Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Desktop wird nicht angezeigt (https://www.trojaner-board.de/116167-desktop-angezeigt.html)

Kornty 01.06.2012 13:11

Desktop wird nicht angezeigt
 
Hallo,

ich habe das Problem, dass mein Desktop nicht angezeigt wird nach dem anmelden. Ich habe mit dem ct Desinfect2012 den Computer bereinigt und da habe ich 120 Viren oder Bedrohungen gelöscht. Mit dem Malewarebyte habe ich 142 Bedrohungen gelöscht. Der Notebook funktioniert aber trotzdem noch nicht wie er soll. im Anhang die OTL files

Danke

cosinus 03.06.2012 14:25

Zitat:

Mit dem Malewarebyte habe ich 142 Bedrohungen gelöscht.
Ohne die Logs hilft diese Agabe so keinem weiter

Kornty 04.06.2012 09:10

Hallo,

hier die Malwarebytes Logs. :headbang:

danke

cosinus 04.06.2012 15:08

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

Kornty 04.06.2012 15:28

Hallo,

ich habe leider keine anderen logs von Malwarebytes.
ich habe aber mit dem Desinfected von c´t zuerst gescannt und da einges an schädlingen rausgelöscht aber da habe ich keine log dateien von. ich hoffe Ihr könnt mir trotzdem helfen

gruß Kornty

cosinus 04.06.2012 16:31

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Kornty 04.06.2012 20:38

so hier ist der ESET log

lg

cosinus 04.06.2012 21:29

Falls du immer noch Probleme mit dem Desktop hast und evtl auch mit dem Startmenü:

Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Kornty 05.06.2012 06:06

kein erfolg. bei mir ist seit dem Befall das Problem dass ich nur über Taskmanager Programme ausführen kann und Desktop garnicht zum vorschein kommt.

danke

cosinus 05.06.2012 10:24

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Kornty 05.06.2012 17:21

OTL Logfile:
Code:

OTL logfile created on: 05.06.2012 18:06:34 - Run 2
OTL by OldTimer - Version 3.2.45.0    Folder = D:\Igor-IT\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
510,98 Mb Total Physical Memory | 385,27 Mb Available Physical Memory | 75,40% Memory free
1,22 Gb Paging File | 1,16 Gb Available in Paging File | 94,78% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 29,92 Gb Total Space | 12,64 Gb Free Space | 42,25% Space Free | Partition Type: FAT32
Drive D: | 7,31 Gb Total Space | 7,30 Gb Free Space | 99,86% Space Free | Partition Type: FAT32
 
Computer Name: ACER-PLALZYB8F0 | User Name: Igor | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - D:\Igor-IT\OTL\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\WINDOWS\system32\LsaWrApi.dll ()
MOD - C:\WINDOWS\system32\C1XStngs.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe File not found
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira GmbH)
SRV - (AntiVirMailService) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WTGService) -- C:\Programme\3DataManager\WTGService.exe ()
SRV - (UI Assistant Service) -- C:\Programme\tele.ring Internet Manager\AssistantServices.exe ()
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (TlntSvr) -- C:\WINDOWS\system32\tlntsvr.exe (Microsoft Corporation)
SRV - (NetDDEdsdm) -- C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (NetDDE) -- C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (ClipSrv) -- C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation)
SRV - (RemoteAccess) -- C:\WINDOWS\system32\mprdim.dll (Microsoft Corporation)
SRV - (Messenger) -- C:\WINDOWS\system32\msgsvc.dll (Microsoft Corporation)
SRV - (Alerter) -- C:\WINDOWS\system32\alrsvc.dll (Microsoft Corporation)
SRV - (S24EventMonitor) -- C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) -- C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (NetSvc) -- C:\Programme\Intel\NCS\Sync\NetSvc.exe (Intel(R) Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (upperdev) -- system32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (StarOpen) --  File not found
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- system32\DRIVERS\LV561AV.SYS File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (MpKslf89215e6) -- c:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Microsoft Antimalware\Definition Updates\{D551FFA7-1469-4E71-9D18-E35A2D37695F}\MpKslf89215e6.sys File not found
DRV - (LVUSBSta) -- system32\drivers\LVUSBSta.sys File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (hwusbfake) -- system32\DRIVERS\ewusbfake.sys File not found
DRV - (Changer) --  File not found
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (hwusbdev) -- C:\WINDOWS\system32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbnmea) -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (BMLoad) -- C:\WINDOWS\system32\drivers\BMLoad.sys (Bytemobile, Inc.)
DRV - (tcpipBM) -- C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (dmboot) -- C:\WINDOWS\system32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
DRV - (Ntfs) -- C:\WINDOWS\System32\drivers\ntfs.sys (Microsoft Corporation)
DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (Udfs) -- C:\WINDOWS\System32\drivers\udfs.sys (Microsoft Corporation)
DRV - (ACEDRV05) -- C:\WINDOWS\system32\drivers\ACEDRV05.sys (Protect Software GmbH)
DRV - (w70n51) Intel(R) -- C:\WINDOWS\system32\drivers\w70n51.sys (Intel® Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (acernbm) -- C:\WINDOWS\system32\drivers\acernbm.sys ()
DRV - (CONAN) -- C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro )
DRV - (LEX_AS_NIC_SERVICE) -- C:\WINDOWS\system32\drivers\Expsab2.sys (LAN-Express)
DRV - (mbxfilt) -- C:\WINDOWS\system32\drivers\mbxfilt.sys (O2 Micro)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (O2SCBUS) -- C:\WINDOWS\system32\drivers\ozscr.sys (O2Micro)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (cbidf2k) -- C:\WINDOWS\System32\drivers\cbidf2k.sys (Microsoft Corporation)
DRV - (Asapi) -- C:\WINDOWS\System32\drivers\asapi.sys (VOB Computersysteme GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=31711dea00000000000000042379ac98&tlver=1.4.19.19&affID=19405
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.acer.com
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Programme\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\ff-bmboc@bytemobile.com: C:\Programme\3-addons\addon [2011.05.31 17:09:50 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2011.02.23 08:56:10 | 000,006,469 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1 99.189.54
O1 - Hosts: 127.0.0.1 99.189.52
O1 - Hosts: 127.0.0.1 98.223.73
O1 - Hosts: 127.0.0.1 97.80.137
O1 - Hosts: 127.0.0.1 95.134.16
O1 - Hosts: 127.0.0.1 95.133.8.
O1 - Hosts: 127.0.0.1 95.133.23
O1 - Hosts: 127.0.0.1 95.133.23
O1 - Hosts: 127.0.0.1 95.133.14
O1 - Hosts: 127.0.0.1 95.133.11
O1 - Hosts: 127.0.0.1 95.105.17
O1 - Hosts: 127.0.0.1 94.53.2.1
O1 - Hosts: 127.0.0.1 94.23.201
O1 - Hosts: 127.0.0.1 94.179.55
O1 - Hosts: 127.0.0.1 94.179.48
O1 - Hosts: 127.0.0.1 94.179.19
O1 - Hosts: 127.0.0.1 94.179.11
O1 - Hosts: 127.0.0.1 94.178.65
O1 - Hosts: 127.0.0.1 93.39.197
O1 - Hosts: 127.0.0.1 93.186.17
O1 - Hosts: 127.0.0.1 93.136.83
O1 - Hosts: 127.0.0.1 93.112.91
O1 - Hosts: 127.0.0.1 92.86.197
O1 - Hosts: 127.0.0.1 92.80.81.
O1 - Hosts: 245 more lines...
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll File not found
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\.DEFAULT..\Run: [DWQueuedReporting] c:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [DWQueuedReporting] c:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006..\RunOnce: [NeroHomeFirstStart] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20F30040-FA66-439C-AF09-410461E2F9B7}: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B5CDAA1-5F88-459B-A06B-67EA91370CDC}: DhcpNameServer = 195.34.133.21 195.34.133.22
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\ArchiverforWin.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\ArchiverforWin.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\Sebring: DllName - (C:\WINDOWS\System32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpReg: AcerNotebookManager - hkey= - key= - C:\Programme\Acer\Notebook Manager\almxptray.exe (Acer)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AGRSMMSG - hkey= - key= - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
MsConfig - StartUpReg: B64Fu7wxCKTba7x - hkey= - key= -  File not found
MsConfig - StartUpReg: BluetoothAuthenticationAgent - hkey= - key= -  File not found
MsConfig - StartUpReg: LaunchApp - hkey= - key= - C:\WINDOWS\Alaunch.exe (Acer Inc.)
MsConfig - StartUpReg: LManager - hkey= - key= - C:\Programme\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
MsConfig - StartUpReg: PRONoMgr.exe - hkey= - key= - C:\Programme\Intel\NCS\PROSet\PRONoMgr.exe (Intel(R) Corporation)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Inc.)
MsConfig - StartUpReg: SoundMan - hkey= - key= - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
MsConfig - StartUpReg: SweetIM - hkey= - key= - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
MsConfig - StartUpReg: UIExec - hkey= - key= - C:\Programme\tele.ring Internet Manager\UIExec.exe ()
MsConfig - StartUpReg: ZCfgSvc.exe - hkey= - key= -  File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {1325db73-d9f1-48f8-8895-6d814ec58889} - Sicherheitsupdate für Windows XP (KB913433)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {588A559B-BBC9-4148-A2C0-96A33D1DBC26} - Microsoft .NET Framework 1.0 Hotfix (KB928367)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {65289DE3-4C1A-11D6-B6E1-00B0D049139F} - Microsoft .NET Framework 1.0 Service Pack 2 (KB867461)
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {78705f0d-e8db-4b2d-8193-982bdda15ecd} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {9BFBE94F-2FAF-11D6-8712-0002B3281F8B} - Microsoft .NET Framework 1.0 Service Pack 1 (KB867461)
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {D82A39FB-1784-4608-BFE8-1ACBFF3079C1} - Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
ActiveX: {F279058C-50B2-4BE4-60C9-369CACF06821} - .NET Framework
ActiveX: {gNlHvcTl-X3Rf-glhX-zEHE-R7LhQcT46ee6} -
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 10
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.04 18:35:41 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.06.01 13:28:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\WLANProfiles
[2012.06.01 10:59:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Malwarebytes
[2012.06.01 10:59:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.06.01 10:59:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.06.01 10:59:32 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.06.01 10:59:31 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.06.01 10:55:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Macromedia
[2012.06.01 10:53:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Adobe
[2012.06.01 10:48:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\IECompatCache
[2012.06.01 10:48:12 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\PrivacIE
[2012.06.01 10:48:05 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\IETldCache
[2012.06.01 10:36:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012.06.01 10:33:44 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Microsoft
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Zubehör
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\SendTo
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Recent
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Favoriten
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Autostart
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten
[2012.06.01 10:33:44 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\Cookies
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Vorlagen
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Netzwerkumgebung
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Identities
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Help
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Druckumgebung
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Desktop
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\ApplicationHistory
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\Eigene Musik
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\Eigene Bilder
[2012.06.01 10:33:43 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\WINDOWS
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\My eBooks
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\Microsoft
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\Help
[2012.06.01 10:01:30 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.05.31 09:38:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012.05.30 10:23:04 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.05 17:55:10 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.06.05 17:54:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.06.05 17:53:26 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2012.06.05 17:53:02 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
[2012.06.05 17:49:02 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{75D58719-DDB3-4148-9293-592056842A0B}.job
[2012.06.05 17:29:02 | 000,001,106 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.05 07:28:02 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.05 07:18:12 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2012.06.01 10:59:36 | 000,000,664 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.01 10:44:26 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.01 10:59:34 | 000,000,664 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.01 10:48:21 | 000,000,416 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
[2012.06.01 10:33:46 | 000,001,507 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Remoteunterstützung.lnk
[2012.06.01 10:33:46 | 000,000,655 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Internet Explorer.lnk
[2012.06.01 10:33:46 | 000,000,626 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Outlook Express.lnk
[2012.06.01 10:33:45 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2012.02.18 08:48:44 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2011.05.29 18:20:28 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2010.12.18 09:40:57 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.11.07 09:35:48 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.10.31 00:01:12 | 000,000,012 | ---- | C] () -- C:\WINDOWS\bthservsdp.dat
 
