Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Computer gesperrt, Bundespolizei (https://www.trojaner-board.de/123998-computer-gesperrt-bundespolizei.html)

Sandi83 13.09.2012 00:13

Computer gesperrt, Bundespolizei
 
Hallo,

ich habe mir leider eine Computersperre Bundespolizei eingefangen.
Laptop Samsung r60plus mit windows vista.

Zuerst habe ich mit der kaspersky rescue CD 10 und windowsunlocker versucht den Laptop zu entsperren, was nicht gelungen ist.
Dann bin ich auf Ihr Forum gelangt.

Da im abgesicherten Modus keine Internetverbindung möglich war, habe ich OLT und die von Ihnen empfohlene Antimalware auf einen anderen PC auf einen USB-Stick geladen. Da ich die Aktualisierung nicht über Internet ausführen konnte, habe ich die rules-Datei geladen und auch über den Stick auf den befallen PC gezogen.

Ich habe erst die OLT, dann die Antimalware ausgeführt.
Beide Programme haben einwandfrei funktioniert (Problem wegen Aktualisierung aufgrund der fehlenden Internetverbindung war klar)
Es wurde befallen Dateien gefunden und entfernt.

Die 3 Logdateien lade ich hoch!

Ich hoffe ich habe den anderen PC nicht über den Stick nun auch infiziert!

Ich hoffe Sie können mir helfen!
Viele Grüße
Sandi83

cosinus 14.09.2012 21:51

Funktioniert der normale Modus nun wieder?
Oder zumindest noch der abgesicherte Modus mit Netzwerktreibern? Mit Internetverbindung?



Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

Sandi83 15.09.2012 09:37

Hallo,

kann jetzt wieder normal starten und habe wieder Zugriff auf das Internet!

Vielen Dank für die Antwort!

Benötige Deine Hilfe um meinen Laptop und den Laptop meines Vaters zu säubern, da der auch befallen ist, aufgrund der Aktion mit dem USB-Stick!

Bin das erste Mal auf einem Forum und kenne mich nicht so gut aus!
Muss ich für den anderen Rechner ein neues Thema erfassen?

cosinus 15.09.2012 14:20

Wir sind hier mit deim einen Rechner noch nichtmal fertig - wenn dann machst du für das andere Gerät auch bitte einen neuen Strang auf! Es macht einfach keinen Sinn mehrere Rechner in einem Strang zu behandeln!

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Sandi83 15.09.2012 23:41

Habe den Vollscan mit Malwarebytes ausgeführt.

Hier das Log:
Code:

Sandra :: SANDRA-PC [Administrator]

Schutz: Aktiviert

15.09.2012 16:45:15
mbam-log-2012-09-15 (16-45-15).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 425785
Laufzeit: 2 Stunde(n), 2 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Beim Quickscan 2 Tage vorher wurden 12 Objekte gefunden, die jetzt noch in der Quarantäne sind.
Hier das Log:
Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.07.13

Windows Vista Service Pack 1 x86 FAT32 (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.6001.19088
Sandra :: SANDRA-PC [Administrator]

Schutz: Deaktiviert

13.09.2012 00:32:30
mbam-log-2012-09-13 (00-32-30).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 220630
Laufzeit: 5 Minute(n), 18 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 7
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{77D6DDFA-7834-4541-B2B3-A8B0FB0E3924} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\ToolBand.XTTBPos00.1 (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\ToolBand.XTTBPos00 (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{055FD26D-3A88-4E15-963D-DC8493744B1D} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D} (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sessmszlotrehpp (Trojan.Phex.THAGen9) -> Daten: C:\Windows\sessmszl.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Windows\sessmszl.exe (Trojan.Phex.THAGen9) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\sessmszl.exe (Trojan.Phex.THAGen9) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sandra\0.3901579260991188.exe (Trojan.Phex.THAGen9) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\ICQToolbar\toolbaru.dll (Trojan.BHO) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Hier das Ergebnis des ESET Online Scans:

Code:

C:\ProgramData\pjssudjrokyxozc\main.html        HTML/Ransom.B trojan
C:\Users\All Users\pjssudjrokyxozc\main.html        HTML/Ransom.B trojan
C:\Users\Sandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.lnk        Win32/Adware.ADON application
C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk        Win32/Adware.ADON application
C:\Users\Sandra\Documents\WinMaximizer2011.exe        a variant of Win32/SlowPCfighter application
C:\Users\Sandra\Pictures\Desktop\BOS\Hoer\4\FFSetup220.zip        Win32/Adware.ADON application

Ich hoffe ich habe alles richtig gemacht!
Vielen Dank für die Hilfe!

cosinus 16.09.2012 18:23

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

Sandi83 16.09.2012 22:43

Hallo Cosinus,

hier die AdwCleaner-Auswertung:
Code:

# AdwCleaner v2.002 - Datei am 09/16/2012 um 23:37:03 erstellt
# Aktualisiert am 16/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (32 bits)
# Benutzer : Sandra - SANDRA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Sandra\Pictures\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
Ordner Gefunden : C:\Program Files\Conduit
Ordner Gefunden : C:\Program Files\DVDVideoSoftTB
Ordner Gefunden : C:\Users\Sandra\AppData\Local\Conduit
Ordner Gefunden : C:\Users\Sandra\AppData\LocalLow\boost_interprocess
Ordner Gefunden : C:\Users\Sandra\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\Sandra\AppData\LocalLow\DVDVideoSoftTB
Ordner Gefunden : C:\Users\Sandra\AppData\LocalLow\PriceGong
Ordner Gefunden : C:\Users\Sandra\AppData\Roaming\Desktopicon

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\AskBarDis
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\DVDVideoSoftTB
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0A022D8E-2F11-43FC-9AE7-D8D45CA58378}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1FE79231-5589-4B85-8C72-95573B25065A}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Schlüssel Gefunden : HKU\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gefunden : HKU\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.19088

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [5339 octets] - [16/09/2012 23:37:03]

########## EOF - C:\AdwCleaner[R1].txt - [5399 octets] ##########

Viele Grüße
Sandi

cosinus 17.09.2012 11:45

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

Sandi83 17.09.2012 12:55

Hallo,

hier die Adwcleaner Textdatei!

Code:

# AdwCleaner v2.002 - Datei am 09/17/2012 um 13:16:23 erstellt
# Aktualisiert am 16/09/2012 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (32 bits)
# Benutzer : Sandra - SANDRA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Sandra\Pictures\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\Sandra\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Sandra\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\Sandra\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Sandra\AppData\LocalLow\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\Sandra\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Sandra\AppData\Roaming\Desktopicon

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\AskBarDis
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0A022D8E-2F11-43FC-9AE7-D8D45CA58378}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1FE79231-5589-4B85-8C72-95573B25065A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.19088

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-21-3543792903-3866326477-39632187-1004\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [5468 octets] - [16/09/2012 23:37:03]
AdwCleaner[S1].txt - [5330 octets] - [17/09/2012 13:16:23]

########## EOF - C:\AdwCleaner[S1].txt - [5390 octets] ##########

Habe heute Urlaub und stehe für weitere Schritte zur Verfügung!

Vielen Dank!

cosinus 17.09.2012 14:39

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

Sandi83 17.09.2012 14:54

Hallo,

der normale Modus geht wieder uneingeschränkt, wenn der PC hochgefahren ist.
Manchmal braucht der PC mehrer Anläufe im normalen Modus hochzufahren!
Im abgesicherten Modus führt er dann das Programm crcdisk.sys aus und bleibt stehen. Kann es sein, dass die Festplatte bereits Fehler hat?
Einmal wurde auch ein Fehler behoben?

Der PC ist von meinem Vater und hat sehr viel Software drauf, die ich entrümpeln müsste.

Nach Überprüfung der Programme ist nur ein Ordner leer. Sony Ericcson

Viele Grüße
Sandi

cosinus 17.09.2012 14:58

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Sandi83 17.09.2012 18:02

Hallo,

hier der Inhalt des OTL.txt:
OTL Logfile:
OTL Logfile:
Code:

OTL logfile created on: 17.09.2012 18:21:04 - Run 2
OTL by OldTimer - Version 3.2.61.5    Folder = C:\Users\Sandra\Pictures\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 59,79% Memory free
6,69 Gb Paging File | 5,39 Gb Available in Paging File | 80,47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 88,31 Gb Total Space | 0,41 Gb Free Space | 0,47% Space Free | Partition Type: NTFS
Drive D: | 88,00 Gb Total Space | 62,29 Gb Free Space | 70,79% Space Free | Partition Type: NTFS
 
Computer Name: SANDRA-PC | User Name: Sandra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Sandra\Pictures\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Programme\LIDL Fotoservice\dd.exe ()
PRC - C:\Programme\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Programme\Sony\Sony PC Companion\PCCompanion.exe (Sony)
PRC - C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe ()
PRC - C:\Programme\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Programme\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
PRC - C:\Programme\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
PRC - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Programme\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Programme\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
PRC - C:\Programme\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
PRC - C:\Programme\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Programme\Common Files\Marmiko Shared\MWLaMaS.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Programme\Samsung\Samsung Update Plus\SLUTrayNotifier.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\Samsung\Samsung Recovery Solution II\WCScheduler.exe ()
PRC - C:\Programme\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Tevion\ScanWizard 5\ScannerFinder.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\LIDL Fotoservice\dd.exe ()
MOD - C:\Programme\Sony\Sony PC Companion\MExplorer.dll ()
MOD - C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe ()
MOD - C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\0a1195c6b5fab213527364c9e8b26ef0\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\1ba19f8efcff8ad7f972aa38ab9a15f5\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\cfb60f99da570cc494e27e0e8ee747e2\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\381fb23cb39e1a61e13b8770eb9800ba\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f1aa2385c0109f3059e0e6ba8b58ff68\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dff86a62a525ec8dc827fe9f50298b7\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qico4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\SDL.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\qtxml4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\QtWebKit4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\qtsql4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\QtOpenGL4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\QtNetwork4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\QtGui4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\QtCore4.dll ()
MOD - C:\Programme\Logitech\Logitech Vid\phonon4.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2767.37247__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2767.37205__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2767.37261__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2767.37462__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2767.37420__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2767.37239__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2767.37261__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2767.37224__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2767.37499__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2767.37429__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2767.37504__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2767.37434__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2767.37218__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2767.37428__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2767.37491__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2767.37365__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2767.37447__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2767.37275__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2767.37225__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2767.37407__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2767.37281__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2767.37268__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2767.37386__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2767.37281__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2767.37385__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2767.37406__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2767.37357__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2767.37194__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2767.37195__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2767.37491__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2767.37280__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2767.37194__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2767.37190__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2767.37497__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2767.37485__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2767.37193__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2767.37189__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2767.37238__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2767.37217__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2767.37203__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2767.37204__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2767.37192__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2767.37193__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2767.37204__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2767.37427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2767.37260__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2767.37453__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2767.37462__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2767.37342__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2767.37419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2767.37224__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2767.37223__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2767.37223__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2767.37385__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2767.37341__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2767.37190__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2767.37204__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2767.37190__90ba9c70f846762e\AEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2767.37195__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray.resources\2.0.2767.37476_de_90ba9c70f846762e\CLI.Component.Systemtray.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2767.37525__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2767.37194__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2767.37485__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2767.37483__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2767.37192__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2767.37192__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2767.37233__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2767.37231__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2767.37193__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2767.37476__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2767.37194__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2767.37196__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2767.37213__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2767.37210__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2767.37210__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2767.37204__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2767.37484__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2767.37253__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2767.37195__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Programme\Samsung\Samsung Update Plus\SLUTrayNotifier.exe ()
MOD - C:\Windows\System32\btwhidcs.dll ()
MOD - C:\Programme\Samsung\Samsung Recovery Solution II\WCScheduler.exe ()
MOD - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll ()
MOD - C:\Programme\Samsung\EBM\ChkSec.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\WinMove.dll ()
MOD - C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll ()
MOD - C:\Programme\Tevion\ScanWizard 5\SFRes.dll ()
MOD - C:\Programme\Tevion\ScanWizard 5\ScannerFinder.exe ()
 
 
========== Services (SafeList) ==========
 
SRV - (RoxLiveShare9) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe File not found
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (BBUpdate) -- C:\Programme\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) -- C:\Programme\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (Kodak AiO Network Discovery Service) -- C:\Programme\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (NeroMediaHomeService.4) -- C:\Programme\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
SRV - (McComponentHostService) -- C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (LVPrcSrv) -- C:\Programme\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LiveUpdate Notice) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec Core LC) -- C:\Programme\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (Automatic LiveUpdate Scheduler) -- C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (comHost) -- C:\Programme\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (Samsung Update Plus) -- C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (SQLWriter) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (SymIMMP) -- system32\DRIVERS\SymIM.sys File not found
DRV - (SipIMNDI) -- system32\DRIVERS\SipIMNDI.sys File not found
DRV - (RimUsb) -- System32\Drivers\RimUsb.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20120524.039\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20120524.039\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (IDSvix86) -- C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20120524.001\IDSvix86.sys (Symantec Corporation)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (RRNetCapMP) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (RRNetCap) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (LVUVC) -- C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (lvpopflt) -- C:\Windows\System32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) -- C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (SymIM) -- C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) -- C:\Windows\System32\drivers\symndisv.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) -- C:\Windows\System32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMREDRV) -- C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMDNS) -- C:\Windows\System32\drivers\symdns.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Programme\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (COH_Mon) -- C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SRTSPL) -- C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (s217unic) -- C:\Windows\System32\drivers\s217unic.sys (MCCI)
DRV - (s217mgmt) -- C:\Windows\System32\drivers\s217mgmt.sys (MCCI Corporation)
DRV - (s217obex) -- C:\Windows\System32\drivers\s217obex.sys (MCCI Corporation)
DRV - (s217nd5) -- C:\Windows\System32\drivers\s217nd5.sys (MCCI Corporation)
DRV - (s217mdm) -- C:\Windows\System32\drivers\s217mdm.sys (MCCI Corporation)
DRV - (s217bus) -- C:\Windows\System32\drivers\s217bus.sys (MCCI Corporation)
DRV - (s217mdfl) -- C:\Windows\System32\drivers\s217mdfl.sys (MCCI Corporation)
DRV - (CO_Mon) -- C:\Windows\System32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (AtiPcie) -- C:\Windows\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (NETw2v32) -- C:\Windows\System32\drivers\NETw2v32.sys (Intel® Corporation)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation                          )
DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/?pc=skyp&ocid=skydhp
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE403
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = 00-17-9A-F9-AF-F8
 
