verfügung - stattdessen habe ich "delete" gewählt. * Combofix hat keinen Neustart erzwungen, als Abschluss wurde das Log ausgegeben. Habe dann manuell neu gestartet. Die Symtome sind jetz eigentlich weg. Der Rechner startet in einer normalen Geschwindigkeit. Ich hoff, damit hat sichs dann! ) Anbei noch die Logs: TDSSKiller (2 Logs): Code:
ATTFilter 20:21:49.0562 0460 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 20:21:49.0718 0460 ============================================================ 20:21:49.0718 0460 Current date / time: 2013/03/24 20:21:49.0718 20:21:49.0718 0460 SystemInfo: 20:21:49.0718 0460 20:21:49.0718 0460 OS Version: 5.1.2600 ServicePack: 3.0 20:21:49.0718 0460 Product type: Workstation 20:21:49.0718 0460 ComputerName: FAMILIE-5RMVRRM 20:21:49.0718 0460 UserName: Alfred 20:21:49.0718 0460 Windows directory: C:\WINDOWS 20:21:49.0718 0460 System windows directory: C:\WINDOWS 20:21:49.0718 0460 Processor architecture: Intel x86 20:21:49.0718 0460 Number of processors: 2 20:21:49.0718 0460 Page size: 0x1000 20:21:49.0718 0460 Boot type: Normal boot 20:21:49.0718 0460 ============================================================ 20:21:52.0906 0460 !crdlk 20:21:52.0921 0460 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A' 20:21:52.0921 0460 ============================================================ 20:21:52.0921 0460 \Device\Harddisk0\DR0: 20:21:52.0921 0460 MBR partitions: 20:21:52.0921 0460 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x88B8F9D 20:21:52.0937 0460 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x88B901B, BlocksNum 0xA15BBE5 20:21:52.0937 0460 ============================================================ 20:21:52.0953 0460 C: <-> \Device\Harddisk0\DR0\Partition1 20:21:53.0015 0460 D: <-> \Device\Harddisk0\DR0\Partition2 20:21:53.0015 0460 ============================================================ 20:21:53.0015 0460 Initialize success 20:21:53.0015 0460 ============================================================ 20:22:34.0796 1324 ============================================================ 20:22:34.0796 1324 Scan started 20:22:34.0796 1324 Mode: Manual; 20:22:34.0796 1324 ============================================================ 20:22:34.0968 1324 ================ Scan system memory ======================== 20:22:34.0968 1324 System memory - ok 20:22:34.0968 1324 ================ Scan services ============================= 20:22:35.0000 1324 Suspicious service (NoAccess): 1f785d9b79d933f1 20:22:35.0109 1324 [ CDAFD93CE777BABE4396781A5BAA2983 ] 1f785d9b79d933f1 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys 20:22:35.0109 1324 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys. md5: CDAFD93CE777BABE4396781A5BAA2983 20:22:35.0812 1324 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - infected 20:22:35.0812 1324 1f785d9b79d933f1 - detected Rootkit.Win32.Necurs.gen (0) 20:22:35.0843 1324 Abiosdsk - ok 20:22:35.0875 1324 abp480n5 - ok 20:22:35.0921 1324 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:22:35.0921 1324 ACPI - ok 20:22:35.0953 1324 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 20:22:35.0953 1324 ACPIEC - ok 20:22:35.0968 1324 adpu160m - ok 20:22:36.0015 1324 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 20:22:36.0015 1324 aec - ok 20:22:36.0062 1324 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 20:22:36.0062 1324 AFD - ok 20:22:36.0140 1324 [ B34B1AB0A7690A0E2301FEC6D17B2FC1 ] AFS2K C:\WINDOWS\system32\drivers\AFS2K.sys 20:22:36.0140 1324 AFS2K - ok 20:22:36.0156 1324 Aha154x - ok 20:22:36.0171 1324 aic78u2 - ok 20:22:36.0187 1324 aic78xx - ok 20:22:36.0250 1324 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WINDOWS\system32\alrsvc.dll 20:22:36.0250 1324 Alerter - ok 20:22:36.0296 1324 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WINDOWS\System32\alg.exe 20:22:36.0296 1324 ALG - ok 20:22:36.0312 1324 AliIde - ok 20:22:36.0328 1324 amsint - ok 20:22:36.0453 1324 [ 459465DA28E49B358ECFE0D788F328F4 ] AntiVirSchedulerService C:\Programme\Avira\AntiVir Desktop\sched.exe 20:22:36.0484 1324 AntiVirSchedulerService - ok 20:22:36.0562 1324 [ BCDD17E8469D647A71B347C4B6F86685 ] AntiVirService C:\Programme\Avira\AntiVir Desktop\avguard.exe 20:22:36.0562 1324 AntiVirService - ok 20:22:36.0609 1324 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 20:22:36.0609 1324 AppMgmt - ok 20:22:36.0656 1324 asc - ok 20:22:36.0671 1324 asc3350p - ok 20:22:36.0687 1324 asc3550 - ok 20:22:36.0781 1324 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 20:22:36.0781 1324 aspnet_state - ok 20:22:36.0843 1324 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:22:36.0843 1324 AsyncMac - ok 20:22:36.0875 1324 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 20:22:36.0875 1324 atapi - ok 20:22:36.0890 1324 Atdisk - ok 20:22:36.0953 1324 [ 89F6CB7B23111572C43F790D222C0415 ] Ati HotKey Poller C:\WINDOWS\System32\Ati2evxx.exe 20:22:36.0968 1324 Ati HotKey Poller - ok 20:22:37.0031 1324 [ B191D38D38E0ACC8CE22FA8E3D83B6B0 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe 20:22:37.0062 1324 ATI Smart - ok 20:22:37.0125 1324 [ 58F6F26083828FD18696F3592323BA21 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 20:22:37.0140 1324 ati2mtag - ok 20:22:37.0203 1324 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:22:37.0218 1324 Atmarpc - ok 20:22:37.0265 1324 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 20:22:37.0281 1324 AudioSrv - ok 20:22:37.0328 1324 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 20:22:37.0328 1324 audstub - ok 20:22:37.0390 1324 [ A5C175039B1D6D85D0E79F5855828E4D ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys 20:22:37.0390 1324 avgntflt - ok 20:22:37.0437 1324 [ 37B854C7D1F477E66C5B49C7700C47CC ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys 20:22:37.0453 1324 avipbb - ok 20:22:37.0500 1324 [ CC4EBA25D80DE42BBC2BF3E553219388 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys 20:22:37.0500 1324 avkmgr - ok 20:22:37.0562 1324 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 20:22:37.0562 1324 Beep - ok 20:22:37.0625 1324 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WINDOWS\system32\qmgr.dll 20:22:37.0656 1324 BITS - ok 20:22:37.0750 1324 [ B42057F06BBB98B31876C0B3F2B54E33 ] Browser C:\WINDOWS\System32\browser.dll 20:22:37.0750 1324 Browser - ok 20:22:37.0781 1324 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 20:22:37.0781 1324 cbidf2k - ok 20:22:37.0812 1324 cd20xrnt - ok 20:22:37.0843 1324 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 20:22:37.0843 1324 Cdaudio - ok 20:22:37.0890 1324 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 20:22:37.0906 1324 Cdfs - ok 20:22:37.0921 1324 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:22:37.0937 1324 Cdrom - ok 20:22:37.0953 1324 Changer - ok 20:22:37.0984 1324 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WINDOWS\system32\cisvc.exe 20:22:37.0984 1324 CiSvc - ok 20:22:38.0031 1324 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 