========== LOP Check ==========
 
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Default User\Anwendungsdaten\InterTrust
[2009.06.07 15:52:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LightScribe
[2009.06.29 19:06:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Pinnacle
[2011.02.13 12:48:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2011.02.13 12:49:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011.06.08 10:46:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MFAData
[2011.06.08 10:49:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files
[2011.06.08 11:54:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canneverbe Limited
[2011.06.08 19:16:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM
[2009.06.21 23:44:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Bytemobile
[2010.11.21 22:15:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\3DataManager
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\InterTrust
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\InterTrust
[2008.03.09 22:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\MAGIX
[2010.03.13 09:45:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\3DataManager
[2010.10.31 20:52:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\Bytemobile
[2011.06.19 21:16:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\Programme
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\InterTrust
[2009.06.20 08:59:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\MAGIX
[2010.10.31 17:45:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Bytemobile
[2010.11.21 17:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Programme
[2010.12.03 14:41:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Notepad++
[2011.01.17 19:21:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Thunderbird
[2011.01.17 19:58:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Netviewer
[2011.02.13 12:49:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\PC Suite
[2011.02.13 14:41:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\PriceGong
[2011.04.05 21:23:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\GetRightToGo
[2011.05.31 17:14:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\3DataManager
[2011.06.08 11:53:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\OpenCandy
[2011.06.08 11:54:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Canneverbe Limited
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2012.06.05 07:18:12 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
[2012.06.05 17:49:02 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{75D58719-DDB3-4148-9293-592056842A0B}.job
[2012.06.05 17:53:02 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
[2010.10.11 13:51:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Application Data\Office Genuine Advantage
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2003.02.23 11:05:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Identities
[2003.02.23 11:08:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Help
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2003.02.23 10:16:26 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Microsoft
[2012.06.01 10:53:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Adobe
[2012.06.01 10:55:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Macromedia
[2012.06.01 10:59:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Malwarebytes
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\AGP440.SYS
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001.08.17 13:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2002.08.29 12:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 00:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002.08.29 12:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2002.08.29 12:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\netlogon.dll
[2004.08.04 00:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 00:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002.08.29 12:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\scecli.dll
 
< MD5 for: USER32.DLL  >
[2005.03.02 19:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll
[2007.03.08 16:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 19:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2007.03.08 16:48:40 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2008.04.14 04:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
[2002.08.29 12:00:00 | 000,561,664 | ---- | M] (Microsoft Corporation) MD5=E3DAFFDB1C86C1AEAC1B205F6CF67009 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2002.08.29 12:00:00 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\userinit.exe
[2004.08.04 00:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004.08.04 00:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002.08.29 12:00:00 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\winlogon.exe
[2008.04.14 04:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2002.08.29 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2002.08.29 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2003.02.23 10:15:32 | 000,413,696 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2003.02.23 10:15:32 | 000,630,784 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2003.02.23 10:15:32 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >

< End of report >

--- --- ---

cosinus 05.06.2012 19:41

Zitat:

Boot Mode: SafeMode with Networking
Wieso in diesem Modus? Geht der normale noch nicht?

Kornty 06.06.2012 09:00

ich kann nur über taskmanager programme ausführen und bekomme keinen desktop angezeigt.


OTL Logfile:
Code:

OTL logfile created on: 06.06.2012 09:17:44 - Run 3
OTL by OldTimer - Version 3.2.45.0    Folder = D:\Igor-IT\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
510,98 Mb Total Physical Memory | 90,61 Mb Available Physical Memory | 17,73% Memory free
1,22 Gb Paging File | 0,85 Gb Available in Paging File | 69,52% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 29,92 Gb Total Space | 12,62 Gb Free Space | 42,19% Space Free | Partition Type: FAT32
Drive D: | 7,31 Gb Total Space | 7,30 Gb Free Space | 99,86% Space Free | Partition Type: FAT32
 