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3543792903-3866326477-39632187-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.24 20:31:43 | 000,000,000 | ---D | M]
 
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (CouponAlerterBHO Class) - {4E52A6BF-3F10-45E7-A6D8-93E4890ADFA9} - C:\Programme\GuteGutscheine\1.0.0.11\CouponAlerter.dll (GuteGutscheine)
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programme\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton-Symbolleiste anzeigen) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\Toolbar\WebBrowser: (no name) - {6D685611-B7A8-4B4C-A161-346390B5189C} - No CLSID value found.
O3 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\Toolbar\WebBrowser: (Norton-Symbolleiste anzeigen) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Conime] C:\Windows\System32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Nero MediaHome 4] C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\.DEFAULT..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\S-1-5-19..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [Device Detection] C:\Programme\LIDL Fotoservice\dd.exe ()
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3543792903-3866326477-39632187-1004..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PMB Medien-Prüfung.lnk = C:\Programme\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Sandra\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: GuteGutscheine - {38872E0C-A571-46D6-8BDA-B46E57BB0AFE} - C:\Programme\GuteGutscheine\1.0.0.11\CouponAlerter.dll (GuteGutscheine)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..Trusted Domains: t-online.de ([sportdienste] http in Vertrauenswürdige Sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 83.169.184.161 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8E96AE2A-3534-4A99-A564-BAE9FB1A8840}: DhcpNameServer = 83.169.184.161 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Sandra\Pictures\Pictures\palms.jpg
O24 - Desktop BackupWallPaper: C:\Users\Sandra\Pictures\Pictures\palms.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\Shell\AutoRun\command - "" = F:\
O33 - MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\Shell\open\Command - "" = rundll32.exe .\desktop.dll,InstallM
O33 - MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\Shell\AutoRun\command - "" = E:\openme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {222A4D03-2E3D-77EA-290A-FECDBD94111D} - Microsoft Windows Media Player 11.0
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2} - C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
System Restore Service not available.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.17 18:11:41 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Sandra\Pictures\Desktop\OTL.exe
[2012.09.15 19:46:49 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.09.15 18:49:37 | 000,000,000 | ---D | C] -- C:\Users\Sandra\Pictures\Desktop\Malwareangriff
[2012.09.13 00:29:47 | 007,443,600 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Sandra\Pictures\Desktop\mbam-rules.exe
[2012.09.13 00:23:46 | 000,000,000 | ---D | C] -- C:\Users\Sandra\AppData\Roaming\Malwarebytes
[2012.09.13 00:23:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.13 00:23:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.13 00:23:29 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.13 00:23:29 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.12 23:50:16 | 010,524,080 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Sandra\Pictures\Desktop\mbam-setup-1.65.0.1400.exe
[2012.09.12 20:31:46 | 000,000,000 | -HSD | C] -- C:\found.000
[2012.09.10 13:18:01 | 000,000,000 | ---D | C] -- C:\ProgramData\pjssudjrokyxozc
[2012.09.02 18:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.08.31 19:15:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2012.08.31 19:14:59 | 000,000,000 | ---D | C] -- C:\Users\Sandra\AppData\Roaming\Skype
[2012.08.31 19:14:45 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2012.08.31 19:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.08.31 19:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.17 18:29:35 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{819C6186-ED6C-4960-9D5E-7BB2A51A9462}.job
[2012.09.17 18:14:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.17 17:56:56 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Sandra\Pictures\Desktop\OTL.exe
[2012.09.17 17:53:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.17 15:43:38 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.17 15:43:38 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.17 15:43:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.17 13:44:44 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.17 13:38:01 | 000,001,356 | ---- | M] () -- C:\Users\Sandra\AppData\Local\d3d9caps.dat
[2012.09.17 13:17:21 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.09.17 13:15:58 | 000,002,043 | ---- | M] () -- C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PMB Medien-Prüfung.lnk
[2012.09.16 23:29:14 | 000,512,737 | ---- | M] () -- C:\Users\Sandra\Pictures\Desktop\adwcleaner.exe
[2012.09.15 13:12:21 | 000,632,252 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.09.15 13:12:21 | 000,598,900 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.09.15 13:12:21 | 000,127,270 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.09.15 13:12:21 | 000,104,914 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.09.13 00:30:34 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.13 00:28:42 | 007,443,600 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Sandra\Pictures\Desktop\mbam-rules.exe
[2012.09.12 23:47:44 | 010,524,080 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Sandra\Pictures\Desktop\mbam-setup-1.65.0.1400.exe
[2012.09.12 22:05:31 | 000,000,157 | ---- | M] () -- C:\Users\Sandra\AppData\Roaming\burnaware.ini
[2012.09.10 13:18:00 | 000,076,341 | ---- | M] () -- C:\ProgramData\onunvebcwdbcngg
[2012.09.10 12:21:48 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.09.10 12:00:52 | 000,118,272 | ---- | M] () -- C:\Users\Sandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.10 09:58:16 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2012.09.08 23:35:40 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.04 14:40:14 | 275,093,686 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.09.02 20:15:26 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.08.27 20:00:00 | 000,000,598 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security Online - Systemprüfung ausführen - Sandra.job
 
========== Files Created - No Company Name ==========
 
[2012.09.16 23:35:51 | 000,512,737 | ---- | C] () -- C:\Users\Sandra\Pictures\Desktop\adwcleaner.exe
[2012.09.13 00:23:31 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.10 13:17:53 | 000,076,341 | ---- | C] () -- C:\ProgramData\onunvebcwdbcngg
[2012.09.02 18:48:37 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.08.31 19:14:45 | 000,002,379 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.06.14 20:11:52 | 000,000,861 | ---- | C] () -- C:\Users\Sandra\.recently-used.xbel
[2012.05.06 16:47:55 | 000,006,205 | ---- | C] () -- C:\Users\Sandra\Diagramm1.crtx
[2012.01.08 17:51:58 | 000,001,356 | ---- | C] () -- C:\Users\Sandra\AppData\Local\d3d9caps.dat
[2011.08.16 23:03:40 | 001,569,039 | ---- | C] () -- C:\Users\Sandra\Grifftabelle_Beta_2.1.pdf
[2011.05.12 22:33:59 | 000,000,256 | ---- | C] () -- C:\Windows\System32\pool.bin
[2010.11.11 18:13:08 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.11.11 18:13:08 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.02.24 20:01:49 | 004,216,973 | ---- | C] () -- C:\Users\Sandra\Vampire Diaries Trailer.mp4
[2008.11.09 21:05:19 | 000,000,157 | ---- | C] () -- C:\Users\Sandra\AppData\Roaming\burnaware.ini
[2008.09.23 10:34:27 | 002,137,671 | ---- | C] () -- C:\Users\Sandra\AppData\Roaming\mdbu.bin
[2008.07.15 11:44:46 | 000,000,000 | ---- | C] () -- C:\ProgramData\f7129022-a000-4847-db07-470265a73c4f
[2008.06.19 08:53:14 | 000,079,336 | ---- | C] () -- C:\Users\Sandra\AppData\Roaming\mdb.bin
[2008.04.06 16:21:42 | 000,026,340 | ---- | C] () -- C:\Users\Sandra\AppData\Roaming\UserTile.png
[2008.04.05 22:22:25 | 000,118,272 | ---- | C] () -- C:\Users\Sandra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.02.27 11:30:18 | 000,000,022 | ---- | C] () -- C:\ProgramData\60a7806a-0eea-424c-a464-20f4730cd631
 
========== LOP Check ==========
 
[2009.08.01 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\digital publishing
[2012.03.22 18:37:47 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\DVDVideoSoft
[2012.03.22 18:36:31 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.06.14 20:11:52 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\gtk-2.0
[2012.07.02 21:19:21 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\ICQ
[2009.03.02 01:04:39 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\ICQ Toolbar
[2008.11.09 21:08:11 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\jpg-Illuminator
[2008.07.09 09:18:00 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Leadertech
[2009.06.10 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Publish Providers
[2011.10.11 19:13:04 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Red Kawa
[2008.09.29 19:29:45 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\RTPlayer
[2012.07.26 19:02:44 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Sony
[2008.04.20 19:45:57 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\T-Online
[2011.04.17 13:29:35 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Temp
[2011.01.11 21:51:00 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Tunebite
[2012.09.17 13:17:22 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.09.17 18:29:35 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{819C6186-ED6C-4960-9D5E-7BB2A51A9462}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2009.06.26 13:52:10 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Adobe
[2008.05.07 21:17:15 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\AdobeUM
[2012.02.27 22:25:09 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Apple Computer
[2008.04.05 19:50:15 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\ATI
[2008.04.06 09:54:22 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\CyberLink
[2009.08.01 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\digital publishing
[2012.03.12 14:00:58 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\DivX
[2012.03.22 18:37:47 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\DVDVideoSoft
[2012.03.22 18:36:31 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.10.31 14:29:27 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Google
[2012.06.14 20:11:52 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\gtk-2.0
[2012.07.02 21:19:21 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\ICQ
[2009.03.02 01:04:39 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\ICQ Toolbar
[2008.04.05 19:49:03 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Identities
[2012.05.23 14:31:39 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\InstallShield
[2008.11.09 21:08:11 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\jpg-Illuminator
[2008.07.09 09:18:00 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Leadertech
[2008.04.06 20:43:06 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Macromedia
[2012.09.13 00:23:46 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Media Center Programs
[2011.11.20 15:04:14 | 000,000,000 | --SD | M] -- C:\Users\Sandra\AppData\Roaming\Microsoft
[2009.03.17 10:37:48 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Mozilla
[2012.02.24 19:42:56 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Nero
[2009.06.10 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Publish Providers
[2011.10.11 19:13:04 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Red Kawa
[2008.09.29 19:29:45 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\RTPlayer
[2012.09.17 16:19:58 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Skype
[2012.08.31 18:54:50 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\skypePM
[2012.07.26 19:02:44 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Sony
[2010.08.02 10:42:01 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Sony Corporation
[2008.04.23 21:36:44 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Symantec
[2008.04.20 19:45:57 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\T-Online
[2011.04.17 13:29:35 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Temp
[2011.01.11 21:51:00 | 000,000,000 | ---D | M] -- C:\Users\Sandra\AppData\Roaming\Tunebite
 
< %APPDATA%\*.exe /s >
[2008.05.07 21:20:32 | 022,319,360 | ---- | M] (                                  ) -- C:\Users\Sandra\AppData\Roaming\Adobe\Acrobat\7.0\Updater\AdbeRdr710_de_DE.exe
[2011.01.08 13:20:52 | 000,010,134 | R--- | M] () -- C:\Users\Sandra\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007.08.08 01:07:30 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007.08.08 01:08:03 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2007.08.08 01:08:03 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2007.08.08 01:08:03 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2007.08.08 01:07:30 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007.08.08 01:07:30 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\SoftwareDistribution\Download\bcfed137e95e2bc1b83ef80262a82b16\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007.08.08 01:08:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007.08.08 01:08:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007.08.08 01:08:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008.04.07 19:07:12 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.04.07 19:07:12 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.04.07 19:07:12 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 09:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 09:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SoftwareDistribution\Download\bcfed137e95e2bc1b83ef80262a82b16\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 09:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\System32\netlogon.dll
[2008.01.19 09:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 09:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\System32\scecli.dll
[2008.01.19 09:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SoftwareDistribution\Download\bcfed137e95e2bc1b83ef80262a82b16\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.08.08 01:00:31 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\SoftwareDistribution\Download\bcfed137e95e2bc1b83ef80262a82b16\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2007.08.08 01:00:32 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2008.01.19 09:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2008.01.19 09:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 09:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 09:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 09:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download\bcfed137e95e2bc1b83ef80262a82b16\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\System32\winlogon.exe
[2008.01.19 09:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.19 07:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.19 07:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2007.08.07 02:30:42 | 000,339,968 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
 
<          >

< End of report >

--- --- ---

--- --- ---

cosinus 18.09.2012 12:30

Code:

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)

Updates ausgestellt oder was? :wtf:
Wieso fehlen hier für dein Vista das SP2 und der IE9?

