|
Log-Analyse und Auswertung: PC neu aufgsetzt, zufälliger GMER Scan->rootkit ?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.04.2013, 10:02 | #1 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Guten Morgen, Heute Morgen habe ich den PC meiner Freundin neu aufgesetzt und musste zu meinem Erschrecken feststellen, dass er anscheinend mit einem rootkit? infiziert ist. Der Scan war mehr ein Zufall, da ich die Top-Suchbegriffe bei heise.de abgesurft bin. Malwarebytes hat nichts gefunden, wohl aber GMER. Danke im Voraus! Habe aus Versehen 2 Mal gescannt, hier die beiden Scans: Logfile GMER: GMER Logfile: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-04-22 10:59:32 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 Maxtor_6L200M0 rev.BANC1E00 189,92GB Running: gmer.exe; Driver: C:\Users\Jochen\AppData\Local\Temp\uxdiqpow.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 8267D3C9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 826B6D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DC21000, 0x227A14, 0xE8000020] ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- Files - GMER 2.1 ---- File C:\Users\Jochen\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{0C52E173-AB24-11E2-B965-000FEAEAB220}.dat 0 bytes File C:\Users\Jochen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\M5GTL8LP\afr[1].htm 0 bytes File C:\Users\Jochen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\M5GTL8LP\afr[2].htm 0 bytes File C:\Users\Jochen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WGY1E022\pd[1].htm 0 bytes File C:\Users\Jochen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XJR9VF1R\likebox[1].htm 0 bytes ---- EOF - GMER 2.1 ---- GMER Logfile: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-04-22 10:43:10 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 Maxtor_6L200M0 rev.BANC1E00 189,92GB Running: gmer.exe; Driver: C:\Users\Jochen\AppData\Local\Temp\uxdiqpow.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 8267D3C9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 826B6D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DC21000, 0x227A14, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[3264] ntdll.dll!LdrGetProcedureAddress + 26 774B22B3 7 Bytes JMP 62D96D70 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3264] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 775E941E 7 Bytes JMP 630ED713 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3264] kernel32.dll!QueryPerformanceCounter + 13 775EC435 7 Bytes JMP 630ED736 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3264] kernel32.dll!LoadAppInitDlls + 355 775EF4F6 7 Bytes JMP 62DB1C62 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3264] GDI32.dll!GetViewportOrgEx + 26C 75E9884B 7 Bytes JMP 630ED694 C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- EOF - GMER 2.1 ---- Geändert von JochenWitt (22.04.2013 um 10:22 Uhr) |
22.04.2013, 12:17 | #2 | |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Hi,
__________________Zitat:
__________________ |
22.04.2013, 13:20 | #3 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Ich habe Mal irgendwo gelesen, dass diese Kernal calls benutzt werden um ein System wieder per BIOS (Graka oder Normales) zu infizieren. Aber das Kompetenzteam eid ihr, von daher auch meine Frage.
__________________Weiterhin habe ich kein FAT DS, sondern NTFS. Weiterhin konnte ich kein Windows-Update durchführen, einige gingen nicht (ist sonst nie so?). Geändert von JochenWitt (22.04.2013 um 13:25 Uhr) |
22.04.2013, 14:10 | #4 |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Also das Gmer-Log bietet kein Grund zur Sorge. Wo bleiben denn die Windows Updates hängen? Bekommst du eine konkrete Fehlermeldung?
__________________ cheers, Leo |
23.04.2013, 10:00 | #5 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Danke für Deine Mühe. Ich war wohl nur etwas zu "paranoid". Jeder Scan zeigt "0" Funde an, von daher sieht das gut aus. Anders hingegen scheint es sich beim Laptop meiner Nichte zu verhalten. Der verhält sich "komisch". Darf ich da mal das Log hier reinposten, falls gewünscht auch per OTL.exe ? |
23.04.2013, 12:38 | #6 |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? In Ordnung. Ja, wenn ich mal schnell den Laptop deiner Nichte anschauen soll, dann poste bitte die Gmer- und OTL-Logs davon.
__________________ --> PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? |
23.04.2013, 15:50 | #7 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? So, da bin ich wieder. Leider mit offensichtlich schlechten nachrichten. Das Sys scheint komplett "fertig" zu sein. Ich würde es auch ohne weiteres einfach neu aufsetzen/formatieren, aber leider sind da wohl noch "wichtige" Sachen meiner Nichte drauf. Ich hoffe also Mal, dass wir das wieder hinbiegen können, so dass ich wenigstens ein sauberes backup ziehen kann. Hier die Logs: Code:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-23 16:24:52 ----------------------------- 16:24:52.015 OS Version: Windows 5.1.2600 Service Pack 3 16:24:52.015 Number of processors: 2 586 0xF06 16:24:52.015 ComputerName: Silke UserName: 16:24:54.546 Initialize success 16:25:08.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-10 16:25:08.500 Disk 0 Vendor: WDC_WD1600DG-00GBB0 02.05D02 Size: 152627MB BusType: 3 16:25:08.828 Disk 0 MBR read successfully 16:25:08.828 Disk 0 MBR scan 16:25:08.828 Disk 0 Windows XP default MBR code 16:25:08.828 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 14998 MB offset 63 16:25:08.828 Disk 0 Partition - 00 0F Extended LBA 137627 MB offset 30716280 16:25:08.843 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 137627 MB offset 30716343 16:25:08.859 Disk 0 scanning sectors +312576705 16:25:09.062 Disk 0 scanning C:\WIN\system32\drivers 16:25:29.500 Service scanning 16:25:45.328 Service sptd C:\WIN\System32\Drivers\sptd.sys **LOCKED** 32 16:25:52.218 Modules scanning 16:26:12.484 Disk 0 trace - called modules: 16:26:12.500 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8a5bb8a8]<< 16:26:12.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a504ab8] 16:26:12.500 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\0000006b[0x8a5739e8] 16:26:12.500 5 ACPI.sys[f74ad620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-10[0x8a512940] 16:26:12.500 Scan finished successfully 16:28:24.234 Disk 0 MBR has been saved successfully to "E:\MBR.dat" 16:28:24.265 The log file has been saved successfully to "E:\aswMBR.txt" Code:
ATTFilter Running: gmer_2.1.19163.exe; Driver: C:\DOKUME~1\silke\LOKALE~1\Temp\fgldqpow.sys ---- System - GMER 2.1 ---- SSDT sptd.sys ZwCreateKey [0xF74EF0D0] SSDT B956A37C ZwCreateThread SSDT sptd.sys ZwEnumerateKey [0xF74F4E2C] SSDT sptd.sys ZwEnumerateValueKey [0xF74F51BA] SSDT sptd.sys ZwOpenKey [0xF74EF0B0] SSDT B956A368 ZwOpenProcess SSDT B956A36D ZwOpenThread SSDT sptd.sys ZwQueryKey [0xF74F5292] SSDT sptd.sys ZwQueryValueKey [0xF74F5112] SSDT sptd.sys ZwSetValueKey [0xF74F5324] ---- Kernel code sections - GMER 2.1 ---- ? C:\WIN\system32\drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. ? System32\Drivers\aklt8ki9.SYS Das System kann den angegebenen Pfad nicht finden. ! ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8A60A1E8 Device \FileSystem\Fastfat \FatCdrom 893777A0 Device \Driver\PCI_NTPNP0588 \Device\00000042 sptd.sys Device \Driver\PCI_NTPNP0588 \Device\00000042 sptd.sys Device \Driver\usbuhci \Device\USBPDO-0 8A3F71E8 Device \Driver\usbuhci \Device\USBPDO-1 8A3F71E8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A59A1E8 Device \Driver\dmio \Device\DmControl\DmConfig 8A59A1E8 Device \Driver\dmio \Device\DmControl\DmPnP 8A59A1E8 Device \Driver\dmio \Device\DmControl\DmInfo 8A59A1E8 Device \Driver\usbehci \Device\USBPDO-2 8A3B61E8 Device \Driver\usbuhci \Device\USBPDO-3 8A3F71E8 Device \Driver\usbuhci \Device\USBPDO-4 8A3F71E8 Device \Driver\usbuhci \Device\USBPDO-5 8A3F71E8 Device \Driver\usbuhci \Device\USBPDO-6 8A3F71E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 8A60C1E8 AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpman.sys AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 timntr.sys Device \Driver\usbehci \Device\USBPDO-7 8A3B61E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A60C1E8 AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 tdrpman.sys AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 timntr.sys Device \Driver\Cdrom \Device\CdRom0 8A3AA1E8 Device \Driver\atapi \Device\Ide\IdePort0 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort4 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort5 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Cdrom \Device\CdRom1 8A3AA1E8 Device \Driver\Cdrom \Device\CdRom2 8A3AA1E8 Device \Driver\NetBT \Device\NetBt_Wins_Export 89C02550 Device \Driver\NetBT \Device\NetbiosSmb 89C02550 Device \Driver\usbuhci \Device\USBFDO-0 8A3F71E8 Device \Driver\USBSTOR \Device\0000007a 8938C7A0 Device \Driver\usbuhci \Device\USBFDO-1 8A3F71E8 Device \Driver\USBSTOR \Device\0000007b 8938C7A0 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89B821E8 Device \Driver\usbehci \Device\USBFDO-2 8A3B61E8 Device \Driver\NetBT \Device\NetBT_Tcpip_{E237ECC0-F671-4385-96BA-58FDE9FDA6A8} 89C02550 Device \FileSystem\MRxSmb \Device\LanmanRedirector 89B821E8 Device \Driver\usbuhci \Device\USBFDO-3 8A3F71E8 Device \Driver\usbuhci \Device\USBFDO-4 8A3F71E8 Device \Driver\Ftdisk \Device\FtControl 8A60C1E8 Device \Driver\usbuhci \Device\USBFDO-5 8A3F71E8 Device \Driver\usbuhci \Device\USBFDO-6 8A3F71E8 Device \Driver\usbehci \Device\USBFDO-7 8A3B61E8 Device \Driver\aklt8ki9 \Device\Scsi\aklt8ki91Port6Path0Target1Lun0 8A3481E8 Device \Driver\aklt8ki9 \Device\Scsi\aklt8ki91 8A3481E8 Device \Driver\aklt8ki9 \Device\Scsi\aklt8ki91Port6Path0Target0Lun0 8A3481E8 Device \FileSystem\Fastfat \Fat 893777A0 Device \FileSystem\Cdfs \Cdfs 8A3161E8 ---- Trace I/O - GMER 2.1 ---- Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8a5bb8a8]<< 8a5bb8a8 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a504ab8] 8a504ab8 Trace 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\0000006b[0x8a5739e8] 8a5739e8 Trace 5 ACPI.sys[f74ad620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-10[0x8a512940] 8a512940 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... ---- EOF - GMER 2.1 ---- Code:
ATTFilter 14:50:32.0156 2784 ============================================================ 14:50:32.0156 2784 \Device\Harddisk0\DR0: 14:50:32.0156 2784 MBR partitions: 14:50:32.0156 2784 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D4B139 14:50:32.0156 2784 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D4B1B7, BlocksNum 0x10CCD90A 14:50:32.0156 2784 \Device\Harddisk1\DR7: 14:50:32.0156 2784 MBR partitions: 14:50:32.0156 2784 \Device\Harddisk1\DR7\Partition1: MBR, Type 0xB, StartLBA 0x800, BlocksNum 0xEE1000 14:50:32.0156 2784 ============================================================ 14:50:32.0562 2784 C: <-> \Device\Harddisk0\DR0\Partition1 14:50:33.0250 2784 D: <-> \Device\Harddisk0\DR0\Partition2 14:50:33.0250 2784 ============================================================ 14:50:33.0250 2784 Initialize success 14:50:33.0250 2784 ============================================================ 14:50:37.0343 3508 ============================================================ 14:50:37.0343 3508 Scan started 14:50:37.0343 3508 Mode: Manual; SigCheck; TDLFS; 14:50:37.0343 3508 ============================================================ 14:50:39.0968 3508 ================ Scan system memory ======================== 14:50:39.0968 3508 System memory - ok 14:50:39.0968 3508 ================ Scan services ============================= 14:50:40.0703 3508 Abiosdsk - ok 14:50:40.0703 3508 abp480n5 - ok 14:50:40.0812 3508 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WIN\system32\DRIVERS\ACPI.sys 14:50:41.0031 3508 ACPI - ok 14:50:41.0078 3508 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WIN\system32\drivers\ACPIEC.sys 14:50:41.0203 3508 ACPIEC - ok 14:50:41.0390 3508 [ D4D6C022733C37E3F770D64A36620268 ] AcrSch2Svc C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe 14:50:41.0468 3508 AcrSch2Svc - ok 14:50:41.0468 3508 adpu160m - ok 14:50:41.0515 3508 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WIN\system32\drivers\aec.sys 14:50:41.0609 3508 aec - ok 14:50:41.0656 3508 [ 7E775010EF291DA96AD17CA4B17137D7 ] AFD C:\WIN\System32\drivers\afd.sys 14:50:41.0718 3508 AFD - ok 14:50:41.0718 3508 Aha154x - ok 14:50:41.0734 3508 aic78u2 - ok 14:50:41.0734 3508 aic78xx - ok 14:50:41.0765 3508 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WIN\system32\alrsvc.dll 14:50:41.0859 3508 Alerter - ok 14:50:41.0875 3508 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WIN\System32\alg.exe 14:50:41.0953 3508 ALG - ok 14:50:41.0953 3508 AliIde - ok 14:50:41.0968 3508 amsint - ok 14:50:42.0062 3508 [ C27D46B06D340293670450FCE9DFB166 ] AntiVirSchedulerService C:\Programme\Avira\AntiVir Desktop\sched.exe 14:50:42.0062 3508 AntiVirSchedulerService - ok 14:50:42.0203 3508 [ 72D90E56563165984224493069C69ED4 ] AntiVirService C:\Programme\Avira\AntiVir Desktop\avguard.exe 14:50:42.0250 3508 AntiVirService - ok 14:50:42.0328 3508 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WIN\System32\appmgmts.dll 14:50:42.0437 3508 AppMgmt - ok 14:50:42.0453 3508 asc - ok 14:50:42.0453 3508 asc3350p - ok 14:50:42.0453 3508 asc3550 - ok 14:50:42.0546 3508 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WIN\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 14:50:42.0593 3508 aspnet_state - ok 14:50:42.0625 3508 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WIN\system32\DRIVERS\asyncmac.sys 14:50:42.0703 3508 AsyncMac - ok 14:50:42.0734 3508 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WIN\system32\DRIVERS\atapi.sys 14:50:42.0890 3508 atapi - ok 14:50:42.0890 3508 Atdisk - ok 14:50:43.0046 3508 [ 8F7865DB9563642AF17075C61EA6A6D4 ] Ati HotKey Poller C:\WIN\system32\Ati2evxx.exe 14:50:43.0234 3508 Ati HotKey Poller - ok 14:50:43.0390 3508 [ 0DB73D7AE092600530F1DCD064D57AE3 ] ATI Smart C:\WIN\system32\ati2sgag.exe 14:50:43.0484 3508 ATI Smart ( UnsignedFile.Multi.Generic ) - warning 14:50:43.0484 3508 ATI Smart - detected UnsignedFile.Multi.Generic (1) 14:50:44.0093 3508 [ B563E7154DB73C2DAC72FA08120295CF ] ati2mtag C:\WIN\system32\DRIVERS\ati2mtag.sys 14:50:45.0062 3508 ati2mtag - ok 14:50:45.0125 3508 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WIN\system32\DRIVERS\atmarpc.sys 14:50:45.0234 3508 Atmarpc - ok 14:50:45.0265 3508 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WIN\System32\audiosrv.dll 14:50:45.0359 3508 AudioSrv - ok 14:50:45.0390 3508 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WIN\system32\DRIVERS\audstub.sys 14:50:45.0468 3508 audstub - ok 14:50:45.0531 3508 [ 0F78D3DAE6DEDD99AE54C9491C62ADF2 ] avipbb C:\WIN\system32\DRIVERS\avipbb.sys 14:50:45.0531 3508 avipbb - ok 14:50:45.0562 3508 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WIN\system32\drivers\Beep.sys 14:50:45.0656 3508 Beep - ok 14:50:45.0781 3508 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WIN\system32\qmgr.dll 14:50:46.0031 3508 BITS - ok 14:50:46.0078 3508 [ B42057F06BBB98B31876C0B3F2B54E33 ] Browser C:\WIN\System32\browser.dll 14:50:46.0171 3508 Browser - ok 14:50:46.0203 3508 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WIN\system32\drivers\cbidf2k.sys 14:50:46.0296 3508 cbidf2k - ok 14:50:46.0296 3508 cd20xrnt - ok 14:50:46.0328 3508 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WIN\system32\drivers\Cdaudio.sys 14:50:46.0406 3508 Cdaudio - ok 14:50:46.0437 3508 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WIN\system32\drivers\Cdfs.sys 14:50:46.0515 3508 Cdfs - ok 14:50:46.0546 3508 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WIN\system32\DRIVERS\cdrom.sys 14:50:46.0625 3508 Cdrom - ok 14:50:46.0640 3508 Changer - ok 14:50:46.0656 3508 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WIN\system32\cisvc.exe 14:50:46.0750 3508 CiSvc - ok 14:50:46.0765 3508 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WIN\system32\clipsrv.exe 14:50:46.0859 3508 ClipSrv - ok 14:50:46.0890 3508 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WIN\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:50:47.0078 3508 clr_optimization_v2.0.50727_32 - ok 14:50:47.0078 3508 CmdIde - ok 14:50:47.0078 3508 COMSysApp - ok 14:50:47.0093 3508 Cpqarray - ok 14:50:47.0125 3508 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WIN\System32\cryptsvc.dll 14:50:47.0234 3508 CryptSvc - ok 14:50:47.0234 3508 dac2w2k - ok 14:50:47.0234 3508 dac960nt - ok 14:50:47.0359 3508 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WIN\system32\rpcss.dll 14:50:47.0593 3508 DcomLaunch - ok 14:50:50.0281 3508 [ 141673E69CFDCF0B1531616343223EE4 ] DevoloNetworkService C:\Programme\devolo\dlan\devolonetsvc.exe 14:50:54.0250 3508 DevoloNetworkService - ok 14:50:54.0296 3508 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WIN\System32\dhcpcsvc.dll 14:50:54.0421 3508 Dhcp - ok 14:50:54.0468 3508 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WIN\system32\DRIVERS\disk.sys 14:50:54.0546 3508 Disk - ok 14:50:54.0546 3508 dmadmin - ok 14:50:54.0953 3508 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WIN\system32\drivers\dmboot.sys 14:50:55.0390 3508 dmboot - ok 14:50:55.0453 3508 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WIN\system32\drivers\dmio.sys 14:50:55.0578 3508 dmio - ok 14:50:55.0625 3508 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WIN\system32\drivers\dmload.sys 14:50:55.0750 3508 dmload - ok 14:50:55.0812 3508 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WIN\System32\dmserver.dll 14:50:55.0921 3508 dmserver - ok 14:50:55.0953 3508 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WIN\system32\drivers\DMusic.sys 14:50:56.0078 3508 DMusic - ok 14:50:56.0140 3508 [ 8C9ED3B2834AAE63081AB2DA831C6FE9 ] Dnscache C:\WIN\System32\dnsrslvr.dll 14:50:56.0296 3508 Dnscache - ok 14:50:56.0906 3508 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WIN\System32\dot3svc.dll 14:50:57.0078 3508 Dot3svc - ok 14:50:57.0078 3508 dpti2o - ok 14:50:57.0406 3508 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WIN\system32\drivers\drmkaud.sys 14:50:57.0500 3508 drmkaud - ok 14:50:57.0718 3508 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WIN\System32\eapsvc.dll 14:50:57.0828 3508 EapHost - ok 14:50:57.0875 3508 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WIN\System32\ersvc.dll 14:50:57.0984 3508 ERSvc - ok 14:50:58.0062 3508 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WIN\system32\services.exe 14:50:58.0203 3508 Eventlog - ok 14:50:58.0406 3508 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WIN\system32\es.dll 14:50:58.0640 3508 EventSystem - ok 14:50:58.0718 3508 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WIN\system32\drivers\Fastfat.sys 14:50:58.0828 3508 Fastfat - ok 14:50:58.0906 3508 [ 40602EBFBE06AA075C8E4560743F6883 ] FastUserSwitchingCompatibility C:\WIN\System32\shsvcs.dll 14:50:59.0046 3508 FastUserSwitchingCompatibility - ok 14:50:59.0078 3508 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WIN\system32\DRIVERS\fdc.sys 14:50:59.0171 3508 Fdc - ok 14:50:59.0250 3508 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WIN\system32\drivers\Fips.sys 14:50:59.0359 3508 Fips - ok 14:50:59.0406 3508 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WIN\system32\DRIVERS\flpydisk.sys 14:50:59.0484 3508 Flpydisk - ok 14:50:59.0546 3508 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WIN\system32\drivers\fltmgr.sys 14:50:59.0687 3508 FltMgr - ok 14:50:59.0781 3508 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WIN\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 14:50:59.0812 3508 FontCache3.0.0.0 - ok 14:50:59.0859 3508 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WIN\system32\drivers\Fs_Rec.sys 14:50:59.0953 3508 Fs_Rec - ok 14:51:00.0015 3508 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WIN\system32\DRIVERS\ftdisk.sys 14:51:00.0187 3508 Ftdisk - ok 14:51:00.0187 3508 GMSIPCI - ok 14:51:00.0218 3508 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WIN\system32\DRIVERS\msgpc.sys 14:51:00.0312 3508 Gpc - ok 14:51:00.0406 3508 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WIN\system32\DRIVERS\HDAudBus.sys 14:51:00.0515 3508 HDAudBus - ok 14:51:00.0609 3508 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WIN\PCHealth\HelpCtr\Binaries\pchsvc.dll 14:51:00.0750 3508 helpsvc - ok 14:51:00.0796 3508 [ B35DA85E60C0103F2E4104532DA2F12B ] HidServ C:\WIN\System32\hidserv.dll 14:51:00.0906 3508 HidServ - ok 14:51:00.0937 3508 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WIN\system32\DRIVERS\hidusb.sys 14:51:02.0015 3508 HidUsb - ok 14:51:02.0109 3508 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WIN\System32\kmsvc.dll 14:51:02.0203 3508 hkmsvc - ok 14:51:02.0203 3508 hpn - ok 14:51:02.0406 3508 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WIN\system32\Drivers\HTTP.sys 14:51:02.0546 3508 HTTP - ok 14:51:02.0578 3508 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WIN\System32\w3ssl.dll 14:51:02.0671 3508 HTTPFilter - ok 14:51:02.0687 3508 i2omgmt - ok 14:51:02.0687 3508 i2omp - ok 14:51:02.0734 3508 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WIN\system32\DRIVERS\i8042prt.sys 14:51:02.0843 3508 i8042prt - ok 14:51:02.0968 3508 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe 14:51:03.0000 3508 IDriverT ( UnsignedFile.Multi.Generic ) - warning 14:51:03.0000 3508 IDriverT - detected UnsignedFile.Multi.Generic (1) 14:51:03.0625 3508 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WIN\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 14:51:04.0312 3508 idsvc - ok 14:51:04.0406 3508 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WIN\system32\DRIVERS\imapi.sys 14:51:04.0531 3508 Imapi - ok 14:51:04.0750 3508 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WIN\system32\imapi.exe 14:51:04.0859 3508 ImapiService - ok 14:51:04.0859 3508 ini910u - ok 14:51:06.0734 3508 [ 1367A51BB535D2F76F642D4AADE72AEE ] IntcAzAudAddService C:\WIN\system32\drivers\RtkHDAud.sys 14:51:12.0281 3508 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - warning 14:51:12.0281 3508 IntcAzAudAddService - detected UnsignedFile.Multi.Generic (1) 14:51:12.0281 3508 IntelIde - ok 14:51:12.0687 3508 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WIN\system32\DRIVERS\intelppm.sys 14:51:13.0937 3508 intelppm - ok 14:51:14.0000 3508 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WIN\system32\drivers\ip6fw.sys 14:51:14.0140 3508 Ip6Fw - ok 14:51:14.0437 3508 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WIN\system32\DRIVERS\ipfltdrv.sys 14:51:14.0640 3508 IpFilterDriver - ok 14:51:14.0734 3508 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WIN\system32\DRIVERS\ipinip.sys 14:51:14.0859 3508 IpInIp - ok 14:51:14.0921 3508 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WIN\system32\DRIVERS\ipnat.sys 14:51:15.0046 3508 IpNat - ok 14:51:15.0093 3508 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WIN\system32\DRIVERS\ipsec.sys 14:51:15.0218 3508 IPSec - ok 14:51:15.0328 3508 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WIN\system32\DRIVERS\irenum.sys 14:51:15.0421 3508 IRENUM - ok 14:51:15.0453 3508 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WIN\system32\DRIVERS\isapnp.sys 14:51:15.0531 3508 isapnp - ok 14:51:15.0765 3508 [ 1834C96FB1F9280BCF6DDFA6DE8338BF ] JavaQuickStarterService C:\Programme\Java\jre6\bin\jqs.exe 14:51:15.0781 3508 JavaQuickStarterService - ok 14:51:15.0796 3508 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WIN\system32\DRIVERS\kbdclass.sys 14:51:15.0875 3508 Kbdclass - ok 14:51:15.0921 3508 [ B6D6C117D771C98130497265F26D1882 ] kbdhid C:\WIN\system32\DRIVERS\kbdhid.sys 14:51:16.0015 3508 kbdhid - ok 14:51:16.0093 3508 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WIN\system32\drivers\kmixer.sys 14:51:16.0359 3508 kmixer - ok 14:51:16.0437 3508 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WIN\system32\drivers\KSecDD.sys 14:51:16.0578 3508 KSecDD - ok 14:51:16.0671 3508 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WIN\System32\srvsvc.dll 14:51:17.0078 3508 lanmanserver - ok 14:51:17.0328 3508 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WIN\System32\wkssvc.dll 14:51:18.0265 3508 lanmanworkstation - ok 14:51:18.0265 3508 lbrtfdc - ok 14:51:18.0484 3508 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WIN\System32\lmhsvc.dll 14:51:18.0593 3508 LmHosts - ok 14:51:18.0687 3508 [ 4A5FFDF0FE830C448830BD4B02B02B4B ] mbamchameleon C:\WIN\system32\drivers\mbamchameleon.sys 14:51:18.0703 3508 mbamchameleon - ok 14:51:18.0750 3508 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WIN\System32\msgsvc.dll 14:51:18.0812 3508 Messenger - ok 14:51:18.0843 3508 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WIN\system32\drivers\mnmdd.sys 14:51:18.0937 3508 mnmdd - ok 14:51:18.0984 3508 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WIN\system32\mnmsrvc.exe 14:51:19.0078 3508 mnmsrvc - ok 14:51:19.0296 3508 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WIN\system32\drivers\Modem.sys 14:51:19.0406 3508 Modem - ok 14:51:19.0437 3508 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WIN\system32\DRIVERS\mouclass.sys 14:51:19.0531 3508 Mouclass - ok 14:51:19.0593 3508 [ 66A6F73C74E1791464160A7065CE711A ] mouhid C:\WIN\system32\DRIVERS\mouhid.sys 14:51:19.0687 3508 mouhid - ok 14:51:19.0812 3508 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WIN\system32\drivers\MountMgr.sys 14:51:19.0906 3508 MountMgr - ok 14:51:19.0968 3508 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe 14:51:20.0015 3508 MozillaMaintenance - ok 14:51:20.0031 3508 mraid35x - ok 14:51:20.0109 3508 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WIN\system32\DRIVERS\mrxdav.sys 14:51:20.0281 3508 MRxDAV - ok 14:51:20.0546 3508 [ F3AEFB11ABC521122B67095044169E98 ] MRxSmb C:\WIN\system32\DRIVERS\mrxsmb.sys 14:51:20.0859 3508 MRxSmb - ok 14:51:20.0890 3508 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WIN\system32\msdtc.exe 14:51:20.0984 3508 MSDTC - ok 14:51:21.0015 3508 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WIN\system32\drivers\Msfs.sys 14:51:21.0125 3508 Msfs - ok 14:51:21.0140 3508 MSIServer - ok 14:51:21.0203 3508 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WIN\system32\drivers\MSKSSRV.sys 14:51:21.0328 3508 MSKSSRV - ok 14:51:21.0359 3508 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WIN\system32\drivers\MSPCLOCK.sys 14:51:21.0437 3508 MSPCLOCK - ok 14:51:21.0531 3508 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WIN\system32\drivers\MSPQM.sys 14:51:21.0625 3508 MSPQM - ok 14:51:21.0718 3508 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WIN\system32\DRIVERS\mssmbios.sys 14:51:21.0796 3508 mssmbios - ok 14:51:21.0843 3508 [ 2F625D11385B1A94360BFC70AAEFDEE1 ] Mup C:\WIN\system32\drivers\Mup.sys 14:51:21.0937 3508 Mup - ok 14:51:22.0609 3508 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WIN\System32\qagentrt.dll 14:51:22.0796 3508 napagent - ok 14:51:22.0859 3508 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WIN\system32\drivers\NDIS.sys 14:51:23.0015 3508 NDIS - ok 14:51:23.0015 3508 [ 1AB3D00C991AB086E69DB84B6C0ED78F ] NdisTapi C:\WIN\system32\DRIVERS\ndistapi.sys 14:51:23.0109 3508 NdisTapi - ok 14:51:23.0203 3508 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WIN\system32\DRIVERS\ndisuio.sys 14:51:23.0296 3508 Ndisuio - ok 14:51:23.0890 3508 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WIN\system32\DRIVERS\ndiswan.sys 14:51:24.0734 3508 NdisWan - ok 14:51:24.0765 3508 [ 6215023940CFD3702B46ABC304E1D45A ] NDProxy C:\WIN\system32\drivers\NDProxy.sys 14:51:24.0843 3508 NDProxy - ok 14:51:24.0875 3508 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WIN\system32\DRIVERS\netbios.sys 14:51:24.0968 3508 NetBIOS - ok 14:51:25.0046 3508 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WIN\system32\DRIVERS\netbt.sys 14:51:25.0218 3508 NetBT - ok 14:51:25.0343 3508 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WIN\system32\netdde.exe 14:51:25.0484 3508 NetDDE - ok 14:51:25.0515 3508 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WIN\system32\netdde.exe 14:51:25.0609 3508 NetDDEdsdm - ok 14:51:25.0640 3508 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WIN\system32\lsass.exe 14:51:25.0734 3508 Netlogon - ok 14:51:25.0843 3508 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WIN\System32\netman.dll 14:51:26.0000 3508 Netman - ok 14:51:26.0078 3508 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WIN\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:51:26.0125 3508 NetTcpPortSharing - ok 14:51:26.0328 3508 [ ACD8BD448A74F344D46FCAF21BAB92AF ] Nla C:\WIN\System32\mswsock.dll 14:51:26.0468 3508 Nla - ok 14:51:26.0765 3508 [ E32686B4E27D11F83E3F2844E104C66C ] NMIndexingService C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe 14:51:26.0765 3508 NMIndexingService - ok 14:51:26.0812 3508 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WIN\system32\drivers\Npfs.sys 14:51:26.0890 3508 Npfs - ok 14:51:26.0937 3508 [ 75AC610A7481CB1F343DC971249BCB19 ] NPF_devolo C:\WIN\system32\drivers\npf_devolo.sys 14:51:26.0953 3508 NPF_devolo ( UnsignedFile.Multi.Generic ) - warning 14:51:26.0953 3508 NPF_devolo - detected UnsignedFile.Multi.Generic (1) 14:51:27.0328 3508 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WIN\system32\drivers\Ntfs.sys 14:51:27.0750 3508 Ntfs - ok 14:51:27.0765 3508 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WIN\system32\lsass.exe 14:51:27.0843 3508 NtLmSsp - ok 14:51:29.0031 3508 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WIN\system32\ntmssvc.dll 14:51:29.0578 3508 NtmsSvc - ok 14:51:29.0734 3508 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WIN\system32\drivers\Null.sys 14:51:29.0812 3508 Null - ok 14:51:29.0859 3508 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WIN\system32\DRIVERS\nwlnkflt.sys 14:51:29.0968 3508 NwlnkFlt - ok 14:51:30.0000 3508 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WIN\system32\DRIVERS\nwlnkfwd.sys 14:51:30.0109 3508 NwlnkFwd - ok 14:51:30.0859 3508 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 14:51:30.0890 3508 ose - ok 14:51:30.0953 3508 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WIN\system32\DRIVERS\parport.sys 14:51:31.0078 3508 Parport - ok 14:51:31.0093 3508 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WIN\system32\drivers\PartMgr.sys 14:51:31.0203 3508 PartMgr - ok 14:51:31.0578 3508 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WIN\system32\drivers\ParVdm.sys 14:51:31.0671 3508 ParVdm - ok 14:51:31.0734 3508 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WIN\system32\DRIVERS\pci.sys 14:51:31.0859 3508 PCI - ok 14:51:31.0859 3508 PCIDump - ok 14:51:31.0890 3508 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WIN\system32\DRIVERS\pciide.sys 14:51:32.0031 3508 PCIIde - ok 14:51:32.0093 3508 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WIN\system32\drivers\Pcmcia.sys 14:51:32.0250 3508 Pcmcia - ok 14:51:32.0296 3508 [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin C:\WIN\system32\Drivers\pcouffin.sys 14:51:32.0312 3508 pcouffin ( UnsignedFile.Multi.Generic ) - warning 14:51:32.0312 3508 pcouffin - detected UnsignedFile.Multi.Generic (1) 14:51:32.0328 3508 PDCOMP - ok 14:51:32.0328 3508 PDFRAME - ok 14:51:32.0328 3508 PDRELI - ok 14:51:32.0328 3508 PDRFRAME - ok 14:51:32.0328 3508 perc2 - ok 14:51:32.0343 3508 perc2hib - ok 14:51:32.0390 3508 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WIN\system32\services.exe 14:51:32.0421 3508 PlugPlay - ok 14:51:32.0453 3508 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WIN\system32\lsass.exe 14:51:32.0531 3508 PolicyAgent - ok 14:51:32.0562 3508 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WIN\system32\DRIVERS\raspptp.sys 14:51:32.0671 3508 PptpMiniport - ok 14:51:32.0687 3508 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WIN\system32\lsass.exe 14:51:32.0781 3508 ProtectedStorage - ok 14:51:32.0812 3508 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WIN\system32\DRIVERS\psched.sys 14:51:32.0921 3508 PSched - ok 14:51:32.0953 3508 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WIN\system32\DRIVERS\ptilink.sys 14:51:33.0031 3508 Ptilink - ok 14:51:33.0078 3508 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WIN\system32\Drivers\PxHelp20.sys 14:51:33.0093 3508 PxHelp20 - ok 14:51:33.0093 3508 ql1080 - ok 14:51:33.0093 3508 Ql10wnt - ok 14:51:33.0093 3508 ql12160 - ok 14:51:33.0093 3508 ql1240 - ok 14:51:33.0109 3508 ql1280 - ok 14:51:33.0250 3508 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WIN\system32\DRIVERS\rasacd.sys 14:51:33.0359 3508 RasAcd - ok 14:51:33.0453 3508 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WIN\System32\rasauto.dll 14:51:33.0578 3508 RasAuto - ok 14:51:33.0593 3508 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WIN\system32\DRIVERS\rasl2tp.sys 14:51:33.0703 3508 Rasl2tp - ok 14:51:33.0843 3508 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WIN\System32\rasmans.dll 14:51:33.0984 3508 RasMan - ok 14:51:34.0015 3508 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WIN\system32\DRIVERS\raspppoe.sys 14:51:34.0140 3508 RasPppoe - ok 14:51:34.0203 3508 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WIN\system32\DRIVERS\raspti.sys 14:51:34.0296 3508 Raspti - ok 14:51:34.0359 3508 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WIN\system32\DRIVERS\rdbss.sys 14:51:34.0500 3508 Rdbss - ok 14:51:34.0531 3508 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WIN\system32\DRIVERS\RDPCDD.sys 14:51:34.0625 3508 RDPCDD - ok 