Computer Name: ACER-PLALZYB8F0 | User Name: Igor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - D:\Igor-IT\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\update.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\3DataManager\WTGService.exe ()
PRC - C:\Programme\tele.ring Internet Manager\AssistantServices.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel)
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Programme\Avira\AntiVir Desktop\scewxmlw.dll ()
MOD - C:\Programme\3DataManager\WTGService.exe ()
MOD - C:\Programme\tele.ring Internet Manager\AssistantServices.exe ()
MOD - C:\WINDOWS\system32\LsaWrApi.dll ()
MOD - C:\WINDOWS\system32\C1XStngs.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe File not found
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira GmbH)
SRV - (AntiVirMailService) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WTGService) -- C:\Programme\3DataManager\WTGService.exe ()
SRV - (UI Assistant Service) -- C:\Programme\tele.ring Internet Manager\AssistantServices.exe ()
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (TlntSvr) -- C:\WINDOWS\system32\tlntsvr.exe (Microsoft Corporation)
SRV - (NetDDEdsdm) -- C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (NetDDE) -- C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (ClipSrv) -- C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation)
SRV - (RemoteAccess) -- C:\WINDOWS\system32\mprdim.dll (Microsoft Corporation)
SRV - (Messenger) -- C:\WINDOWS\system32\msgsvc.dll (Microsoft Corporation)
SRV - (Alerter) -- C:\WINDOWS\system32\alrsvc.dll (Microsoft Corporation)
SRV - (S24EventMonitor) -- C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) -- C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (NetSvc) -- C:\Programme\Intel\NCS\Sync\NetSvc.exe (Intel(R) Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (upperdev) -- system32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (StarOpen) --  File not found
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- system32\DRIVERS\LV561AV.SYS File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (MpKslf89215e6) -- c:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Microsoft Antimalware\Definition Updates\{D551FFA7-1469-4E71-9D18-E35A2D37695F}\MpKslf89215e6.sys File not found
DRV - (LVUSBSta) -- system32\drivers\LVUSBSta.sys File not found
DRV - (lbrtfdc) --  File not found
DRV - (i2omgmt) --  File not found
DRV - (hwusbfake) -- system32\DRIVERS\ewusbfake.sys File not found
DRV - (Changer) --  File not found
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (hwusbdev) -- C:\WINDOWS\system32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbnmea) -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (BMLoad) -- C:\WINDOWS\system32\drivers\BMLoad.sys (Bytemobile, Inc.)
DRV - (tcpipBM) -- C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (dmboot) -- C:\WINDOWS\system32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
DRV - (Ntfs) -- C:\WINDOWS\System32\drivers\ntfs.sys (Microsoft Corporation)
DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (Udfs) -- C:\WINDOWS\System32\drivers\udfs.sys (Microsoft Corporation)
DRV - (ACEDRV05) -- C:\WINDOWS\system32\drivers\ACEDRV05.sys (Protect Software GmbH)
DRV - (w70n51) Intel(R) -- C:\WINDOWS\system32\drivers\w70n51.sys (Intel® Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (acernbm) -- C:\WINDOWS\system32\drivers\acernbm.sys ()
DRV - (CONAN) -- C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro )
DRV - (LEX_AS_NIC_SERVICE) -- C:\WINDOWS\system32\drivers\Expsab2.sys (LAN-Express)
DRV - (mbxfilt) -- C:\WINDOWS\system32\drivers\mbxfilt.sys (O2 Micro)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (O2SCBUS) -- C:\WINDOWS\system32\drivers\ozscr.sys (O2Micro)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (cbidf2k) -- C:\WINDOWS\System32\drivers\cbidf2k.sys (Microsoft Corporation)
DRV - (Asapi) -- C:\WINDOWS\System32\drivers\asapi.sys (VOB Computersysteme GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=31711dea00000000000000042379ac98&tlver=1.4.19.19&affID=19405
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.acer.com
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Programme\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\ff-bmboc@bytemobile.com: C:\Programme\3-addons\addon [2011.05.31 17:09:50 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2012.06.05 19:01:46 | 000,000,818 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll File not found
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKU\.DEFAULT..\Run: [DWQueuedReporting] c:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [DWQueuedReporting] c:\Programme\Gemeinsame Dateien\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006..\RunOnce: [NeroHomeFirstStart] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20F30040-FA66-439C-AF09-410461E2F9B7}: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B5CDAA1-5F88-459B-A06B-67EA91370CDC}: DhcpNameServer = 195.34.133.21 195.34.133.22
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\ArchiverforWin.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\ArchiverforWin.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\Sebring: DllName - (C:\WINDOWS\System32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpReg: AcerNotebookManager - hkey= - key= - C:\Programme\Acer\Notebook Manager\almxptray.exe (Acer)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AGRSMMSG - hkey= - key= - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
MsConfig - StartUpReg: B64Fu7wxCKTba7x - hkey= - key= -  File not found
MsConfig - StartUpReg: BluetoothAuthenticationAgent - hkey= - key= -  File not found
MsConfig - StartUpReg: LaunchApp - hkey= - key= - C:\WINDOWS\Alaunch.exe (Acer Inc.)
MsConfig - StartUpReg: LManager - hkey= - key= - C:\Programme\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
MsConfig - StartUpReg: PRONoMgr.exe - hkey= - key= - C:\Programme\Intel\NCS\PROSet\PRONoMgr.exe (Intel(R) Corporation)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\qttask.exe (Apple Inc.)
MsConfig - StartUpReg: SoundMan - hkey= - key= - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
MsConfig - StartUpReg: SweetIM - hkey= - key= - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
MsConfig - StartUpReg: UIExec - hkey= - key= - C:\Programme\tele.ring Internet Manager\UIExec.exe ()
MsConfig - StartUpReg: ZCfgSvc.exe - hkey= - key= -  File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {1325db73-d9f1-48f8-8895-6d814ec58889} - Sicherheitsupdate für Windows XP (KB913433)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {588A559B-BBC9-4148-A2C0-96A33D1DBC26} - Microsoft .NET Framework 1.0 Hotfix (KB928367)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {65289DE3-4C1A-11D6-B6E1-00B0D049139F} - Microsoft .NET Framework 1.0 Service Pack 2 (KB867461)
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {78705f0d-e8db-4b2d-8193-982bdda15ecd} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {9BFBE94F-2FAF-11D6-8712-0002B3281F8B} - Microsoft .NET Framework 1.0 Service Pack 1 (KB867461)
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {D82A39FB-1784-4608-BFE8-1ACBFF3079C1} - Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
ActiveX: {F279058C-50B2-4BE4-60C9-369CACF06821} - .NET Framework
ActiveX: {gNlHvcTl-X3Rf-glhX-zEHE-R7LhQcT46ee6} -
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.04 18:35:41 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.06.01 13:28:38 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Igor\WLANProfiles
[2012.06.01 10:59:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Malwarebytes
[2012.06.01 10:59:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.06.01 10:59:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.06.01 10:59:32 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.06.01 10:59:31 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.06.01 10:55:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Macromedia
[2012.06.01 10:53:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Adobe
[2012.06.01 10:48:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\IECompatCache
[2012.06.01 10:48:12 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\PrivacIE
[2012.06.01 10:48:05 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\IETldCache
[2012.06.01 10:36:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012.06.01 10:33:44 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Microsoft
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Zubehör
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\SendTo
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Recent
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Favoriten
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Autostart
[2012.06.01 10:33:44 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten
[2012.06.01 10:33:44 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Igor\Cookies
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Vorlagen
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Netzwerkumgebung
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Identities
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Help
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Druckumgebung
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Desktop
[2012.06.01 10:33:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\ApplicationHistory
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\Eigene Musik
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien
[2012.06.01 10:33:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\Eigene Bilder
[2012.06.01 10:33:43 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\WINDOWS
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Eigene Dateien\My eBooks
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\Microsoft
[2012.06.01 10:33:43 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\Help
[2012.06.01 10:01:30 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.05.31 09:38:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012.05.30 10:23:04 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.06 09:39:02 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{75D58719-DDB3-4148-9293-592056842A0B}.job
[2012.06.06 09:38:02 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
[2012.06.06 09:29:02 | 000,001,106 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.06 09:15:08 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.06.06 09:14:18 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.06 09:14:18 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2012.06.06 09:14:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.06.05 17:53:26 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2012.06.01 10:59:36 | 000,000,664 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.01 10:44:26 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.01 10:59:34 | 000,000,664 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.01 10:48:21 | 000,000,416 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
[2012.06.01 10:33:46 | 000,001,507 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Remoteunterstützung.lnk
[2012.06.01 10:33:46 | 000,000,655 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Internet Explorer.lnk
[2012.06.01 10:33:46 | 000,000,626 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Startmenü\Programme\Outlook Express.lnk
[2012.06.01 10:33:45 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Igor\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2012.02.18 08:48:44 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2011.05.29 18:20:28 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2010.12.18 09:40:57 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.11.07 09:35:48 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.10.31 00:01:12 | 000,000,012 | ---- | C] () -- C:\WINDOWS\bthservsdp.dat
 
========== LOP Check ==========
 
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Default User\Anwendungsdaten\InterTrust
[2009.06.07 15:52:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LightScribe
[2009.06.29 19:06:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Pinnacle
[2011.02.13 12:48:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2011.02.13 12:49:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011.06.08 10:46:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MFAData
[2011.06.08 10:49:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files
[2011.06.08 11:54:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canneverbe Limited
[2011.06.08 19:16:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM
[2009.06.21 23:44:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Bytemobile
[2010.11.21 22:15:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\3DataManager
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\InterTrust
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\InterTrust
[2008.03.09 22:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\MAGIX
[2010.03.13 09:45:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\3DataManager
[2010.10.31 20:52:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\Bytemobile
[2011.06.19 21:16:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\doris\Anwendungsdaten\Programme
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\InterTrust
[2009.06.20 08:59:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\MAGIX
[2010.10.31 17:45:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Bytemobile
[2010.11.21 17:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Programme
[2010.12.03 14:41:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Notepad++
[2011.01.17 19:21:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Thunderbird
[2011.01.17 19:58:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Netviewer
[2011.02.13 12:49:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\PC Suite
[2011.02.13 14:41:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\PriceGong
[2011.04.05 21:23:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\GetRightToGo
[2011.05.31 17:14:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\3DataManager
[2011.06.08 11:53:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\OpenCandy
[2011.06.08 11:54:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Oberpullendorf\Anwendungsdaten\Canneverbe Limited
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2012.06.06 09:14:18 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
[2012.06.06 09:39:02 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{75D58719-DDB3-4148-9293-592056842A0B}.job
[2012.06.06 09:38:02 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D40CFB35-F5FA-473F-8E4F-95AD0ABDFE45}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
[2010.10.11 13:51:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Application Data\Office Genuine Advantage
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2003.02.23 11:05:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Identities
[2003.02.23 11:08:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Help
[2003.02.23 11:17:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\InterTrust
[2003.02.23 10:16:26 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Microsoft
[2012.06.01 10:53:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Adobe
[2012.06.01 10:55:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Macromedia
[2012.06.01 10:59:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Igor\Anwendungsdaten\Malwarebytes
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\AGP440.SYS
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001.08.17 13:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2002.08.29 12:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010.10.12 07:28:24 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 00:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002.08.29 12:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 04:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2002.08.29 12:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\netlogon.dll
[2004.08.04 00:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 04:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 00:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002.08.29 12:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\scecli.dll
 
< MD5 for: USER32.DLL  >
[2005.03.02 19:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll
[2007.03.08 16:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 19:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2007.03.08 16:48:40 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2008.04.14 04:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
[2002.08.29 12:00:00 | 000,561,664 | ---- | M] (Microsoft Corporation) MD5=E3DAFFDB1C86C1AEAC1B205F6CF67009 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 04:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2002.08.29 12:00:00 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\userinit.exe
[2004.08.04 00:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004.08.04 00:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002.08.29 12:00:00 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\WINDOWS\SoftwareDistribution\Download\0aa6f42a4dd3d56906fedce124be80cb\backup\winlogon.exe
[2008.04.14 04:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2002.08.29 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2002.08.29 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2003.02.23 10:15:32 | 000,413,696 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2003.02.23 10:15:32 | 000,630,784 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2003.02.23 10:15:32 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >

< End of report >

--- --- ---

cosinus 06.06.2012 13:10

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll File not found
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll File not found
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006..\RunOnce: [NeroHomeFirstStart] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
MsConfig - StartUpReg: SweetIM - hkey= - key= - C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
:Files
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM
C:\Programme\Conduit*
C:\Programme\SweetIM
C:\Programme\softonic*
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Kornty 06.06.2012 15:31

noch immer kein Desktop.