Müssen wir nachher dringend ändern, bitte jetzt nichts an Updates installieren



Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
O3 - HKU\S-1-5-21-3543792903-3866326477-39632187-1003\..\Toolbar\WebBrowser: (no name) - {6D685611-B7A8-4B4C-A161-346390B5189C} - No CLSID value found.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O9 - Extra Button: GuteGutscheine - {38872E0C-A571-46D6-8BDA-B46E57BB0AFE} - C:\Programme\GuteGutscheine\1.0.0.11\CouponAlerter.dll (GuteGutscheine)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\Shell\AutoRun\command - "" = F:\
O33 - MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\Shell\open\Command - "" = rundll32.exe .\desktop.dll,InstallM
O33 - MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\Shell\AutoRun\command - "" = E:\openme.exe
:Files
C:\Programme\GuteGutscheine
C:\found.*
C:\Users\Sandra\AppData\Roaming\ICQ Toolbar
C:\ProgramData\onunvebcwdbcngg
C:\ProgramData\pjssudjrokyxozc
C:\Users\All Users\pjssudjrokyxozc
C:\Users\All Users\onunvebcwdbcngg
C:\Users\Sandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.lnk
C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
C:\Users\Sandra\Documents\WinMaximizer2011.exe
C:\Users\Sandra\Pictures\Desktop\BOS\Hoer\4\FFSetup220.zip
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Sandi83 18.09.2012 14:16

Hallo,

hier das Logfile:
Code:


All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-3543792903-3866326477-39632187-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{6D685611-B7A8-4B4C-A161-346390B5189C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D685611-B7A8-4B4C-A161-346390B5189C}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\NoHotStart deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{38872E0C-A571-46D6-8BDA-B46E57BB0AFE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{38872E0C-A571-46D6-8BDA-B46E57BB0AFE}\ deleted successfully.
C:\Programme\GuteGutscheine\1.0.0.11\CouponAlerter.dll moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2cea985e-242d-11de-be47-00137764b517}\ not found.
File F:\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2cea985e-242d-11de-be47-00137764b517}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2cea985e-242d-11de-be47-00137764b517}\ not found.
File rundll32.exe .\desktop.dll,InstallM not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bd5eff1d-d9db-11dc-be7c-806e6f6e6963}\ not found.
File E:\openme.exe not found.
========== FILES ==========
File\Folder C:\Programme\GuteGutscheine not found.
C:\found.000\dir0001.chk folder moved successfully.
C:\found.000\dir0000.chk folder moved successfully.
C:\found.000 folder moved successfully.
C:\Users\Sandra\AppData\Roaming\ICQ Toolbar folder moved successfully.
C:\ProgramData\onunvebcwdbcngg moved successfully.
C:\ProgramData\pjssudjrokyxozc folder moved successfully.
File\Folder C:\Users\All Users\pjssudjrokyxozc not found.
File\Folder C:\Users\All Users\onunvebcwdbcngg not found.
C:\Users\Sandra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.lnk moved successfully.
File\Folder C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk not found.
C:\Users\Sandra\Documents\WinMaximizer2011.exe moved successfully.
C:\Users\Sandra\Pictures\Desktop\BOS\Hoer\4\FFSetup220.zip moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Sandra\Pictures\Desktop\cmd.bat deleted successfully.
C:\Users\Sandra\Pictures\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: NeroMediaHomeUser.4
->Temp folder emptied: 1650712 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Public
 
User: Sandra
->Temp folder emptied: 397949290 bytes
->Temporary Internet Files folder emptied: 77292354 bytes
->Java cache emptied: 6117953 bytes
->Google Chrome cache emptied: 42426780 bytes
->Flash cache emptied: 20437 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 312195056 bytes
RecycleBin emptied: 600064 bytes
 
Total Files Cleaned = 799,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.5 log created on 09182012_141411

Files\Folders moved on Reboot...
C:\Users\NeroMediaHomeUser.4\AppData\Local\Temp\etilqs_z6NcJlSQ4SWptLNNyu3c moved successfully.
C:\Users\NeroMediaHomeUser.4\AppData\Local\Temp\etilqs_z6NcJlSQ4SWptLNNyu3c-journal moved successfully.
File\Folder C:\Windows\temp\logishrd\LVPrcInj03.dll not found!
File\Folder C:\Windows\temp\JET8130.tmp not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 19.09.2012 12:53

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

Sandi83 19.09.2012 18:55

Hallo,

hier das Ergebnis des TDSS-Killers:


Code:



19:31:47.0796 5212  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
19:31:48.0022 5212  ============================================================
19:31:48.0022 5212  Current date / time: 2012/09/19 19:31:48.0022
19:31:48.0022 5212  SystemInfo:
19:31:48.0022 5212 
19:31:48.0022 5212  OS Version: 6.0.6001 ServicePack: 1.0
19:31:48.0022 5212  Product type: Workstation
19:31:48.0022 5212  ComputerName: SANDRA-PC
19:31:48.0023 5212  UserName: Sandra
19:31:48.0023 5212  Windows directory: C:\Windows
19:31:48.0023 5212  System windows directory: C:\Windows
19:31:48.0023 5212  Processor architecture: Intel x86
19:31:48.0023 5212  Number of processors: 2
19:31:48.0023 5212  Page size: 0x1000
19:31:48.0023 5212  Boot type: Normal boot
19:31:48.0023 5212  ============================================================
19:31:49.0269 5212  Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:31:49.0271 5212  ============================================================
19:31:49.0272 5212  \Device\Harddisk0\DR0:
19:31:49.0272 5212  MBR partitions:
19:31:49.0272 5212  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0xB09E800
19:31:49.0272 5212  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC49F000, BlocksNum 0xAFFF800
19:31:49.0272 5212  ============================================================
19:31:49.0303 5212  C: <-> \Device\Harddisk0\DR0\Partition1
19:31:49.0351 5212  D: <-> \Device\Harddisk0\DR0\Partition2
19:31:49.0351 5212  ============================================================
19:31:49.0351 5212  Initialize success
19:31:49.0351 5212  ============================================================
19:32:17.0427 3216  ============================================================
19:32:17.0427 3216  Scan started
19:32:17.0427 3216  Mode: Manual; SigCheck; TDLFS;
19:32:17.0427 3216  ============================================================
19:32:18.0097 3216  ================ Scan system memory ========================
19:32:18.0098 3216  System memory - ok
19:32:18.0098 3216  ================ Scan services =============================
19:32:18.0302 3216  [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI            C:\Windows\system32\drivers\acpi.sys
19:32:18.0505 3216  ACPI - ok
19:32:18.0593 3216  [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
19:32:18.0635 3216  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
19:32:18.0635 3216  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
19:32:18.0732 3216  [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
19:32:18.0751 3216  AdobeFlashPlayerUpdateSvc - ok
19:32:18.0782 3216  [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
19:32:18.0810 3216  adp94xx - ok
19:32:18.0832 3216  [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci        C:\Windows\system32\drivers\adpahci.sys
19:32:18.0852 3216  adpahci - ok
19:32:18.0870 3216  [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
19:32:18.0885 3216  adpu160m - ok
19:32:18.0904 3216  [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320        C:\Windows\system32\drivers\adpu320.sys
19:32:18.0920 3216  adpu320 - ok
19:32:18.0957 3216  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
19:32:19.0062 3216  AeLookupSvc - ok
19:32:19.0145 3216  [ 48EB99503533C27AC6135648E5474457 ] AFD            C:\Windows\system32\drivers\afd.sys
19:32:19.0207 3216  AFD - ok
19:32:19.0230 3216  [ 39E435C90C9C4F780FA0ED05CA3C3A1B ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe
19:32:19.0294 3216  AgereModemAudio - ok
19:32:19.0374 3216  [ A19871AE65A769C65034B4DC44C29023 ] AgereSoftModem  C:\Windows\system32\DRIVERS\AGRSM.sys
19:32:19.0497 3216  AgereSoftModem - ok
19:32:19.0532 3216  [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440          C:\Windows\system32\drivers\agp440.sys
19:32:19.0548 3216  agp440 - ok
19:32:19.0560 3216  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
19:32:19.0578 3216  aic78xx - ok
19:32:19.0616 3216  [ A1545B731579895D8CC44FC0481C1192 ] ALG            C:\Windows\System32\alg.exe
19:32:19.0670 3216  ALG - ok
19:32:19.0695 3216  [ 90395B64600EBB4552E26E178C94B2E4 ] aliide          C:\Windows\system32\drivers\aliide.sys
19:32:19.0709 3216  aliide - ok
19:32:19.0724 3216  [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
19:32:19.0738 3216  amdagp - ok
19:32:19.0756 3216  [ 0577DF1D323FE75A739C787893D300EA ] amdide          C:\Windows\system32\drivers\amdide.sys
19:32:19.0769 3216  amdide - ok
19:32:19.0790 3216  [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
19:32:19.0968 3216  AmdK7 - ok
19:32:19.0984 3216  [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
19:32:20.0073 3216  AmdK8 - ok
19:32:20.0107 3216  [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo        C:\Windows\System32\appinfo.dll
19:32:20.0166 3216  Appinfo - ok
19:32:20.0286 3216  [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:32:20.0301 3216  Apple Mobile Device - ok
19:32:20.0316 3216  [ 5F673180268BB1FDB69C99B6619FE379 ] arc            C:\Windows\system32\drivers\arc.sys
19:32:20.0334 3216  arc - ok
19:32:20.0370 3216  [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
19:32:20.0389 3216  arcsas - ok
19:32:20.0426 3216  [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
19:32:20.0505 3216  AsyncMac - ok
19:32:20.0560 3216  [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi          C:\Windows\system32\drivers\atapi.sys
19:32:20.0580 3216  atapi - ok
19:32:20.0636 3216  [ B0C272DEF210B149C0BFA0D85600CE4B ] athr            C:\Windows\system32\DRIVERS\athr.sys
19:32:20.0750 3216  athr - ok
19:32:20.0805 3216  [ D045C4FC41EFA6CE74D85CAB4DA75C1F ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
19:32:20.0869 3216  Ati External Event Utility - ok
19:32:20.0989 3216  [ 5439B251AF73E7EFAE4B8771D7116159 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
19:32:21.0168 3216  atikmdag - ok
19:32:21.0210 3216  [ 4AA1EB65481C392955939E735D27118B ] AtiPcie        C:\Windows\system32\DRIVERS\AtiPcie.sys
19:32:21.0235 3216  AtiPcie - ok
19:32:21.0272 3216  [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:32:21.0324 3216  AudioEndpointBuilder - ok
19:32:21.0350 3216  [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
19:32:21.0386 3216  Audiosrv - ok
19:32:21.0445 3216  [ 7C813EB232C7AEFA627A12A104DDA221 ] Automatic LiveUpdate Scheduler C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
19:32:21.0459 3216  Automatic LiveUpdate Scheduler - ok
19:32:21.0549 3216  [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc          C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
19:32:21.0571 3216  BBSvc - ok
19:32:21.0591 3216  [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate        C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
19:32:21.0614 3216  BBUpdate - ok
19:32:21.0648 3216  [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep            C:\Windows\system32\drivers\Beep.sys
19:32:21.0735 3216  Beep - ok
19:32:21.0783 3216  [ 8582E233C346AEFE759833E8A30DD697 ] BFE            C:\Windows\System32\bfe.dll
19:32:21.0844 3216  BFE - ok
19:32:21.0907 3216  [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS            C:\Windows\System32\qmgr.dll
19:32:21.0959 3216  BITS - ok
19:32:21.0966 3216  blbdrive - ok
19:32:22.0056 3216  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
19:32:22.0075 3216  Bonjour Service - ok
19:32:22.0129 3216  [ 8153396D5551276227FA146900F734E6 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
19:32:22.0182 3216  bowser - ok
19:32:22.0212 3216  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
19:32:22.0261 3216  BrFiltLo - ok
19:32:22.0281 3216  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
19:32:22.0341 3216  BrFiltUp - ok
19:32:22.0376 3216  [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser        C:\Windows\System32\browser.dll
19:32:22.0441 3216  Browser - ok
19:32:22.0460 3216  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
19:32:22.0570 3216  Brserid - ok
19:32:22.0590 3216  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
19:32:22.0667 3216  BrSerWdm - ok
19:32:22.0732 3216  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
19:32:22.0796 3216  BrUsbMdm - ok
19:32:22.0828 3216  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
19:32:22.0893 3216  BrUsbSer - ok
19:32:22.0915 3216  [ 064FBC56921051DE1075495D628B815F ] BthEnum        C:\Windows\system32\DRIVERS\BthEnum.sys
19:32:22.0957 3216  BthEnum - ok
19:32:22.0974 3216  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
19:32:23.0041 3216  BTHMODEM - ok
19:32:23.0069 3216  [ B8C3D9DDF85FD197C3E5F849FEF71144 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
19:32:23.0156 3216  BthPan - ok
19:32:23.0177 3216  [ B24757D9154CCA035E1BBD3DB92966D7 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
19:32:23.0211 3216  BTHPORT - ok
19:32:23.0247 3216  [ 58EE7F5E68310BC8D4E7CEBD8358C12E ] BthServ        C:\Windows\System32\bthserv.dll
19:32:23.0304 3216  BthServ - ok
19:32:23.0325 3216  [ D42CF5F0C7635B3F1578810FE34D9E41 ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
19:32:23.0351 3216  BTHUSB - ok
19:32:23.0393 3216  [ 636F45A8500C1438CFA7DEE15FC5C184 ] btwaudio        C:\Windows\system32\drivers\btwaudio.sys
19:32:23.0437 3216  btwaudio - ok
19:32:23.0454 3216  [ BF9256FF01B093A5D90BB7A35EC90410 ] btwavdt        C:\Windows\system32\drivers\btwavdt.sys
19:32:23.0467 3216  btwavdt - ok
19:32:23.0500 3216  [ 0AB8C1AC177AFB27309E1072FAF34A37 ] btwrchid        C:\Windows\system32\DRIVERS\btwrchid.sys
19:32:23.0510 3216  btwrchid - ok
19:32:23.0568 3216  [ 2F237AAB91497AAA03AF48EAE68758FC ] ccEvtMgr        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
19:32:23.0580 3216  ccEvtMgr - ok
19:32:23.0587 3216  [ 2F237AAB91497AAA03AF48EAE68758FC ] ccSetMgr        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
19:32:23.0599 3216  ccSetMgr - ok
19:32:23.0642 3216  [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
19:32:23.0696 3216  cdfs - ok
19:32:23.0736 3216  [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
19:32:23.0770 3216  cdrom - ok
19:32:23.0800 3216  [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc    C:\Windows\System32\certprop.dll
19:32:23.0850 3216  CertPropSvc - ok
19:32:23.0877 3216  [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass        C:\Windows\system32\drivers\circlass.sys
19:32:23.0962 3216  circlass - ok
19:32:24.0041 3216  [ 465745561C832B29F7C48B488AAB3842 ] CLFS            C:\Windows\system32\CLFS.sys
19:32:24.0065 3216  CLFS - ok
19:32:24.0149 3216  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:32:24.0167 3216  clr_optimization_v2.0.50727_32 - ok
19:32:24.0220 3216  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:32:24.0239 3216  clr_optimization_v4.0.30319_32 - ok
19:32:24.0257 3216  [ 2F237AAB91497AAA03AF48EAE68758FC ] CLTNetCnService C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
19:32:24.0271 3216  CLTNetCnService - ok
19:32:24.0326 3216  [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
19:32:24.0380 3216  CmBatt - ok
19:32:24.0407 3216  [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
19:32:24.0423 3216  cmdide - ok
19:32:24.0484 3216  [ 6186B6B953BDC884F0F379B84B3E3A98 ] COH_Mon        C:\Windows\system32\Drivers\COH_Mon.sys
19:32:24.0496 3216  COH_Mon - ok
19:32:24.0548 3216  [ 75A69CA9998577F8B2BE8695040E5DF4 ] comHost        C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
19:32:24.0560 3216  comHost - ok
19:32:24.0607 3216  [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
19:32:24.0628 3216  Compbatt - ok
19:32:24.0638 3216  COMSysApp - ok
19:32:24.0681 3216  [ 73F5D6835BFA66019C03E316D99649DA ] CO_Mon          C:\Windows\system32\drivers\CO_Mon.sys
19:32:24.0697 3216  CO_Mon - ok
19:32:24.0706 3216  [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
19:32:24.0727 3216  crcdisk - ok
19:32:24.0743 3216  [ 22A7F883508176489F559EE745B5BF5D ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
19:32:24.0848 3216  Crusoe - ok
19:32:24.0900 3216  [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
19:32:24.0976 3216  CryptSvc - ok
19:32:25.0030 3216  [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch      C:\Windows\system32\rpcss.dll
19:32:25.0117 3216  DcomLaunch - ok
19:32:25.0177 3216  [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
19:32:25.0227 3216  DfsC - ok
19:32:25.0327 3216  [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR            C:\Windows\system32\DFSR.exe
19:32:25.0555 3216  DFSR - ok
19:32:25.0607 3216  [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
19:32:25.0683 3216  Dhcp - ok
19:32:25.0748 3216  [ 64109E623ABD6955C8FB110B592E68B7 ] disk            C:\Windows\system32\drivers\disk.sys
19:32:25.0762 3216  disk - ok
19:32:25.0798 3216  [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache        C:\Windows\System32\dnsrslvr.dll
19:32:25.0837 3216  Dnscache - ok
19:32:25.0870 3216  [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc        C:\Windows\System32\dot3svc.dll
19:32:25.0923 3216  dot3svc - ok
19:32:25.0965 3216  [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS            C:\Windows\system32\dps.dll
19:32:26.0000 3216  DPS - ok
19:32:26.0054 3216  [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
19:32:26.0088 3216  drmkaud - ok
19:32:26.0172 3216  [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
19:32:26.0289 3216  DXGKrnl - ok
19:32:26.0322 3216  [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
19:32:26.0425 3216  E1G60 - ok
19:32:26.0461 3216  [ C0B95E40D85CD807D614E264248A45B9 ] EapHost        C:\Windows\System32\eapsvc.dll
19:32:26.0512 3216  EapHost - ok
19:32:26.0568 3216  [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache          C:\Windows\system32\drivers\ecache.sys
19:32:26.0586 3216  Ecache - ok
19:32:26.0639 3216  [ 579A6B6135D32B857FAF0E3A974535D8 ] eeCtrl          C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
19:32:26.0666 3216  eeCtrl - ok
19:32:26.0725 3216  [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
19:32:26.0761 3216  ehRecvr - ok
19:32:26.0785 3216  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
19:32:26.0828 3216  ehSched - ok
19:32:26.0836 3216  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
19:32:26.0870 3216  ehstart - ok
19:32:26.0895 3216  [ E8F3F21A71720C84BCF423B80028359F ] elxstor        C:\Windows\system32\drivers\elxstor.sys
19:32:26.0927 3216  elxstor - ok
19:32:26.0986 3216  [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
19:32:27.0072 3216  EMDMgmt - ok
19:32:27.0127 3216  [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem    C:\Windows\system32\es.dll
19:32:27.0183 3216  EventSystem - ok
19:32:27.0228 3216  [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat          C:\Windows\system32\drivers\exfat.sys
19:32:27.0293 3216  exfat - ok
19:32:27.0336 3216  [ 3C489390C2E2064563727752AF8EAB9E ] fastfat        C:\Windows\system32\drivers\fastfat.sys
19:32:27.0401 3216  fastfat - ok
19:32:27.0437 3216  [ 63BDADA84951B9C03E641800E176898A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
19:32:27.0538 3216  fdc - ok
19:32:27.0565 3216  [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost        C:\Windows\system32\fdPHost.dll
19:32:27.0634 3216  fdPHost - ok
19:32:27.0667 3216  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
19:32:27.0780 3216  FDResPub - ok
19:32:27.0828 3216  [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
19:32:27.0850 3216  FileInfo - ok
19:32:27.0886 3216  [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
19:32:27.0940 3216  Filetrace - ok
19:32:27.0956 3216  [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
19:32:28.0058 3216  flpydisk - ok
19:32:28.0124 3216  [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
19:32:28.0152 3216  FltMgr - ok
19:32:28.0213 3216  [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:32:28.0233 3216  FontCache3.0.0.0 - ok
19:32:28.0252 3216  [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
19:32:28.0310 3216  Fs_Rec - ok
19:32:28.0344 3216  [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
19:32:28.0365 3216  gagp30kx - ok
19:32:28.0400 3216  [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:32:28.0416 3216  GEARAspiWDM - ok
19:32:28.0482 3216  [ D9F1113D9401185245573350712F92FC ] gpsvc          C:\Windows\System32\gpsvc.dll
19:32:28.0572 3216  gpsvc - ok
19:32:28.0646 3216  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files\Google\Update\GoogleUpdate.exe
19:32:28.0668 3216  gupdate - ok
19:32:28.0684 3216  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
19:32:28.0703 3216  gupdatem - ok
19:32:28.0738 3216  [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
19:32:28.0760 3216  gusvc - ok
19:32:28.0796 3216  [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:32:28.0904 3216  HdAudAddService - ok
19:32:28.0951 3216  [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
19:32:29.0022 3216  HDAudBus - ok
19:32:29.0052 3216  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
19:32:29.0159 3216  HidBth - ok
19:32:29.0188 3216  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr          C:\Windows\system32\drivers\hidir.sys
19:32:29.0294 3216  HidIr - ok
19:32:29.0325 3216  [ 8FA640195279ACE21BEA91396A0054FC ] hidserv        C:\Windows\system32\hidserv.dll
19:32:29.0417 3216  hidserv - ok
19:32:29.0460 3216  [ 854CA287AB7FAF949617A788306D967E ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
19:32:29.0533 3216  HidUsb - ok
19:32:29.0569 3216  [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc          C:\Windows\system32\kmsvc.dll
19:32:29.0637 3216  hkmsvc - ok
19:32:29.0674 3216  [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
19:32:29.0690 3216  HpCISSs - ok
19:32:29.0736 3216  [ 96E241624C71211A79C84F50A8E71CAB ] HTTP            C:\Windows\system32\drivers\HTTP.sys
19:32:29.0806 3216  HTTP - ok
19:32:29.0825 3216  [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
19:32:29.0839 3216  i2omp - ok
19:32:29.0880 3216  [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
19:32:29.0924 3216  i8042prt - ok
19:32:29.0959 3216  [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
19:32:29.0979 3216  iaStorV - ok
19:32:30.0061 3216  [ 6F95324909B502E2651442C1548AB12F ] IDriverT        C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
19:32:30.0097 3216  IDriverT ( UnsignedFile.Multi.Generic ) - warning
19:32:30.0097 3216  IDriverT - detected UnsignedFile.Multi.Generic (1)
19:32:30.0179 3216  [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:32:30.0257 3216  idsvc - ok
19:32:30.0490 3216  [ F85DC24DAFA76237722FE38B3196C61A ] IDSvix86        C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20120524.001\IDSvix86.sys
19:32:30.0521 3216  IDSvix86 - ok
19:32:30.0557 3216  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
19:32:30.0582 3216  iirsp - ok
19:32:30.0628 3216  [ A3BC480A2BF8AA8E4DABD2D5DCE0AFAC ] IKEEXT          C:\Windows\System32\ikeext.dll
19:32:30.0705 3216  IKEEXT - ok
19:32:30.0810 3216  [ 7BD4E0428776D11C8E8E26F9F5508690 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
19:32:30.0996 3216  IntcAzAudAddService - ok
19:32:31.0012 3216  [ 97469037714070E45194ED318D636401 ] intelide        C:\Windows\system32\drivers\intelide.sys
19:32:31.0025 3216  intelide - ok
19:32:31.0095 3216  [ 224191001E78C89DFA78924C3EA595FF ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
19:32:31.0152 3216  intelppm - ok
19:32:31.0201 3216  [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
19:32:31.0253 3216  IPBusEnum - ok
19:32:31.0301 3216  [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:32:31.0352 3216  IpFilterDriver - ok
19:32:31.0459 3216  [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
19:32:31.0507 3216  iphlpsvc - ok
19:32:31.0516 3216  IpInIp - ok
19:32:31.0557 3216  [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
19:32:31.0647 3216  IPMIDRV - ok
19:32:31.0739 3216  [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