14:51:34.0687 3508 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WIN\system32\DRIVERS\rdpdr.sys 14:51:34.0828 3508 rdpdr - ok 14:51:34.0953 3508 [ 6728E45B66F93C08F11DE2E316FC70DD ] RDPWD C:\WIN\system32\drivers\RDPWD.sys 14:51:35.0093 3508 RDPWD - ok 14:51:35.0250 3508 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WIN\system32\sessmgr.exe 14:51:35.0406 3508 RDSessMgr - ok 14:51:35.0453 3508 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WIN\system32\DRIVERS\redbook.sys 14:51:35.0562 3508 redbook - ok 14:51:35.0671 3508 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WIN\System32\mprdim.dll 14:51:35.0781 3508 RemoteAccess - ok 14:51:35.0812 3508 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WIN\system32\regsvc.dll 14:51:35.0921 3508 RemoteRegistry - ok 14:51:35.0937 3508 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WIN\system32\locator.exe 14:51:36.0062 3508 RpcLocator - ok 14:51:36.0343 3508 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WIN\system32\rpcss.dll 14:51:36.0453 3508 RpcSs - ok 14:51:36.0515 3508 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WIN\system32\rsvp.exe 14:51:36.0625 3508 RSVP - ok 14:51:36.0687 3508 [ BB0AE2171F08129F4F3FF9DF20FFBF89 ] RTLE8023xp C:\WIN\system32\DRIVERS\Rtenicxp.sys 14:51:36.0828 3508 RTLE8023xp - ok 14:51:36.0828 3508 RTLWUSB - ok 14:51:36.0843 3508 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WIN\system32\lsass.exe 14:51:36.0921 3508 SamSs - ok 14:51:36.0968 3508 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WIN\System32\SCardSvr.exe 14:51:37.0062 3508 SCardSvr - ok 14:51:37.0156 3508 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WIN\system32\schedsvc.dll 14:51:37.0328 3508 Schedule - ok 14:51:37.0515 3508 [ 331E7BDE228914574FC9AE6CD520DAFA ] SeaPort C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 14:51:37.0531 3508 SeaPort - ok 14:51:37.0656 3508 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WIN\system32\DRIVERS\secdrv.sys 14:51:37.0734 3508 Secdrv - ok 14:51:37.0765 3508 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WIN\System32\seclogon.dll 14:51:37.0875 3508 seclogon - ok 14:51:37.0906 3508 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WIN\system32\sens.dll 14:51:38.0015 3508 SENS - ok 14:51:38.0062 3508 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WIN\system32\DRIVERS\serenum.sys 14:51:38.0156 3508 serenum - ok 14:51:38.0203 3508 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WIN\system32\DRIVERS\serial.sys 14:51:38.0328 3508 Serial - ok 14:51:38.0390 3508 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WIN\system32\drivers\Sfloppy.sys 14:51:38.0500 3508 Sfloppy - ok 14:51:38.0656 3508 [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess C:\WIN\System32\ipnathlp.dll 14:51:38.0968 3508 SharedAccess - ok 14:51:39.0015 3508 [ 40602EBFBE06AA075C8E4560743F6883 ] ShellHWDetection C:\WIN\System32\shsvcs.dll 14:51:39.0109 3508 ShellHWDetection - ok 14:51:39.0125 3508 Simbad - ok 14:51:39.0281 3508 [ BCC773872041AA59BC9A6CF770FB32E2 ] snapman C:\WIN\system32\DRIVERS\snapman.sys 14:51:39.0312 3508 snapman - ok 14:51:39.0328 3508 Sparrow - ok 14:51:39.0359 3508 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WIN\system32\drivers\splitter.sys 14:51:39.0453 3508 splitter - ok 14:51:39.0500 3508 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WIN\system32\spoolsv.exe 14:51:39.0562 3508 Spooler - ok 14:51:39.0765 3508 [ 4F576E516CC76EC50A244586BCFA1C78 ] sptd C:\WIN\system32\Drivers\sptd.sys 14:51:39.0765 3508 Suspicious file (NoAccess): C:\WIN\system32\Drivers\sptd.sys. md5: 4F576E516CC76EC50A244586BCFA1C78 14:51:39.0765 3508 sptd ( LockedFile.Multi.Generic ) - warning 14:51:39.0765 3508 sptd - detected LockedFile.Multi.Generic (1) 14:51:39.0812 3508 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WIN\system32\DRIVERS\sr.sys 14:51:39.0906 3508 sr - ok 14:51:39.0984 3508 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WIN\system32\srsvc.dll 14:51:40.0125 3508 srservice - ok 14:51:40.0375 3508 [ 0F6AEFAD3641A657E18081F52D0C15AF ] Srv C:\WIN\system32\DRIVERS\srv.sys 14:51:40.0531 3508 Srv - ok 14:51:40.0578 3508 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WIN\System32\ssdpsrv.dll 14:51:40.0671 3508 SSDPSRV - ok 14:51:40.0703 3508 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\WIN\system32\DRIVERS\ssmdrv.sys 14:51:40.0718 3508 ssmdrv - ok 14:51:40.0750 3508 [ A2DBCC4C8860449DF1AB758EA28B4DE0 ] StillCam C:\WIN\system32\DRIVERS\serscan.sys 14:51:40.0843 3508 StillCam - ok 14:51:40.0984 3508 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WIN\system32\wiaservc.dll 14:51:41.0390 3508 stisvc - ok 14:51:41.0468 3508 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WIN\system32\DRIVERS\swenum.sys 14:51:41.0562 3508 swenum - ok 14:51:41.0609 3508 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WIN\system32\drivers\swmidi.sys 14:51:41.0703 3508 swmidi - ok 14:51:41.0703 3508 SwPrv - ok 14:51:41.0703 3508 symc810 - ok 14:51:41.0718 3508 symc8xx - ok 14:51:41.0718 3508 sym_hi - ok 14:51:41.0718 3508 sym_u3 - ok 14:51:41.0765 3508 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WIN\system32\drivers\sysaudio.sys 14:51:41.0859 3508 sysaudio - ok 14:51:41.0921 3508 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WIN\system32\smlogsvc.exe 14:51:42.0031 3508 SysmonLog - ok 14:51:42.0140 3508 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WIN\System32\tapisrv.dll 14:51:42.0343 3508 TapiSrv - ok 14:51:42.0515 3508 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WIN\system32\DRIVERS\tcpip.sys 14:51:42.0812 3508 Tcpip - ok 14:51:42.0875 3508 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WIN\system32\drivers\TDPIPE.sys 14:51:42.0953 3508 TDPIPE - ok 14:51:43.0078 3508 [ 3B7B6779EB231F731BBA8F9FE67AADFC ] tdrpman C:\WIN\system32\DRIVERS\tdrpman.sys 14:51:43.0421 3508 tdrpman - ok 14:51:43.0687 3508 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WIN\system32\drivers\TDTCP.sys 14:51:43.0781 3508 TDTCP - ok 14:51:59.0187 3508 [ 6B1B2F8D62D606B200C2072564090104 ] TeamViewer8 C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe 14:52:01.0953 3508 TeamViewer8 - ok 14:52:01.0984 3508 [ 88155247177638048422893737429D9E ] TermDD C:\WIN\system32\DRIVERS\termdd.sys 14:52:02.0125 3508 TermDD - ok 14:52:02.0375 3508 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WIN\System32\termsrv.dll 14:52:02.0562 3508 TermService - ok 14:52:02.0640 3508 [ 40602EBFBE06AA075C8E4560743F6883 ] Themes C:\WIN\System32\shsvcs.dll 14:52:02.0718 3508 Themes - ok 14:52:02.0765 3508 [ B0B3122BFF3910E0BA97014045467778 ] tifsfilter C:\WIN\system32\DRIVERS\tifsfilt.sys 14:52:02.0765 3508 tifsfilter - ok 14:52:02.0906 3508 [ 13BFE330880AC0CE8672D00AA5AFF738 ] timounter C:\WIN\system32\DRIVERS\timntr.sys 14:52:03.0250 3508 timounter - ok 14:52:03.0390 3508 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WIN\system32\tlntsvr.exe 14:52:03.0500 3508 TlntSvr - ok 14:52:03.0500 3508 TosIde - ok 14:52:03.0562 3508 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WIN\system32\trkwks.dll 14:52:03.0703 3508 TrkWks - ok 14:52:04.0015 3508 [ ABEE0A9ED1E0EB558C60F0881132AE32 ] TryAndDecideService C:\Programme\Gemeinsame Dateien\Acronis\Fomatik\TrueImageTryStartService.exe 14:52:04.0125 3508 TryAndDecideService - ok 14:52:04.0468 3508 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WIN\system32\drivers\Udfs.sys 14:52:04.0593 3508 Udfs - ok 14:52:04.0593 3508 ultra - ok 14:52:04.0625 3508 [ C81B8635DEE0D3EF5F64B3DD643023A5 ] UMWdf C:\WIN\system32\wdfmgr.exe 14:52:04.0671 3508 UMWdf - ok 14:52:04.0828 3508 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WIN\system32\DRIVERS\update.sys 14:52:05.0218 3508 Update - ok 14:52:05.0437 3508 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WIN\System32\upnphost.dll 14:52:05.0578 3508 upnphost - ok 14:52:05.0609 3508 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WIN\System32\ups.exe 14:52:05.0703 3508 UPS - ok 14:52:05.0734 3508 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WIN\system32\DRIVERS\usbccgp.sys 14:52:05.0828 3508 usbccgp - ok 14:52:05.0859 3508 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WIN\system32\DRIVERS\usbehci.sys 14:52:05.0953 3508 usbehci - ok 14:52:05.0984 3508 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WIN\system32\DRIVERS\usbhub.sys 14:52:06.0140 3508 usbhub - ok 14:52:06.0234 3508 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WIN\system32\DRIVERS\usbprint.sys 14:52:06.0343 3508 usbprint - ok 14:52:06.0406 3508 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WIN\system32\DRIVERS\usbscan.sys 14:52:06.0515 3508 usbscan - ok 14:52:06.0531 3508 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WIN\system32\DRIVERS\USBSTOR.SYS 14:52:06.0640 3508 USBSTOR - ok 14:52:06.0687 3508 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WIN\system32\DRIVERS\usbuhci.sys 14:52:06.0781 3508 usbuhci - ok 14:52:07.0421 3508 [ 50676F61C6A44A3B25FB29A18A7CBA95 ] uvnc_service C:\Programme\UltraVNC\WinVNC.exe 14:52:08.0484 3508 uvnc_service - ok 14:52:08.0765 3508 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WIN\System32\drivers\vga.sys 14:52:08.0859 3508 VgaSave - ok 14:52:08.0875 3508 ViaIde - ok 14:52:08.0906 3508 [ 4EC979B157D1AA075330362ACB5424E5 ] vncdrv C:\WIN\system32\DRIVERS\vncdrv.sys 14:52:08.0921 3508 vncdrv ( UnsignedFile.Multi.Generic ) - warning 14:52:08.0921 3508 vncdrv - detected UnsignedFile.Multi.Generic (1) 14:52:08.0968 3508 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WIN\system32\drivers\VolSnap.sys 14:52:09.0062 3508 VolSnap - ok 14:52:09.0328 3508 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WIN\System32\vssvc.exe 14:52:09.0531 3508 VSS - ok 14:52:09.0625 3508 [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time C:\WIN\system32\w32time.dll 14:52:09.0781 3508 W32Time - ok 14:52:09.0828 3508 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WIN\system32\DRIVERS\wanarp.sys 14:52:09.0937 3508 Wanarp - ok 14:52:09.0937 3508 WDICA - ok 14:52:10.0000 3508 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WIN\system32\drivers\wdmaud.sys 14:52:10.0109 3508 wdmaud - ok 14:52:10.0203 3508 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WIN\System32\webclnt.dll 14:52:10.0312 3508 WebClient - ok 14:52:10.0468 3508 [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt C:\WIN\system32\wbem\WMIsvc.dll 14:52:10.0640 3508 winmgmt - ok 14:52:10.0687 3508 [ A477391B7A8B0A0DAABADB17CF533A4B ] WmdmPmSN C:\WIN\system32\mspmsnsv.dll 14:52:10.0750 3508 WmdmPmSN - ok 14:52:11.0015 3508 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WIN\System32\advapi32.dll 14:52:11.0765 3508 Wmi - ok 14:52:11.0843 3508 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WIN\system32\wbem\wmiapsrv.exe 14:52:11.0937 3508 WmiApSrv - ok 14:52:12.0000 3508 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WIN\system32\wscsvc.dll 14:52:12.0171 3508 wscsvc - ok 14:52:12.0703 3508 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv C:\WIN\system32\wuauserv.dll 14:52:12.0796 3508 wuauserv - ok 14:52:12.0968 3508 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WIN\System32\wzcsvc.dll 14:52:13.0406 3508 WZCSVC - ok 14:52:14.0593 3508 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WIN\System32\xmlprov.dll 14:52:14.0812 3508 xmlprov - ok 14:52:14.0812 3508 ================ Scan global =============================== 14:52:14.0859 3508 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WIN\system32\basesrv.dll 14:52:15.0015 3508 [ E9B93B97B1A2965144361F4FD8BD2BEF ] C:\WIN\system32\winsrv.dll 14:52:15.0359 3508 [ E9B93B97B1A2965144361F4FD8BD2BEF ] C:\WIN\system32\winsrv.dll 14:52:15.0406 3508 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WIN\system32\services.exe 14:52:15.0406 3508 [Global] - ok 14:52:15.0406 3508 ================ Scan MBR ================================== 14:52:15.0437 3508 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 14:52:21.0000 3508 \Device\Harddisk0\DR0 - ok 14:52:21.0015 3508 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR7 14:52:21.0156 3508 \Device\Harddisk1\DR7 - ok 14:52:21.0156 3508 ================ Scan VBR ================================== 14:52:21.0421 3508 [ 50D18AF9D01BE94D42E3DA4AE13A20B5 ] \Device\Harddisk0\DR0\Partition1 14:52:21.0500 3508 \Device\Harddisk0\DR0\Partition1 - ok 14:52:21.0593 3508 [ 196AAA05A3A9520F6C1C09E696FB1181 ] \Device\Harddisk0\DR0\Partition2 14:52:21.0687 3508 \Device\Harddisk0\DR0\Partition2 - ok 14:52:21.0687 3508 [ E1461613ED5FB4D7DBA03E5A2AD645B0 ] \Device\Harddisk1\DR7\Partition1 14:52:21.0687 3508 \Device\Harddisk1\DR7\Partition1 - ok 14:52:21.0687 3508 ============================================================ 14:52:21.0687 3508 Scan finished 14:52:21.0687 3508 ============================================================ 14:52:21.0796 3624 Detected object count: 7 14:52:21.0796 3624 Actual detected object count: 7 14:52:38.0234 3624 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 NPF_devolo ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 NPF_devolo ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 sptd ( LockedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 14:52:38.0234 3624 vncdrv ( UnsignedFile.Multi.Generic ) - skipped by user 14:52:38.0234 3624 vncdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip Code:
ATTFilter OTL logfile created on: 23.04.2013 14:47:23 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\silke\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 79,27% Memory free 3,85 Gb Paging File | 3,58 Gb Available in Paging File | 93,10% Paging File free Paging file location(s): D:\pagefile.sys 2046 4096 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WIN | %ProgramFiles% = C:\Programme Drive C: | 14,65 Gb Total Space | 0,57 Gb Free Space | 3,87% Space Free | Partition Type: NTFS Drive D: | 134,40 Gb Total Space | 50,28 Gb Free Space | 37,41% Space Free | Partition Type: NTFS Drive E: | 7,42 Gb Total Space | 7,29 Gb Free Space | 98,13% Space Free | Partition Type: FAT32 Computer Name: WEST | User Name: silke | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Dokumente und Einstellungen\silke\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH) PRC - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) PRC - C:\Programme\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.) PRC - C:\Programme\devolo\dlan\devolonetsvc.exe (devolo AG) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\UltraVnc\winvnc.exe (UltraVNC) PRC - C:\WIN\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Gemeinsame Dateien\Acronis\Fomatik\TrueImageTryStartService.exe () PRC - C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) PRC - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe (Acronis) PRC - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe (Acronis) PRC - C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG) PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe (Nero AG) PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG) ========== Modules (No Company Name) ========== MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll () MOD - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU () MOD - C:\Programme\Gemeinsame Dateien\Acronis\Fomatik\TrueImageTryStartService.exe () MOD - C:\Programme\Acronis\TrueImageHome\fox.dll () MOD - C:\Programme\WinRAR\RarExt.dll () ========== Services (SafeList) ========== SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (TeamViewer8) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH) SRV - (DevoloNetworkService) -- C:\Programme\devolo\dlan\devolonetsvc.exe (devolo AG) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (uvnc_service) -- C:\Programme\UltraVnc\winvnc.exe (UltraVNC) SRV - (TryAndDecideService) -- C:\Programme\Gemeinsame Dateien\Acronis\Fomatik\TrueImageTryStartService.exe () SRV - (AcrSch2Svc) -- C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe (Acronis) SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe (Nero AG) SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found DRV - (RTLWUSB) -- system32\DRIVERS\RTL8187.sys File not found DRV - (PDRFRAME) -- File not found DRV - (PDRELI) -- File not found DRV - (PDFRAME) -- File not found DRV - (PDCOMP) -- File not found DRV - (PCIDump) -- File not found DRV - (lbrtfdc) -- File not found DRV - (i2omgmt) -- File not found DRV - (GMSIPCI) -- E:\INSTALL\GMSIPCI.SYS File not found DRV - (Changer) -- File not found DRV - (aklt8ki9) -- File not found DRV - (mbamchameleon) -- C:\WIN\system32\drivers\mbamchameleon.sys () DRV - (NPF_devolo) -- C:\WIN\system32\drivers\npf_devolo.sys (CACE Technologies) DRV - (avipbb) -- C:\WIN\system32\drivers\avipbb.sys (Avira GmbH) DRV - (ssmdrv) -- C:\WIN\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (timounter) -- C:\WIN\system32\drivers\timntr.sys (Acronis) DRV - (tifsfilter) -- C:\WIN\system32\drivers\tifsfilt.sys (Acronis) DRV - (snapman) -- C:\WIN\system32\drivers\snapman.sys (Acronis) DRV - (tdrpman) -- C:\WIN\system32\drivers\tdrpman.sys (Acronis) DRV - (sptd) -- C:\WIN\system32\drivers\sptd.sys () DRV - (ati2mtag) -- C:\WIN\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (IntcAzAudAddService) -- C:\WIN\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (RTLE8023xp) -- C:\WIN\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (vncdrv) -- C:\WIN\system32\drivers\vncdrv.sys (RDV Soft) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.live.com/sphome.aspx IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1993962763-1645522239-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WIN\system32\blank.htm IE - HKU\S-1-5-21-1993962763-1645522239-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.live.com IE - HKU\S-1-5-21-1993962763-1645522239-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\S-1-5-21-1993962763-1645522239-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: jqs%40sun.com:1.0 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WIN\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WIN\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WIN\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011.06.20 16:56:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Programme\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011.06.20 16:57:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.09 12:47:20 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.03.09 12:45:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.12\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2011.08.31 08:58:28 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.12\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2010.01.27 12:27:27 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Mozilla\Extensions [2010.01.27 12:27:27 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.10.29 17:01:35 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Mozilla\Firefox\Profiles\nnaqmudx.default\extensions [2010.06.16 14:13:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Mozilla\Firefox\Profiles\nnaqmudx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013.03.09 12:45:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.03.09 12:45:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\reporter@mozilla.org [2010.03.31 20:16:31 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2013.03.09 12:47:19 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll [2006.10.03 05:59:57 | 000,040,552 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\mozilla firefox\plugins\NPAdbESD.dll [2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll [2013.01.17 02:11:04 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.01.17 02:11:04 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2013.01.17 02:11:04 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2013.01.17 02:11:04 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2013.01.17 02:11:04 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2013.01.17 02:11:04 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml Hosts file not found O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe (Acronis) O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Alcmtr] C:\WIN\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [muBlinder] C:\Dokumente und Einstellungen\silke\Desktop\muBlinder.exe (KRX) O4 - HKLM..\Run: [smapp] File not found O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" File not found O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O4 - HKU\S-1-5-21-1993962763-1645522239-725345543-1005..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-1993962763-1645522239-725345543-1005..\Run: [HP Officejet Pro 8500 A910 (NET)] C:\Programme\HP\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\ATI CATALYST System Tray.lnk = C:\Programme\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1993962763-1645522239-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_20.dll (Sun Microsystems, Inc.) O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263989268578 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E237ECC0-F671-4385-96BA-58FDE9FDA6A8}: NameServer = 141.1.1.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIN\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WIN\system32\userinit.exe) - C:\WIN\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WIN\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O30 - LSA: Authentication Packages - (relog_ap) - C:\WIN\System32\relog_ap.dll (Acronis) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004.05.26 13:17:02 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2013.04.15 20:27:12 | 000,000,016 | -H-- | M] () - E:\AUTORUN.INF -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.04.23 14:50:12 | 002,239,840 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\silke\Desktop\tds.exe [2013.04.23 14:46:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\silke\Desktop\OTL.exe [2013.04.19 14:01:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\Malwarebytes [2013.04.16 17:18:37 | 000,000,000 | ---D | C] -- C:\werkzeuge [2013.03.31 18:47:08 | 000,000,000 | ---D | C] -- C:\WIN\System32\Adobe [2013.03.31 11:12:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Rovio [2013.03.31 11:10:39 | 000,000,000 | ---D | C] -- C:\Programme\Rovio [2013.03.31 11:10:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WIN\Startmenü\Programme\Rovio [2013.03.25 16:35:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\UltraVNC [2013.03.25 11:18:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users.WIN\Startmenü\Programme\TeamViewer 8 [2013.03.25 11:17:42 | 000,000,000 | ---D | C] -- C:\Programme\TeamViewer [2010.06.16 14:19:44 | 000,047,360 | ---- | C] (VSO Software) -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\pcouffin.sys [4 C:\WIN\*.tmp files -> C:\WIN\*.tmp -> ] [2 C:\WIN\System32\*.tmp files -> C:\WIN\System32\*.tmp -> ] [2 C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.04.23 14:43:56 | 000,000,295 | -HS- | M] () -- C:\boot.ini [2013.04.23 14:41:55 | 000,001,643 | ---- | M] () -- C:\Dokumente und Einstellungen\silke\Startmenü\Programme\Autostart\Tintenwarnungen überwachen - HP Officejet Pro 8500 A910 (Netzwerk).lnk [2013.04.23 14:41:44 | 000,192,512 | ---- | M] (ICSharpCode.net) -- C:\Dokumente und Einstellungen\silke\Desktop\ICSharpCode.SharpZipLib.dll [2013.04.23 14:39:19 | 000,002,206 | ---- | M] () -- C:\WIN\System32\wpa.dbl [2013.04.23 14:39:17 | 000,002,048 | --S- | M] () -- C:\WIN\bootstat.dat [2013.04.19 14:01:34 | 000,035,144 | ---- | M] () -- C:\WIN\System32\drivers\mbamchameleon.sys [2013.04.16 16:34:00 | 000,377,856 | ---- | M] () -- C:\Dokumente und Einstellungen\silke\Desktop\gmer_2.1.19163.exe [2013.04.16 13:40:25 | 000,452,300 | ---- | M] () -- C:\WIN\System32\perfh007.dat [2013.04.16 13:40:25 | 000,435,396 | ---- | M] () -- C:\WIN\System32\perfh009.dat [2013.04.16 13:40:25 | 000,081,126 | ---- | M] () -- C:\WIN\System32\perfc007.dat [2013.04.16 13:40:25 | 000,068,292 | ---- | M] () -- C:\WIN\System32\perfc009.dat [2013.04.11 16:00:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\silke\Desktop\OTL.exe [2013.04.11 15:21:56 | 002,239,840 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\silke\Desktop\tds.exe [2013.04.04 14:23:24 | 001,114,112 | ---- | M] () -- C:\rechnung2000.mdb [2013.03.31 11:12:19 | 000,000,924 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\Angry Birds Star Wars.lnk [2013.03.25 15:26:21 | 000,002,235 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\Skype.lnk [2013.03.25 11:31:17 | 000,120,544 | ---- | M] () -- C:\WIN\System32\FNTCACHE.DAT [2013.03.25 11:21:10 | 000,002,012 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\HP Officejet Pro 8500 A910.lnk [2013.03.25 11:21:10 | 000,000,947 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\Shop für Zubehör - HP Officejet Pro 8500 A910.lnk [2013.03.25 11:18:05 | 000,000,842 | ---- | M] () -- C:\Dokumente und Einstellungen\silke\Desktop\TeamViewer 8.lnk [2013.03.25 11:18:05 | 000,000,830 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\TeamViewer 8.lnk [2013.03.25 11:16:47 | 000,000,057 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\Ament.ini [4 C:\WIN\*.tmp files -> C:\WIN\*.tmp -> ] [2 C:\WIN\System32\*.tmp files -> C:\WIN\System32\*.tmp -> ] [2 C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.04.23 14:46:43 | 000,377,856 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Desktop\gmer_2.1.19163.exe [2013.04.19 14:01:34 | 000,035,144 | ---- | C] () -- C:\WIN\System32\drivers\mbamchameleon.sys [2013.03.31 11:12:19 | 000,000,924 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\Angry Birds Star Wars.lnk [2013.03.25 11:24:12 | 000,001,643 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Startmenü\Programme\Autostart\Tintenwarnungen überwachen - HP Officejet Pro 8500 A910 (Netzwerk).lnk [2013.03.25 11:21:10 | 000,002,012 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\HP Officejet Pro 8500 A910.lnk [2013.03.25 11:21:10 | 000,000,947 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\Shop für Zubehör - HP Officejet Pro 8500 A910.lnk [2013.03.25 11:18:05 | 000,000,842 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Desktop\TeamViewer 8.lnk [2013.03.25 11:18:05 | 000,000,830 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WIN\Desktop\TeamViewer 8.lnk [2013.03.25 11:16:47 | 000,000,057 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\Ament.ini [2010.06.16 14:19:44 | 000,087,608 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\inst.exe [2010.06.16 14:19:44 | 000,007,887 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\pcouffin.cat [2010.06.16 14:19:44 | 000,001,144 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\pcouffin.inf [2008.01.12 21:46:17 | 000,012,800 | ---- | C] () -- C:\Dokumente und Einstellungen\silke\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2004.05.26 13:16:29 | 000,022,080 | -H-- | C] () -- C:\Programme\folder.htt ========== ZeroAccess Check ========== [2008.10.24 12:05:10 | 000,000,227 | RHS- | M] () -- C:\WIN\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2010.09.09 16:17:08 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WIN\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WIN\system32\wbem\wbemess.dll -- [2008.04.14 08:52:34 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2006.11.18 09:44:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\AVG7 [2005.10.15 12:23:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\.ABC [2005.06.20 18:22:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\.ABC 3.01 [2004.11.17 14:05:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\Acronis [2004.11.21 11:30:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\Azureus [2005.11.03 14:18:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\FlashFXP [2005.06.21 10:37:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\GlobalSCAPE [2004.06.04 12:57:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\IsolatedStorage [2004.10.14 11:54:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\klickTel [2005.08.30 13:48:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\NASA [2005.03.15 15:07:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\PixelPlanet [2004.10.06 14:02:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\Research In Motion [2004.06.29 08:30:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\Teledat USB 2 ab [2005.06.14 11:33:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\Ulead Systems [2006.01.03 18:36:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.bak\Anwendungsdaten\uTorrent [2006.11.24 11:29:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avg7 [2006.09.17 20:44:29 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ [2004.06.04 12:54:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PowerQuest [2005.06.14 11:27:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ulead Systems [2008.02.13 15:04:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\Acronis [2007.12.04 15:00:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users.WIN\Anwendungsdaten\Motora [2008.04.05 10:56:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Acronis [2008.11.27 09:55:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\JAM Software [2013.03.31 11:12:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Rovio [2010.01.27 12:27:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Thunderbird [2010.06.16 14:19:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\silke\Anwendungsdaten\Vso [2006.04.04 12:36:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Ingrid\Anwendungsdaten\.bittorrent [2006.02.14 12:25:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Ingrid\Anwendungsdaten\klickTel [2006.04.20 12:54:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Ingrid\Anwendungsdaten\Ulead Systems [2007.05.30 10:41:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Ingrid\Anwendungsdaten\uTorrent [2008.02.13 15:07:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Acronis ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Dokumente und Einstellungen\silke\Desktop\Spesen.pif:SummaryInformation < End of report > [/CODE] |
23.04.2013, 16:25 | #8 | |||
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Hallo, Zitat:
Zitat:
Einfach wie immer beim Backup darauf achten, dass wirklich nur gezielt persönliche Dateien (wie Bilder, Musik, Worddateien, Emails, Favoriten, ..) und keine Programme oder sonstigen ausführebaren Dateien gesichert werden. Diese kann man alle neu installieren bzw. neu aus dem Internet herunterladen. Wenn man das nicht im laufenden Windows machen will, geht es auch in einer Linux-Umgebung: http://www.trojaner-board.de/82533-d...ted-magic.html Zitat:
__________________ cheers, Leo |
23.04.2013, 16:33 | #9 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Können wir gemeinsam einen Versuch wagen, es sauber zu kriegen? Ich hätte jetzt Zeit und bin auch leider in der misslichen Lage, keine Windows CD zu besitzen. Gerne zeige ich mich erkenntlich und überweis euch etwas Geld. Danke im Voraus ! |
23.04.2013, 16:48 | #10 |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Ja klar, dann schauen wir als erstes mal, wie das Gmer-Log nach Deaktivierung des Emulator-Treibers aussieht... Schritt 1 Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
Schritt 2 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 3 Downloade dir bitte aswMBR.exe und speichere die Datei auf deinen Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung. Hinweis: Sollte der Scan Button ausgeblendet sein, schliesse das Tool und starte es erneut. Sollte es erneut nicht klappen, teile mir das bitte mit. Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
23.04.2013, 17:08 | #11 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? OK mach ich sofort, Danke ! Weisst Du zufaellig wo ich die avast files hinkopieren muss die aswmbr zieht, weil ich möchte den PC nur sehr ungerne ans Netz packen und die aktuellen avast files hätte ich hier auf meinem PC. |
23.04.2013, 17:11 | #12 |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Das kann ich dir jetzt grad so im Moment nicht sagen, nein. Es sollte aber kein Problem sein, den Rechner für diesen Scan ins Netz zu hängen. Aber wenn du das noch nicht möchtest, dann mach einfach den aswmbr-Scan ohne die avast-Definitionen.
__________________ cheers, Leo |
23.04.2013, 20:15 | #13 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Hi, der scannt sich zu Tode im GMER ;(( Soll ich abbrechen, er ist wirklich gescheid lahm. Aber es geht wohl (noch) vorwärts .... Danke nochmal für Deine Hilfe. GMER Logfile: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-04-23 23:58:58 Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-10 WDC_WD1600JD-00GBB0 rev.02.05D02 149,05GB Running: gmer_2.1.19163.exe; Driver: C:\DOKUME~1\silke\LOKALE~1\Temp\fgldqpow.sys ---- System - GMER 2.1 ---- SSDT AC21864C ZwCreateThread SSDT AC218638 ZwOpenProcess SSDT AC21863D ZwOpenThread ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0xAB 0x84 0x3D ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8E 0x0D 0xF2 0x6E ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF5 0x0A 0xFB 0x13 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x82 0xB2 0xB1 0x13 ... ---- EOF - GMER 2.1 ---- aswmbr hat nichts angezeigt, habs aber leider nicht kopiert. soll ichs noch besorgen oder ist ok so? lg |
24.04.2013, 01:32 | #14 | |
/// TB-Ausbilder | PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Hallo, das ist ok so. Startet und läuft der Rechner im Moment besonders langsam..? (Für den Schritt 2 muss der Rechner Internetzugriff haben.) Schritt 1 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 2 Warnung für Mitleser: Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix.