Code:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ deleted successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll moved successfully.
HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully.
C:\Programme\softonic-de3\prxtbsof0.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ not found.
File de3\prxtbsof0.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ deleted successfully.
File C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found.
File C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NeroHomeFirstStart deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found.
Registry value HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1453689397-1417066420-3376078148-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SweetIM\ deleted successfully.
========== FILES ==========
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Toolbars\Internet Explorer\cache folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Toolbars\Internet Explorer folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Toolbars folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\conf\users folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\conf folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\update folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\logs folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\data\contentdb folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\data\Bars\Default folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\data\Bars folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger\data folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM\Messenger folder moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM folder moved successfully.
File\Folder C:\Programme\Conduit* not found.
C:\Programme\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\conf folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\orange folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\green folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\blue folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer\resources folder moved successfully.
C:\Programme\SweetIM\Toolbars\Internet Explorer folder moved successfully.
C:\Programme\SweetIM\Toolbars folder moved successfully.
C:\Programme\SweetIM\Messenger\resources\images folder moved successfully.
C:\Programme\SweetIM\Messenger\resources folder moved successfully.
C:\Programme\SweetIM\Messenger folder moved successfully.
C:\Programme\SweetIM folder moved successfully.
C:\Programme\softonic-de3 folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Default User
 
User: All Users
 
User: NetworkService
->Temp folder emptied: 12270 bytes
->Temporary Internet Files folder emptied: 33237 bytes
 
User: LocalService
->Temp folder emptied: 190537 bytes
->Temporary Internet Files folder emptied: 3803911 bytes
 
User: Administrator
 
User: doris
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 14415881 bytes
->FireFox cache emptied: 54463656 bytes
->Flash cache emptied: 22438 bytes
 
User: Oberpullendorf
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 98711147 bytes
->Java cache emptied: 176241 bytes
->FireFox cache emptied: 14565727 bytes
->Google Chrome cache emptied: 6083672 bytes
->Flash cache emptied: 45862 bytes
 
User: Igor
->Temp folder emptied: 180224 bytes
->Temporary Internet Files folder emptied: 21146682 bytes
->Flash cache emptied: 515 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 39097 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 27768752 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 230,00 mb
 
 
[EMPTYFLASH]
 
User: Default User
 
User: All Users
 
User: NetworkService
 
User: LocalService
 
User: Administrator
 
User: doris
->Flash cache emptied: 0 bytes
 
User: Oberpullendorf
->Flash cache emptied: 0 bytes
 
User: Igor
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.45.0 log created on 06062012_161952


cosinus 06.06.2012 15:42

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

Kornty 06.06.2012 16:50

Code:

17:43:05.0248 3180        TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
17:43:05.0529 3180        ============================================================
17:43:05.0529 3180        Current date / time: 2012/06/06 17:43:05.0529
17:43:05.0529 3180        SystemInfo:
17:43:05.0529 3180       
17:43:05.0529 3180        OS Version: 5.1.2600 ServicePack: 3.0
17:43:05.0529 3180        Product type: Workstation
17:43:05.0529 3180        ComputerName: ACER-PLALZYB8F0
17:43:05.0529 3180        UserName: Igor
17:43:05.0529 3180        Windows directory: C:\WINDOWS
17:43:05.0529 3180        System windows directory: C:\WINDOWS
17:43:05.0529 3180        Processor architecture: Intel x86
17:43:05.0529 3180        Number of processors: 1
17:43:05.0529 3180        Page size: 0x1000
17:43:05.0529 3180        Boot type: Normal boot
17:43:05.0529 3180        ============================================================
17:43:07.0822 3180        Drive \Device\Harddisk0\DR0 - Size: 0x950A60000 (37.26 Gb), SectorSize: 0x200, Cylinders: 0x1300, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
17:43:07.0822 3180        ============================================================
17:43:07.0822 3180        \Device\Harddisk0\DR0:
17:43:07.0822 3180        MBR partitions:
17:43:07.0822 3180        \Device\Harddisk0\DR0\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x3BDFA05
17:43:07.0822 3180        \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x3BDFA44, BlocksNum 0xEA58BC
17:43:07.0822 3180        ============================================================
17:43:07.0852 3180        C: <-> \Device\Harddisk0\DR0\Partition0
17:43:07.0862 3180        D: <-> \Device\Harddisk0\DR0\Partition1
17:43:07.0962 3180        ============================================================
17:43:07.0962 3180        Initialize success
17:43:07.0962 3180        ============================================================
17:45:59.0609 2096        ============================================================
17:45:59.0609 2096        Scan started
17:45:59.0609 2096        Mode: Manual; SigCheck; TDLFS;
17:45:59.0609 2096        ============================================================
17:46:00.0330 2096        Abiosdsk - ok
17:46:00.0370 2096        abp480n5 - ok
17:46:00.0470 2096        ACEDRV05        (0a1e97197609f92d2425b67da0bb0a7f) C:\WINDOWS\System32\drivers\ACEDRV05.sys
17:46:00.0821 2096        ACEDRV05 ( UnsignedFile.Multi.Generic ) - warning
17:46:00.0821 2096        ACEDRV05 - detected UnsignedFile.Multi.Generic (1)
17:46:00.0881 2096        acernbm        (1f056a9dc1e5941b064907a1869ee230) C:\WINDOWS\system32\drivers\acernbm.sys
17:46:00.0901 2096        acernbm ( UnsignedFile.Multi.Generic ) - warning
17:46:00.0901 2096        acernbm - detected UnsignedFile.Multi.Generic (1)
17:46:01.0021 2096        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:46:02.0393 2096        ACPI - ok
17:46:02.0453 2096        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
17:46:02.0613 2096        ACPIEC - ok
17:46:02.0634 2096        adpu160m - ok
17:46:02.0774 2096        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:46:02.0974 2096        aec - ok
17:46:03.0054 2096        AegisP          (f64a0e456d08e6cda801fe13a5996e86) C:\WINDOWS\system32\DRIVERS\AegisP.sys
17:46:03.0094 2096        AegisP ( UnsignedFile.Multi.Generic ) - warning
17:46:03.0094 2096        AegisP - detected UnsignedFile.Multi.Generic (1)
17:46:03.0164 2096        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:46:03.0254 2096        AFD - ok
17:46:03.0405 2096        AgereSoftModem  (ed5c8b22de2021339a7c7fccfe5c5d7e) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
17:46:03.0555 2096        AgereSoftModem - ok
17:46:03.0605 2096        agp440          (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
17:46:03.0875 2096        agp440 - ok
17:46:03.0915 2096        Aha154x - ok
17:46:03.0935 2096        aic78u2 - ok
17:46:03.0975 2096        aic78xx - ok
17:46:04.0116 2096        ALCXWDM        (e3e7c0f401e7024e8dc0dbe3ce7dcd59) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
17:46:04.0236 2096        ALCXWDM - ok
17:46:04.0386 2096        Alerter        (738d80cc01d7bc7584be917b7f544394) C:\WINDOWS\system32\alrsvc.dll
17:46:04.0576 2096        Alerter - ok
17:46:04.0636 2096        ALG            (190cd73d4984f94d823f9444980513e5) C:\WINDOWS\System32\alg.exe
17:46:04.0837 2096        ALG - ok
17:46:04.0857 2096        AliIde - ok
17:46:04.0897 2096        amsint - ok
17:46:05.0097 2096        AntiVirMailService (d1d8e6ad41a8d948e1c2c1ec2bf8ad20) C:\Programme\Avira\AntiVir Desktop\avmailc.exe
17:46:05.0127 2096        AntiVirMailService - ok
17:46:05.0187 2096        AntiVirSchedulerService (b3e6fde223f21f5d477087f71db27de9) C:\Programme\Avira\AntiVir Desktop\sched.exe
17:46:05.0197 2096        AntiVirSchedulerService - ok
17:46:05.0267 2096        AntiVirService  (ff4d522213d4ee19f166dff157ffd490) C:\Programme\Avira\AntiVir Desktop\avguard.exe
17:46:05.0307 2096        AntiVirService - ok
17:46:05.0397 2096        AntiVirWebService (ebaac0fb8c09ba0b14e9da6822e1bec7) C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE
17:46:05.0428 2096        AntiVirWebService - ok
17:46:05.0488 2096        AppMgmt        (d45960be52c3c610d361977057f98c54) C:\WINDOWS\System32\appmgmts.dll
17:46:05.0718 2096        AppMgmt - ok
17:46:05.0778 2096        Arp1394        (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
17:46:05.0978 2096        Arp1394 - ok
17:46:06.0058 2096        Asapi          (875f9079cabee679d34b49e466b61701) C:\WINDOWS\system32\drivers\Asapi.sys
17:46:06.0078 2096        Asapi ( UnsignedFile.Multi.Generic ) - warning
17:46:06.0078 2096        Asapi - detected UnsignedFile.Multi.Generic (1)
17:46:06.0119 2096        asc - ok
17:46:06.0159 2096        asc3350p - ok
17:46:06.0199 2096        asc3550 - ok
17:46:06.0479 2096        aspnet_state    (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
17:46:06.0499 2096        aspnet_state - ok
17:46:06.0539 2096        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:46:06.0719 2096        AsyncMac - ok
17:46:06.0890 2096        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:46:07.0100 2096        atapi - ok
17:46:07.0140 2096        Atdisk - ok
17:46:07.0210 2096        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:46:07.0360 2096        Atmarpc - ok
17:46:07.0480 2096        AudioSrv        (58ed0d5452df7be732193e7999c6b9a4) C:\WINDOWS\System32\audiosrv.dll
17:46:07.0691 2096        AudioSrv - ok
17:46:07.0751 2096        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:46:07.0961 2096        audstub - ok
17:46:08.0061 2096        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
17:46:08.0071 2096        avgio - ok
17:46:08.0141 2096        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
17:46:08.0232 2096        avgntflt - ok
17:46:08.0282 2096        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
17:46:08.0292 2096        avipbb - ok
17:46:08.0402 2096        bcm4sbxp        (ba03a18635d4b0830c9262cd80d4026b) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
17:46:08.0462 2096        bcm4sbxp - ok
17:46:08.0522 2096        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:46:08.0752 2096        Beep - ok
17:46:08.0923 2096        BITS            (d6f603772a789bb3228f310d650b8bd1) C:\WINDOWS\system32\qmgr.dll
17:46:09.0143 2096        BITS - ok
17:46:09.0273 2096        BMLoad          (d002033c1a37f6af51b5f0ba6d0211bc) C:\WINDOWS\system32\drivers\BMLoad.sys
17:46:09.0293 2096        BMLoad ( UnsignedFile.Multi.Generic ) - warning
17:46:09.0293 2096        BMLoad - detected UnsignedFile.Multi.Generic (1)
17:46:09.0393 2096        Browser        (b42057f06bbb98b31876c0b3f2b54e33) C:\WINDOWS\System32\browser.dll
17:46:09.0614 2096        Browser - ok
17:46:09.0654 2096        BthEnum        (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
17:46:09.0894 2096        BthEnum - ok
17:46:09.0934 2096        BthPan          (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
17:46:10.0134 2096        BthPan - ok
17:46:10.0285 2096        BTHPORT        (592e1cedbe314d0ef184dc6f46141e76) C:\WINDOWS\system32\Drivers\BTHport.sys
17:46:10.0335 2096        BTHPORT - ok
17:46:10.0415 2096        BthServ        (26c601ef7525e31379744abfc6f35a1b) C:\WINDOWS\System32\bthserv.dll
17:46:10.0605 2096        BthServ - ok
17:46:10.0655 2096        BTHUSB          (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
17:46:10.0885 2096        BTHUSB - ok
17:46:10.0976 2096        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:46:11.0166 2096        cbidf2k - ok
17:46:11.0286 2096        CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:46:11.0456 2096        CCDECODE - ok
17:46:11.0486 2096        cd20xrnt - ok
17:46:11.0556 2096        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:46:11.0757 2096        Cdaudio - ok
17:46:11.0877 2096        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:46:12.0037 2096        Cdfs - ok
17:46:12.0167 2096        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:46:12.0337 2096        Cdrom - ok
17:46:12.0358 2096        Changer - ok
17:46:12.0478 2096        CiSvc          (28e3040d1f1ca2008cd6b29dfebc9a5e) C:\WINDOWS\system32\cisvc.exe
17:46:12.0678 2096        CiSvc - ok
17:46:12.0758 2096        ClipSrv        (778a30ed3c134eb7e406afc407e9997d) C:\WINDOWS\system32\clipsrv.exe
17:46:12.0968 2096        ClipSrv - ok
17:46:13.0079 2096        clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:46:13.0119 2096        clr_optimization_v2.0.50727_32 - ok
17:46:13.0159 2096        CmBatt          (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
17:46:13.0329 2096        CmBatt - ok
17:46:13.0369 2096        CmdIde - ok
17:46:13.0459 2096        Compbatt        (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
17:46:13.0619 2096        Compbatt - ok
17:46:13.0679 2096        COMSysApp - ok
17:46:13.0800 2096        CONAN          (765255876a4b5b2dc3e10a846aa9269a) C:\WINDOWS\system32\drivers\o2mmb.sys
17:46:13.0870 2096        CONAN - ok
17:46:13.0940 2096        Cpqarray - ok
17:46:14.0030 2096        CryptSvc        (611f824e5c703a5a899f84c5f1699e4d) C:\WINDOWS\System32\cryptsvc.dll
17:46:14.0190 2096        CryptSvc - ok
17:46:14.0210 2096        dac2w2k - ok
17:46:14.0230 2096        dac960nt - ok
17:46:14.0380 2096        DcomLaunch      (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
17:46:14.0531 2096        DcomLaunch - ok
17:46:14.0651 2096        Dhcp            (c29a1c9b75ba38fa37f8c44405dec360) C:\WINDOWS\System32\dhcpcsvc.dll
17:46:14.0861 2096        Dhcp - ok
17:46:15.0202 2096        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:46:15.0392 2096        Disk - ok
17:46:15.0472 2096        DKbFltr        (96a48bda68bf734aae79f910ab884a34) C:\WINDOWS\system32\Drivers\DKbFltr.sys
17:46:15.0492 2096        DKbFltr ( UnsignedFile.Multi.Generic ) - warning
17:46:15.0492 2096        DKbFltr - detected UnsignedFile.Multi.Generic (1)
17:46:15.0572 2096        dmadmin - ok
17:46:15.0692 2096        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
17:46:15.0943 2096        dmboot - ok
17:46:16.0093 2096        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
17:46:16.0273 2096        dmio - ok
17:46:16.0373 2096        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:46:16.0564 2096        dmload - ok
17:46:16.0634 2096        dmserver        (25c83ffbba13b554eb6d59a9b2e2ee78) C:\WINDOWS\System32\dmserver.dll
17:46:16.0784 2096        dmserver - ok
17:46:16.0874 2096        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:46:17.0044 2096        DMusic - ok
17:46:17.0194 2096        Dnscache        (407f3227ac618fd1ca54b335b083de07) C:\WINDOWS\System32\dnsrslvr.dll
17:46:17.0235 2096        Dnscache - ok
17:46:17.0345 2096        Dot3svc        (676e36c4ff5bcea1900f44182b9723e6) C:\WINDOWS\System32\dot3svc.dll
17:46:17.0525 2096        Dot3svc - ok
17:46:17.0555 2096        dpti2o - ok
17:46:17.0665 2096        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:46:17.0966 2096        drmkaud - ok
17:46:18.0036 2096        EapHost        (4e4f2fddab0a0736d7671134dcce91fb) C:\WINDOWS\System32\eapsvc.dll
17:46:18.0266 2096        EapHost - ok
17:46:18.0376 2096        ERSvc          (877c18558d70587aa7823a1a308ac96b) C:\WINDOWS\System32\ersvc.dll
17:46:18.0757 2096        ERSvc - ok
17:46:18.0807 2096        Eventlog        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
17:46:18.0897 2096        Eventlog - ok
17:46:18.0997 2096        EventSystem    (af4f6b5739d18ca7972ab53e091cbc74) C:\WINDOWS\System32\es.dll
17:46:19.0057 2096        EventSystem - ok
17:46:19.0107 2096        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:46:19.0287 2096        Fastfat - ok
17:46:19.0398 2096        FastUserSwitchingCompatibility (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:46:19.0478 2096        FastUserSwitchingCompatibility - ok
17:46:19.0568 2096        Fax            (08b8b302af0d1b3b8543429bbac8f21f) C:\WINDOWS\system32\fxssvc.exe
17:46:19.0748 2096        Fax - ok
17:46:19.0858 2096        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:46:20.0079 2096        Fdc - ok
17:46:20.0169 2096        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
17:46:20.0359 2096        Fips - ok
17:46:20.0479 2096        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:46:20.0659 2096        Flpydisk - ok
17:46:20.0790 2096        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:46:20.0970 2096        FltMgr - ok
17:46:21.0220 2096        FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
17:46:21.0230 2096        FontCache3.0.0.0 - ok
17:46:21.0280 2096        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:46:21.0491 2096        Fs_Rec - ok
17:46:21.0591 2096        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:46:21.0831 2096        Ftdisk - ok
17:46:21.0881 2096        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:46:22.0081 2096        Gpc - ok
17:46:22.0352 2096        gupdate        (f02a533f517eb38333cb12a9e8963773) C:\Programme\Google\Update\GoogleUpdate.exe
17:46:22.0362 2096        gupdate - ok
17:46:22.0392 2096        gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Programme\Google\Update\GoogleUpdate.exe
17:46:22.0422 2096        gupdatem - ok
17:46:22.0492 2096        helpsvc        (cb66bf85bf599befd6c6a57c2e20357f) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
17:46:22.0702 2096        helpsvc - ok
17:46:22.0823 2096        HidServ        (b35da85e60c0103f2e4104532da2f12b) C:\WINDOWS\System32\hidserv.dll
17:46:23.0073 2096        HidServ - ok
17:46:23.0223 2096        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:46:23.0373 2096        HidUsb - ok
17:46:23.0473 2096        hkmsvc          (ed29f14101523a6e0e808107405d452c) C:\WINDOWS\System32\kmsvc.dll
17:46:23.0644 2096        hkmsvc - ok
17:46:23.0664 2096        hpn - ok