19:32:31.0822 3216  IPNAT - ok
19:32:31.0896 3216  [ 49918803B661367023BF325CF602AFDC ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
19:32:31.0932 3216  iPod Service - ok
19:32:31.0980 3216  [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
19:32:32.0021 3216  IRENUM - ok
19:32:32.0114 3216  [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
19:32:32.0141 3216  isapnp - ok
19:32:32.0186 3216  [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
19:32:32.0213 3216  iScsiPrt - ok
19:32:32.0232 3216  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
19:32:32.0253 3216  iteatapi - ok
19:32:32.0269 3216  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
19:32:32.0286 3216  iteraid - ok
19:32:32.0335 3216  [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
19:32:32.0348 3216  kbdclass - ok
19:32:32.0363 3216  [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
19:32:32.0436 3216  kbdhid - ok
19:32:32.0471 3216  [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso          C:\Windows\system32\lsass.exe
19:32:32.0512 3216  KeyIso - ok
19:32:32.0541 3216  [ EBC507F129DF8F0E0CA270DCFC0CF87F ] KMDFMEMIO      C:\Windows\system32\DRIVERS\kmdfmemio.sys
19:32:32.0579 3216  KMDFMEMIO - ok
19:32:32.0693 3216  [ 27277A11DB52FEFAE5B01DC8FB570B28 ] Kodak AiO Network Discovery Service C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
19:32:32.0711 3216  Kodak AiO Network Discovery Service - ok
19:32:32.0745 3216  [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
19:32:32.0790 3216  KSecDD - ok
19:32:32.0818 3216  [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm          C:\Windows\system32\msdtckrm.dll
19:32:32.0891 3216  KtmRm - ok
19:32:32.0945 3216  [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer    C:\Windows\system32\srvsvc.dll
19:32:32.0995 3216  LanmanServer - ok
19:32:33.0027 3216  [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:32:33.0072 3216  LanmanWorkstation - ok
19:32:33.0207 3216  [ 63ED50A6ED61829C2DEF5B733D258A05 ] LiveUpdate      C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
19:32:33.0355 3216  LiveUpdate - ok
19:32:33.0380 3216  [ 2F237AAB91497AAA03AF48EAE68758FC ] LiveUpdate Notice C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
19:32:33.0393 3216  LiveUpdate Notice - ok
19:32:33.0431 3216  [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
19:32:33.0488 3216  lltdio - ok
19:32:33.0519 3216  [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
19:32:33.0582 3216  lltdsvc - ok
19:32:33.0631 3216  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
19:32:33.0726 3216  lmhosts - ok
19:32:33.0758 3216  [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
19:32:33.0780 3216  LSI_FC - ok
19:32:33.0802 3216  [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
19:32:33.0816 3216  LSI_SAS - ok
19:32:33.0836 3216  [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
19:32:33.0850 3216  LSI_SCSI - ok
19:32:33.0902 3216  [ 8F5C7426567798E62A3B3614965D62CC ] luafv          C:\Windows\system32\drivers\luafv.sys
19:32:33.0936 3216  luafv - ok
19:32:33.0967 3216  [ 9FB982DE1C8DD769F8ED681DD878B12F ] lvpopflt        C:\Windows\system32\DRIVERS\lvpopflt.sys
19:32:33.0981 3216  lvpopflt - ok
19:32:34.0019 3216  [ 1A7DB7A00A4B0D8DA24CD691A4547291 ] LVPr2Mon        C:\Windows\system32\DRIVERS\LVPr2Mon.sys
19:32:34.0033 3216  LVPr2Mon - ok
19:32:34.0108 3216  [ 0DDFDCAA92C7F553328DB06BA599BEA9 ] LVPrcSrv        C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
19:32:34.0123 3216  LVPrcSrv - ok
19:32:34.0180 3216  [ 37072EC9299E825F4335CC554B6FAC6A ] LVRS            C:\Windows\system32\DRIVERS\lvrs.sys
19:32:34.0201 3216  LVRS - ok
19:32:34.0455 3216  [ A240E42A7402E927A71B6E8AA4629B13 ] LVUVC          C:\Windows\system32\DRIVERS\lvuvc.sys
19:32:34.0958 3216  LVUVC - ok
19:32:35.0060 3216  [ 65E794E86468B61F2BC79ABC48BC4433 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
19:32:35.0073 3216  MBAMProtector - ok
19:32:35.0150 3216  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:32:35.0170 3216  MBAMScheduler - ok
19:32:35.0228 3216  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:32:35.0258 3216  MBAMService - ok
19:32:35.0309 3216  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
19:32:35.0325 3216  McComponentHostService - ok
19:32:35.0370 3216  [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
19:32:35.0395 3216  Mcx2Svc - ok
19:32:35.0429 3216  [ D153B14FC6598EAE8422A2037553ADCE ] megasas        C:\Windows\system32\drivers\megasas.sys
19:32:35.0442 3216  megasas - ok
19:32:35.0463 3216  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS          C:\Windows\system32\mmcss.dll
19:32:35.0515 3216  MMCSS - ok
19:32:35.0546 3216  [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem          C:\Windows\system32\drivers\modem.sys
19:32:35.0596 3216  Modem - ok
19:32:35.0641 3216  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
19:32:35.0674 3216  monitor - ok
19:32:35.0685 3216  [ 5BF6A1326A335C5298477754A506D263 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
19:32:35.0699 3216  mouclass - ok
19:32:35.0746 3216  [ 93B8D4869E12CFBE663915502900876F ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
19:32:35.0817 3216  mouhid - ok
19:32:35.0854 3216  [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
19:32:35.0868 3216  MountMgr - ok
19:32:35.0888 3216  [ 583A41F26278D9E0EA548163D6139397 ] mpio            C:\Windows\system32\drivers\mpio.sys
19:32:35.0902 3216  mpio - ok
19:32:35.0939 3216  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
19:32:35.0966 3216  mpsdrv - ok
19:32:36.0007 3216  [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc          C:\Windows\system32\mpssvc.dll
19:32:36.0079 3216  MpsSvc - ok
19:32:36.0114 3216  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
19:32:36.0131 3216  Mraid35x - ok
19:32:36.0146 3216  [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
19:32:36.0187 3216  MRxDAV - ok
19:32:36.0256 3216  [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
19:32:36.0299 3216  mrxsmb - ok
19:32:36.0349 3216  [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:32:36.0389 3216  mrxsmb10 - ok
19:32:36.0414 3216  [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:32:36.0446 3216  mrxsmb20 - ok
19:32:36.0467 3216  [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci          C:\Windows\system32\drivers\msahci.sys
19:32:36.0483 3216  msahci - ok
19:32:36.0503 3216  [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
19:32:36.0521 3216  msdsm - ok
19:32:36.0554 3216  [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC          C:\Windows\System32\msdtc.exe
19:32:36.0599 3216  MSDTC - ok
19:32:36.0644 3216  [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
19:32:36.0697 3216  Msfs - ok
19:32:36.0752 3216  [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
19:32:36.0768 3216  msisadrv - ok
19:32:36.0811 3216  [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
19:32:36.0874 3216  MSiSCSI - ok
19:32:36.0894 3216  msiserver - ok
19:32:36.0925 3216  [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
19:32:36.0974 3216  MSKSSRV - ok
19:32:37.0008 3216  [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
19:32:37.0041 3216  MSPCLOCK - ok
19:32:37.0074 3216  [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
19:32:37.0122 3216  MSPQM - ok
19:32:37.0157 3216  [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
19:32:37.0172 3216  MsRPC - ok
19:32:37.0236 3216  [ E384487CB84BE41D09711C30CA79646C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
19:32:37.0249 3216  mssmbios - ok
19:32:37.0260 3216  [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
19:32:37.0297 3216  MSTEE - ok
19:32:37.0369 3216  [ 493138C4F4119E938427DA02486F09CB ] MTOnlPktAlyX    C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis1\MTOnlPktAlyX.SYS
19:32:37.0396 3216  MTOnlPktAlyX ( UnsignedFile.Multi.Generic ) - warning
19:32:37.0396 3216  MTOnlPktAlyX - detected UnsignedFile.Multi.Generic (1)
19:32:37.0434 3216  [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup            C:\Windows\system32\Drivers\mup.sys
19:32:37.0451 3216  Mup - ok
19:32:37.0492 3216  [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent        C:\Windows\system32\qagentRT.dll
19:32:37.0560 3216  napagent - ok
19:32:37.0606 3216  [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
19:32:37.0643 3216  NativeWifiP - ok
19:32:37.0767 3216  [ F11033730B38260B6892E837C457FB4B ] NAVENG          C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVENG.SYS
19:32:37.0780 3216  NAVENG - ok
19:32:37.0844 3216  [ 4E4E7C0259D3BB97DE24A636C0E06ABA ] NAVEX15        C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVEX15.SYS
19:32:37.0935 3216  NAVEX15 - ok
19:32:37.0988 3216  [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS            C:\Windows\system32\drivers\ndis.sys
19:32:38.0040 3216  NDIS - ok
19:32:38.0083 3216  [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
19:32:38.0140 3216  NdisTapi - ok
19:32:38.0177 3216  [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
19:32:38.0232 3216  Ndisuio - ok
19:32:38.0277 3216  [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
19:32:38.0333 3216  NdisWan - ok
19:32:38.0378 3216  [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
19:32:38.0422 3216  NDProxy - ok
19:32:38.0502 3216  [ D660376BD52DF3D33390ACAE9FA1A54C ] NeroMediaHomeService.4 C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
19:32:38.0523 3216  NeroMediaHomeService.4 - ok
19:32:38.0544 3216  [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
19:32:38.0588 3216  NetBIOS - ok
19:32:38.0642 3216  [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
19:32:38.0693 3216  netbt - ok
19:32:38.0716 3216  [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon        C:\Windows\system32\lsass.exe
19:32:38.0736 3216  Netlogon - ok
19:32:38.0778 3216  [ C8052711DAECC48B982434C5116CA401 ] Netman          C:\Windows\System32\netman.dll
19:32:38.0826 3216  Netman - ok
19:32:38.0870 3216  [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm        C:\Windows\System32\netprofm.dll
19:32:38.0914 3216  netprofm - ok
19:32:38.0947 3216  [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:32:38.0965 3216  NetTcpPortSharing - ok
19:32:39.0086 3216  [ 6E9EDC1020B319E7676387B8CDF2398C ] NETw2v32        C:\Windows\system32\DRIVERS\NETw2v32.sys
19:32:39.0349 3216  NETw2v32 - ok
19:32:39.0379 3216  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
19:32:39.0401 3216  nfrd960 - ok
19:32:39.0437 3216  [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc          C:\Windows\System32\nlasvc.dll
19:32:39.0518 3216  NlaSvc - ok
19:32:39.0569 3216  [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs            C:\Windows\system32\drivers\Npfs.sys
19:32:39.0635 3216  Npfs - ok
19:32:39.0673 3216  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi            C:\Windows\system32\nsisvc.dll
19:32:39.0740 3216  nsi - ok
19:32:39.0776 3216  [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
19:32:39.0829 3216  nsiproxy - ok
19:32:39.0896 3216  [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
19:32:39.0970 3216  Ntfs - ok
19:32:40.0020 3216  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
19:32:40.0096 3216  ntrigdigi - ok
19:32:40.0137 3216  [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null            C:\Windows\system32\drivers\Null.sys
19:32:40.0171 3216  Null - ok
19:32:40.0185 3216  [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
19:32:40.0200 3216  nvraid - ok
19:32:40.0220 3216  [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor          C:\Windows\system32\drivers\nvstor.sys
19:32:40.0233 3216  nvstor - ok
19:32:40.0252 3216  [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
19:32:40.0267 3216  nv_agp - ok
19:32:40.0273 3216  NwlnkFlt - ok
19:32:40.0281 3216  NwlnkFwd - ok
19:32:40.0376 3216  [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:32:40.0406 3216  odserv - ok
19:32:40.0431 3216  [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
19:32:40.0501 3216  ohci1394 - ok
19:32:40.0519 3216  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:32:40.0537 3216  ose - ok
19:32:40.0605 3216  [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
19:32:40.0708 3216  p2pimsvc - ok
19:32:40.0773 3216  [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc          C:\Windows\system32\p2psvc.dll
19:32:40.0822 3216  p2psvc - ok
19:32:40.0881 3216  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\drivers\parport.sys
19:32:40.0982 3216  Parport - ok
19:32:41.0025 3216  [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr        C:\Windows\system32\drivers\partmgr.sys
19:32:41.0039 3216  partmgr - ok
19:32:41.0054 3216  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
19:32:41.0110 3216  Parvdm - ok
19:32:41.0148 3216  [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc          C:\Windows\System32\pcasvc.dll
19:32:41.0182 3216  PcaSvc - ok
19:32:41.0222 3216  [ 01B94418DEB235DFF777CC80076354B4 ] pci            C:\Windows\system32\drivers\pci.sys
19:32:41.0237 3216  pci - ok
19:32:41.0253 3216  [ FC175F5DDAB666D7F4D17449A547626F ] pciide          C:\Windows\system32\drivers\pciide.sys
19:32:41.0266 3216  pciide - ok
19:32:41.0283 3216  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
19:32:41.0300 3216  pcmcia - ok
19:32:41.0343 3216  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
19:32:41.0470 3216  PEAUTH - ok
19:32:41.0551 3216  [ B1689DF169143F57053F795390C99DB3 ] pla            C:\Windows\system32\pla.dll
19:32:41.0714 3216  pla - ok
19:32:41.0759 3216  [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
19:32:41.0808 3216  PlugPlay - ok
19:32:41.0849 3216  [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
19:32:41.0893 3216  PNRPAutoReg - ok
19:32:41.0939 3216  [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
19:32:41.0988 3216  PNRPsvc - ok
19:32:42.0041 3216  [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
19:32:42.0106 3216  PolicyAgent - ok
19:32:42.0133 3216  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
19:32:42.0187 3216  PptpMiniport - ok
19:32:42.0223 3216  [ 0E3CEF5D28B40CF273281D620C50700A ] Processor      C:\Windows\system32\drivers\processr.sys
19:32:42.0328 3216  Processor - ok
19:32:42.0354 3216  [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc        C:\Windows\system32\profsvc.dll
19:32:42.0433 3216  ProfSvc - ok
19:32:42.0450 3216  [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:32:42.0481 3216  ProtectedStorage - ok
19:32:42.0532 3216  [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
19:32:42.0576 3216  PSched - ok
19:32:42.0630 3216  [ CCDAC889326317792480C0A67156A1EC ] ql2300          C:\Windows\system32\drivers\ql2300.sys
19:32:42.0720 3216  ql2300 - ok
19:32:42.0736 3216  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
19:32:42.0751 3216  ql40xx - ok
19:32:42.0791 3216  [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE          C:\Windows\system32\qwave.dll
19:32:42.0829 3216  QWAVE - ok
19:32:42.0865 3216  [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
19:32:42.0901 3216  QWAVEdrv - ok
19:32:43.0010 3216  [ 5439B251AF73E7EFAE4B8771D7116159 ] R300            C:\Windows\system32\DRIVERS\atikmdag.sys
19:32:43.0146 3216  R300 - ok
19:32:43.0187 3216  [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
19:32:43.0223 3216  RasAcd - ok
19:32:43.0259 3216  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto        C:\Windows\System32\rasauto.dll
19:32:43.0386 3216  RasAuto - ok
19:32:43.0445 3216  [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
19:32:43.0496 3216  Rasl2tp - ok
19:32:43.0519 3216  [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan          C:\Windows\System32\rasmans.dll
19:32:43.0567 3216  RasMan - ok
19:32:43.0605 3216  [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
19:32:43.0638 3216  RasPppoe - ok
19:32:43.0670 3216  [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
19:32:43.0714 3216  RasSstp - ok
19:32:43.0743 3216  [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
19:32:43.0782 3216  rdbss - ok
19:32:43.0827 3216  [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
19:32:43.0877 3216  RDPCDD - ok
19:32:43.0915 3216  [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
19:32:43.0988 3216  rdpdr - ok
19:32:43.0996 3216  [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
19:32:44.0064 3216  RDPENCDD - ok
19:32:44.0113 3216  [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
19:32:44.0167 3216  RDPWD - ok
19:32:44.0211 3216  [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
19:32:44.0248 3216  RemoteAccess - ok
19:32:44.0285 3216  [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
19:32:44.0337 3216  RemoteRegistry - ok
19:32:44.0379 3216  [ 7EC90C316177BA3F1BCE92005264B447 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
19:32:44.0435 3216  RFCOMM - ok
19:32:44.0529 3216  [ 2AF094B1CE4725E4551F38FDA2348637 ] RichVideo      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
19:32:44.0552 3216  RichVideo ( UnsignedFile.Multi.Generic ) - warning
19:32:44.0552 3216  RichVideo - detected UnsignedFile.Multi.Generic (1)
19:32:44.0559 3216  RimUsb - ok
19:32:44.0601 3216  [ D9B34325EE5DF78B8F28A3DE9F577C7D ] RimVSerPort    C:\Windows\system32\DRIVERS\RimSerial.sys
19:32:44.0625 3216  RimVSerPort - ok
19:32:44.0648 3216  [ 75E8A6BFA7374ABA833AE92BF41AE4E6 ] ROOTMODEM      C:\Windows\system32\Drivers\RootMdm.sys
19:32:44.0688 3216  ROOTMODEM - ok
19:32:44.0781 3216  RoxLiveShare9 - ok
19:32:44.0827 3216  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
19:32:44.0895 3216  RpcLocator - ok
19:32:44.0930 3216  [ 301AE00E12408650BADDC04DBC832830 ] RpcSs          C:\Windows\system32\rpcss.dll
19:32:44.0966 3216  RpcSs - ok
19:32:44.0995 3216  [ FCEAE318066198C162D2176EC2975ACE ] RRNetCap        C:\Windows\system32\DRIVERS\rrnetcap.sys
19:32:45.0027 3216  RRNetCap - ok
19:32:45.0033 3216  [ FCEAE318066198C162D2176EC2975ACE ] RRNetCapMP      C:\Windows\system32\DRIVERS\rrnetcap.sys
19:32:45.0051 3216  RRNetCapMP - ok
19:32:45.0104 3216  [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
19:32:45.0145 3216  rspndr - ok
19:32:45.0182 3216  [ 959EF612D2CCFDB6D9E443F8E3655013 ] RTL8023xp      C:\Windows\system32\DRIVERS\Rtnicxp.sys
19:32:45.0257 3216  RTL8023xp - ok
19:32:45.0284 3216  [ 0266151DE3F36429F6AC3C4B28085061 ] s217bus        C:\Windows\system32\DRIVERS\s217bus.sys
19:32:45.0297 3216  s217bus - ok
19:32:45.0314 3216  [ A43C0AF0E46BE7EF0C7E8CCF0F058600 ] s217mdfl        C:\Windows\system32\DRIVERS\s217mdfl.sys
19:32:45.0324 3216  s217mdfl - ok
19:32:45.0342 3216  [ 005F5DED1ED8F8A9D2399D765EAD20F1 ] s217mdm        C:\Windows\system32\DRIVERS\s217mdm.sys
19:32:45.0355 3216  s217mdm - ok
19:32:45.0377 3216  [ DE9562AD0C91E1857D11F65A91EE1A47 ] s217mgmt        C:\Windows\system32\DRIVERS\s217mgmt.sys
19:32:45.0389 3216  s217mgmt - ok
19:32:45.0406 3216  [ 11CC5D7F992799E7E75D018E9C018563 ] s217nd5        C:\Windows\system32\DRIVERS\s217nd5.sys
19:32:45.0416 3216  s217nd5 - ok
19:32:45.0437 3216  [ 0F9F4045799AFB66B85EEF999D0609EC ] s217obex        C:\Windows\system32\DRIVERS\s217obex.sys
19:32:45.0450 3216  s217obex - ok
19:32:45.0465 3216  [ 1C91E1023F07B6407D84B5A43537D984 ] s217unic        C:\Windows\system32\DRIVERS\s217unic.sys
19:32:45.0478 3216  s217unic - ok
19:32:45.0494 3216  [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs          C:\Windows\system32\lsass.exe
19:32:45.0513 3216  SamSs - ok
19:32:45.0566 3216  [ 4BFB51CDB25D4D4B9E8FCCAB635F262E ] Samsung Update Plus C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
19:32:45.0574 3216  Samsung Update Plus ( UnsignedFile.Multi.Generic ) - warning
19:32:45.0574 3216  Samsung Update Plus - detected UnsignedFile.Multi.Generic (1)
19:32:45.0598 3216  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