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
Schritt 3
Code:
ATTFilter reg query "HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0" /c reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}" /s /c
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.04.2013, 05:40 | #15 |
| PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? Es ist was schlimmes passiert! Ich habe wohl meinen PC irgendwie ebenfalls verseucht. Kann es der USB Stick gewesen sein, der eig. mit Panda Vacc immunisiert war? Nun hab ich Angst, da auf dem PC meine Uni-Sachen drauf sind und ... Oh mein Gott. Ich habe daher auch mal von meinem Desktop Sys ein Aswmbr und ein GMemer gemacht und Deine Schritte 1:1 übernommen. Hoffe das war OK so. Tut mir leid dass das so chaotisch verläuft, aber DAS war wirklich nicht beabsichtigt. Ohne meinen Desktop PC habe ich kein Netz, evtl. sollten wir kurz die Priorität dynamisch anpassen zu meinen Gunsten, Danke im Voraus. Code:
ATTFilter ComboFix 13-04-24.01 - Jochen 24.04.2013 6:52.3.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1033.18.8191.6765 [GMT 2:00] ausgeführt von:: G:\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\PolicyDefinitions c:\windows\PolicyDefinitions\ActiveXInstallService.admx c:\windows\PolicyDefinitions\AddRemovePrograms.admx c:\windows\PolicyDefinitions\AppCompat.admx c:\windows\PolicyDefinitions\AttachmentManager.admx c:\windows\PolicyDefinitions\AutoPlay.admx c:\windows\PolicyDefinitions\Biometrics.admx c:\windows\PolicyDefinitions\Bits.admx c:\windows\PolicyDefinitions\CEIPEnable.admx c:\windows\PolicyDefinitions\CipherSuiteOrder.admx c:\windows\PolicyDefinitions\COM.admx c:\windows\PolicyDefinitions\Conf.admx c:\windows\PolicyDefinitions\ControlPanel.admx c:\windows\PolicyDefinitions\ControlPanelDisplay.admx c:\windows\PolicyDefinitions\Cpls.admx c:\windows\PolicyDefinitions\CredentialProviders.admx c:\windows\PolicyDefinitions\CredSsp.admx c:\windows\PolicyDefinitions\CredUI.admx c:\windows\PolicyDefinitions\CtrlAltDel.admx c:\windows\PolicyDefinitions\DCOM.admx c:\windows\PolicyDefinitions\de-DE\ActiveXInstallService.adml c:\windows\PolicyDefinitions\de-DE\AddRemovePrograms.adml c:\windows\PolicyDefinitions\de-DE\AppCompat.adml c:\windows\PolicyDefinitions\de-DE\AttachmentManager.adml c:\windows\PolicyDefinitions\de-DE\AutoPlay.adml c:\windows\PolicyDefinitions\de-DE\Biometrics.adml c:\windows\PolicyDefinitions\de-DE\Bits.adml c:\windows\PolicyDefinitions\de-DE\CEIPEnable.adml c:\windows\PolicyDefinitions\de-DE\CipherSuiteOrder.adml c:\windows\PolicyDefinitions\de-DE\COM.adml c:\windows\PolicyDefinitions\de-DE\Conf.adml c:\windows\PolicyDefinitions\de-DE\ControlPanel.adml c:\windows\PolicyDefinitions\de-DE\ControlPanelDisplay.adml c:\windows\PolicyDefinitions\de-DE\Cpls.adml c:\windows\PolicyDefinitions\de-DE\CredentialProviders.adml c:\windows\PolicyDefinitions\de-DE\CredSsp.adml c:\windows\PolicyDefinitions\de-DE\CredUI.adml c:\windows\PolicyDefinitions\de-DE\CtrlAltDel.adml c:\windows\PolicyDefinitions\de-DE\DCOM.adml c:\windows\PolicyDefinitions\de-DE\Desktop.adml c:\windows\PolicyDefinitions\de-DE\DeviceInstallation.adml c:\windows\PolicyDefinitions\de-DE\DeviceRedirection.adml c:\windows\PolicyDefinitions\de-DE\DFS.adml c:\windows\PolicyDefinitions\de-DE\DigitalLocker.adml c:\windows\PolicyDefinitions\de-DE\DiskDiagnostic.adml c:\windows\PolicyDefinitions\de-DE\DiskNVCache.adml c:\windows\PolicyDefinitions\de-DE\DiskQuota.adml c:\windows\PolicyDefinitions\de-DE\DistributedLinkTracking.adml c:\windows\PolicyDefinitions\de-DE\DnsClient.adml c:\windows\PolicyDefinitions\de-DE\DWM.adml c:\windows\PolicyDefinitions\de-DE\EncryptFilesonMove.adml c:\windows\PolicyDefinitions\de-DE\EnhancedStorage.adml c:\windows\PolicyDefinitions\de-DE\ErrorReporting.adml c:\windows\PolicyDefinitions\de-DE\EventForwarding.adml c:\windows\PolicyDefinitions\de-DE\EventLog.adml c:\windows\PolicyDefinitions\de-DE\EventViewer.adml c:\windows\PolicyDefinitions\de-DE\Explorer.adml c:\windows\PolicyDefinitions\de-DE\FileRecovery.adml c:\windows\PolicyDefinitions\de-DE\FileSys.adml c:\windows\PolicyDefinitions\de-DE\FolderRedirection.adml c:\windows\PolicyDefinitions\de-DE\FramePanes.adml c:\windows\PolicyDefinitions\de-DE\fthsvc.adml c:\windows\PolicyDefinitions\de-DE\GameExplorer.adml c:\windows\PolicyDefinitions\de-DE\Globalization.adml c:\windows\PolicyDefinitions\de-DE\GroupPolicy.adml c:\windows\PolicyDefinitions\de-DE\Help.adml c:\windows\PolicyDefinitions\de-DE\HelpAndSupport.adml c:\windows\PolicyDefinitions\de-DE\HotStart.adml c:\windows\PolicyDefinitions\de-DE\ICM.adml c:\windows\PolicyDefinitions\de-DE\IIS.adml c:\windows\PolicyDefinitions\de-DE\InetRes.adml c:\windows\PolicyDefinitions\de-DE\InkWatson.adml c:\windows\PolicyDefinitions\de-DE\InputPersonalization.adml c:\windows\PolicyDefinitions\de-DE\iSCSI.adml c:\windows\PolicyDefinitions\de-DE\Kerberos.adml c:\windows\PolicyDefinitions\de-DE\LanmanServer.adml c:\windows\PolicyDefinitions\de-DE\LeakDiagnostic.adml c:\windows\PolicyDefinitions\de-DE\LinkLayerTopologyDiscovery.adml c:\windows\PolicyDefinitions\de-DE\Logon.adml c:\windows\PolicyDefinitions\de-DE\MediaCenter.adml c:\windows\PolicyDefinitions\de-DE\MMC.adml c:\windows\PolicyDefinitions\de-DE\MMCSnapins.adml c:\windows\PolicyDefinitions\de-DE\MobilePCMobilityCenter.adml c:\windows\PolicyDefinitions\de-DE\MobilePCPresentationSettings.adml c:\windows\PolicyDefinitions\de-DE\MSDT.adml c:\windows\PolicyDefinitions\de-DE\Msi-FileRecovery.adml c:\windows\PolicyDefinitions\de-DE\MSI.adml c:\windows\PolicyDefinitions\de-DE\NCSI.adml c:\windows\PolicyDefinitions\de-DE\Netlogon.adml c:\windows\PolicyDefinitions\de-DE\NetworkConnections.adml c:\windows\PolicyDefinitions\de-DE\NetworkProjection.adml c:\windows\PolicyDefinitions\de-DE\OfflineFiles.adml c:\windows\PolicyDefinitions\de-DE\P2P-pnrp.adml c:\windows\PolicyDefinitions\de-DE\ParentalControls.adml c:\windows\PolicyDefinitions\de-DE\pca.adml c:\windows\PolicyDefinitions\de-DE\PeerToPeerCaching.adml c:\windows\PolicyDefinitions\de-DE\PenTraining.adml c:\windows\PolicyDefinitions\de-DE\PerfCenterCPL.adml c:\windows\PolicyDefinitions\de-DE\PerformanceDiagnostics.adml c:\windows\PolicyDefinitions\de-DE\PerformancePerftrack.adml c:\windows\PolicyDefinitions\de-DE\Power.adml c:\windows\PolicyDefinitions\de-DE\PreviousVersions.adml c:\windows\PolicyDefinitions\de-DE\Printing.adml c:\windows\PolicyDefinitions\de-DE\Programs.adml c:\windows\PolicyDefinitions\de-DE\QOS.adml c:\windows\PolicyDefinitions\de-DE\RacWmiProv.adml c:\windows\PolicyDefinitions\de-DE\Radar.adml c:\windows\PolicyDefinitions\de-DE\ReAgent.adml c:\windows\PolicyDefinitions\de-DE\Reliability.adml c:\windows\PolicyDefinitions\de-DE\RemoteAssistance.adml c:\windows\PolicyDefinitions\de-DE\RemovableStorage.adml c:\windows\PolicyDefinitions\de-DE\RPC.adml c:\windows\PolicyDefinitions\de-DE\Scripts.adml c:\windows\PolicyDefinitions\de-DE\sdiageng.adml c:\windows\PolicyDefinitions\de-DE\sdiagschd.adml c:\windows\PolicyDefinitions\de-DE\Search.adml c:\windows\PolicyDefinitions\de-DE\Securitycenter.adml c:\windows\PolicyDefinitions\de-DE\Sensors.adml c:\windows\PolicyDefinitions\de-DE\Setup.adml c:\windows\PolicyDefinitions\de-DE\ShapeCollector.adml c:\windows\PolicyDefinitions\de-DE\SharedFolders.adml c:\windows\PolicyDefinitions\de-DE\Sharing.adml c:\windows\PolicyDefinitions\de-DE\Shell-CommandPrompt-RegEditTools.adml c:\windows\PolicyDefinitions\de-DE\ShellWelcomeCenter.adml c:\windows\PolicyDefinitions\de-DE\Sidebar.adml c:\windows\PolicyDefinitions\de-DE\Sideshow.adml c:\windows\PolicyDefinitions\de-DE\Smartcard.adml c:\windows\PolicyDefinitions\de-DE\Snmp.adml c:\windows\PolicyDefinitions\de-DE\SoundRec.adml c:\windows\PolicyDefinitions\de-DE\StartMenu.adml c:\windows\PolicyDefinitions\de-DE\SystemResourceManager.adml c:\windows\PolicyDefinitions\de-DE\SystemRestore.adml c:\windows\PolicyDefinitions\de-DE\TabletPCInputPanel.adml c:\windows\PolicyDefinitions\de-DE\TabletShell.adml c:\windows\PolicyDefinitions\de-DE\Taskbar.adml c:\windows\PolicyDefinitions\de-DE\TaskScheduler.adml c:\windows\PolicyDefinitions\de-DE\tcpip.adml c:\windows\PolicyDefinitions\de-DE\TerminalServer.adml c:\windows\PolicyDefinitions\de-DE\Thumbnails.adml c:\windows\PolicyDefinitions\de-DE\TouchInput.adml c:\windows\PolicyDefinitions\de-DE\TPM.adml c:\windows\PolicyDefinitions\de-DE\UserDataBackup.adml c:\windows\PolicyDefinitions\de-DE\UserProfiles.adml c:\windows\PolicyDefinitions\de-DE\VolumeEncryption.adml c:\windows\PolicyDefinitions\de-DE\W32Time.adml c:\windows\PolicyDefinitions\de-DE\WDI.adml c:\windows\PolicyDefinitions\de-DE\WinCal.adml c:\windows\PolicyDefinitions\de-DE\Windows.adml c:\windows\PolicyDefinitions\de-DE\WindowsAnytimeUpgrade.adml c:\windows\PolicyDefinitions\de-DE\WindowsBackup.adml c:\windows\PolicyDefinitions\de-DE\WindowsColorSystem.adml c:\windows\PolicyDefinitions\de-DE\WindowsConnectNow.adml c:\windows\PolicyDefinitions\de-DE\WindowsDefender.adml c:\windows\PolicyDefinitions\de-DE\WindowsExplorer.adml c:\windows\PolicyDefinitions\de-DE\WindowsFileProtection.adml c:\windows\PolicyDefinitions\de-DE\WindowsFirewall.adml c:\windows\PolicyDefinitions\de-DE\WindowsMail.adml c:\windows\PolicyDefinitions\de-DE\WindowsMediaDRM.adml c:\windows\PolicyDefinitions\de-DE\WindowsMediaPlayer.adml c:\windows\PolicyDefinitions\de-DE\WindowsMessenger.adml c:\windows\PolicyDefinitions\de-DE\WindowsProducts.adml c:\windows\PolicyDefinitions\de-DE\WindowsRemoteManagement.adml c:\windows\PolicyDefinitions\de-DE\WindowsRemoteShell.adml c:\windows\PolicyDefinitions\de-DE\WindowsUpdate.adml c:\windows\PolicyDefinitions\de-DE\WinInit.adml c:\windows\PolicyDefinitions\de-DE\WinLogon.adml c:\windows\PolicyDefinitions\de-DE\Winsrv.adml c:\windows\PolicyDefinitions\de-DE\WordWheel.adml c:\windows\PolicyDefinitions\Desktop.admx c:\windows\PolicyDefinitions\DeviceInstallation.admx c:\windows\PolicyDefinitions\DeviceRedirection.admx c:\windows\PolicyDefinitions\DFS.admx c:\windows\PolicyDefinitions\DigitalLocker.admx c:\windows\PolicyDefinitions\DiskDiagnostic.admx c:\windows\PolicyDefinitions\DiskNVCache.admx c:\windows\PolicyDefinitions\DiskQuota.admx c:\windows\PolicyDefinitions\DistributedLinkTracking.admx c:\windows\PolicyDefinitions\DnsClient.admx c:\windows\PolicyDefinitions\DWM.admx c:\windows\PolicyDefinitions\en-US\ActiveXInstallService.adml c:\windows\PolicyDefinitions\en-US\AddRemovePrograms.adml c:\windows\PolicyDefinitions\en-US\AppCompat.adml c:\windows\PolicyDefinitions\en-US\AttachmentManager.adml c:\windows\PolicyDefinitions\en-US\AutoPlay.adml c:\windows\PolicyDefinitions\en-US\Biometrics.adml c:\windows\PolicyDefinitions\en-US\Bits.adml c:\windows\PolicyDefinitions\en-US\CEIPEnable.adml c:\windows\PolicyDefinitions\en-US\CipherSuiteOrder.adml c:\windows\PolicyDefinitions\en-US\COM.adml c:\windows\PolicyDefinitions\en-US\Conf.adml c:\windows\PolicyDefinitions\en-US\ControlPanel.adml c:\windows\PolicyDefinitions\en-US\ControlPanelDisplay.adml c:\windows\PolicyDefinitions\en-US\Cpls.adml c:\windows\PolicyDefinitions\en-US\CredentialProviders.adml c:\windows\PolicyDefinitions\en-US\CredSsp.adml c:\windows\PolicyDefinitions\en-US\CredUI.adml c:\windows\PolicyDefinitions\en-US\CtrlAltDel.adml c:\windows\PolicyDefinitions\en-US\DCOM.adml c:\windows\PolicyDefinitions\en-US\Desktop.adml c:\windows\PolicyDefinitions\en-US\DeviceInstallation.adml c:\windows\PolicyDefinitions\en-US\DeviceRedirection.adml c:\windows\PolicyDefinitions\en-US\DFS.adml c:\windows\PolicyDefinitions\en-US\DigitalLocker.adml c:\windows\PolicyDefinitions\en-US\DiskDiagnostic.adml c:\windows\PolicyDefinitions\en-US\DiskNVCache.adml c:\windows\PolicyDefinitions\en-US\DiskQuota.adml c:\windows\PolicyDefinitions\en-US\DistributedLinkTracking.adml c:\windows\PolicyDefinitions\en-US\DnsClient.adml c:\windows\PolicyDefinitions\en-US\DWM.adml c:\windows\PolicyDefinitions\en-US\EncryptFilesonMove.adml c:\windows\PolicyDefinitions\en-US\EnhancedStorage.adml c:\windows\PolicyDefinitions\en-US\ErrorReporting.adml c:\windows\PolicyDefinitions\en-US\EventForwarding.adml c:\windows\PolicyDefinitions\en-US\EventLog.adml c:\windows\PolicyDefinitions\en-US\EventViewer.adml c:\windows\PolicyDefinitions\en-US\Explorer.adml c:\windows\PolicyDefinitions\en-US\FileRecovery.adml c:\windows\PolicyDefinitions\en-US\FileSys.adml c:\windows\PolicyDefinitions\en-US\FolderRedirection.adml c:\windows\PolicyDefinitions\en-US\FramePanes.adml c:\windows\PolicyDefinitions\en-US\fthsvc.adml c:\windows\PolicyDefinitions\en-US\GameExplorer.adml c:\windows\PolicyDefinitions\en-US\Globalization.adml c:\windows\PolicyDefinitions\en-US\GroupPolicy.adml c:\windows\PolicyDefinitions\en-US\Help.adml c:\windows\PolicyDefinitions\en-US\HelpAndSupport.adml c:\windows\PolicyDefinitions\en-US\HotStart.adml c:\windows\PolicyDefinitions\en-US\ICM.adml c:\windows\PolicyDefinitions\en-US\IIS.adml c:\windows\PolicyDefinitions\en-US\InetRes.adml c:\windows\PolicyDefinitions\en-US\InkWatson.adml c:\windows\PolicyDefinitions\en-US\InputPersonalization.adml c:\windows\PolicyDefinitions\en-US\iSCSI.adml c:\windows\PolicyDefinitions\en-US\Kerberos.adml c:\windows\PolicyDefinitions\en-US\LanmanServer.adml c:\windows\PolicyDefinitions\en-US\LeakDiagnostic.adml c:\windows\PolicyDefinitions\en-US\LinkLayerTopologyDiscovery.adml c:\windows\PolicyDefinitions\en-US\Logon.adml c:\windows\PolicyDefinitions\en-US\MediaCenter.adml c:\windows\PolicyDefinitions\en-US\MMC.adml c:\windows\PolicyDefinitions\en-US\MMCSnapins.adml c:\windows\PolicyDefinitions\en-US\MobilePCMobilityCenter.adml c:\windows\PolicyDefinitions\en-US\MobilePCPresentationSettings.adml c:\windows\PolicyDefinitions\en-US\MSDT.adml c:\windows\PolicyDefinitions\en-US\Msi-FileRecovery.adml c:\windows\PolicyDefinitions\en-US\MSI.adml c:\windows\PolicyDefinitions\en-US\NCSI.adml c:\windows\PolicyDefinitions\en-US\Netlogon.adml c:\windows\PolicyDefinitions\en-US\NetworkConnections.adml c:\windows\PolicyDefinitions\en-US\NetworkProjection.adml c:\windows\PolicyDefinitions\en-US\OfflineFiles.adml c:\windows\PolicyDefinitions\en-US\P2P-pnrp.adml c:\windows\PolicyDefinitions\en-US\ParentalControls.adml c:\windows\PolicyDefinitions\en-US\pca.adml c:\windows\PolicyDefinitions\en-US\PeerToPeerCaching.adml c:\windows\PolicyDefinitions\en-US\PenTraining.adml c:\windows\PolicyDefinitions\en-US\PerfCenterCPL.adml c:\windows\PolicyDefinitions\en-US\PerformanceDiagnostics.adml c:\windows\PolicyDefinitions\en-US\PerformancePerftrack.adml c:\windows\PolicyDefinitions\en-US\Power.adml c:\windows\PolicyDefinitions\en-US\PreviousVersions.adml c:\windows\PolicyDefinitions\en-US\Printing.adml c:\windows\PolicyDefinitions\en-US\Programs.adml c:\windows\PolicyDefinitions\en-US\QOS.adml c:\windows\PolicyDefinitions\en-US\RacWmiProv.adml c:\windows\PolicyDefinitions\en-US\Radar.adml c:\windows\PolicyDefinitions\en-US\ReAgent.adml c:\windows\PolicyDefinitions\en-US\Reliability.adml c:\windows\PolicyDefinitions\en-US\RemoteAssistance.adml c:\windows\PolicyDefinitions\en-US\RemovableStorage.adml c:\windows\PolicyDefinitions\en-US\RPC.adml c:\windows\PolicyDefinitions\en-US\Scripts.adml c:\windows\PolicyDefinitions\en-US\sdiageng.adml c:\windows\PolicyDefinitions\en-US\sdiagschd.adml c:\windows\PolicyDefinitions\en-US\Search.adml c:\windows\PolicyDefinitions\en-US\Securitycenter.adml c:\windows\PolicyDefinitions\en-US\Sensors.adml c:\windows\PolicyDefinitions\en-US\Setup.adml c:\windows\PolicyDefinitions\en-US\ShapeCollector.adml c:\windows\PolicyDefinitions\en-US\SharedFolders.adml c:\windows\PolicyDefinitions\en-US\Sharing.adml c:\windows\PolicyDefinitions\en-US\Shell-CommandPrompt-RegEditTools.adml c:\windows\PolicyDefinitions\en-US\ShellWelcomeCenter.adml c:\windows\PolicyDefinitions\en-US\Sidebar.adml c:\windows\PolicyDefinitions\en-US\Sideshow.adml c:\windows\PolicyDefinitions\en-US\Smartcard.adml c:\windows\PolicyDefinitions\en-US\Snmp.adml c:\windows\PolicyDefinitions\en-US\SoundRec.adml c:\windows\PolicyDefinitions\en-US\StartMenu.adml c:\windows\PolicyDefinitions\en-US\SystemResourceManager.adml c:\windows\PolicyDefinitions\en-US\SystemRestore.adml c:\windows\PolicyDefinitions\en-US\TabletPCInputPanel.adml c:\windows\PolicyDefinitions\en-US\TabletShell.adml c:\windows\PolicyDefinitions\en-US\Taskbar.adml c:\windows\PolicyDefinitions\en-US\TaskScheduler.adml c:\windows\PolicyDefinitions\en-US\tcpip.adml c:\windows\PolicyDefinitions\en-US\TerminalServer.adml