17:46:23.0804 2096        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:46:23.0884 2096        HTTP - ok
17:46:23.0994 2096        HTTPFilter      (9e4adb854cebcfb81a4b36718feecd16) C:\WINDOWS\System32\w3ssl.dll
17:46:24.0154 2096        HTTPFilter - ok
17:46:24.0315 2096        hwdatacard      (0515065a3c7e8869dd01253e987c5bd1) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
17:46:24.0375 2096        hwdatacard - ok
17:46:24.0455 2096        hwusbdev        (ac6b4aabf92867584445d0c435b9248f) C:\WINDOWS\system32\DRIVERS\ewusbdev.sys
17:46:24.0505 2096        hwusbdev - ok
17:46:24.0535 2096        hwusbfake - ok
17:46:24.0575 2096        i2omgmt - ok
17:46:24.0615 2096        i2omp - ok
17:46:24.0695 2096        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:46:24.0916 2096        i8042prt - ok
17:46:25.0106 2096        idsvc          (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:46:25.0166 2096        idsvc - ok
17:46:25.0226 2096        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:46:25.0486 2096        Imapi - ok
17:46:25.0536 2096        ImapiService    (d4b413aa210c21e46aedd2ba5b68d38e) C:\WINDOWS\System32\imapi.exe
17:46:25.0747 2096        ImapiService - ok
17:46:25.0767 2096        ini910u - ok
17:46:25.0897 2096        IntelIde        (69c4e3c9e67a1f103b94e14fdd5f3213) C:\WINDOWS\system32\DRIVERS\intelide.sys
17:46:26.0077 2096        IntelIde - ok
17:46:26.0177 2096        intelppm        (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:46:26.0358 2096        intelppm - ok
17:46:26.0488 2096        ip6fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:46:26.0688 2096        ip6fw - ok
17:46:26.0788 2096        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:46:26.0989 2096        IpFilterDriver - ok
17:46:27.0059 2096        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:46:27.0219 2096        IpInIp - ok
17:46:27.0309 2096        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:46:27.0479 2096        IpNat - ok
17:46:27.0589 2096        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:46:27.0750 2096        IPSec - ok
17:46:27.0890 2096        irda            (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
17:46:28.0030 2096        irda - ok
17:46:28.0180 2096        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:46:28.0330 2096        IRENUM - ok
17:46:28.0391 2096        Irmon          (2efe1db1ec58a26b0c14bfda122e246f) C:\WINDOWS\System32\irmon.dll
17:46:28.0551 2096        Irmon - ok
17:46:28.0701 2096        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:46:28.0851 2096        isapnp - ok
17:46:28.0881 2096        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:46:29.0062 2096        Kbdclass - ok
17:46:29.0202 2096        kbdhid          (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
17:46:29.0352 2096        kbdhid - ok
17:46:29.0492 2096        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:46:29.0743 2096        kmixer - ok
17:46:29.0883 2096        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:46:29.0973 2096        KSecDD - ok
17:46:30.0073 2096        lanmanserver    (2bbdcb79900990f0716dfcb714e72de7) C:\WINDOWS\System32\srvsvc.dll
17:46:30.0123 2096        lanmanserver - ok
17:46:30.0233 2096        lanmanworkstation (1869b14b06b44b44af70548e1ea3303f) C:\WINDOWS\System32\wkssvc.dll
17:46:30.0283 2096        lanmanworkstation - ok
17:46:30.0313 2096        lbrtfdc - ok
17:46:30.0674 2096        LEX_AS_NIC_SERVICE (05271ae7fcf0014dcc6591f145ac2fb0) C:\WINDOWS\system32\DRIVERS\Expsab2.sys
17:46:30.0734 2096        LEX_AS_NIC_SERVICE - ok
17:46:30.0804 2096        LmHosts        (636714b7d43c8d0c80449123fd266920) C:\WINDOWS\System32\lmhsvc.dll
17:46:30.0994 2096        LmHosts - ok
17:46:31.0014 2096        LVUSBSta - ok
17:46:31.0094 2096        massfilter      (567d3cbc0ba3332887d091a237d4fd3c) C:\WINDOWS\system32\drivers\massfilter.sys
17:46:31.0145 2096        massfilter - ok
17:46:31.0215 2096        MBAMProtector  (fb097bbc1a18f044bd17bd2fccf97865) C:\WINDOWS\system32\drivers\mbam.sys
17:46:31.0225 2096        MBAMProtector - ok
17:46:31.0385 2096        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
17:46:31.0455 2096        MBAMService - ok
17:46:31.0515 2096        mbxfilt        (8e82c593b4c46b8a12fe36cba1f1eea9) C:\WINDOWS\system32\drivers\MbxFilt.sys
17:46:31.0545 2096        mbxfilt - ok
17:46:31.0635 2096        Messenger      (b7550a7107281d170ce85524b1488c98) C:\WINDOWS\System32\msgsvc.dll
17:46:31.0856 2096        Messenger - ok
17:46:31.0906 2096        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:46:32.0096 2096        mnmdd - ok
17:46:32.0156 2096        mnmsrvc        (c2f1d365fd96791b037ee504868065d3) C:\WINDOWS\System32\mnmsrvc.exe
17:46:32.0346 2096        mnmsrvc - ok
17:46:32.0386 2096        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
17:46:32.0547 2096        Modem - ok
17:46:32.0587 2096        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:46:32.0847 2096        Mouclass - ok
17:46:33.0067 2096        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:46:33.0258 2096        mouhid - ok
17:46:33.0298 2096        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:46:33.0478 2096        MountMgr - ok
17:46:33.0628 2096        MpKslf89215e6 - ok
17:46:33.0668 2096        mraid35x - ok
17:46:33.0768 2096        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:46:33.0959 2096        MRxDAV - ok
17:46:34.0139 2096        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:46:34.0249 2096        MRxSmb - ok
17:46:34.0309 2096        MSDTC          (35a031af38c55f92d28aa03ee9f12cc9) C:\WINDOWS\System32\msdtc.exe
17:46:34.0509 2096        MSDTC - ok
17:46:34.0610 2096        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:46:34.0800 2096        Msfs - ok
17:46:34.0980 2096        MSIServer - ok
17:46:35.0060 2096        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:46:35.0250 2096        MSKSSRV - ok
17:46:35.0270 2096        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:46:35.0431 2096        MSPCLOCK - ok
17:46:35.0491 2096        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:46:35.0721 2096        MSPQM - ok
17:46:35.0771 2096        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:46:35.0921 2096        mssmbios - ok
17:46:35.0951 2096        MSTEE          (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:46:36.0142 2096        MSTEE - ok
17:46:36.0212 2096        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:46:36.0582 2096        Mup - ok
17:46:36.0632 2096        NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:46:36.0843 2096        NABTSFEC - ok
17:46:36.0953 2096        napagent        (46bb15ae2ac7d025d6d2567b876817bd) C:\WINDOWS\System32\qagentrt.dll
17:46:37.0153 2096        napagent - ok
17:46:37.0203 2096        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:46:37.0383 2096        NDIS - ok
17:46:37.0514 2096        NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:46:37.0684 2096        NdisIP - ok
17:46:37.0824 2096        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:46:37.0884 2096        NdisTapi - ok
17:46:37.0944 2096        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:46:38.0135 2096        Ndisuio - ok
17:46:38.0195 2096        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:46:38.0355 2096        NdisWan - ok
17:46:38.0525 2096        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:46:38.0565 2096        NDProxy - ok
17:46:38.0605 2096        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:46:38.0786 2096        NetBIOS - ok
17:46:38.0906 2096        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:46:39.0096 2096        NetBT - ok
17:46:39.0296 2096        NetDDE          (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
17:46:39.0466 2096        NetDDE - ok
17:46:39.0527 2096        NetDDEdsdm      (8ace4251bffd09ce75679fe940e996cc) C:\WINDOWS\system32\netdde.exe
17:46:39.0667 2096        NetDDEdsdm - ok
17:46:39.0747 2096        Netlogon        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:46:39.0917 2096        Netlogon - ok
17:46:40.0027 2096        Netman          (e6d88f1f6745bf00b57e7855a2ab696c) C:\WINDOWS\System32\netman.dll
17:46:40.0188 2096        Netman - ok
17:46:40.0458 2096        NetSvc          (25d4fd2151185172b6643c94f34f36be) C:\Programme\Intel\NCS\Sync\NetSvc.exe
17:46:40.0478 2096        NetSvc ( UnsignedFile.Multi.Generic ) - warning
17:46:40.0478 2096        NetSvc - detected UnsignedFile.Multi.Generic (1)
17:46:40.0668 2096        NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:46:40.0678 2096        NetTcpPortSharing - ok
17:46:40.0728 2096        NIC1394        (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
17:46:40.0959 2096        NIC1394 - ok
17:46:41.0059 2096        Nla            (f1b67b6b0751ae0e6e964b02821206a3) C:\WINDOWS\System32\mswsock.dll
17:46:41.0109 2096        Nla - ok
17:46:41.0199 2096        NMIndexingService - ok
17:46:41.0299 2096        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:46:41.0469 2096        Npfs - ok
17:46:41.0620 2096        NSCIRDA        (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
17:46:41.0770 2096        NSCIRDA - ok
17:46:41.0950 2096        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:46:42.0220 2096        Ntfs - ok
17:46:42.0311 2096        NTIDrvr        (3c25d8a23c366fbe1511b4a250a1a2ad) C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
17:46:42.0331 2096        NTIDrvr ( UnsignedFile.Multi.Generic ) - warning
17:46:42.0331 2096        NTIDrvr - detected UnsignedFile.Multi.Generic (1)
17:46:42.0361 2096        NtLmSsp        (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:46:42.0541 2096        NtLmSsp - ok
17:46:42.0661 2096        NtmsSvc        (56af4064996fa5bac9c449b1514b4770) C:\WINDOWS\system32\ntmssvc.dll
17:46:42.0851 2096        NtmsSvc - ok
17:46:43.0022 2096        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:46:43.0192 2096        Null - ok
17:46:43.0312 2096        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:46:43.0492 2096        NwlnkFlt - ok
17:46:43.0542 2096        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:46:43.0753 2096        NwlnkFwd - ok
17:46:43.0903 2096        O2SCBUS        (7f8d43fd4159b16ebfd65e13ee34677f) C:\WINDOWS\system32\DRIVERS\ozscr.sys
17:46:43.0953 2096        O2SCBUS - ok
17:46:44.0023 2096        ohci1394        (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
17:46:44.0193 2096        ohci1394 - ok
17:46:44.0414 2096        ose            (7a56cf3e3f12e8af599963b16f50fb6a) C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
17:46:44.0424 2096        ose - ok
17:46:44.0484 2096        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
17:46:44.0694 2096        Parport - ok
17:46:44.0794 2096        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:46:44.0974 2096        PartMgr - ok
17:46:45.0115 2096        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
17:46:45.0315 2096        ParVdm - ok
17:46:45.0385 2096        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
17:46:45.0555 2096        PCI - ok
17:46:45.0585 2096        PCIDump - ok
17:46:45.0725 2096        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:46:45.0906 2096        PCIIde - ok
17:46:46.0026 2096        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
17:46:46.0306 2096        Pcmcia - ok
17:46:46.0356 2096        PDCOMP - ok
17:46:46.0396 2096        PDFRAME - ok
17:46:46.0447 2096        PDRELI - ok
17:46:46.0487 2096        PDRFRAME - ok
17:46:46.0537 2096        perc2 - ok
17:46:46.0577 2096        perc2hib - ok
17:46:46.0727 2096        PID_0928 - ok
17:46:46.0807 2096        PlugPlay        (a3edbe9053889fb24ab22492472b39dc) C:\WINDOWS\system32\services.exe
17:46:46.0867 2096        PlugPlay - ok
17:46:46.0917 2096        PolicyAgent    (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\System32\lsass.exe
17:46:47.0077 2096        PolicyAgent - ok
17:46:47.0117 2096        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:46:47.0288 2096        PptpMiniport - ok
17:46:47.0358 2096        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
17:46:47.0528 2096        Processor - ok
17:46:47.0558 2096        ProtectedStorage (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
17:46:47.0748 2096        ProtectedStorage - ok
17:46:47.0798 2096        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:46:47.0989 2096        PSched - ok
17:46:48.0099 2096        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:46:48.0309 2096        Ptilink - ok
17:46:48.0329 2096        ql1080 - ok
17:46:48.0359 2096        Ql10wnt - ok
17:46:48.0379 2096        ql12160 - ok
17:46:48.0389 2096        ql1240 - ok
17:46:48.0389 2096        ql1280 - ok
17:46:48.0499 2096        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:46:48.0680 2096        RasAcd - ok
17:46:48.0830 2096        RasAuto        (f5ba6caccdb66c8f048e867563203246) C:\WINDOWS\System32\rasauto.dll
17:46:48.0990 2096        RasAuto - ok
17:46:49.0110 2096        Rasirda        (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
17:46:49.0200 2096        Rasirda - ok
17:46:49.0251 2096        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:46:49.0431 2096        Rasl2tp - ok
17:46:49.0531 2096        RasMan          (f9a7b66ea345726edb5862a46b1eccd5) C:\WINDOWS\System32\rasmans.dll
17:46:49.0711 2096        RasMan - ok
17:46:49.0801 2096        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:46:49.0982 2096        RasPppoe - ok
17:46:50.0112 2096        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:46:50.0322 2096        Raspti - ok
17:46:50.0432 2096        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:46:50.0613 2096        Rdbss - ok
17:46:50.0703 2096        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:46:50.0883 2096        RDPCDD - ok
17:46:51.0023 2096        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:46:51.0183 2096        rdpdr - ok
17:46:51.0344 2096        RDPWD          (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
17:46:51.0414 2096        RDPWD - ok
17:46:51.0534 2096        RDSessMgr      (263af18af0f3db99f574c95f284ccec9) C:\WINDOWS\system32\sessmgr.exe
17:46:51.0684 2096        RDSessMgr - ok
17:46:51.0814 2096        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:46:52.0045 2096        redbook - ok
17:46:52.0195 2096        RegSrvc        (51c2342f43e94e959847aa7c2cf4a72b) C:\WINDOWS\System32\RegSrvc.exe
17:46:52.0215 2096        RegSrvc ( UnsignedFile.Multi.Generic ) - warning
17:46:52.0215 2096        RegSrvc - detected UnsignedFile.Multi.Generic (1)
17:46:52.0335 2096        RemoteAccess    (0e97ec96d6942ceec2d188cc2eb69a01) C:\WINDOWS\System32\mprdim.dll
17:46:52.0515 2096        RemoteAccess - ok
17:46:52.0675 2096        RemoteRegistry  (e4cd1f3d84e1c2ca0b8cf7501e201593) C:\WINDOWS\system32\regsvc.dll
17:46:52.0886 2096        RemoteRegistry - ok