19:32:45.0616 3216  sbp2port - ok
19:32:45.0656 3216  [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
19:32:45.0701 3216  SCardSvr - ok
19:32:45.0780 3216  [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule        C:\Windows\system32\schedsvc.dll
19:32:45.0874 3216  Schedule - ok
19:32:45.0913 3216  [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc    C:\Windows\System32\certprop.dll
19:32:45.0953 3216  SCPolicySvc - ok
19:32:45.0981 3216  [ 4339A2585708C7D9B0C0CE5AAD3DD6FF ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
19:32:46.0063 3216  sdbus - ok
19:32:46.0085 3216  [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
19:32:46.0135 3216  SDRSVC - ok
19:32:46.0149 3216  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
19:32:46.0217 3216  secdrv - ok
19:32:46.0254 3216  [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon        C:\Windows\system32\seclogon.dll
19:32:46.0304 3216  seclogon - ok
19:32:46.0322 3216  [ A9BBAB5759771E523F55563D6CBE140F ] SENS            C:\Windows\System32\sens.dll
19:32:46.0366 3216  SENS - ok
19:32:46.0379 3216  [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum        C:\Windows\system32\drivers\serenum.sys
19:32:46.0433 3216  Serenum - ok
19:32:46.0446 3216  [ C70D69A918B178D3C3B06339B40C2E1B ] Serial          C:\Windows\system32\drivers\serial.sys
19:32:46.0503 3216  Serial - ok
19:32:46.0522 3216  [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
19:32:46.0557 3216  sermouse - ok
19:32:46.0622 3216  [ D2193326F729B163125610DBF3E17D57 ] SessionEnv      C:\Windows\system32\sessenv.dll
19:32:46.0659 3216  SessionEnv - ok
19:32:46.0683 3216  [ 103B79418DA647736EE95645F305F68A ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
19:32:46.0753 3216  sffdisk - ok
19:32:46.0775 3216  [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
19:32:46.0832 3216  sffp_mmc - ok
19:32:46.0851 3216  [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
19:32:46.0919 3216  sffp_sd - ok
19:32:46.0944 3216  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
19:32:46.0999 3216  sfloppy - ok
19:32:47.0049 3216  [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
19:32:47.0098 3216  SharedAccess - ok
19:32:47.0153 3216  [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:32:47.0230 3216  ShellHWDetection - ok
19:32:47.0246 3216  SipIMNDI - ok
19:32:47.0268 3216  [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
19:32:47.0285 3216  sisagp - ok
19:32:47.0318 3216  [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
19:32:47.0334 3216  SiSRaid2 - ok
19:32:47.0354 3216  [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
19:32:47.0371 3216  SiSRaid4 - ok
19:32:47.0530 3216  [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
19:32:47.0700 3216  Skype C2C Service - ok
19:32:47.0733 3216  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate    C:\Program Files\Skype\Updater\Updater.exe
19:32:47.0753 3216  SkypeUpdate - ok
19:32:47.0895 3216  [ 0BA91E1358AD25236863039BB2609A2E ] slsvc          C:\Windows\system32\SLsvc.exe
19:32:48.0086 3216  slsvc - ok
19:32:48.0132 3216  [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
19:32:48.0168 3216  SLUINotify - ok
19:32:48.0182 3216  [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
19:32:48.0224 3216  Smb - ok
19:32:48.0261 3216  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
19:32:48.0281 3216  SNMPTRAP - ok
19:32:48.0355 3216  [ DC4DC886D3779C446F9B0E9D6B006E72 ] SPBBCDrv        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
19:32:48.0396 3216  SPBBCDrv - ok
19:32:48.0414 3216  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr          C:\Windows\system32\drivers\spldr.sys
19:32:48.0431 3216  spldr - ok
19:32:48.0477 3216  [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler        C:\Windows\System32\spoolsv.exe
19:32:48.0521 3216  Spooler - ok
19:32:48.0566 3216  [ 9263C8898732E2B890F7E954E7729AB7 ] SQLWriter      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
19:32:48.0582 3216  SQLWriter - ok
19:32:48.0633 3216  [ 655773F2F1A3730C6CF20280A49F4EE1 ] SRTSP          C:\Windows\system32\Drivers\SRTSP.SYS
19:32:48.0654 3216  SRTSP - ok
19:32:48.0675 3216  [ 2A0AAF370D4C6574A34AE2F4A0709CAE ] SRTSPL          C:\Windows\system32\Drivers\SRTSPL.SYS
19:32:48.0697 3216  SRTSPL - ok
19:32:48.0714 3216  [ 3104BDCEACE2D5710776DD05E6A286C1 ] SRTSPX          C:\Windows\system32\Drivers\SRTSPX.SYS
19:32:48.0727 3216  SRTSPX - ok
19:32:48.0773 3216  [ 2252AEF839B1093D16761189F45AF885 ] srv            C:\Windows\system32\DRIVERS\srv.sys
19:32:48.0825 3216  srv - ok
19:32:48.0873 3216  [ B7FF59408034119476B00A81BB53D5D1 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
19:32:48.0939 3216  srv2 - ok
19:32:48.0957 3216  [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
19:32:48.0998 3216  srvnet - ok
19:32:49.0044 3216  [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
19:32:49.0111 3216  SSDPSRV - ok
19:32:49.0154 3216  [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
19:32:49.0204 3216  SstpSvc - ok
19:32:49.0235 3216  [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc          C:\Windows\System32\wiaservc.dll
19:32:49.0281 3216  stisvc - ok
19:32:49.0297 3216  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
19:32:49.0321 3216  swenum - ok
19:32:49.0386 3216  [ B36C7CDB86F7F7A8E884479219766950 ] swprv          C:\Windows\System32\swprv.dll
19:32:49.0443 3216  swprv - ok
19:32:49.0552 3216  [ FA2F6A8849219B16460BF44F9D1F3AA7 ] Symantec Core LC C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
19:32:49.0598 3216  Symantec Core LC - ok
19:32:49.0652 3216  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
19:32:49.0665 3216  Symc8xx - ok
19:32:49.0715 3216  [ FE9F8B3A8BC22D85332B42E92308DDF9 ] SYMDNS          C:\Windows\System32\Drivers\SYMDNS.SYS
19:32:49.0746 3216  SYMDNS - ok
19:32:49.0771 3216  [ 06B95820DF51502099A8A15C93E87986 ] SymEvent        C:\Windows\system32\Drivers\SYMEVENT.SYS
19:32:49.0785 3216  SymEvent - ok
19:32:49.0802 3216  [ A0EA9D273889E53CFAABF2444692CCBF ] SYMFW          C:\Windows\System32\Drivers\SYMFW.SYS
19:32:49.0817 3216  SYMFW - ok
19:32:49.0879 3216  [ 8EAB28DD6CD25355B951AE460FA86B48 ] SymIM          C:\Windows\system32\DRIVERS\SymIMv.sys
19:32:49.0916 3216  SymIM - ok
19:32:49.0923 3216  SymIMMP - ok
19:32:49.0961 3216  [ C94EACA4B522012EE0691F1E79C42A7D ] SYMNDISV        C:\Windows\System32\Drivers\SYMNDISV.SYS
19:32:49.0985 3216  SYMNDISV - ok
19:32:50.0006 3216  [ 7C6505EA598E58099D3B7E1F70426864 ] SYMREDRV        C:\Windows\System32\Drivers\SYMREDRV.SYS
19:32:50.0019 3216  SYMREDRV - ok
19:32:50.0063 3216  [ E6FF7ACE71D07CA90119F2C6AB592BA4 ] SYMTDI          C:\Windows\System32\Drivers\SYMTDI.SYS
19:32:50.0081 3216  SYMTDI - ok
19:32:50.0109 3216  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
19:32:50.0132 3216  Sym_hi - ok
19:32:50.0153 3216  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
19:32:50.0169 3216  Sym_u3 - ok
19:32:50.0195 3216  [ C1777074592BBB55B1F1A2FBC7A60498 ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
19:32:50.0214 3216  SynTP - ok
19:32:50.0271 3216  [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain        C:\Windows\system32\sysmain.dll
19:32:50.0352 3216  SysMain - ok
19:32:50.0392 3216  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:32:50.0433 3216  TabletInputService - ok
19:32:50.0478 3216  [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv        C:\Windows\System32\tapisrv.dll
19:32:50.0538 3216  TapiSrv - ok
19:32:50.0580 3216  [ 77BD6143C6DCE0A1BF7B5571BED860DC ] tbhsd          C:\Windows\system32\drivers\tbhsd.sys
19:32:50.0593 3216  tbhsd - ok
19:32:50.0633 3216  [ CB05822CD9CC6C688168E113C603DBE7 ] TBS            C:\Windows\System32\tbssvc.dll
19:32:50.0682 3216  TBS - ok
19:32:50.0783 3216  [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
19:32:50.0854 3216  Tcpip - ok
19:32:50.0917 3216  [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
19:32:50.0991 3216  Tcpip6 - ok
19:32:51.0010 3216  [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
19:32:51.0050 3216  tcpipreg - ok
19:32:51.0114 3216  [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
19:32:51.0152 3216  TDPIPE - ok
19:32:51.0205 3216  [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
19:32:51.0251 3216  TDTCP - ok
19:32:51.0292 3216  [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
19:32:51.0344 3216  tdx - ok
19:32:51.0369 3216  [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
19:32:51.0384 3216  TermDD - ok
19:32:51.0501 3216  [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService    C:\Windows\System32\termsrv.dll
19:32:51.0614 3216  TermService - ok
19:32:51.0652 3216  [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes          C:\Windows\system32\shsvcs.dll
19:32:51.0682 3216  Themes - ok
19:32:51.0764 3216  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER    C:\Windows\system32\mmcss.dll
19:32:51.0815 3216  THREADORDER - ok
19:32:51.0855 3216  [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks          C:\Windows\System32\trkwks.dll
19:32:51.0917 3216  TrkWks - ok
19:32:51.0979 3216  [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:32:52.0033 3216  TrustedInstaller - ok
19:32:52.0074 3216  [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
19:32:52.0127 3216  tssecsrv - ok
19:32:52.0160 3216  [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
19:32:52.0188 3216  tunmp - ok
19:32:52.0200 3216  [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
19:32:52.0222 3216  tunnel - ok
19:32:52.0253 3216  [ C3ADE15414120033A36C0F293D4A4121 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
19:32:52.0270 3216  uagp35 - ok
19:32:52.0319 3216  [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
19:32:52.0357 3216  udfs - ok
19:32:52.0409 3216  [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
19:32:52.0444 3216  UI0Detect - ok
19:32:52.0469 3216  [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
19:32:52.0483 3216  uliagpkx - ok
19:32:52.0511 3216  [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci        C:\Windows\system32\drivers\uliahci.sys
19:32:52.0530 3216  uliahci - ok
19:32:52.0564 3216  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
19:32:52.0579 3216  UlSata - ok
19:32:52.0594 3216  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
19:32:52.0610 3216  ulsata2 - ok
19:32:52.0653 3216  [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
19:32:52.0686 3216  umbus - ok
19:32:52.0785 3216  [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost        C:\Windows\System32\upnphost.dll
19:32:52.0846 3216  upnphost - ok
19:32:52.0896 3216  [ 83CAFCB53201BBAC04D822F32438E244 ] USBAAPL        C:\Windows\system32\Drivers\usbaapl.sys
19:32:52.0925 3216  USBAAPL - ok
19:32:52.0976 3216  [ 292A25BB75A568AE2C67169BA2C6365A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
19:32:53.0018 3216  usbaudio - ok
19:32:53.0037 3216  [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
19:32:53.0073 3216  usbccgp - ok
19:32:53.0094 3216  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
19:32:53.0167 3216  usbcir - ok
19:32:53.0205 3216  [ CEBE90821810E76320155BEBA722FCF9 ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
19:32:53.0260 3216  usbehci - ok
19:32:53.0289 3216  [ CC6B28E4CE39951357963119CE47B143 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
19:32:53.0327 3216  usbhub - ok
19:32:53.0349 3216  [ 7BDB7B0E7D45AC0402D78B90789EF47C ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
19:32:53.0382 3216  usbohci - ok
19:32:53.0427 3216  [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
19:32:53.0474 3216  usbprint - ok
19:32:53.0518 3216  [ A508C9BD8724980512136B039BBA65E9 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
19:32:53.0567 3216  usbscan - ok
19:32:53.0618 3216  [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:32:53.0657 3216  USBSTOR - ok
19:32:53.0673 3216  [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
19:32:53.0746 3216  usbuhci - ok
19:32:53.0782 3216  [ 0A6B81F01BC86399482E27E6FDA7B33B ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
19:32:53.0851 3216  usbvideo - ok
19:32:53.0888 3216  [ 032A0ACC3909AE7215D524E29D536797 ] UxSms          C:\Windows\System32\uxsms.dll
19:32:53.0939 3216  UxSms - ok
19:32:53.0983 3216  [ B13BC395B9D6116628F5AF47E0802AC4 ] vds            C:\Windows\System32\vds.exe
19:32:54.0057 3216  vds - ok
19:32:54.0098 3216  [ 7D92BE0028ECDEDEC74617009084B5EF ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
19:32:54.0166 3216  vga - ok
19:32:54.0203 3216  [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave        C:\Windows\System32\drivers\vga.sys
19:32:54.0256 3216  VgaSave - ok
19:32:54.0279 3216  [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp          C:\Windows\system32\drivers\viaagp.sys
19:32:54.0296 3216  viaagp - ok
19:32:54.0319 3216  [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7          C:\Windows\system32\drivers\viac7.sys
19:32:54.0402 3216  ViaC7 - ok
19:32:54.0432 3216  [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide          C:\Windows\system32\drivers\viaide.sys
19:32:54.0447 3216  viaide - ok
19:32:54.0463 3216  [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
19:32:54.0480 3216  volmgr - ok
19:32:54.0534 3216  [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
19:32:54.0559 3216  volmgrx - ok
19:32:54.0589 3216  [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
19:32:54.0620 3216  volsnap - ok
19:32:54.0670 3216  [ D984439746D42B30FC65A4C3546C6829 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
19:32:54.0694 3216  vsmraid - ok
19:32:54.0773 3216  [ D5FB73D19C46ADE183F968E13F186B23 ] VSS            C:\Windows\system32\vssvc.exe
19:32:54.0932 3216  VSS - ok
19:32:54.0965 3216  [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time        C:\Windows\system32\w32time.dll
19:32:55.0045 3216  W32Time - ok
19:32:55.0084 3216  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
19:32:55.0174 3216  WacomPen - ok
19:32:55.0210 3216  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
19:32:55.0251 3216  Wanarp - ok
19:32:55.0256 3216  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
19:32:55.0284 3216  Wanarpv6 - ok
19:32:55.0315 3216  [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
19:32:55.0361 3216  wcncsvc - ok
19:32:55.0384 3216  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:32:55.0428 3216  WcsPlugInService - ok
19:32:55.0450 3216  [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd              C:\Windows\system32\drivers\wd.sys
19:32:55.0464 3216  Wd - ok
19:32:55.0494 3216  [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
19:32:55.0537 3216  Wdf01000 - ok
19:32:55.0579 3216  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
19:32:55.0638 3216  WdiServiceHost - ok
19:32:55.0645 3216  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
19:32:55.0689 3216  WdiSystemHost - ok
19:32:55.0710 3216  [ CF9A5F41789B642DB967021DE06A2713 ] WebClient      C:\Windows\System32\webclnt.dll
19:32:55.0738 3216  WebClient - ok
19:32:55.0784 3216  [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc          C:\Windows\system32\wecsvc.dll
19:32:55.0847 3216  Wecsvc - ok
19:32:55.0883 3216  [ 670FF720071ED741206D69BD995EA453 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
19:32:55.0920 3216  wercplsupport - ok
19:32:55.0958 3216  [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc          C:\Windows\System32\WerSvc.dll
19:32:55.0996 3216  WerSvc - ok
19:32:56.0063 3216  [ 4575AA12561C5648483403541D0D7F2B ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
19:32:56.0094 3216  WinDefend - ok
19:32:56.0104 3216  WinHttpAutoProxySvc - ok
19:32:56.0171 3216  [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
19:32:56.0244 3216  Winmgmt - ok
19:32:56.0328 3216  [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM          C:\Windows\system32\WsmSvc.dll
19:32:56.0478 3216  WinRM - ok
19:32:56.0558 3216  [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc        C:\Windows\System32\wlansvc.dll
19:32:56.0647 3216  Wlansvc - ok
19:32:56.0677 3216  [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
19:32:56.0766 3216  WmiAcpi - ok
19:32:56.0806 3216  [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
19:32:56.0842 3216  wmiApSrv - ok
19:32:56.0927 3216  [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
19:32:57.0021 3216  WMPNetworkSvc - ok
19:32:57.0062 3216  [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
19:32:57.0093 3216  WPCSvc - ok
19:32:57.0124 3216  [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
19:32:57.0144 3216  WPDBusEnum - ok
19:32:57.0179 3216  [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
19:32:57.0233 3216  WpdUsb - ok
19:32:57.0346 3216  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:32:57.0414 3216  WPFFontCache_v0400 - ok
19:32:57.0450 3216  [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
19:32:57.0504 3216  ws2ifsl - ok
19:32:57.0543 3216  [ 683DD16B590372F2C9661D277F35E49C ] wscsvc          C:\Windows\System32\wscsvc.dll
19:32:57.0593 3216  wscsvc - ok
19:32:57.0604 3216  WSearch - ok
19:32:57.0716 3216  [ 6298277B73C77FA99106B271A7525163 ] wuauserv        C:\Windows\system32\wuaueng.dll
19:32:57.0822 3216  wuauserv - ok
19:32:57.0857 3216  [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
19:32:57.0901 3216  WUDFRd - ok
19:32:57.0938 3216  [ 575A4190D989F64732119E4114045A4F ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
19:32:57.0974 3216  wudfsvc - ok
19:32:58.0014 3216  [ ADE7A4943003020216952B56A6741EC7 ] yukonwlh        C:\Windows\system32\DRIVERS\yk60x86.sys
19:32:58.0060 3216  yukonwlh - ok
19:32:58.0071 3216  ================ Scan global ===============================
19:32:58.0146 3216  [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
19:32:58.0187 3216  [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:32:58.0231 3216  [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:32:58.0277 3216  [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
19:32:58.0283 3216  [Global] - ok
19:32:58.0283 3216  ================ Scan MBR ==================================
19:32:58.0295 3216  [ 61A349592C4728853F4A90FF78F7628E ] \Device\Harddisk0\DR0
19:32:59.0218 3216  \Device\Harddisk0\DR0 - ok
19:32:59.0218 3216  ================ Scan VBR ==================================
19:32:59.0253 3216  [ A1E20959446CE325749A621106FA7247 ] \Device\Harddisk0\DR0\Partition1
19:32:59.0281 3216  \Device\Harddisk0\DR0\Partition1 - ok
19:32:59.0322 3216  [ 9EB5B3DF4438C02B99FED91486368398 ] \Device\Harddisk0\DR0\Partition2
19:32:59.0325 3216  \Device\Harddisk0\DR0\Partition2 - ok
19:32:59.0325 3216  ============================================================
19:32:59.0325 3216  Scan finished
19:32:59.0325 3216  ============================================================
19:32:59.0349 5900  Detected object count: 5
19:32:59.0349 5900  Actual detected object count: 5
19:33:58.0594 5900  C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe - copied to quarantine
19:33:58.0594 5900  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
19:33:58.0673 5900  C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe - copied to quarantine
19:33:58.0673 5900  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
19:33:58.0692 5900  C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis1\MTOnlPktAlyX.SYS - copied to quarantine
19:33:58.0692 5900  MTOnlPktAlyX ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
19:33:58.0719 5900  C:\Program Files\CyberLink\Shared Files\RichVideo.exe - copied to quarantine
19:33:58.0719 5900  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
19:33:58.0744 5900  C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe - copied to quarantine
19:33:58.0744 5900  Samsung Update Plus ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
19:36:16.0340 3424  Deinitialize success