c:\windows\PolicyDefinitions\en-US\Thumbnails.adml c:\windows\PolicyDefinitions\en-US\TouchInput.adml c:\windows\PolicyDefinitions\en-US\TPM.adml c:\windows\PolicyDefinitions\en-US\UserDataBackup.adml c:\windows\PolicyDefinitions\en-US\UserProfiles.adml c:\windows\PolicyDefinitions\en-US\VolumeEncryption.adml c:\windows\PolicyDefinitions\en-US\W32Time.adml c:\windows\PolicyDefinitions\en-US\WDI.adml c:\windows\PolicyDefinitions\en-US\WinCal.adml c:\windows\PolicyDefinitions\en-US\Windows.adml c:\windows\PolicyDefinitions\en-US\WindowsAnytimeUpgrade.adml c:\windows\PolicyDefinitions\en-US\WindowsBackup.adml c:\windows\PolicyDefinitions\en-US\WindowsColorSystem.adml c:\windows\PolicyDefinitions\en-US\WindowsConnectNow.adml c:\windows\PolicyDefinitions\en-US\WindowsDefender.adml c:\windows\PolicyDefinitions\en-US\WindowsExplorer.adml c:\windows\PolicyDefinitions\en-US\WindowsFileProtection.adml c:\windows\PolicyDefinitions\en-US\WindowsFirewall.adml c:\windows\PolicyDefinitions\en-US\WindowsMail.adml c:\windows\PolicyDefinitions\en-US\WindowsMediaDRM.adml c:\windows\PolicyDefinitions\en-US\WindowsMediaPlayer.adml c:\windows\PolicyDefinitions\en-US\WindowsMessenger.adml c:\windows\PolicyDefinitions\en-US\WindowsProducts.adml c:\windows\PolicyDefinitions\en-US\WindowsRemoteManagement.adml c:\windows\PolicyDefinitions\en-US\WindowsRemoteShell.adml c:\windows\PolicyDefinitions\en-US\WindowsUpdate.adml c:\windows\PolicyDefinitions\en-US\WinInit.adml c:\windows\PolicyDefinitions\en-US\WinLogon.adml c:\windows\PolicyDefinitions\en-US\Winsrv.adml c:\windows\PolicyDefinitions\en-US\WordWheel.adml c:\windows\PolicyDefinitions\EncryptFilesonMove.admx c:\windows\PolicyDefinitions\EnhancedStorage.admx c:\windows\PolicyDefinitions\ErrorReporting.admx c:\windows\PolicyDefinitions\EventForwarding.admx c:\windows\PolicyDefinitions\EventLog.admx c:\windows\PolicyDefinitions\EventViewer.admx c:\windows\PolicyDefinitions\Explorer.admx c:\windows\PolicyDefinitions\FileRecovery.admx c:\windows\PolicyDefinitions\FileSys.admx c:\windows\PolicyDefinitions\FolderRedirection.admx c:\windows\PolicyDefinitions\FramePanes.admx c:\windows\PolicyDefinitions\fthsvc.admx c:\windows\PolicyDefinitions\GameExplorer.admx c:\windows\PolicyDefinitions\Globalization.admx c:\windows\PolicyDefinitions\GroupPolicy.admx c:\windows\PolicyDefinitions\Help.admx c:\windows\PolicyDefinitions\HelpAndSupport.admx c:\windows\PolicyDefinitions\HotStart.admx c:\windows\PolicyDefinitions\ICM.admx c:\windows\PolicyDefinitions\IIS.admx c:\windows\PolicyDefinitions\inetres.admx c:\windows\PolicyDefinitions\InkWatson.admx c:\windows\PolicyDefinitions\InputPersonalization.admx c:\windows\PolicyDefinitions\iSCSI.admx c:\windows\PolicyDefinitions\Kerberos.admx c:\windows\PolicyDefinitions\LanmanServer.admx c:\windows\PolicyDefinitions\LeakDiagnostic.admx c:\windows\PolicyDefinitions\LinkLayerTopologyDiscovery.admx c:\windows\PolicyDefinitions\Logon.admx c:\windows\PolicyDefinitions\MediaCenter.admx c:\windows\PolicyDefinitions\MMC.admx c:\windows\PolicyDefinitions\MMCSnapins.admx c:\windows\PolicyDefinitions\MobilePCMobilityCenter.admx c:\windows\PolicyDefinitions\MobilePCPresentationSettings.admx c:\windows\PolicyDefinitions\MSDT.admx c:\windows\PolicyDefinitions\Msi-FileRecovery.admx c:\windows\PolicyDefinitions\MSI.admx c:\windows\PolicyDefinitions\NCSI.admx c:\windows\PolicyDefinitions\Netlogon.admx c:\windows\PolicyDefinitions\NetworkConnections.admx c:\windows\PolicyDefinitions\NetworkProjection.admx c:\windows\PolicyDefinitions\OfflineFiles.admx c:\windows\PolicyDefinitions\P2P-pnrp.admx c:\windows\PolicyDefinitions\ParentalControls.admx c:\windows\PolicyDefinitions\pca.admx c:\windows\PolicyDefinitions\PeerToPeerCaching.admx c:\windows\PolicyDefinitions\PenTraining.admx c:\windows\PolicyDefinitions\PerfCenterCPL.admx c:\windows\PolicyDefinitions\PerformanceDiagnostics.admx c:\windows\PolicyDefinitions\PerformancePerftrack.admx c:\windows\PolicyDefinitions\Power.admx c:\windows\PolicyDefinitions\PreviousVersions.admx c:\windows\PolicyDefinitions\Printing.admx c:\windows\PolicyDefinitions\Programs.admx c:\windows\PolicyDefinitions\QOS.admx c:\windows\PolicyDefinitions\RacWmiProv.admx c:\windows\PolicyDefinitions\Radar.admx c:\windows\PolicyDefinitions\ReAgent.admx c:\windows\PolicyDefinitions\Reliability.admx c:\windows\PolicyDefinitions\RemoteAssistance.admx c:\windows\PolicyDefinitions\RemovableStorage.admx c:\windows\PolicyDefinitions\RPC.admx c:\windows\PolicyDefinitions\Scripts.admx c:\windows\PolicyDefinitions\sdiageng.admx c:\windows\PolicyDefinitions\sdiagschd.admx c:\windows\PolicyDefinitions\Search.admx c:\windows\PolicyDefinitions\Securitycenter.admx c:\windows\PolicyDefinitions\Sensors.admx c:\windows\PolicyDefinitions\Setup.admx c:\windows\PolicyDefinitions\ShapeCollector.admx c:\windows\PolicyDefinitions\SharedFolders.admx c:\windows\PolicyDefinitions\Sharing.admx c:\windows\PolicyDefinitions\Shell-CommandPrompt-RegEditTools.admx c:\windows\PolicyDefinitions\ShellWelcomeCenter.admx c:\windows\PolicyDefinitions\Sidebar.admx c:\windows\PolicyDefinitions\Sideshow.admx c:\windows\PolicyDefinitions\Smartcard.admx c:\windows\PolicyDefinitions\Snmp.admx c:\windows\PolicyDefinitions\SoundRec.admx c:\windows\PolicyDefinitions\StartMenu.admx c:\windows\PolicyDefinitions\SystemResourceManager.admx c:\windows\PolicyDefinitions\SystemRestore.admx c:\windows\PolicyDefinitions\TabletPCInputPanel.admx c:\windows\PolicyDefinitions\TabletShell.admx c:\windows\PolicyDefinitions\Taskbar.admx c:\windows\PolicyDefinitions\TaskScheduler.admx c:\windows\PolicyDefinitions\tcpip.admx c:\windows\PolicyDefinitions\TerminalServer.admx c:\windows\PolicyDefinitions\Thumbnails.admx c:\windows\PolicyDefinitions\TouchInput.admx c:\windows\PolicyDefinitions\TPM.admx c:\windows\PolicyDefinitions\UserDataBackup.admx c:\windows\PolicyDefinitions\UserProfiles.admx c:\windows\PolicyDefinitions\VolumeEncryption.admx c:\windows\PolicyDefinitions\W32Time.admx c:\windows\PolicyDefinitions\WDI.admx c:\windows\PolicyDefinitions\WinCal.admx c:\windows\PolicyDefinitions\Windows.admx c:\windows\PolicyDefinitions\WindowsAnytimeUpgrade.admx c:\windows\PolicyDefinitions\WindowsBackup.admx c:\windows\PolicyDefinitions\WindowsColorSystem.admx c:\windows\PolicyDefinitions\WindowsConnectNow.admx c:\windows\PolicyDefinitions\WindowsDefender.admx c:\windows\PolicyDefinitions\WindowsExplorer.admx c:\windows\PolicyDefinitions\WindowsFileProtection.admx c:\windows\PolicyDefinitions\WindowsFirewall.admx c:\windows\PolicyDefinitions\WindowsMail.admx c:\windows\PolicyDefinitions\WindowsMediaDRM.admx c:\windows\PolicyDefinitions\WindowsMediaPlayer.admx c:\windows\PolicyDefinitions\WindowsMessenger.admx c:\windows\PolicyDefinitions\WindowsProducts.admx c:\windows\PolicyDefinitions\WindowsRemoteManagement.admx c:\windows\PolicyDefinitions\WindowsRemoteShell.admx c:\windows\PolicyDefinitions\WindowsUpdate.admx c:\windows\PolicyDefinitions\WinInit.admx c:\windows\PolicyDefinitions\WinLogon.admx c:\windows\PolicyDefinitions\Winsrv.admx c:\windows\PolicyDefinitions\WordWheel.admx . . ((((((((((((((((((((((( Dateien erstellt von 2013-03-24 bis 2013-04-24 )))))))))))))))))))))))))))))) . . 2013-04-24 04:55 . 2013-04-24 04:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-04-24 03:22 . 2013-04-24 03:22 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A812B06-B0BF-414B-B142-A057EB20A060}\offreg.dll 2013-04-23 21:43 . 2013-04-23 21:43 -------- d-----w- c:\program files\CCleaner 2013-04-23 20:44 . 2013-04-23 21:54 -------- d-----w- c:\users\Jochen\AppData\Roaming\mIRC 2013-04-23 20:44 . 2013-04-23 20:44 -------- d-----w- c:\program files (x86)\mIRC 2013-04-23 20:12 . 2013-04-23 20:12 -------- d-----w- c:\program files (x86)\OWASP 2013-04-23 17:58 . 2013-04-23 18:10 -------- d-----w- c:\program files (x86)\WhatsRunning 2013-04-23 16:11 . 2013-04-23 16:11 -------- d-----w- c:\program files (x86)\ESET 2013-04-23 15:30 . 2013-04-23 15:30 -------- d-----w- c:\windows\CheckSur 2013-04-23 12:22 . 2013-03-07 11:37 19032 ------w- c:\windows\system32\pwdrvio.sys 2013-04-23 12:22 . 2013-03-07 11:37 3074240 ----a-w- c:\windows\system32\pwNative.exe 2013-04-23 12:22 . 2013-03-07 11:37 9584 ------w- c:\windows\system32\pwdspio.sys 2013-04-23 12:22 . 2013-04-23 12:22 -------- d-----w- c:\program files (x86)\MiniTool Partition Wizard Home Edition 7.8 2013-04-23 12:21 . 2013-04-23 12:21 -------- d-----w- c:\users\Jochen\AppData\Local\GHISLER 2013-04-23 12:20 . 2013-04-23 12:20 -------- d-----w- C:\totalcmd 2013-04-23 12:20 . 2013-04-23 12:20 -------- d-----w- c:\users\Jochen\AppData\Roaming\GHISLER 2013-04-23 12:16 . 2013-04-23 12:16 -------- d-----w- c:\programdata\Panda Security 2013-04-23 12:16 . 2013-04-23 12:16 -------- d-----w- c:\program files (x86)\Panda USB Vaccine 2013-04-23 12:03 . 2013-04-23 12:03 -------- d-----w- c:\program files\Sandboxie 2013-04-23 09:37 . 2013-04-23 09:37 -------- d-----w- c:\users\Jochen\AppData\Local\Opera 2013-04-23 09:37 . 2013-04-23 09:37 -------- d-----w- c:\program files (x86)\Opera 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\XPSViewer 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\drivers\UMDF\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\drivers\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\de 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\0407 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\SysWow64\wbem\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\system32\drivers\UMDF\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\system32\drivers\de-DE 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\system32\0407 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\system32\de 2013-04-23 08:53 . 2013-04-23 08:53 -------- d-----w- c:\windows\system32\wbem\de-DE 2013-04-23 08:49 . 2013-04-23 08:49 -------- d-----w- c:\program files (x86)\TeamViewer 2013-04-23 08:49 . 2009-07-13 17:05 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\de-DE\LXKPTPRC.DLL.mui 2013-04-23 08:44 . 2013-04-23 08:44 -------- d-----w- c:\program files (x86)\Marvell 2013-04-23 08:42 . 2009-05-14 07:26 15416 ----a-w- c:\windows\system32\drivers\ASACPI.sys 2013-04-22 23:04 . 2013-04-22 23:04 -------- d-----w- c:\program files (x86)\Microsoft.NET 2013-04-22 22:47 . 2013-04-23 01:51 -------- d-----w- c:\users\Jochen\AppData\Roaming\Trillian 2013-04-22 22:46 . 2013-04-22 22:47 -------- d-----w- c:\program files (x86)\Trillian 2013-04-22 21:54 . 2013-04-22 21:54 -------- d-----w- C:\Meine Backups 2013-04-22 19:07 . 2013-04-22 19:07 367200 ----a-w- c:\windows\system32\drivers\afcdp.sys 2013-04-22 19:07 . 2013-04-22 19:07 1462560 ----a-w- c:\windows\system32\drivers\tdrpman.sys 2013-04-22 19:07 . 2013-04-22 19:07 183224 ----a-w- c:\windows\system32\drivers\tib_mounter.sys 2013-04-22 19:07 . 2013-04-22 19:07 1120032 ----a-w- c:\windows\system32\drivers\tib.sys 2013-04-22 19:07 . 2013-04-22 19:07 161568 ----a-w- c:\windows\system32\drivers\vididr.sys 2013-04-22 19:07 . 2013-04-22 19:07 117024 ----a-w- c:\windows\system32\drivers\vidsflt.sys 2013-04-22 19:07 . 2013-04-22 19:07 233760 ----a-w- c:\windows\system32\drivers\snapman.sys 2013-04-22 19:07 . 2013-04-22 19:07 108832 ----a-w- c:\windows\system32\drivers\fltsrv.sys 2013-04-22 19:06 . 2013-04-22 19:06 -------- d-----w- c:\program files (x86)\Acronis 2013-04-22 18:49 . 2013-04-23 18:46 -------- d-----w- c:\users\UpdatusUser 2013-04-22 18:49 . 2013-04-22 18:49 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2013-04-22 18:48 . 2013-01-18 15:00 6390048 ----a-w- c:\windows\system32\nvcpl.dll 2013-04-22 18:48 . 2013-01-18 15:00 3460896 ----a-w- c:\windows\system32\nvsvc64.dll 2013-04-22 18:48 . 2013-01-18 15:00 884512 ----a-w- c:\windows\system32\nvvsvc.exe 2013-04-22 18:48 . 2013-01-18 15:00 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-04-22 18:48 . 2013-01-18 15:00 2558240 ----a-w- c:\windows\system32\nvsvcr.dll 2013-04-22 18:48 . 2013-01-18 15:00 118560 ----a-w- c:\windows\system32\nvmctray.dll 2013-04-22 18:48 . 2013-02-25 22:32 61216 ----a-w- c:\windows\system32\OpenCL.dll 2013-04-22 18:48 . 2013-02-25 22:32 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-04-22 18:48 . 2013-04-22 18:49 -------- d-----w- c:\program files\NVIDIA Corporation 2013-04-22 18:05 . 2013-04-22 19:06 -------- d-----w- c:\program files (x86)\Common Files\Acronis 2013-04-22 18:04 . 2013-04-01 17:58 72702784 ----a-w- c:\windows\system32\MRT.exe 2013-04-22 18:02 . 2013-04-17 04:31 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A812B06-B0BF-414B-B142-A057EB20A060}\mpengine.dll 2013-04-22 18:00 . 2013-04-22 18:00 -------- d-----w- c:\users\Jochen\AppData\Roaming\Canneverbe Limited 2013-04-22 18:00 . 2013-04-22 18:00 -------- d-----w- c:\programdata\Canneverbe Limited 2013-04-22 17:59 . 2013-04-22 17:59 -------- d-----w- c:\program files (x86)\CDBurnerXP 2013-04-22 17:59 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2013-04-22 17:58 . 2013-04-24 00:19 -------- d-----r- c:\users\Jochen\Dropbox 2013-04-22 17:55 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll 2013-04-22 17:55 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll 2013-04-22 17:55 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2013-04-22 17:55 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2013-04-22 17:55 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll 2013-04-22 17:55 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2013-04-22 17:53 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-04-22 17:53 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2013-04-22 17:53 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2013-04-22 17:53 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2013-04-22 17:53 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2013-04-22 17:50 . 2013-04-23 23:36 -------- d-----w- c:\users\Jochen\AppData\Roaming\Dropbox 2013-04-22 17:48 . 2013-03-02 05:55 1111040 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-04-22 17:47 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll 2013-04-22 17:45 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2013-04-22 17:44 . 2013-04-22 17:44 -------- d-----w- c:\users\Jochen\AppData\Local\Macromedia 2013-04-22 17:43 . 2013-04-23 12:03 -------- d-sh--w- c:\windows\Installer 2013-04-22 17:43 . 2013-04-22 17:43 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-22 17:43 . 2013-04-22 17:43 691592 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-22 17:43 . 2013-04-22 17:43 -------- d-----w- c:\windows\SysWow64\Macromed 2013-04-22 17:43 . 2013-04-22 17:43 -------- d-----w- c:\windows\system32\Macromed 2013-04-22 17:40 . 2013-04-22 17:46 -------- d-----w- c:\users\Jochen\AppData\Local\Google 2013-04-22 17:40 . 2013-04-22 17:46 -------- d-----w- c:\program files (x86)\Google 2013-04-22 17:33 . 2013-04-22 17:33 -------- d-----w- c:\users\Jochen\AppData\Roaming\Malwarebytes 2013-04-22 17:33 . 2013-04-22 17:33 -------- d-----w- c:\users\Jochen\AppData\Local\Programs 2013-04-22 17:32 . 2013-04-22 17:32 -------- d-----w- c:\program files\WinRAR 2013-04-21 23:16 . 2013-04-21 23:16 -------- d-----w- c:\program files (x86)\devolo . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-11 23:10 . 2010-11-21 03:27 282744 ------w- c:\windows\system32\MpSigStub.exe 2013-03-04 06:43 . 2013-03-04 06:43 81920 ----a-w- c:\windows\SysWow64\devolopacket.dll 2013-03-04 06:43 . 2013-03-04 06:43 34048 ----a-w- c:\windows\SysWow64\drivers\npf_devolo.sys 2013-03-04 06:43 . 2013-03-04 06:43 221184 ----a-w- c:\windows\SysWow64\devolopcap.dll 2013-02-25 22:32 . 2013-02-25 22:32 25256224 ----a-w- c:\windows\system32\nvcompiler.dll 2013-02-25 22:32 . 2013-02-25 22:32 2505144 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-02-25 22:32 . 2013-02-25 22:32 15129960 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-02-25 22:32 . 2013-02-25 22:32 6262608 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-02-25 22:32 . 2013-02-25 22:32 2826040 ----a-w- c:\windows\system32\nvapi64.dll 2013-02-25 22:32 . 2013-02-25 22:32 1814304 ----a-w- c:\windows\system32\nvdispco64.dll 2013-02-25 22:32 . 2013-02-25 22:32 18055184 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-02-25 22:32 . 2013-02-25 22:32 2720544 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-02-25 22:32 . 2013-02-25 22:32 26929440 ----a-w- c:\windows\system32\nvoglv64.dll 2013-02-25 22:32 . 2013-02-25 22:32 7932256 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-02-25 22:32 . 