17:46:53.0026 2096        RFCOMM          (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
17:46:53.0206 2096        RFCOMM - ok
17:46:53.0326 2096        RpcLocator      (2a02e21867497df20b8fc95631395169) C:\WINDOWS\System32\locator.exe
17:46:53.0487 2096        RpcLocator - ok
17:46:53.0627 2096        RpcSs          (3127afbf2c1ed0ab14a1bbb7aaecb85b) C:\WINDOWS\system32\rpcss.dll
17:46:53.0727 2096        RpcSs - ok
17:46:53.0787 2096        RSVP            (4bdd71b4b521521499dfd14735c4f398) C:\WINDOWS\System32\rsvp.exe
17:46:53.0987 2096        RSVP - ok
17:46:54.0138 2096        S24EventMonitor (52f9b286b360c171da695911fb4bd686) C:\WINDOWS\System32\S24EvMon.exe
17:46:54.0158 2096        S24EventMonitor ( UnsignedFile.Multi.Generic ) - warning
17:46:54.0158 2096        S24EventMonitor - detected UnsignedFile.Multi.Generic (1)
17:46:54.0198 2096        s24trans        (2a61800db21771439ac232cd0d9d1135) C:\WINDOWS\system32\DRIVERS\s24trans.sys
17:46:54.0228 2096        s24trans ( UnsignedFile.Multi.Generic ) - warning
17:46:54.0228 2096        s24trans - detected UnsignedFile.Multi.Generic (1)
17:46:54.0318 2096        SamSs          (afb8261b56cba0d86aeb6df682af9785) C:\WINDOWS\system32\lsass.exe
17:46:54.0478 2096        SamSs - ok
17:46:54.0628 2096        sbp2port        (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys
17:46:54.0819 2096        sbp2port - ok
17:46:54.0919 2096        SCardSvr        (dcec079fad95d36c8dd5cb6d779dfe32) C:\WINDOWS\System32\SCardSvr.exe
17:46:55.0119 2096        SCardSvr - ok
17:46:55.0229 2096        Schedule        (a050194a44d7fa8d7186ed2f4e8367ae) C:\WINDOWS\system32\schedsvc.dll
17:46:55.0379 2096        Schedule - ok
17:46:55.0530 2096        Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:46:55.0670 2096        Secdrv - ok
17:46:55.0810 2096        seclogon        (bee4cfd1d48c23b44cf4b974b0b79b2b) C:\WINDOWS\System32\seclogon.dll
17:46:55.0980 2096        seclogon - ok
17:46:56.0110 2096        SENS            (2aac9b6ed9eddffb721d6452e34d67e3) C:\WINDOWS\system32\sens.dll
17:46:56.0301 2096        SENS - ok
17:46:56.0401 2096        serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:46:56.0591 2096        serenum - ok
17:46:56.0711 2096        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
17:46:56.0892 2096        Serial - ok
17:46:57.0052 2096        ServiceLayer    (dd1328a18712a0b9c9a946ee55a2b1ec) C:\Programme\PC Connectivity Solution\ServiceLayer.exe
17:46:57.0112 2096        ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
17:46:57.0112 2096        ServiceLayer - detected UnsignedFile.Multi.Generic (1)
17:46:57.0232 2096        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:46:57.0412 2096        Sfloppy - ok
17:46:57.0542 2096        SharedAccess    (cad058d5f8b889a87ca3eb3cf624dcef) C:\WINDOWS\System32\ipnathlp.dll
17:46:57.0763 2096        SharedAccess - ok
17:46:57.0863 2096        ShellHWDetection (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:46:57.0933 2096        ShellHWDetection - ok
17:46:57.0953 2096        Simbad - ok
17:46:58.0033 2096        SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:46:58.0223 2096        SLIP - ok
17:46:58.0264 2096        Sparrow - ok
17:46:58.0334 2096        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:46:58.0514 2096        splitter - ok
17:46:58.0644 2096        Spooler        (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
17:46:58.0694 2096        Spooler - ok
17:46:58.0724 2096        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
17:46:58.0874 2096        sr - ok
17:46:59.0025 2096        srservice      (fe77a85495065f3ad59c5c65b6c54182) C:\WINDOWS\System32\srsvc.dll
17:46:59.0185 2096        srservice - ok
17:46:59.0355 2096        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:46:59.0465 2096        Srv - ok
17:46:59.0555 2096        SSDPSRV        (4df5b05dfaec29e13e1ed6f6ee12c500) C:\WINDOWS\System32\ssdpsrv.dll
17:46:59.0716 2096        SSDPSRV - ok
17:46:59.0826 2096        ssmdrv          (5ec550b8952882ee856b862cf648522d) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
17:46:59.0846 2096        ssmdrv - ok
17:46:59.0886 2096        StarOpen - ok
17:46:59.0996 2096        stisvc          (bc2c5985611c5356b24aeb370953ded9) C:\WINDOWS\system32\wiaservc.dll
17:47:00.0186 2096        stisvc - ok
17:47:00.0316 2096        streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:47:00.0477 2096        streamip - ok
17:47:00.0527 2096        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:47:00.0697 2096        swenum - ok
17:47:00.0847 2096        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:47:00.0997 2096        swmidi - ok
17:47:01.0048 2096        SwPrv - ok
17:47:01.0108 2096        symc810 - ok
17:47:01.0138 2096        symc8xx - ok
17:47:01.0178 2096        sym_hi - ok
17:47:01.0228 2096        sym_u3 - ok
17:47:01.0298 2096        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:47:01.0658 2096        sysaudio - ok
17:47:01.0769 2096        SysmonLog      (2903fffa2523926d6219428040dce6b9) C:\WINDOWS\system32\smlogsvc.exe
17:47:01.0939 2096        SysmonLog - ok
17:47:02.0059 2096        TapiSrv        (05903cac4b98908d55ea5774775b382e) C:\WINDOWS\System32\tapisrv.dll
17:47:02.0289 2096        TapiSrv - ok
17:47:02.0419 2096        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:47:02.0440 2096        Tcpip - ok
17:47:02.0510 2096        tcpipBM        (dcfeb82ca988598ceb8f83148616038e) C:\WINDOWS\system32\drivers\tcpipBM.sys
17:47:02.0520 2096        tcpipBM ( UnsignedFile.Multi.Generic ) - warning
17:47:02.0520 2096        tcpipBM - detected UnsignedFile.Multi.Generic (1)
17:47:02.0590 2096        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:47:02.0760 2096        TDPIPE - ok
17:47:02.0790 2096        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:47:02.0970 2096        TDTCP - ok
17:47:03.0141 2096        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:47:03.0331 2096        TermDD - ok
17:47:03.0431 2096        TermService    (b7de02c863d8f5a005a7bf375375a6a4) C:\WINDOWS\System32\termsrv.dll
17:47:03.0631 2096        TermService - ok
17:47:03.0751 2096        Themes          (2db7d303c36ddd055215052f118e8e75) C:\WINDOWS\System32\shsvcs.dll
17:47:03.0771 2096        Themes - ok
17:47:03.0872 2096        TlntSvr        (03681a1ce77f51586903869a5ab1deab) C:\WINDOWS\System32\tlntsvr.exe
17:47:04.0032 2096        TlntSvr - ok
17:47:04.0102 2096        TosIde - ok
17:47:04.0212 2096        TrkWks          (626504572b175867f30f3215c04b3e2f) C:\WINDOWS\system32\trkwks.dll
17:47:04.0412 2096        TrkWks - ok
17:47:04.0523 2096        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:47:04.0703 2096        Udfs - ok
17:47:04.0823 2096        UI Assistant Service (aff98416fa9f0adccae642e5bcf8c1af) C:\Programme\tele.ring Internet Manager\AssistantServices.exe
17:47:04.0853 2096        UI Assistant Service ( UnsignedFile.Multi.Generic ) - warning
17:47:04.0853 2096        UI Assistant Service - detected UnsignedFile.Multi.Generic (1)
17:47:04.0873 2096        ultra - ok
17:47:04.0933 2096        UMWdf          (c81b8635dee0d3ef5f64b3dd643023a5) C:\WINDOWS\system32\wdfmgr.exe
17:47:04.0993 2096        UMWdf - ok
17:47:05.0053 2096        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:47:05.0294 2096        Update - ok
17:47:05.0404 2096        upnphost        (1dfd8975d8c89214b98d9387c1125b49) C:\WINDOWS\System32\upnphost.dll
17:47:05.0574 2096        upnphost - ok
17:47:05.0624 2096        upperdev - ok
17:47:05.0724 2096        UPS            (9b11e6118958e63e1fef129466e2bda7) C:\WINDOWS\System32\ups.exe
17:47:05.0874 2096        UPS - ok
17:47:05.0935 2096        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:47:06.0115 2096        usbccgp - ok
17:47:06.0225 2096        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:47:06.0405 2096        usbehci - ok
17:47:06.0545 2096        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:47:06.0716 2096        usbhub - ok
17:47:06.0826 2096        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:47:06.0986 2096        usbscan - ok
17:47:07.0026 2096        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:47:07.0206 2096        USBSTOR - ok
17:47:07.0327 2096        usbuhci        (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:47:07.0497 2096        usbuhci - ok
17:47:07.0647 2096        USB_RNDIS      (bee793d4a059caea55d6ac20e19b3a8f) C:\WINDOWS\system32\DRIVERS\usb8023.sys
17:47:07.0807 2096        USB_RNDIS - ok
17:47:07.0927 2096        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:47:08.0088 2096        VgaSave - ok
17:47:08.0128 2096        ViaIde - ok
17:47:08.0258 2096        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
17:47:08.0408 2096        VolSnap - ok
17:47:08.0558 2096        VSS            (68f106273be29e7b7ef8266977268e78) C:\WINDOWS\System32\vssvc.exe
17:47:08.0749 2096        VSS - ok
17:47:08.0869 2096        W32Time        (7b353059e665f8b7ad2bbeaef597cf45) C:\WINDOWS\System32\w32time.dll
17:47:09.0059 2096        W32Time - ok
17:47:09.0339 2096        w70n51          (c559ad65a908d1be718dc45664197413) C:\WINDOWS\system32\DRIVERS\w70n51.sys
17:47:09.0800 2096        w70n51 - ok
17:47:09.0920 2096        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:47:10.0091 2096        Wanarp - ok
17:47:10.0281 2096        Wdf01000        (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
17:47:10.0341 2096        Wdf01000 - ok
17:47:10.0371 2096        WDICA - ok
17:47:10.0461 2096        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:47:10.0621 2096        wdmaud - ok
17:47:10.0862 2096        WebClient      (81727c9873e3905a2ffc1ebd07265002) C:\WINDOWS\System32\webclnt.dll
17:47:11.0022 2096        WebClient - ok
17:47:11.0172 2096        winmgmt        (6f3f3973d97714cc5f906a19fe883729) C:\WINDOWS\system32\wbem\WMIsvc.dll
17:47:11.0402 2096        winmgmt - ok
17:47:11.0623 2096        WLSetupSvc      (94a85e956a065e23e0010a6a7826243b) C:\Programme\Windows Live\installer\WLSetupSvc.exe
17:47:11.0723 2096        WLSetupSvc - ok
17:47:11.0823 2096        WmdmPmSN        (a477391b7a8b0a0daabadb17cf533a4b) C:\WINDOWS\system32\mspmsnsv.dll
17:47:11.0863 2096        WmdmPmSN - ok
17:47:12.0023 2096        Wmi            (ffa4d901d46d07a5bab2d8307fbb51a6) C:\WINDOWS\System32\advapi32.dll
17:47:12.0143 2096        Wmi - ok
17:47:12.0254 2096        WmiApSrv        (93908111ba57a6e60ec2fa2de202105c) C:\WINDOWS\System32\wbem\wmiapsrv.exe
17:47:12.0444 2096        WmiApSrv - ok
17:47:12.0504 2096        WpdUsb          (c1b3d9d75c3fb735f5fa3a5806aded57) C:\WINDOWS\system32\Drivers\wpdusb.sys
17:47:12.0514 2096        WpdUsb - ok
17:47:12.0584 2096        WS2IFSL        (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:47:12.0774 2096        WS2IFSL - ok
17:47:12.0865 2096        wscsvc          (300b3e84faf1a5c1f791c159ba28035d) C:\WINDOWS\system32\wscsvc.dll
17:47:13.0045 2096        wscsvc - ok
17:47:13.0115 2096        WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:47:13.0285 2096        WSTCODEC - ok
17:47:13.0415 2096        WTGService      (1d448834ebaeb2d99ae7c6634b8d17be) C:\Programme\3DataManager\WTGService.exe
17:47:13.0445 2096        WTGService - ok
17:47:13.0535 2096        wuauserv        (7b4fe05202aa6bf9f4dfd0e6a0d8a085) C:\WINDOWS\system32\wuauserv.dll
17:47:13.0696 2096        wuauserv - ok
17:47:13.0816 2096        WZCSVC          (c4f109c005f6725162d2d12ca751e4a7) C:\WINDOWS\System32\wzcsvc.dll
17:47:14.0056 2096        WZCSVC - ok
17:47:14.0136 2096        xmlprov        (0ada34871a2e1cd2caafed1237a47750) C:\WINDOWS\System32\xmlprov.dll
17:47:14.0327 2096        xmlprov - ok
17:47:14.0427 2096        ZTEusbmdm6k    (c2215c6ada8b1e9feb507cee9b446661) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys
17:47:14.0487 2096        ZTEusbmdm6k - ok
17:47:14.0527 2096        ZTEusbnmea      (f16ce3c7690ab7426dc96520d54a737e) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys
17:47:14.0607 2096        ZTEusbnmea - ok
17:47:14.0667 2096        ZTEusbser6k    (c2215c6ada8b1e9feb507cee9b446661) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys
17:47:14.0687 2096        ZTEusbser6k - ok
17:47:14.0917 2096        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
17:47:15.0588 2096        \Device\Harddisk0\DR0 - ok
17:47:15.0608 2096        Boot (0x1200)  (a9fec69fce0ea683bf694fa06f3440ad) \Device\Harddisk0\DR0\Partition0
17:47:15.0608 2096        \Device\Harddisk0\DR0\Partition0 - ok
17:47:15.0649 2096        Boot (0x1200)  (75efae29b6f23456fae9ab977caf630f) \Device\Harddisk0\DR0\Partition1
17:47:15.0659 2096        \Device\Harddisk0\DR0\Partition1 - ok
17:47:15.0659 2096        ============================================================
17:47:15.0659 2096        Scan finished
17:47:15.0659 2096        ============================================================
17:47:15.0819 2144        Detected object count: 14
17:47:15.0819 2144        Actual detected object count: 14
17:49:17.0424 2144        ACEDRV05 ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        ACEDRV05 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        acernbm ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        acernbm ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        AegisP ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        Asapi ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        Asapi ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        BMLoad ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        BMLoad ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        DKbFltr ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0424 2144        DKbFltr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0424 2144        NetSvc ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0434 2144        NetSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0434 2144        NTIDrvr ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0434 2144        NTIDrvr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0434 2144        RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0434 2144        RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0434 2144        S24EventMonitor ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0434 2144        S24EventMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0454 2144        s24trans ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0454 2144        s24trans ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0454 2144        ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0454 2144        ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0474 2144        tcpipBM ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0474 2144        tcpipBM ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:49:17.0474 2144        UI Assistant Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:49:17.0474 2144        UI Assistant Service ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 07.06.2012 10:47