Das Ergebnis habe ich in die Quarantäne geschoben.

Habe wie üblich mit rechter Maustaste als Administrator gestartet.
Hoffe es passt so!

Viele Grüße
Sandi

cosinus 20.09.2012 10:46

Zitat:

Das Ergebnis habe ich in die Quarantäne geschoben.
Mal wieder wurde die Anleitung nur überflogen :stirn:
Ich hab extra in fetter blauer Schrift etwas aus etwas wichtiges hingewiesen :balla:

Sandi83 20.09.2012 12:53

Hallo Cosinus,

tut mir Leid die Funktion Skip habe ich nicht verstanden, und da auch bei Malewarebytes bereits Dateien in der Quarantäne sind und nicht gelöscht wurde, dachte ich hier wäre es genau so!

Was kann ich nun machen?

cosinus 20.09.2012 15:14

So erstmal garnichts, beim TDSS-Killer ist mir eine Funktion bekannt, mit der man auf Knopfdruck gelöschte Elemente so in den Ursprungszustand zurückversetzen kann

Ja es ist richtig, dass du bei malwarebytes in die Q schicken sollst, aber bei sonst KEINEM anderen Tool! Deswegen wurde das extra fett und blau hervorgehoben aber die besten Anleitungen bringen nichts, wenn sie nicht gelesen werden! :(


Edit: Du hast offensichtlich NICHTS entfernt, sondern nur alls in die Q kopiert, dann sollte alles ok sein. :) Ich hab mich in deinem Fall ohne Grund aufgeregt :o

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Sandi83 20.09.2012 22:10

Hallo,

hier die Logdatei des ComboFix:

Code:


Combofix Logfile:

       
Code:

       
ComboFix 12-09-20.02 - Sandra 20.09.2012  21:09:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.49.1031.18.3325.2146 [GMT 2:00]
ausgeführt von:: c:\users\Sandra\Pictures\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\60a7806a-0eea-424c-a464-20f4730cd631
c:\programdata\f7129022-a000-4847-db07-470265a73c4f
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-08-20 bis 2012-09-20  ))))))))))))))))))))))))))))))
.
.
2012-09-20 19:17 . 2012-09-20 19:20        --------        d-----w-        c:\users\NeroMediaHomeUser.4\AppData\Local\temp
2012-09-20 19:17 . 2012-09-20 20:17        --------        d-----w-        c:\users\Sandra\AppData\Local\temp
2012-09-20 19:17 . 2012-09-20 19:17        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-19 17:33 . 2012-09-19 17:33        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-09-18 12:14 . 2012-09-18 12:14        --------        d-----w-        C:\_OTL
2012-09-18 08:20 . 2012-08-27 23:50        7022536        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{C083F6BB-9E6A-47FD-AD4C-3C1177BD62B3}\mpengine.dll
2012-09-15 17:46 . 2012-09-15 17:46        --------        d-----w-        c:\program files\ESET
2012-09-12 22:23 . 2012-09-12 22:23        --------        d-----w-        c:\users\Sandra\AppData\Roaming\Malwarebytes
2012-09-12 22:23 . 2012-09-12 22:23        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-12 22:23 . 2012-09-12 22:30        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-09-12 22:23 . 2012-09-07 15:04        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-11 09:01 . 2012-05-31 10:25        237072        ------w-        c:\windows\system32\MpSigStub.exe
2012-08-31 17:15 . 2012-08-31 17:15        --------        d-----w-        c:\program files\Microsoft
2012-08-31 17:14 . 2012-09-20 20:17        --------        d-----w-        c:\users\Sandra\AppData\Roaming\Skype
2012-08-31 17:14 . 2012-08-31 17:15        --------        d-----r-        c:\program files\Skype
2012-08-31 17:14 . 2012-08-31 17:14        --------        d-----w-        c:\program files\Common Files\Skype
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-02 16:47 . 2012-04-05 17:05        696520        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-02 16:47 . 2011-06-05 07:54        73416        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-08 17:35 . 2008-09-23 08:34        2137671        ----a-w-        c:\users\Sandra\AppData\Roaming\mdbu.bin
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"InfoCockpit"="c:\program files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE" [2007-07-30 176128]
"T-Online_Software_6\WLAN-Access Finder"="c:\program files\T-Online\WLAN-Access Finder\ToWLaAcF.exe" [2008-04-08 671796]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-31 39408]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2012-05-31 445624]
"Device Detection"="c:\program files\LIDL Fotoservice\dd.exe" [2012-07-24 788416]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2010-10-29 5178664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-23 857648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 68640]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-15 57344]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"Conime"="c:\windows\system32\conime.exe" [2008-01-19 69120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2011-06-16 2510848]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2010-10-29 5178664]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"InfoCockpit"="c:\program files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE" [2007-07-30 176128]
"T-Online_Software_6\WLAN-Access Finder"="c:\program files\T-Online\WLAN-Access Finder\ToWLaAcF.exe" [2008-04-08 671796]
.
c:\users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
PMB Medien-Prüfung.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-8-2 333088]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-24 723760]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Tevion Scanner Finder.lnk - c:\program files\Tevion\ScanWizard 5\ScannerFinder.exe [2008-12-2 315392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - COMHOST
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ           BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 17:02        114688        ----a-w-        c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:47]
.
2012-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-31 12:10]
.
2012-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-31 12:10]
.
2012-08-27 c:\windows\Tasks\Norton Internet Security Online - Systemprüfung ausführen - Sandra.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
.
2012-09-20 c:\windows\Tasks\User_Feed_Synchronization-{819C6186-ED6C-4960-9D5E-7BB2A51A9462}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to MP3 Converter - c:\users\Sandra\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: t-online.de\sportdienste
TCP: DhcpNameServer = 83.169.184.161 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-eBay Icon - c:\users\Sandra\AppData\Roaming\Desktopicon\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-09-20 22:17
Windows 6.0.6001 Service Pack 1 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2544)
c:\windows\system32\btmmhook.dll
c:\windows\system32\btncopy.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Kodak\AiO\Center\EKAiOHostService.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Samsung\Samsung Recovery Solution II\WCScheduler.exe
c:\program files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\windows\RtHDVCpl.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Marmiko Shared\MWLaMaS.exe
c:\program files\Sony\Sony PC Companion\PCCompanionInfo.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-09-20  22:23:28 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-09-20 20:23
.
Vor Suchlauf: 748.867.584 Bytes frei
Nach Suchlauf: 985.714.688 Bytes frei
.
- - End Of File - - 8285F17AB83B58775AD91FF2E1ACED22