20:22:38.0031 1324 ClipSrv - ok 20:22:38.0078 1324 CmdIde - ok 20:22:38.0140 1324 [ E5ADEEF2C0DB43964223F408F1FCC97E ] cmuda C:\WINDOWS\system32\drivers\cmuda.sys 20:22:38.0187 1324 cmuda - ok 20:22:38.0203 1324 COMSysApp - ok 20:22:38.0234 1324 Cpqarray - ok 20:22:38.0296 1324 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 20:22:38.0296 1324 CryptSvc - ok 20:22:38.0328 1324 dac2w2k - ok 20:22:38.0343 1324 dac960nt - ok 20:22:38.0406 1324 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 20:22:38.0421 1324 DcomLaunch - ok 20:22:38.0484 1324 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 20:22:38.0484 1324 Dhcp - ok 20:22:38.0531 1324 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 20:22:38.0546 1324 Disk - ok 20:22:38.0562 1324 dmadmin - ok 20:22:38.0609 1324 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 20:22:38.0625 1324 dmboot - ok 20:22:38.0687 1324 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WINDOWS\system32\drivers\dmio.sys 20:22:38.0687 1324 dmio - ok 20:22:38.0734 1324 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 20:22:38.0734 1324 dmload - ok 20:22:38.0781 1324 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WINDOWS\System32\dmserver.dll 20:22:38.0781 1324 dmserver - ok 20:22:38.0812 1324 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 20:22:38.0812 1324 DMusic - ok 20:22:38.0859 1324 [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 20:22:38.0859 1324 Dnscache - ok 20:22:38.0953 1324 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 20:22:38.0953 1324 Dot3svc - ok 20:22:39.0000 1324 dpti2o - ok 20:22:39.0031 1324 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 20:22:39.0031 1324 drmkaud - ok 20:22:39.0093 1324 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WINDOWS\System32\eapsvc.dll 20:22:39.0093 1324 EapHost - ok 20:22:39.0171 1324 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WINDOWS\System32\ersvc.dll 20:22:39.0171 1324 ERSvc - ok 20:22:39.0234 1324 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WINDOWS\system32\services.exe 20:22:39.0234 1324 Eventlog - ok 20:22:39.0281 1324 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WINDOWS\System32\es.dll 20:22:39.0296 1324 EventSystem - ok 20:22:39.0359 1324 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 20:22:39.0359 1324 Fastfat - ok 20:22:39.0406 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 20:22:39.0421 1324 FastUserSwitchingCompatibility - ok 20:22:39.0468 1324 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 20:22:39.0468 1324 Fdc - ok 20:22:39.0500 1324 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys 20:22:39.0500 1324 FETNDIS - ok 20:22:39.0546 1324 [ B7186B33B6CF3A23841015531E6E7D68 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys 20:22:39.0546 1324 FETNDISB - ok 20:22:39.0578 1324 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 20:22:39.0578 1324 Fips - ok 20:22:39.0625 1324 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20:22:39.0625 1324 Flpydisk - ok 20:22:39.0687 1324 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 20:22:39.0687 1324 FltMgr - ok 20:22:39.0718 1324 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:22:39.0718 1324 Fs_Rec - ok 20:22:39.0750 1324 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:22:39.0750 1324 Ftdisk - ok 20:22:39.0781 1324 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys 20:22:39.0781 1324 gameenum - ok 20:22:39.0828 1324 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:22:39.0828 1324 Gpc - ok 20:22:39.0921 1324 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Programme\Google\Update\GoogleUpdate.exe 20:22:39.0937 1324 gupdate - ok 20:22:39.0968 1324 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Programme\Google\Update\GoogleUpdate.exe 20:22:39.0968 1324 gupdatem - ok 20:22:40.0046 1324 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 20:22:40.0062 1324 helpsvc - ok 20:22:40.0078 1324 HidServ - ok 20:22:40.0125 1324 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:22:40.0125 1324 HidUsb - ok 20:22:40.0187 1324 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 20:22:40.0187 1324 hkmsvc - ok 20:22:40.0234 1324 hpn - ok 20:22:40.0265 1324 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 20:22:40.0281 1324 HTTP - ok 20:22:40.0343 1324 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 20:22:40.0343 1324 HTTPFilter - ok 20:22:40.0375 1324 i2omgmt - ok 20:22:40.0390 1324 i2omp - ok 20:22:40.0437 1324 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 20:22:40.0453 1324 i8042prt - ok 20:22:40.0468 1324 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 20:22:40.0468 1324 Imapi - ok 20:22:40.0515 1324 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WINDOWS\System32\imapi.exe 20:22:40.0515 1324 ImapiService - ok 20:22:40.0609 1324 ini910u - ok 20:22:40.0640 1324 IntelIde - ok 20:22:40.0703 1324 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:22:40.0703 1324 intelppm - ok 20:22:40.0734 1324 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys 20:22:40.0734 1324 ip6fw - ok 20:22:40.0781 1324 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:22:40.0796 1324 IpFilterDriver - ok 20:22:40.0828 1324 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:22:40.0828 1324 IpInIp - ok 20:22:40.0859 1324 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:22:40.0859 1324 IpNat - ok 20:22:40.0906 1324 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:22:40.0906 1324 IPSec - ok 20:22:40.0937 1324 [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda C:\WINDOWS\system32\DRIVERS\irda.sys 20:22:40.0937 1324 irda - ok 20:22:40.0953 1324 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 20:22:40.0953 1324 IRENUM - ok 20:22:41.0000 1324 [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon C:\WINDOWS\System32\irmon.dll 20:22:41.0000 1324 Irmon - ok 20:22:41.0031 1324 [ 0501F0B9AB08425F8C0EACBDCC04AA32 ] irsir C:\WINDOWS\system32\DRIVERS\irsir.sys 20:22:41.0031 1324 irsir - ok 20:22:41.0078 1324 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:22:41.0078 1324 isapnp - ok 20:22:41.0125 1324 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:22:41.0125 1324 Kbdclass - ok 20:22:41.0140 1324 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 20:22:41.0140 1324 kmixer - ok 20:22:41.0171 1324 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 20:22:41.0171 1324 KSecDD - ok 20:22:41.0265 1324 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 20:22:41.0265 1324 lanmanserver - ok 20:22:41.0328 1324 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 20:22:41.0343 1324 lanmanworkstation - ok 20:22:41.0390 1324 lbrtfdc - ok 20:22:41.0437 1324 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 20:22:41.0437 1324 LmHosts - ok 20:22:41.0515 1324 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE 20:22:41.0531 1324 MDM - ok 20:22:41.0593 1324 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WINDOWS\System32\msgsvc.dll 