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Kornty 11.06.2012 09:12

Hallo Arne,

leider stürtzt das Combpfix bei mir ab. Ich mach es genau nach anleitung und bewege auch nicht die maus oder tastatur aber trotzdem nach dem update von combofix und registry sicherung meldet er bei blauem bildschirm dass er jetzt scannt und dass es länger wie 10min dauern kann und dann nach ca. 10-20 sec hört die Hdd leuchte auf zu blinken und am laptop funktioniert dann maus und die tastatur nicht mehr also absturz! ich kann dann nur auschalten und den pc neu starten! ich habe ihn auch eine ganze nacht in dem zustand gelassen in der hoffnung es passiert noch was aber leider ohne erfolg.

unhide log habe ich vergessen zu posten

lg igor

Code:

Unhide by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Unhide.exe can be found at this link:
  hxxp://www.bleepingcomputer.com/forums/topic405109.html

Program started at: 06/05/2012 07:03:48 AM
Windows Version: Windows XP

Please be patient while your files are made visible again.

Processing the C:\ drive
Finished processing the C:\ drive. 77063 files processed.

Processing the D:\ drive
Finished processing the D:\ drive. 15 files processed.

The C:\DOKUME~1\Igor\LOKALE~1\Temp\smtmp\ folder does not exist!!
Unhide cannot restore your missing shortcuts!!
Please see this topic in order to learn how to restore default
Start Menu shortcuts: hxxp://www.bleepingcomputer.com/forums/topic405109.html

Searching for Windows Registry changes made by FakeHDD rogues.
 - Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 - Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 - Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
No registry changes detected.

Restarting Explorer.exe in order to apply changes.

Program finished at: 06/05/2012 07:09:32 AM
Execution time: 0 hours(s), 5 minute(s), and 45 seconds(s)


cosinus 11.06.2012 12:25

Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.

Kornty 11.06.2012 16:27

Hallo,

ich habe es einige male jetzt versucht aber das Notebook stürtzt immer ab nach einer Zeit.

lg

cosinus 11.06.2012 20:19

Auch im abgesicherten Modus mit Netzwerktreibern getestet?

Kornty 12.06.2012 11:16

stürtzt auch ab! ich kann nur abgesichert ohne netzwerktreiber auf den desktop sonst bleibt er nach dem anmelden immer stecken kann nicht mal jetzt taskmngr starten!
schön langsam nervt der laptop. :-)

lg

cosinus 12.06.2012 12:50

Dann müssen wir CF weglassen. Mach weiter wieder wieder im normalen Windowsmodus

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Kornty 14.06.2012 10:05

Hallo Arne,

nach langem hin und her habe ich mich entschlossen den Notebook neu aufzusetzen.

vielen danke für deine mühe und entschuldige dass wir das nicht abschließen konnten aber ich habe den Notebook dringend benötigt und daher format c:
eine kleine Spende folgt!

lg Igor

cosinus 14.06.2012 13:18

Ok, danke für den Hinweis und danke für die Spende! :daumenhoc


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:56 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131