2013-02-25 22:32 2346784 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-02-25 22:32 . 2013-02-25 22:32 1510176 ----a-w- c:\windows\system32\nvdispgenco64.dll 2013-02-25 22:32 . 2013-02-25 22:32 11036448 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-02-25 22:32 . 2013-02-25 22:32 2904352 ----a-w- c:\windows\system32\nvcuvid.dll 2013-02-25 22:32 . 2013-02-25 22:32 20449056 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-02-25 22:32 . 2009-07-13 21:59 15053264 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-02-25 22:32 . 2013-02-25 22:32 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2013-02-25 22:32 . 2013-02-25 22:32 7564040 ----a-w- c:\windows\system32\nvopencl.dll 2013-02-25 22:32 . 2013-02-25 22:32 1985824 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-02-25 22:32 . 2013-02-25 22:32 12641992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-02-25 22:32 . 2013-02-25 22:32 9390760 ----a-w- c:\windows\system32\nvcuda.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2013-04-22 367200] R3 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2013-04-22 3816440] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2013-03-07 19032] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2013-03-07 9584] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992] R3 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264] R3 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2013-03-20 7094592] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 tsusbhub;tsusbhub;tsusbhub [x] S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys [2013-04-22 108832] S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys [2013-04-22 1120032] S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys [2013-04-22 183224] S2 DevoloNetworkService;devolo Network Service;c:\program files (x86)\devolo\dlan\devolonetsvc.exe [2013-03-25 3507704] S2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\sysWOW64\drivers\npf_devolo.sys [2013-03-04 34048] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-22 17:46 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-04-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-22 17:43] . 2013-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-22 17:44] . 2013-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-22 17:44] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError] @="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}" [HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}] 2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress] @="{00F848DC-B1D4-4892-9C25-CAADC86A215D}" [HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}] 2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk] @="{71573297-552E-46fc-BE3D-3DFAF88D47B7}" [HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}] 2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-04-10 05:37 164016 ----a-w- c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-04-10 05:37 164016 ----a-w- c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-04-10 05:37 164016 ----a-w- c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-04-10 05:37 164016 ----a-w- c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2013-02-15 517912] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: Interfaces\{613A590F-16D9-4EE7-9E69-63A741F7D4E1}: NameServer = 8.8.8.8 FF - ProfilePath - c:\users\Jochen\AppData\Roaming\Mozilla\Firefox\Profiles\jkov78vz.default\ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 8888 FF - prefs.js: network.proxy.ssl - 127.0.0.1 FF - prefs.js: network.proxy.ssl_port - 8888 FF - prefs.js: network.proxy.type - 1 FF - ExtSQL: 2013-04-22 19:41; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Jochen\AppData\Roaming\Mozilla\Firefox\Profiles\jkov78vz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-04-22 19:45; fiddlerhook@fiddler2.com; c:\program files (x86)\Fiddler2\FiddlerHook FF - ExtSQL: 2013-04-23 12:33; {8b86149f-01fb-4842-9dd8-4d7eb02fd055}; c:\users\Jochen\AppData\Roaming\Mozilla\Firefox\Profiles\jkov78vz.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll AddRemove-Dropbox - c:\users\Jochen\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-04-24 06:57:26 ComboFix-quarantined-files.txt 2013-04-24 04:57 ComboFix2.txt 2013-04-23 23:19 . Vor Suchlauf: 10 Verzeichnis(se), 98.712.293.376 Bytes frei Nach Suchlauf: 11 Verzeichnis(se), 98.653.245.440 Bytes frei . - - End Of File - - ED1D3BC6E11350A1CDCD2619A6FD73A7 AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.202 - Logfile created 04/24/2013 at 07:02:08 # Updated 23/04/2013 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : Jochen - Jochen-PC # Boot Mode : Normal # Running from : C:\Users\Jochen\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Registry is clean. -\\ Mozilla Firefox v20.0.1 (de) File : C:\Users\Jochen\AppData\Roaming\Mozilla\Firefox\Profiles\jkov78vz.default\prefs.js [OK] File is clean. -\\ Google Chrome v26.0.1410.64 File : C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. -\\ Opera v12.15.1748.0 File : C:\Users\Jochen\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[R4].txt - [1062 octets] - [24/04/2013 04:46:58] AdwCleaner[R5].txt - [1099 octets] - [24/04/2013 06:12:43] AdwCleaner[R6].txt - [900 octets] - [24/04/2013 06:44:28] AdwCleaner[R7].txt - [1114 octets] - [24/04/2013 07:02:08] AdwCleaner[S1].txt - [1237 octets] - [24/04/2013 06:46:21] ########## EOF - C:\AdwCleaner[R7].txt - [1234 octets] ########## OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.04.2013 07:12:21 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jochen\Downloads 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 8,00 Gb Total Physical Memory | 6,47 Gb Available Physical Memory | 80,83% Memory free 16,00 Gb Paging File | 14,29 Gb Available in Paging File | 89,31% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 150,64 Gb Total Space | 91,95 Gb Free Space | 61,04% Space Free | Partition Type: NTFS Drive D: | 3,09 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Drive E: | 380,86 Gb Total Space | 380,76 Gb Free Space | 99,97% Space Free | Partition Type: NTFS Drive F: | 399,91 Gb Total Space | 399,81 Gb Free Space | 99,98% Space Free | Partition Type: NTFS Drive G: | 7,42 Gb Total Space | 7,28 Gb Free Space | 98,02% Space Free | Partition Type: FAT32 Computer Name: Jochen-PC | User Name: Jochen | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.11 16:00:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jochen\Downloads\OTL.exe PRC - [2013.04.09 10:57:09 | 001,312,720 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe PRC - [2013.03.25 15:23:04 | 003,507,704 | ---- | M] (devolo AG) -- C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe PRC - [2013.03.06 17:30:43 | 010,220,896 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe PRC - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.03.06 17:22:26 | 000,185,696 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe PRC - [2009.11.13 16:43:34 | 004,972,544 | ---- | M] (WhatsRunning.net) -- C:\Program Files (x86)\WhatsRunning\WhatsRunning.exe PRC - [2009.09.23 16:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe ========== Modules (No Company Name) ========== MOD - [2013.04.09 10:57:07 | 000,390,096 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll MOD - [2013.04.09 10:57:05 | 004,050,896 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll MOD - [2013.04.09 10:56:15 | 000,598,480 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libglesv2.dll MOD - [2013.04.09 10:56:14 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libegl.dll MOD - [2013.04.09 10:56:13 | 001,606,096 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ffmpegsumo.dll MOD - [2009.11.13 16:36:26 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\WhatsRunning\PSInfoPS.dll ========== Services (SafeList) ========== SRV:64bit: - [2012.12.16 13:25:38 | 000,123,664 | ---- | M] (SANDBOXIE L.T.D) [On_Demand | Stopped] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc) SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2013.04.22 21:07:13 | 003,816,440 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2013.04.22 19:43:46 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.10 08:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.03.25 15:23:04 | 003,507,704 | ---- | M] (devolo AG) [Auto | Running] -- C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe -- (DevoloNetworkService) SRV - [2013.03.20 19:31:44 | 007,094,592 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe -- (syncagentsrv) SRV - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.02.26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013.02.15 13:02:10 | 001,144,704 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.04.22 21:07:14 | 000,367,200 | ---- | M] (Acronis) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp) DRV:64bit: - [2013.04.22 21:07:12 | 001,462,560 | ---- | M] (Acronis International GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tdrpman.sys -- (tdrpman) DRV:64bit: - [2013.04.22 21:07:10 | 000,183,224 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tib_mounter.sys -- (tib_mounter) DRV:64bit: - [2013.04.22 21:07:09 | 001,120,032 | ---- | M] (Acronis International GmbH) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tib.sys -- (tib) DRV:64bit: - [2013.04.22 21:07:08 | 000,161,568 | ---- | M] (Acronis International GmbH) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vididr.sys -- (vididr) DRV:64bit: - [2013.04.22 21:07:07 | 000,117,024 | ---- | M] (Acronis International GmbH) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vidsflt.sys -- (vidsflt) DRV:64bit: - [2013.04.22 21:07:04 | 000,233,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman) DRV:64bit: - [2013.04.22 21:07:04 | 000,108,832 | ---- | M] (Acronis International GmbH) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fltsrv.sys -- (fltsrv) DRV:64bit: - [2013.03.07 13:37:54 | 000,019,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio) DRV:64bit: - [2013.03.07 13:37:32 | 000,009,584 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio) DRV:64bit: - [2012.12.16 13:25:34 | 000,202,632 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Stopped] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv) DRV:64bit: - [2012.03.27 16:48:00 | 000,398,112 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2010.11.21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2010.11.21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:64bit: - [2010.11.21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.11.21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.14 09:26:24 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor) DRV - [2013.03.04 08:43:26 | 000,034,048 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\npf_devolo.sys -- (NPF_devolo) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 1A 07 6F 7D 3F CE 01 [binary data] IE - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: fiddlerhook%40fiddler2.com:2.4.3.7 FF - prefs.js..extensions.enabledAddons: %7B8b86149f-01fb-4842-9dd8-4d7eb02fd055%7D:0.25.1 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - prefs.js..network.proxy.http: "127.0.0.1" FF - prefs.js..network.proxy.http_port: 8888 FF - prefs.js..network.proxy.no_proxies_on: "" FF - prefs.js..network.proxy.ssl: "127.0.0.1" FF - prefs.js..network.proxy.ssl_port: 8888 FF - prefs.js..network.proxy.type: 1 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fiddlerhook@fiddler2.com: C:\Program Files (x86)\Fiddler2\FiddlerHook [2013.04.22 19:45:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2002.01.01 07:59:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2002.01.01 07:59:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jochen\AppData\Roaming\mozilla\Extensions [2013.04.23 12:33:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jochen\AppData\Roaming\mozilla\Firefox\Profiles\jkov78vz.default\extensions [2013.04.23 12:33:43 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Users\Jochen\AppData\Roaming\mozilla\Firefox\Profiles\jkov78vz.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055} [2013.04.22 19:41:13 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Jochen\AppData\Roaming\mozilla\firefox\profiles\jkov78vz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2002.01.01 07:59:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.04.22 19:45:15 | 000,000,000 | ---D | M] (FiddlerHook) -- C:\PROGRAM FILES (X86)\FIDDLER2\FIDDLERHOOK [2013.04.10 08:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013.04.10 10:18:46 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.04.10 10:18:46 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2013.04.10 10:18:46 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2013.04.10 10:18:46 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2013.04.10 10:18:46 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2013.04.10 10:18:46 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll CHR - Extension: Google Docs = C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: Google Drive = C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Google-Suche = C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: Google Mail = C:\Users\Jochen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2013.04.24 06:55:57 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2927705667-812167833-4165969349-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9:64bit: - Extra Button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik) O9:64bit: - Extra 'Tools' menuitem : Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik) O9 - Extra Button: Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik) O9 - Extra 'Tools' menuitem : Fiddler - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Telerik) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613A590F-16D9-4EE7-9E69-63A741F7D4E1}: NameServer = 8.8.8.8 O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010.11.21 10:33:27 | 000,000,122 | R--- | M] () - D:\autorun.inf -- [ UDF ] O32 - AutoRun File - [2013.04.15 20:27:12 | 000,000,016 | -H-- | M] () - G:\AUTORUN.INF -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.24 06:57:28 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.04.24 06:05:12 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Jochen\Desktop\aswMBR.exe [2013.04.24 01:14:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.04.24 01:14:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.04.24 01:14:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.04.24 01:14:24 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.04.24 01:14:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.04.24 01:07:32 | 000,000,000 | ---D | C] -- C:\Users\Jochen\Desktop\mbar [2013.04.24 00:43:29 | 002,239,840 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Jochen\Desktop\tds.exe [2013.04.24 00:43:06 | 005,059,674 | R--- | C] (Swearware) -- C:\Users\Jochen\Desktop\ComboFix.exe [2013.04.23 23:43:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2013.04.23 23:43:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2013.04.23 22:44:12 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\mIRC [2013.04.23 22:44:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC [2013.04.23 22:44:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mIRC [2013.04.23 22:12:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OWASP [2013.04.23 22:12:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OWASP [2013.04.23 19:58:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\What's Running [2013.04.23 19:58:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WhatsRunning [2013.04.23 18:11:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET [2013.04.23 17:30:00 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur [2013.04.23 14:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Home Edition 7.8 [2013.04.23 14:22:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 7.8 [2013.04.23 14:21:23 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Local\GHISLER [2013.04.23 14:20:43 | 000,000,000 | ---D | C] -- C:\totalcmd [2013.04.23 14:20:43 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander [2013.04.23 14:20:43 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\GHISLER [2013.04.23 14:16:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security [2013.04.23 14:16:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda USB Vaccine [2013.04.23 14:16:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security [2013.04.23 14:03:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie [2013.04.23 14:03:13 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie [2013.04.23 11:37:53 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Opera [2013.04.23 11:37:53 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Local\Opera [2013.04.23 11:37:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera [2013.04.23 10:53:54 | 000,000,000 | ---D | C] -- C:\Windows\de-DE [2013.04.23 10:53:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer [2013.04.23 10:53:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\de-DE [2013.04.23 10:53:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\de [2013.04.23 10:53:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\0407 [2013.04.23 10:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\de-DE [2013.04.23 10:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0407 [2013.04.23 10:53:39 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\de [2013.04.23 10:49:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer [2013.04.23 10:49:33 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\de-DE\pscr.sys.mui [2013.04.23 10:48:52 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerId.sys.mui [2013.04.23 10:48:52 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerIb.sys.mui [2013.04.23 10:48:52 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrParwdm.sys.mui [2013.04.23 10:44:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Marvell [2013.04.23 04:29:16 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2013.04.23 01:22:05 | 000,000,000 | ---D | C] -- C:\Users\Jochen\Documents\Fiddler2 [2013.04.23 01:04:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2013.04.23 00:47:01 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Trillian [2013.04.23 00:46:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trillian [2013.04.22 23:54:15 | 000,000,000 | ---D | C] -- C:\Meine Backups [2013.04.22 23:52:38 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Acronis [2013.04.22 21:06:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis [2013.04.22 21:06:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acronis [2013.04.22 21:03:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2013.04.22 20:49:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation [2013.04.22 20:48:35 | 000,061,216 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll [2013.04.22 20:48:35 | 000,053,024 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll [2013.04.22 20:48:04 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation [2013.04.22 20:05:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Acronis [2013.04.22 20:05:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Acronis [2013.04.22 20:00:01 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Canneverbe Limited [2013.04.22 20:00:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited [2013.04.22 19:59:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP [2013.04.22 19:58:08 | 000,000,000 | R--D | C] -- C:\Users\Jochen\Dropbox [2013.04.22 19:52:43 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox [2013.04.22 19:50:32 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Dropbox [2013.04.22 19:46:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2013.04.22 19:45:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fiddler2 [2013.04.22 19:44:44 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Local\Macromedia [2013.04.22 19:43:59 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2013.04.22 19:43:44 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2013.04.22 19:43:36 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed [2013.04.22 19:43:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2013.04.22 19:40:50 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Local\Google [2013.04.22 19:40:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2013.04.22 19:33:25 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Malwarebytes [2013.04.22 19:33:13 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Local\Programs [2013.04.22 19:32:58 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\WinRAR [2013.04.22 19:32:58 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2013.04.22 19:32:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2013.04.22 19:32:56 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2013.04.22 01:17:03 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Macromedia [2013.04.22 01:17:03 | 000,000,000 | ---D | C] -- C:\Users\Jochen\AppData\Roaming\Adobe [2013.04.22 01:16:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devolo [2013.04.22 01:16:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\devolo ========== Files - Modified Within 30 Days ========== [2013.04.24 06:55:57 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013.04.24 06:54:43 | 000,026,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.24 06:54:43 | 000,026,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.24 06:54:31 | 001,611,160 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.04.24 06:54:31 | 000,693,972 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.04.24 06:54:31 | 000,651,450 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.04.24 06:54:31 | 000,147,096 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.04.24 06:54:31 | 000,120,382 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.04.24 06:49:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.24 06:47:45 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.24 06:47:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.24 06:31:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.24 06:28:31 | 001,094,714 | ---- | M] () -- C:\Users\Jochen\Documents\sys1.xml [2013.04.24 06:07:15 | 000,000,512 | ---- | M] () -- C:\Users\Jochen\Documents\MBR.dat [2013.04.24 05:50:43 | 000,000,000 | ---- | M] () -- C:\Users\Jochen\defogger_reenable [2013.04.24 05:05:33 | 646,237,550 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013.04.24 01:24:54 | 000,001,450 | ---- | M] () -- C:\Windows\Sandboxie.ini [2013.04.24 01:24:02 | 000,275,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.04.23 23:43:56 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.04.23 23:15:32 | 000,000,600 | ---- | M] () -- C:\Users\Jochen\AppData\Local\PUTTY.RND [2013.04.23 22:44:12 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\mIRC.lnk [2013.04.23 19:58:19 | 000,000,983 | ---- | M] () -- C:\Users\Jochen\Desktop\What's Running.lnk [2013.04.23 18:29:32 | 005,059,674 | R--- | M] (Swearware) -- C:\Users\Jochen\Desktop\ComboFix.exe [2013.04.23 18:14:14 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Jochen\Desktop\aswMBR.exe [2013.04.23 14:22:56 | 000,001,282 | ---- | M] () -- C:\Users\Public\Desktop\MiniTool Partition Wizard Home Edition.lnk [2013.04.23 14:20:44 | 000,000,646 | ---- | M] () -- C:\Users\Jochen\Desktop\Total Commander 64 bit.lnk [2013.04.23 14:03:14 | 000,000,914 | ---- | M] () -- C:\Users\Jochen\Desktop\Sandboxed Web Browser.lnk [2013.04.23 14:03:14 | 000,000,914 | ---- | M] () -- C:\Users\Jochen\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk [2013.04.23 11:37:51 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk [2013.04.23 10:53:30 | 000,295,922 | ---- | M] () -- C:\Windows\SysNative\perfi007.dat [2013.04.23 10:53:30 | 000,038,104 | ---- | M] () -- C:\Windows\SysNative\perfd007.dat [2013.04.23 10:49:57 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.23 01:08:40 | 000,763,706 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013.04.23 00:47:01 | 000,001,079 | ---- | M] () -- C:\Users\Jochen\Desktop\Trillian.lnk [2013.04.22 21:07:00 | 000,001,205 | ---- | M] () -- C:\Users\Public\Desktop\True Image 2013.lnk [2013.04.22 19:59:58 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2013.04.22 19:58:08 | 000,001,043 | ---- | M] () -- C:\Users\Jochen\Desktop\Dropbox.lnk [2013.04.22 19:52:43 | 000,002,279 | ---- | M] () -- C:\Users\Jochen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2013.04.22 19:46:12 | 000,002,255 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2013.04.22 01:17:03 | 000,002,123 | ---- | M] () -- C:\Users\Public\Desktop\devolo dLAN Cockpit.lnk [2013.04.16 16:34:00 | 000,377,856 | ---- | M] () -- C:\Users\Jochen\Desktop\gmer_2.1.19163.exe [2013.04.11 15:21:56 | 002,239,840 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Jochen\Desktop\tds.exe [2013.04.04 09:55:28 | 000,377,856 | ---- | M] () -- C:\Users\Jochen\Desktop\gnom.com [2013.04.04 09:55:28 | 000,377,856 | ---- | M] () -- C:\Users\Jochen\Desktop\gmer.exe ========== Files Created - No Company Name ========== [2013.04.24 06:28:31 | 001,094,714 | ---- | C] () -- C:\Users\Jochen\Documents\sys1.xml [2013.04.24 06:07:15 | 000,000,512 | ---- | C] () -- C:\Users\Jochen\Documents\MBR.dat [2013.04.24 05:54:10 | 000,377,856 | ---- | C] () -- C:\Users\Jochen\Desktop\gmer.exe [2013.04.24 05:53:32 | 000,377,856 | ---- | C] () -- C:\Users\Jochen\Desktop\gnom.com [2013.04.24 05:50:43 | 000,000,000 | ---- | C] () -- C:\Users\Jochen\defogger_reenable [2013.04.24 05:05:33 | 646,237,550 | ---- | C] () -- C:\Windows\MEMORY.DMP [2013.04.24 01:23:54 | 000,275,576 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.04.24 01:14:28 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.04.24 01:14:28 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.04.24 01:14:28 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.04.24 01:14:28 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.04.24 01:14:28 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.04.24 00:43:16 | 000,377,856 | ---- | C] () -- C:\Users\Jochen\Desktop\gmer_2.1.19163.exe [2013.04.23 23:43:56 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.04.23 22:44:12 | 000,000,951 | ---- | C] () -- C:\Users\Public\Desktop\mIRC.lnk [2013.04.23 19:58:19 | 000,000,983 | ---- | C] () -- C:\Users\Jochen\Desktop\What's Running.lnk [2013.04.23 14:25:32 | 000,000,600 | ---- | C] () -- C:\Users\Jochen\AppData\Local\PUTTY.RND [2013.04.23 14:22:59 | 003,074,240 | ---- | C] () -- C:\Windows\SysNative\pwNative.exe [2013.04.23 14:22:59 | 000,019,032 | ---- | C] () -- C:\Windows\SysNative\pwdrvio.sys [2013.04.23 14:22:58 | 000,009,584 | ---- | C] () -- C:\Windows\SysNative\pwdspio.sys [2013.04.23 14:22:56 | 000,001,282 | ---- | C] () -- C:\Users\Public\Desktop\MiniTool Partition Wizard Home Edition.lnk [2013.04.23 14:20:44 | 000,000,646 | ---- | C] () -- C:\Users\Jochen\Desktop\Total Commander 64 bit.lnk [2013.04.23 14:04:27 | 000,000,914 | ---- | C] () -- C:\Users\Jochen\Desktop\Sandboxed Web Browser.lnk [2013.04.23 14:04:27 | 000,000,914 | ---- | C] () -- C:\Users\Jochen\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk [2013.04.23 14:04:25 | 000,001,450 | ---- | C] () -- C:\Windows\Sandboxie.ini [2013.04.23 11:37:51 | 000,001,841 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk [2013.04.23 11:37:51 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk [2013.04.23 10:54:40 | 000,295,922 | ---- | C] () -- C:\Windows\SysNative\perfi007.dat [2013.04.23 10:54:39 | 000,693,972 | ---- | C] () -- C:\Windows\SysNative\perfh007.dat [2013.04.23 10:54:39 | 000,147,096 | ---- | C] () -- C:\Windows\SysNative\perfc007.dat [2013.04.23 10:54:39 | 000,038,104 | ---- | C] () -- C:\Windows\SysNative\perfd007.dat [2013.04.23 10:49:57 | 000,001,174 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.23 10:49:57 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.23 10:42:15 | 000,015,416 | ---- | C] () -- C:\Windows\SysNative\drivers\ASACPI.sys [2013.04.23 01:08:38 | 000,763,706 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013.04.23 00:47:01 | 000,001,109 | ---- | C] () -- C:\Users\Jochen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trillian.lnk [2013.04.23 00:47:01 | 000,001,079 | ---- | C] () -- C:\Users\Jochen\Desktop\Trillian.lnk [2013.04.22 21:07:00 | 000,001,205 | ---- | C] () -- C:\Users\Public\Desktop\True Image 2013.lnk [2013.04.22 19:59:58 | 000,001,941 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2013.04.22 19:59:58 | 000,001,899 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk [2013.04.22 19:58:08 | 000,001,043 | ---- | C] () -- C:\Users\Jochen\Desktop\Dropbox.lnk [2013.04.22 19:46:12 | 000,002,279 | ---- | C] () -- C:\Users\Jochen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2013.04.22 19:46:12 | 000,002,255 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2013.04.22 19:45:15 | 000,001,888 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fiddler2.lnk [2013.04.22 19:43:46 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.22 19:40:57 | 000,001,112 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.22 19:40:54 | 000,001,108 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.22 01:17:03 | 000,002,123 | ---- | C] () -- C:\Users\Public\Desktop\devolo dLAN Cockpit.lnk ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.04.22 23:52:38 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\Acronis [2013.04.22 20:00:01 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\Canneverbe Limited [2013.04.24 01:36:31 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\Dropbox [2013.04.23 14:20:43 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\GHISLER [2013.04.23 11:37:53 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\Opera [2013.04.23 03:51:11 | 000,000,000 | ---D | M] -- C:\Users\Jochen\AppData\Roaming\Trillian ========== Purity Check ========== ========== Custom Scans ========== < reg query "HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0" /c > < reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}" /s /c > HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318} Class REG_SZ hdc ClassDesc REG_SZ @%SystemRoot%\System32\SysClass.Dll,-3001 (Standard) REG_SZ IDE ATA/ATAPI controllers IconPath REG_MULTI_SZ %SystemRoot%\System32\setupapi.dll,-9 Installer32 REG_SZ SysClass.Dll,HdcClassInstaller HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0000 InfPath REG_SZ mshdc.inf InfSection REG_SZ pciide_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ pci\cc_0101 DriverDesc REG_SZ Standard Dual Channel PCI IDE Controller Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0001 InfPath REG_SZ mshdc.inf InfSection REG_SZ pciide_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ pci\cc_0101 DriverDesc REG_SZ Standard Dual Channel PCI IDE Controller Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0002 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0003 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0004 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0005 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0006 InfPath REG_SZ mshdc.inf InfSection REG_SZ pciide_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ pci\cc_0101 DriverDesc REG_SZ Standard Dual Channel PCI IDE Controller Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0007 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0008 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0009 InfPath REG_SZ mshdc.inf InfSection REG_SZ pciide_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ pci\cc_0101 DriverDesc REG_SZ Standard Dual Channel PCI IDE Controller Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0010 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\0011 CoInstallers32 REG_MULTI_SZ storprop.dll,HdcCoInstaller EnumPropPages32 REG_SZ storprop.dll,AtaPropPageProvider InfPath REG_SZ mshdc.inf InfSection REG_SZ atapi_Inst ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 00808CA3C594C601 DriverDate REG_SZ 6-21-2006 DriverVersion REG_SZ 6.1.7601.17514 MatchingDeviceId REG_SZ internal_ide_channel DriverDesc REG_SZ IDE Channel Migrated REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\CLASS\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties < End of report > [/CODE] Ah, wieder geöffnet. Puhh ... wie gesagt, ich habe mir heute Abend freigehalten - sag mir Bescheid wies weitergeht. Danke nochmal! Geändert von JochenWitt (24.04.2013 um 06:30 Uhr) |
Themen zu PC neu aufgsetzt, zufälliger GMER Scan->rootkit ? |
appdata, c:\windows, code, device, driver, explorer, freundin, gmer, guten, harddisk, ide, infiziert, internet, internet explorer, microsoft, neu, nichts, ntdll.dll, recovery, rootkit, scan, service, system, system32, temp, temporary |