20:22:41.0593 1324 Messenger - ok 20:22:41.0625 1324 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 20:22:41.0625 1324 mnmdd - ok 20:22:41.0656 1324 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe 20:22:41.0671 1324 mnmsrvc - ok 20:22:41.0718 1324 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 20:22:41.0734 1324 Modem - ok 20:22:41.0781 1324 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys 20:22:41.0781 1324 MODEMCSA - ok 20:22:41.0812 1324 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:22:41.0812 1324 Mouclass - ok 20:22:41.0859 1324 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 20:22:41.0859 1324 MountMgr - ok 20:22:41.0937 1324 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 20:22:41.0937 1324 MozillaMaintenance - ok 20:22:41.0968 1324 mraid35x - ok 20:22:42.0031 1324 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:22:42.0031 1324 MRxDAV - ok 20:22:42.0078 1324 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:22:42.0093 1324 MRxSmb - ok 20:22:42.0156 1324 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WINDOWS\System32\msdtc.exe 20:22:42.0156 1324 MSDTC - ok 20:22:42.0187 1324 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 20:22:42.0187 1324 Msfs - ok 20:22:42.0218 1324 MSIServer - ok 20:22:42.0250 1324 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:22:42.0250 1324 MSKSSRV - ok 20:22:42.0281 1324 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:22:42.0281 1324 MSPCLOCK - ok 20:22:42.0328 1324 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 20:22:42.0328 1324 MSPQM - ok 20:22:42.0390 1324 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:22:42.0390 1324 mssmbios - ok 20:22:42.0437 1324 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys 20:22:42.0437 1324 ms_mpu401 - ok 20:22:42.0484 1324 [ 6433EC4BCE450447C7947F6181A9E268 ] Mtlmnt5 C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys 20:22:42.0500 1324 Mtlmnt5 - ok 20:22:42.0562 1324 [ 30B87862B93574A20D78E1FF63C88694 ] Mtlstrm C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys 20:22:42.0609 1324 Mtlstrm - ok 20:22:42.0687 1324 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 20:22:42.0687 1324 Mup - ok 20:22:42.0734 1324 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WINDOWS\System32\qagentrt.dll 20:22:42.0765 1324 napagent - ok 20:22:42.0828 1324 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 20:22:42.0828 1324 NDIS - ok 20:22:42.0859 1324 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:22:42.0859 1324 NdisTapi - ok 20:22:42.0890 1324 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:22:42.0890 1324 Ndisuio - ok 20:22:42.0921 1324 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:22:42.0937 1324 NdisWan - ok 20:22:42.0984 1324 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 20:22:42.0984 1324 NDProxy - ok 20:22:43.0015 1324 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 20:22:43.0015 1324 NetBIOS - ok 20:22:43.0031 1324 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 20:22:43.0046 1324 NetBT - ok 20:22:43.0093 1324 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WINDOWS\system32\netdde.exe 20:22:43.0093 1324 NetDDE - ok 20:22:43.0125 1324 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 20:22:43.0140 1324 NetDDEdsdm - ok 20:22:43.0171 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WINDOWS\System32\lsass.exe 20:22:43.0187 1324 Netlogon - ok 20:22:43.0234 1324 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WINDOWS\System32\netman.dll 20:22:43.0234 1324 Netman - ok 20:22:43.0296 1324 [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla C:\WINDOWS\System32\mswsock.dll 20:22:43.0312 1324 Nla - ok 20:22:43.0375 1324 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 20:22:43.0375 1324 Npfs - ok 20:22:43.0406 1324 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 20:22:43.0421 1324 Ntfs - ok 20:22:43.0453 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WINDOWS\System32\lsass.exe 20:22:43.0453 1324 NtLmSsp - ok 20:22:43.0531 1324 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 20:22:43.0546 1324 NtmsSvc - ok 20:22:43.0625 1324 [ 576B34CEAE5B7E5D9FD2775E93B3DB53 ] NtMtlFax C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys 20:22:43.0625 1324 NtMtlFax - ok 20:22:43.0687 1324 [ A568B9A9FFE2D9387222A5C90F86D731 ] NTSIM C:\WINDOWS\System32\ntsim.sys 20:22:43.0687 1324 NTSIM - ok 20:22:43.0734 1324 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 20:22:43.0734 1324 Null - ok 20:22:43.0781 1324 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:22:43.0781 1324 NwlnkFlt - ok 20:22:43.0812 1324 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:22:43.0812 1324 NwlnkFwd - ok 20:22:43.0859 1324 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 20:22:43.0859 1324 ose - ok 20:22:43.0953 1324 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 20:22:43.0953 1324 Parport - ok 20:22:43.0984 1324 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 20:22:43.0984 1324 PartMgr - ok 20:22:44.0015 1324 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 20:22:44.0031 1324 ParVdm - ok 20:22:44.0078 1324 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 20:22:44.0093 1324 PCI - ok 20:22:44.0109 1324 PCIDump - ok 20:22:44.0140 1324 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 20:22:44.0140 1324 PCIIde - ok 20:22:44.0171 1324 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 20:22:44.0171 1324 Pcmcia - ok 20:22:44.0218 1324 PDCOMP - ok 20:22:44.0234 1324 PDFRAME - ok 20:22:44.0250 1324 PDRELI - ok 20:22:44.0281 1324 PDRFRAME - ok 20:22:44.0296 1324 perc2 - ok 20:22:44.0312 1324 perc2hib - ok 20:22:44.0406 1324 [ 2ABA2F545B35F9C6CC2CFC4E1D539A80 ] PLCNDIS5 C:\WINDOWS\system32\plcndis5.sys 20:22:44.0406 1324 PLCNDIS5 - ok 20:22:44.0437 1324 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WINDOWS\system32\services.exe 20:22:44.0437 1324 PlugPlay - ok 20:22:44.0453 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WINDOWS\System32\lsass.exe 20:22:44.0453 1324 PolicyAgent - ok 20:22:44.0515 1324 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:22:44.0515 1324 PptpMiniport - ok 20:22:44.0546 1324 [ 2CB55427C58679F49AD600FCCBA76360 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys 20:22:44.0546 1324 Processor - ok 20:22:44.0562 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 20:22:44.0578 1324 ProtectedStorage - ok 20:22:44.0593 1324 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 20:22:44.0593 1324 PSched - ok 20:22:44.0640 1324 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:22:44.0640 1324 Ptilink - ok 20:22:44.0687 1324 ql1080 - ok 20:22:44.0703 1324 Ql10wnt - ok 20:22:44.0718 1324 ql12160 - ok 20:22:44.0750 1324 ql1240 - ok 20:22:44.0765 1324 ql1280 - ok 20:22:44.0781 1324 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:22:44.0781 1324 RasAcd - ok 20:22:44.0843 1324 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WINDOWS\System32\rasauto.dll 20:22:44.0843 1324 RasAuto - ok 20:22:44.0875 1324 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys 20:22:44.0875 1324 Rasirda - ok 20:22:44.0921 1324 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:22:44.0937 1324 Rasl2tp - ok 20:22:44.0984 1324 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WINDOWS\System32\rasmans.dll 20:22:45.0000 1324 RasMan - ok 20:22:45.0015 1324 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:22:45.0015 1324 RasPppoe - ok 20:22:45.0062 1324 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 20:22:45.0062 1324 Raspti - ok 20:22:45.0093 1324 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:22:45.0093 1324 Rdbss - ok 20:22:45.0125 1324 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:22:45.0125 1324 RDPCDD - ok 20:22:45.0156 1324 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 20:22:45.0156 1324 rdpdr - ok 20:22:45.0218 1324 [ 5B3055DAA788BD688594D2F5981F2A83 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 20:22:45.0234 1324 RDPWD - ok 20:22:45.0265 1324 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 20:22:45.0281 1324 RDSessMgr - ok 20:22:45.0343 1324 [ 41315D97BB319BD5B5E1B367570E7B3C ] RecAgent C:\WINDOWS\system32\DRIVERS\RecAgent.sys 20:22:45.0343 1324 RecAgent - ok 20:22:45.0390 1324 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 20:22:45.0390 1324 redbook - ok 20:22:45.0453 1324 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 20:22:45.0453 1324 RemoteAccess - ok 20:22:45.0500 1324 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 20:22:45.0515 1324 RemoteRegistry - ok 20:22:45.0546 1324 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WINDOWS\System32\locator.exe 20:22:45.0546 1324 RpcLocator - ok 20:22:45.0609 1324 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WINDOWS\system32\rpcss.dll 20:22:45.0609 1324 RpcSs - ok 20:22:45.0656 1324 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\System32\rsvp.exe 20:22:45.0656 1324 RSVP - ok 20:22:45.0703 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WINDOWS\system32\lsass.exe 20:22:45.0703 1324 SamSs - ok 20:22:45.0750 1324 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 20:22:45.0750 1324 SCardSvr - ok 20:22:45.0812 1324 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WINDOWS\system32\schedsvc.dll 20:22:45.0828 1324 Schedule - ok 20:22:45.0906 1324 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:22:45.0906 1324 Secdrv - ok 20:22:45.0953 1324 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WINDOWS\System32\seclogon.dll 20:22:45.0953 1324 seclogon - ok 20:22:46.0015 1324 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WINDOWS\system32\sens.dll 20:22:46.0015 1324 SENS - ok 20:22:46.0062 1324 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 20:22:46.0062 1324 serenum - ok 20:22:46.0109 1324 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 20:22:46.0109 1324 Serial - ok 20:22:46.0140 1324 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 20:22:46.0140 1324 Sfloppy - ok 20:22:46.0203 1324 [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 20:22:46.0203 1324 SharedAccess - ok 20:22:46.0296 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 20:22:46.0296 1324 ShellHWDetection - ok 20:22:46.0312 1324 Simbad - ok 20:22:46.0375 1324 [ F3A4AB7230646941D41A9E2E754F047A ] Slnt7554 C:\WINDOWS\system32\DRIVERS\slnt7554.sys 20:22:46.0390 1324 Slnt7554 - ok 20:22:46.0437 1324 [ F06507086FF9BFDBCF3C5098A4848B5D ] SlNtHal C:\WINDOWS\system32\DRIVERS\Slnthal.sys 20:22:46.0437 1324 SlNtHal - ok 20:22:46.0453 1324 SLService - ok 20:22:46.0500 1324 [ CD4F4CEE4481E11BDA806A9366785A1D ] SlWdmSup C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys 20:22:46.0500 1324 SlWdmSup - ok 20:22:46.0531 1324 Sparrow - ok 20:22:46.0578 1324 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 20:22:46.0578 1324 splitter - ok 20:22:46.0625 1324 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 20:22:46.0625 1324 Spooler - ok 20:22:46.0640 1324 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 20:22:46.0656 1324 sr - ok 20:22:46.0703 1324 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WINDOWS\System32\srsvc.dll 20:22:46.0703 1324 srservice - ok 20:22:46.0781 1324 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 20:22:46.0796 1324 Srv - ok 20:22:46.0843 1324 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 20:22:46.0843 1324 SSDPSRV - ok 20:22:46.0921 1324 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 20:22:46.0921 1324 ssmdrv - ok 20:22:46.0968 1324 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WINDOWS\system32\wiaservc.dll 20:22:47.0000 1324 stisvc - ok 20:22:47.0046 1324 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 20:22:47.0046 1324 swenum - ok 20:22:47.0078 1324 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 20:22:47.0078 1324 swmidi - ok 20:22:47.0093 1324 SwPrv - ok 20:22:47.0125 1324 symc810 - ok 20:22:47.0156 1324 symc8xx - ok 20:22:47.0171 1324 sym_hi - ok 20:22:47.0218 1324 sym_u3 - ok 20:22:47.0265 1324 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 20:22:47.0265 1324 sysaudio - ok 20:22:47.0312 1324 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 20:22:47.0312 1324 SysmonLog - ok 20:22:47.0375 1324 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 20:22:47.0390 1324 TapiSrv - ok 20:22:47.0453 1324 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:22:47.0468 1324 Tcpip - ok 20:22:47.0515 1324 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 20:22:47.0515 1324 TDPIPE - ok 20:22:47.0562 1324 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 20:22:47.0562 1324 TDTCP - ok 20:22:47.0609 1324 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 20:22:47.0609 1324 TermDD - ok 20:22:47.0671 1324 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WINDOWS\System32\termsrv.dll 20:22:47.0703 1324 TermService - ok 20:22:47.0750 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] Themes C:\WINDOWS\System32\shsvcs.dll 20:22:47.0750 1324 Themes - ok 20:22:47.0796 1324 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe 20:22:47.0796 1324 TlntSvr - ok 20:22:47.0843 1324 TosIde - ok 20:22:47.0890 1324 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WINDOWS\system32\trkwks.dll 20:22:47.0906 1324 TrkWks - ok 20:22:47.0937 1324 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 20:22:47.0937 1324 Udfs - ok 20:22:47.0953 1324 ultra - ok 20:22:48.0000 1324 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 20:22:48.0015 1324 Update - ok 20:22:48.0093 1324 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WINDOWS\System32\upnphost.dll 20:22:48.0109 1324 upnphost - ok 20:22:48.0140 1324 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WINDOWS\System32\ups.exe 20:22:48.0140 1324 UPS - ok 20:22:48.0203 1324 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 20:22:48.0203 1324 usbccgp - ok 20:22:48.0250 1324 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:22:48.0250 1324 usbehci - ok 20:22:48.0296 1324 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:22:48.0296 1324 usbhub - ok 20:22:48.0343 1324 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 20:22:48.0359 1324 usbscan - ok 20:22:48.0390 1324 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:22:48.0390 1324 USBSTOR - ok 20:22:48.0468 1324 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:22:48.0468 1324 usbuhci - ok 20:22:48.0500 1324 [ BEE793D4A059CAEA55D6AC20E19B3A8F ] USB_RNDIS C:\WINDOWS\system32\DRIVERS\usb8023.sys 20:22:48.0500 1324 USB_RNDIS - ok 20:22:48.0531 1324 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 20:22:48.0531 1324 VgaSave - ok 20:22:48.0593 1324 [ 4B039BBD037B01F5DB5A144C837F283A ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys 20:22:48.0593 1324 viaagp1 - ok 20:22:48.0640 1324 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 20:22:48.0640 1324 ViaIde - ok 20:22:48.0687 1324 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 20:22:48.0687 1324 VolSnap - ok 20:22:48.0734 1324 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WINDOWS\System32\vssvc.exe 20:22:48.0750 1324 VSS - ok 20:22:48.0828 1324 [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time C:\WINDOWS\System32\w32time.dll 20:22:48.0828 1324 W32Time - ok 20:22:48.0875 1324 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:22:48.0875 1324 Wanarp - ok 20:22:48.0890 1324 WDICA - ok 20:22:48.0921 1324 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 20:22:48.0921 1324 wdmaud - ok 20:22:48.0984 1324 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WINDOWS\System32\webclnt.dll 20:22:48.0984 1324 WebClient - ok 20:22:49.0062 1324 [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 20:22:49.0062 1324 winmgmt - ok 20:22:49.0156 1324 [ 6E18978B749F0696A774DE3F2CB142DD ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 20:22:49.0156 1324 WmdmPmSN - ok 20:22:49.0250 1324 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WINDOWS\System32\advapi32.dll 20:22:49.0281 1324 Wmi - ok 20:22:49.0359 1324 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe 20:22:49.0359 1324 WmiApSrv - ok 20:22:49.0421 1324 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WINDOWS\system32\wscsvc.dll 20:22:49.0437 1324 wscsvc - ok 20:22:49.0484 1324 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 20:22:49.0484 1324 wuauserv - ok 20:22:49.0531 1324 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 20:22:49.0562 1324 WZCSVC - ok 20:22:49.0625 1324 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 20:22:49.0640 1324 xmlprov - ok 20:22:49.0687 1324 ================ Scan global =============================== 20:22:49.0750 1324 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll 20:22:49.0781 1324 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 20:22:49.0812 1324 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll 20:22:49.0843 1324 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe 20:22:49.0843 1324 [Global] - ok 20:22:49.0843 1324 ================ Scan MBR ================================== 20:22:49.0875 1324 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 20:22:50.0031 1324 \Device\Harddisk0\DR0 - ok 20:22:50.0031 1324 ================ Scan VBR ================================== 20:22:50.0031 1324 [ 419E0E86CCAEA9B1007E36922D127ADB ] \Device\Harddisk0\DR0\Partition1 20:22:50.0046 1324 \Device\Harddisk0\DR0\Partition1 - ok 20:22:50.0062 1324 [ 3A078522B2D615653713BB15F22B968C ] \Device\Harddisk0\DR0\Partition2 20:22:50.0062 1324 \Device\Harddisk0\DR0\Partition2 - ok 20:22:50.0062 1324 ============================================================ 20:22:50.0062 1324 Scan finished 20:22:50.0062 1324 ============================================================ 20:22:50.0203 1564 Detected object count: 1 20:22:50.0203 1564 Actual detected object count: 1 20:24:54.0203 1564 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys - copied to quarantine 20:24:54.0218 1564 HKLM\SYSTEM\ControlSet001\services\1f785d9b79d933f1 - will be deleted on reboot 20:24:54.0265 1564 HKLM\SYSTEM\ControlSet002\services\1f785d9b79d933f1 - will be deleted on reboot 20:24:54.0421 1564 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys - will be deleted on reboot 20:24:54.0421 1564 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete 20:26:14.0046 1532 Deinitialize success Code:
ATTFilter 20:27:54.0843 0352 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 20:27:55.0500 0352 ============================================================ 20:27:55.0500 0352 Current date / time: 2013/03/24 20:27:55.0500 20:27:55.0500 0352 SystemInfo: 20:27:55.0500 0352 20:27:55.0500 0352 OS Version: 5.1.2600 ServicePack: 3.0 20:27:55.0500 0352 Product type: Workstation 20:27:55.0500 0352 ComputerName: FAMILIE-5RMVRRM 20:27:55.0500 0352 UserName: Alfred 20:27:55.0500 0352 Windows directory: C:\WINDOWS 20:27:55.0500 0352 System windows directory: C:\WINDOWS 20:27:55.0500 0352 Processor architecture: Intel x86 20:27:55.0500 0352 Number of processors: 2 20:27:55.0500 0352 Page size: 0x1000 20:27:55.0500 0352 Boot type: Normal boot 20:27:55.0500 0352 ============================================================ 20:27:58.0906 0352 BG loaded 20:28:02.0671 0352 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:28:02.0687 0352 ============================================================ 20:28:02.0687 0352 \Device\Harddisk0\DR0: 20:28:02.0687 0352 MBR partitions: 20:28:02.0687 0352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x88B8F9D 20:28:02.0734 0352 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x88B901B, BlocksNum 0xA15BBE5 20:28:02.0734 0352 ============================================================ 20:28:02.0812 0352 C: <-> \Device\Harddisk0\DR0\Partition1 20:28:02.0921 0352 D: <-> \Device\Harddisk0\DR0\Partition2 20:28:02.0921 0352 ============================================================ 20:28:02.0921 0352 Initialize success 20:28:02.0921 0352 ============================================================ 20:32:38.0218 1324 Deinitialize success Code:
ATTFilter ComboFix 13-03-24.03 - Alfred 24.03.2013 20:41:36.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.511.122 [GMT 1:00] ausgeführt von:: c:\dokumente und einstellungen\Alfred\Desktop\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\dokumente und einstellungen\Alfred\pl468q4scf.exe c:\dokumente und einstellungen\Alfred\WINDOWS c:\windows\system32\_000008_.tmp.dll c:\windows\system32\SET1A.tmp c:\windows\system32\SET1B.tmp c:\windows\system32\URTTemp c:\windows\system32\URTTemp\fusion.dll c:\windows\system32\URTTemp\mscoree.dll c:\windows\system32\URTTemp\mscoree.dll.local c:\windows\system32\URTTemp\mscorsn.dll c:\windows\system32\URTTemp\mscorwks.dll c:\windows\system32\URTTemp\msvcr71.dll c:\windows\system32\URTTemp\regtlib.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 )))))))))))))))))))))))))))))) . . 2013-03-24 19:29 . 2013-03-24 19:31 -------- d-----w- c:\windows\LastGood 2013-03-24 19:24 . 2013-03-24 19:24 -------- d-----w- C:\TDSSKiller_Quarantine 2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\dokumente und einstellungen\Alfred\Anwendungsdaten\Malwarebytes 2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes 2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware 2013-03-23 10:48 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-24 10:36 . 2006-02-14 14:33 1409 ----a-w- c:\windows\QTFont.for 2012-12-30 07:45 . 2012-09-30 08:43 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2012-12-30 07:45 . 2012-09-30 08:43 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2012-12-30 07:45 . 2012-09-30 08:43 134336 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-06-20 09:46 . 2009-06-20 09:44 53634800 ----a-w- c:\programme\ExcelViewer.exe 2013-03-07 14:30 . 2013-03-09 11:28 263064 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 339968] "ISUSPM Startup"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "QuickTime Task"="c:\windows\system32\qttask.exe" [2006-02-14 77824] "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-15 196608] "avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-02-15 385248] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-01-11 21:16 39792 ----a-w- c:\programme\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2004-11-02 19:24 32768 ----a-w- c:\programme\CyberLink\PowerDVD\PDVDServ.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon] 2002-04-17 09:42 69632 ----a-w- c:\programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Programme\\devolo\\informer\\devinf.exe"= "c:\\Programme\\aon\\aonController\\aonController.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Programme\\aon\\aonInstaller\\Installer.exe"= . R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [30.09.2012 09:43 36552] R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [30.09.2012 09:43 86752] R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\plcndis5.sys [17.05.2004 11:21 17280] S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [04.08.2004 06:41 224888] . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 00848729 *NewlyCreated* - 31272864 *NewlyCreated* - AVGNTFLT *NewlyCreated* - AVIPBB *NewlyCreated* - AVKMGR *NewlyCreated* - SSMDRV *Deregistered* - 00848729 *Deregistered* - 31272864 . Inhalt des "geplante Tasks" Ordners . 2013-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\programme\Google\Update\GoogleUpdate.exe [2011-12-26 15:26] . 2013-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\programme\Google\Update\GoogleUpdate.exe [2011-12-26 15:26] . 2013-03-24 c:\windows\Tasks\User_Feed_Synchronization-{92EA0041-BA85-4B6E-A2C1-892B498D1258}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 02:31] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.telekom.at mWindow Title = UTA Telekom AG IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: uni-graz.at TCP: DhcpNameServer = 10.0.0.138 10.0.0.138 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\dokumente und einstellungen\Alfred\Anwendungsdaten\Mozilla\Firefox\Profiles\d7ywe9b3.default-1364029350796\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-E06DXLRD_1476890 - c:\programme\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE HKLM-Run-Cmaudio - cmicnfg.cpl HKLM-Run-NWEReboot - (no file) SafeBoot-00848729.sys MSConfigStartUp-E06DXLRD_720156 - c:\programme\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-03-24 20:49 Windows 5.1.2600 Service Pack 3 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0f,7e,39,c6,ed,4e,3b,47,b3,60,7f,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0f,7e,39,c6,ed,4e,3b,47,b3,60,7f,\ . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'winlogon.exe'(676) c:\windows\system32\Ati2evxx.dll . Zeit der Fertigstellung: 2013-03-24 20:52:30 ComboFix-quarantined-files.txt 2013-03-24 19:52 . Vor Suchlauf: 8 Verzeichnis(se), 59.617.886.208 Bytes frei Nach Suchlauf: 10 Verzeichnis(se), 60.130.217.984 Bytes frei . WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn . - - End Of File - - 9E3026E4117384DE9C52C0ABFFC14035 Code:
ATTFilter OTL logfile created on: 24.03.2013 21:01:52 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Alfred\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 511,23 Mb Total Physical Memory | 124,53 Mb Available Physical Memory | 24,36% Memory free 1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,54% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 68,36 Gb Total Space | 56,03 Gb Free Space | 81,97% Space Free | Partition Type: NTFS Drive D: | 80,68 Gb Total Space | 77,19 Gb Free Space | 95,67% Space Free | Partition Type: NTFS Computer Name: FAMILIE-5RMVRRM | User Name: Alfred | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\qttask.exe (Apple Computer, Inc.) PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG) PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation) PRC - C:\WINDOWS\system32\slserv.exe (Smart Link) PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP) ========== Modules (No Company Name) ========== MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll () MOD - C:\Programme\Mozilla Firefox\mozjs.dll () MOD - C:\WINDOWS\system32\msdmo.dll () MOD - C:\WINDOWS\system32\ati2evxx.dll () MOD - C:\WINDOWS\system32\pdfcmnnt.dll () ========== Services (SafeList) ========== SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (SLService) -- C:\WINDOWS\System32\slserv.exe (Smart Link) SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found DRV - (PDRFRAME) -- File not found DRV - (PDRELI) -- File not found DRV - (PDFRAME) -- File not found DRV - (PDCOMP) -- File not found DRV - (PCIDump) -- File not found DRV - (lbrtfdc) -- File not found DRV - (i2omgmt) -- File not found DRV - (Changer) -- File not found DRV - (catchme) -- C:\DOKUME~1\Alfred\LOKALE~1\Temp\catchme.sys File not found DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation) DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation) DRV - (AFS2K) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.) DRV - (Mtlstrm) -- C:\WINDOWS\system32\drivers\mtlstrm.sys ( ) DRV - (Mtlmnt5) -- C:\WINDOWS\system32\drivers\mtlmnt5.sys ( ) DRV - (Slnt7554) -- C:\WINDOWS\system32\drivers\slnt7554.sys ( ) DRV - (SlNtHal) -- C:\WINDOWS\system32\drivers\slnthal.sys ( ) DRV - (RecAgent) -- C:\WINDOWS\system32\drivers\RecAgent.sys ( ) DRV - (SlWdmSup) -- C:\WINDOWS\system32\drivers\slwdmsup.sys ( ) DRV - (NtMtlFax) -- C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link) DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (PLCNDIS5) -- C:\WINDOWS\system32\plcndis5.sys (Intellon, Inc.) DRV - (viaagp1) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.) DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation) DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.telekom.at IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes,DefaultScope = {99968DBC-2B29-494F-A050-29B9BDB22FCF} IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{99968DBC-2B29-494F-A050-29B9BDB22FCF}: "URL" = hxxp://www.google.at/search?hl=de&q={searchTerms}&meta= IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.23 10:04:56 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.03.09 12:28:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.03.23 10:07:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions [2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.03.23 10:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.03.07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2013.03.07 16:45:15 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.07 16:45:15 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2013.03.07 16:45:15 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2013.03.07 16:45:15 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2013.03.07 16:45:15 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2013.03.07 16:45:15 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.03.24 20:49:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {147D6308-0614-4112-89B1-31402F9B82C4} - No CLSID value found. O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP) O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe (Apple Computer, Inc.) O4 - HKU\S-1-5-21-436374069-1614895754-839522115-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe (Nero AG) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O15 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..Trusted Domains: uni-graz.at ([]https in Vertrauenswürdige Sites) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1348999421515 (WUWebControl Class) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CD0B796-8D2C-433B-8D55-EB74130C2239}: DhcpNameServer = 195.34.133.21 195.34.133.22 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B10F9BE5-DA3F-4B17-9954-DED73D9F9628}: DhcpNameServer = 195.34.133.21 195.34.133.22 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D3D40258-515E-4126-B155-DCCACE2B1CF7}: DhcpNameServer = 10.0.0.138 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3A5CA91-A3DF-4D41-9D1D-F3B6AE8ADCEF}: DhcpNameServer = 195.34.133.21 195.34.133.22 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll () O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.02.13 17:03:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.03.24 20:52:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2013.03.24 20:36:08 | 000,000,000 | RHSD | C] -- C:\cmdcons [2013.03.24 20:34:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2013.03.24 20:34:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2013.03.24 20:34:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2013.03.24 20:34:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2013.03.24 20:34:10 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.03.24 20:34:02 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Alfred\Startmenü\Programme\Verwaltung [2013.03.24 20:34:02 | 000,000,000 | R--D | C] -- d:\Eigene Videos [2013.03.24 20:33:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt [2013.03.24 20:25:53 | 005,044,071 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\Alfred\Desktop\ComboFix.exe [2013.03.24 20:24:54 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine [2013.03.24 08:39:53 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Alfred\Desktop\tdsskiller.exe [2013.03.24 08:38:36 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\Alfred\Desktop\aswMBR.exe [2013.03.23 12:28:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe [2013.03.23 12:26:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Desktop\LOGS [2013.03.23 11:48:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Malwarebytes [2013.03.23 11:48:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware [2013.03.23 11:48:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes [2013.03.23 11:48:15 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2013.03.23 11:48:15 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2013.03.23 10:16:16 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira [2013.03.09 12:28:08 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox [2009.06.20 10:44:29 | 053,634,800 | ---- | C] (Microsoft Corporation) -- C:\Programme\ExcelViewer.exe [1 d:\*.tmp files -> d:\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.03.24 21:03:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{92EA0041-BA85-4B6E-A2C1-892B498D1258}.job [2013.03.24 20:58:23 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn [2013.03.24 20:58:14 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013.03.24 20:58:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013.03.24 20:52:39 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for [2013.03.24 20:49:34 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2013.03.24 20:36:18 | 000,000,327 | RHS- | M] () -- C:\boot.ini [2013.03.24 20:25:42 | 005,044,071 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\Alfred\Desktop\ComboFix.exe [2013.03.24 20:13:00 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013.03.24 08:39:30 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Alfred\Desktop\tdsskiller.exe [2013.03.24 08:38:18 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Dokumente und Einstellungen\Alfred\Desktop\aswMBR.exe [2013.03.23 12:28:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe [2013.03.23 12:25:36 | 000,609,993 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe [2013.03.23 11:48:18 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.23 10:16:16 | 000,001,677 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk [2013.03.23 10:07:36 | 000,001,638 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk [2013.03.23 10:05:01 | 000,000,702 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2013.03.23 09:52:22 | 000,002,509 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\Microsoft Office Word 2003.lnk [2013.03.06 17:56:09 | 000,000,278 | ---- | M] () -- C:\WINDOWS\hpqcopy.INI [2013.03.01 11:47:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [1 d:\*.tmp files -> d:\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.03.24 20:36:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak [2013.03.24 20:36:11 | 000,262,448 | RHS- | C] () -- C:\cmldr [2013.03.24 20:34:30 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2013.03.24 20:34:30 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2013.03.24 20:34:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2013.03.24 20:34:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2013.03.24 20:34:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2013.03.23 12:26:00 | 000,609,993 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe [2013.03.23 11:48:18 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.23 10:05:01 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2012.09.30 12:20:55 | 000,292,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.02.16 11:32:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2010.03.09 17:01:04 | 000,000,082 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\default.pls [2006.07.09 10:13:00 | 000,038,451 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Microsoft Excel.ADR [2006.07.09 10:05:13 | 000,009,354 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Tabulatorgetrennte Werte (Windows).EML [2006.07.09 06:51:20 | 000,045,424 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\IMG_3054[2].jpg [2006.02.14 15:08:14 | 000,000,139 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2006.02.14 12:49:18 | 000,007,680 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.02.14 12:29:00 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 03:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2006.02.19 20:25:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Alawar [2007.07.25 10:09:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\AUTOSICH [2008.11.07 19:41:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\mquadr.at [2011.01.17 18:03:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Ordner HP Share-to-Web [2010.04.24 15:18:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Thunderbird [2008.11.07 19:41:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\m2backup [2008.11.07 19:41:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mquadr.at [2006.02.28 16:41:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSScanAppDataDir [2009.08.05 11:33:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PCSettings [2008.11.07 19:39:23 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{0AB34A1C-91C1-45BB-8B32-A0746A30DC96} [2008.11.07 19:38:47 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{C3358ED5-0ADD-4BA0-8F60-B5A7CD34BD14} ========== Purity Check ========== < End of report > |
24.03.2013, 21:32 | #6 | |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Hi, Zitat:
Schritt 1 Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinen Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers. Bitte poste in deiner nächsten Antwort:
__________________ --> Virus/Trojaner "pl468q4scf.exe" |
24.03.2013, 21:51 | #7 |
| Virus/Trojaner "pl468q4scf.exe" sooo... Hier noch das mbar log: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.01.0.1021 www.malwarebytes.org Database version: v2013.03.24.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Alfred :: FAMILIE-5RMVRRM [administrator] 24.03.2013 21:50:09 mbar-log-2013-03-24 (21-50-09).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 25115 Time elapsed: 12 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) |
24.03.2013, 21:58 | #8 |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Gut. Noch eine letzte Kontrolle und dann sollten wir unbedingt noch dafür sorgen, dass der Rechner besser abgesichert ist und sowas nicht mehr vorkommen kann. Schritt 1
Code:
ATTFilter :commands [emptytemp]
Schritt 2
Schritt 3 Lade das Setup des ESET Online Scanners herunter und speichere es auf den Desktop.
Schritt 4 Downloade dir bitte SecurityCheck (Link 2).
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
25.03.2013, 00:33 | #9 |
| Virus/Trojaner "pl468q4scf.exe" Cool, da wird nichts dem Zufall überlassen! ;-) OTL: Code:
ATTFilter All processes killed ========== COMMANDS ========== [EMPTYTEMP] User: Alfred ->Temp folder emptied: 3235465 bytes ->Temporary Internet Files folder emptied: 9301856 bytes ->FireFox cache emptied: 35183917 bytes ->Flash cache emptied: 9170 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 5357813 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3235777 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 54,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 03242013_220224 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Malware Bytes: Code:
ATTFilter Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.03.23.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Alfred :: FAMILIE-5RMVRRM [Administrator] 24.03.2013 22:10:53 mbam-log-2013-03-24 (22-10-53).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214131 Laufzeit: 4 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter C:\Qoobox\Quarantine\C\Dokumente und Einstellungen\Alfred\pl468q4scf.exe.vir a variant of Win32/Kryptik.AFZO trojan C:\TDSSKiller_Quarantine\24.03.2013_20.21.49\necurs0000\svc0000\tsk0000.dta a variant of Win32/Rootkit.Kryptik.MZ trojan SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.61 Windows XP Service Pack 3 x86 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Warten Sie, w„hrend WMIC installiert wird.d i s p l a y N a m e ECHO ist ausgeschaltet (OFF). A v i r a ECHO ist ausgeschaltet (OFF). D e s k t o p ECHO ist ausgeschaltet (OFF). Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 CCleaner Adobe Flash Player 11.6.602.180 Adobe Reader XI Mozilla Firefox (19.0.2) Mozilla Thunderbird (17.0.4) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C:: ````````````````````End of Log`````````````````````` |
25.03.2013, 01:39 | #10 | |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Hallo, Zitat:
Die werden wir jetzt mit den letzten Schritten noch löschen lassen. Hast du in der Zwischenzeit den Adobe PDF Reader und den Flashplayer aktualisiert? Zu Beginn des Themas waren da nämlich noch sehr alte Versionen davon zu sehen.. (Und das waren wohl auch die Einfallstore für die Malware, denn diese nutzt beim Surfen Sicherheitslücken in diesen alten Versionen von Browser und seinen Plugins aus, um sich unbemerkt zu installieren..) Bleibt nur noch: Überprüfe mit diesem Plugin-Check, ob alle deine verwendeten Versionen aktuell sind und update sie anderenfalls. Und dann räumen wir alles auf: Schritt 1 Bitte deaktiviere jetzt temporär das Antiviren-Programm, evtl. vorhandenes Skript-Blocking und Antimalware-Programme. Drücke bitte die + R Taste, kopiere folgenden Text in das Ausführen Fenster Code:
ATTFilter Combofix /Uninstall Du kannst die eben deaktivierten Programme nun wieder einschalten. Schritt 2 Den ESET Online Scanner kannst du behalten, um ab und zu für eine Zweitmeinung dein System damit zu scannen. Falls du ESET aber deinstallieren möchtest, dann: Drücke bitte die + R Taste, kopiere folgenden Text in das Ausführen Fenster Code:
ATTFilter "%ProgramFiles%\Eset\Eset Online Scanner\OnlineScannerUninstaller.exe" Schritt 3 Downloade dir bitte delfix auf deinen Desktop.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
25.03.2013, 08:29 | #11 |
| Virus/Trojaner "pl468q4scf.exe" VIELEN DANK!! Soweit ich das beurteilen kann, funktioniert alles tadellos... Ihr seid da echt fix drauf! Schön, auch mal die guten Seiten des Internets kennen zu lernen! LG |
25.03.2013, 14:04 | #12 |
/// TB-Ausbilder | Virus/Trojaner "pl468q4scf.exe" Danke für die Rückmeldung. Freut mich, dass wir helfen konnten. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu Virus/Trojaner "pl468q4scf.exe" |
.dll, adobe, askbar, avira, bho, computer, echtzeit-scanner, entfernen, error, excel, explorer, flash player, format, google, hilfreich, mozilla, programm, registry, rundll, security, software, svchost.exe, tcp, temp, udp, usb, virus, windows internet |