--- --- ---


cosinus 21.09.2012 14:48

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Sandi83 22.09.2012 12:39

Hallo,

hier erst mal die GMER-Logdatei:

Code:



GMER Logfile:

       
Code:

       
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-22 13:21:19
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 FUJITSU_MHY2200BH rev.0000000B
Running: cqr4b1qs.exe; Driver: C:\Users\Sandra\AppData\Local\Temp\kwdiqpob.sys


---- System - GMER 1.0.15 ----

SSDT            886C5F28                                                                                                                                     ZwAlertResumeThread
SSDT            886C3500                                                                                                                                     ZwAlertThread
SSDT            886C3F38                                                                                                                                     ZwAllocateVirtualMemory
SSDT            87F8D260                                                                                                                                     ZwAlpcConnectPort
SSDT            886C5C78                                                                                                                                     ZwCreateMutant
SSDT            886D65E0                                                                                                                                     ZwCreateThread
SSDT            886C59D8                                                                                                                                     ZwDebugActiveProcess
SSDT            886C3D98                                                                                                                                     ZwFreeVirtualMemory
SSDT            886C5D68                                                                                                                                     ZwImpersonateAnonymousToken
SSDT            886C5E48                                                                                                                                     ZwImpersonateThread
SSDT            886C3C98                                                                                                                                     ZwMapViewOfSection
SSDT            886C5B98                                                                                                                                     ZwOpenEvent
SSDT            886D6520                                                                                                                                     ZwOpenProcessToken
SSDT            886C39D8                                                                                                                                     ZwOpenThreadToken
SSDT            886C9498                                                                                                                                     ZwResumeThread
SSDT            886C38F8                                                                                                                                     ZwSetContextThread
SSDT            886C3AC8                                                                                                                                     ZwSetInformationProcess
SSDT            886C3808                                                                                                                                     ZwSetInformationThread
SSDT            886C5AB8                                                                                                                                     ZwSuspendProcess
SSDT            886C3648                                                                                                                                     ZwSuspendThread
SSDT            886CE318                                                                                                                                     ZwTerminateProcess
SSDT            886C3728                                                                                                                                     ZwTerminateThread
SSDT            886C3BB8                                                                                                                                     ZwUnmapViewOfSection
SSDT            886C3E68                                                                                                                                     ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!KeInsertQueue + 30D                                                                                                             828AC8D4 8 Bytes  [28, 5F, 6C, 88, 00, 35, 6C, ...]
.text           ntoskrnl.exe!KeInsertQueue + 321                                                                                                             828AC8E8 4 Bytes  [38, 3F, 6C, 88]
.text           ntoskrnl.exe!KeInsertQueue + 32D                                                                                                             828AC8F4 4 Bytes  [60, D2, F8, 87]
.text           ntoskrnl.exe!KeInsertQueue + 3E5                                                                                                             828AC9AC 4 Bytes  [78, 5C, 6C, 88]
.text           ntoskrnl.exe!KeInsertQueue + 411                                                                                                             828AC9D8 4 Bytes  [E0, 65, 6D, 88]
.text           ...                                                                                                                                         

---- User code sections - GMER 1.0.15 ----

.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!IsZoomed + 80                                                       766C0731 7 Bytes  JMP 10053940 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!GetClassLongW + 529                                                 766C1EB5 7 Bytes  JMP 100537F0 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!DdeUninitialize + 360                                               766E02A5 7 Bytes  JMP 10053920 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxIndirectA + F5                                            7670D566 7 Bytes  JMP 10053990 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxIndirectW + 61                                            7670D5CC 7 Bytes  JMP 10053A60 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)
.text           C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe[3608] USER32.dll!MessageBoxExA + 1F                                                  7670D5F0 7 Bytes  JMP 10053A10 C:\Program Files\Sony\Sony PC Companion\NewUI.dll (New UI/Avanquest Software)

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                        [748C8864] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                         [74909855] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                     [748CB984] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                               [748BFB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                         [748C7A29] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                      [748BEA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                          [748FB12D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                             [748CBC4A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                     [748C0756] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                      [748C06BD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                       [748B71B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                               [7494D9E0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                  [748E7329] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                     [748BE109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                               [748B697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                              [748B69A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2320] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                 [748C2475] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3dc\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]         [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]           [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]           [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW]          [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW]        [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey]            [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]          [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]            [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]            [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA]         [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW]       [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW]         [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA]           [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW]           [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA]        [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA]          [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey]            [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW]          [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]        [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]          [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]          [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW]         [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW]       [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA]         [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey]           [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA]           [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW]           [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]          [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]        [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]          [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey]           [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA]       [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA]         [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW]       [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW]         [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]          [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]            [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]            [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot]  [00408590] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey]             [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW]           [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]         [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA]           [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA]          [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW]          [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW]       [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW]         [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey]           [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExW]       [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExW]         [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExA]       [004088F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExA]         [00408C40] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [ADVAPI32.dll!RegCloseKey]           [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW]          [00407850] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW]        [00407650] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA]          [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA]          [00407870] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW]       [00408AD0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW]         [00408DE0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[2952] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey]           [004087F0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                               [00352F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                                    [00352CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                      [00352C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[3080] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                          [00352CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                 [01AE2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                      [01AE2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]        [01AE2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]            [01AE2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile]                               [000C2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose]                                    [000C2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile]                      [000C2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT             C:\Program Files\Windows Sidebar\sidebar.exe[4420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject]                          [000C2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                                                      Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                                                      Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                      SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00027875488f (not active ControlSet)                                             
Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00027875abd1 (not active ControlSet)                                             
Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00197ef0e983 (not active ControlSet)                                             
Reg             HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875488f (not active ControlSet)                                             
Reg             HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875abd1 (not active ControlSet)                                             
Reg             HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00197ef0e983 (not active ControlSet)                                             
Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875488f                                                                 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875abd1                                                                 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00197ef0e983                                                                 

---- EOF - GMER 1.0.15 ----


--- --- ---

Alles weiter folgt!

Hallo,

hier die OSAM Logdatei und die aswMBR.txt.

Hoffe es passt so!

[code]
OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 14:30:12 on 22.09.2012

OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit
Default Browser: Google Inc. Google Chrome 21.0.1180.89

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Norton Internet Security Online - Systemprüfung ausführen - Sandra.job" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"BlackBerry-Smartphone" (RimUsb) - ? - C:\Windows\System32\Drivers\RimUsb.sys  (File not found)
"catchme" (catchme) - ? - C:\Users\Sandra\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"kwdiqpob" (kwdiqpob) - ? - C:\Users\Sandra\AppData\Local\Temp\kwdiqpob.sys  (Hidden registry entry, rootkit activity | File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MTOnlPktAlyX NDIS Protocol Driver" (MTOnlPktAlyX) - "Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH" - C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis1\MTOnlPktAlyX.SYS
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120524.039\NAVEX15.SYS
"SPBBCDrv" (SPBBCDrv) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
"SRTSP" (SRTSP) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSP.SYS
"SRTSPL" (SRTSPL) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPL.SYS
"SRTSPX" (SRTSPX) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPX.SYS
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Intrusion Prevention Driver" (IDSvix86) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20120524.001\IDSvix86.sys
"SYMDNS" (SYMDNS) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMDNS.SYS
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\Windows\system32\Drivers\SYMEVENT.SYS
"SYMFW" (SYMFW) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMFW.SYS
"SymIMMP" (SymIMMP) - ? - C:\Windows\System32\DRIVERS\SymIM.sys  (File not found)
"SYMNDISV" (SYMNDISV) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMNDISV.SYS
"SYMREDRV" (SYMREDRV) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMREDRV.SYS
"SYMTDI" (SYMTDI) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMTDI.SYS
"T-Online Dialerschutz VoIP Service" (SipIMNDI) - ? - C:\Windows\System32\DRIVERS\SipIMNDI.sys  (File not found)

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2} "PixiePack Codec Pack 1.1.1200.0" - ? - C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{5574006C-28F5-4a65-A28C-74DE6BFBE0BB} "Haali Matroska Shell Property Page" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{327669A0-59A7-4be9-B99E-1C9F3A57611A} "Haali Matroska Thumbnail Extractor" - ? - C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll  (File found, but it contains no detailed information)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{5BD933E7-F18F-4D3B-A16B-B1A40B04764E} "KodakPrintShellExtensionNative" - "Eastman Kodak Company" - C:\Program Files\Kodak\AiO\Center\Inkjet.ShellExtension.Native_Win32.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "Norton-Symbolleiste anzeigen" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
<binary data> "{855F3B16-6D32-4FE6-8A56-BBB695989046}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -  (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
"ICQ6" - "ICQ, LLC." - C:\Program Files\ICQ6.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{8dcb7100-df86-4384-8842-8fa844297b3f} "Bing Bar" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} "Norton-Symbolleiste anzeigen" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} "Bing Bar Helper" - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
{4E52A6BF-3F10-45E7-A6D8-93E4890ADFA9} "CouponAlerterBHO Class" - ? - C:\Program Files\GuteGutscheine\1.0.0.11\CouponAlerter.dll  (File not found)
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} "Symantec Intrusion Prevention" - "Symantec Corporation" - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} "{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}" - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"PMB Medien-Prüfung.lnk" - "Sony Corporation" - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Adobe Reader - Schnellstart.lnk" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"McAfee Security Scan Plus.lnk" - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe  (Shortcut exists | File exists)
"Tevion Scanner Finder.lnk" - ? - C:\Program Files\Tevion\ScanWizard 5\ScannerFinder.exe  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Device Detection" - ? - C:\Program Files\LIDL Fotoservice\dd.exe
"InfoCockpit" - "Deutsche Telekom AG, T-Com" - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE /nosplash
"ISUSPM" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"Logitech Vid" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
"Nero MediaHome 4" - "Nero AG" - "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
"Sony PC Companion" - "Sony" - "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
"swg" - "Google Inc." - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"T-Online_Software_6\WLAN-Access Finder" - "Deutsche Telekom AG, Marmiko IT-Solutions GmbH" - C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe /StartMinimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Photo Downloader" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ccApp" - "Symantec Corporation" - "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
"DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"LogitechQuickCamRibbon" - "Logitech Inc." - "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
"Nero MediaHome 4" - "Nero AG" - "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"StartCCC" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe  (File found, but it contains no detailed information)
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Adobe LM Service" (Adobe LM Service) - "Adobe Systems" - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Automatisches LiveUpdate - Scheduler" (Automatic LiveUpdate Scheduler) - "Symantec Corporation" - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
"BBUpdate" (BBUpdate) - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
"BingBar Service" (BBSvc) - "Microsoft Corporation." - C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
"COM Host" (comHost) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Kodak AiO Network Discovery Service" (Kodak AiO Network Discovery Service) - "Eastman Kodak Company" - C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
"LiveShare P2P Server 9" (RoxLiveShare9) - ? - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe"  (File not found)
"LiveUpdate" (LiveUpdate) - "Symantec Corporation" - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
"LiveUpdate Notice" (LiveUpdate Notice) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"McAfee Security Scan Component Host Service" (McComponentHostService) - "McAfee, Inc." - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Nero MediaHome 4 Service" (NeroMediaHomeService.4) - "Nero AG" - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"Symantec Core LC" (Symantec Core LC) - ? - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
"Symantec Event Manager" (ccEvtMgr) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec Lic NetConnect service" (CLTNetCnService) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec Settings Manager" (ccSetMgr) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---


Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-22 14:36:37
-----------------------------
14:36:37.837    OS Version: Windows 6.0.6001 Service Pack 1
14:36:37.837    Number of processors: 2 586 0xF0D
14:36:37.839    ComputerName: SANDRA-PC  UserName: Sandra
14:36:39.185    Initialize success
14:41:21.381    AVAST engine defs: 12092100
14:43:27.362    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:43:27.365    Disk 0 Vendor: FUJITSU_MHY2200BH 0000000B Size: 190782MB BusType: 3
14:43:27.786    Disk 0 MBR read successfully
14:43:27.789    Disk 0 MBR scan
14:43:27.796    Disk 0 unknown MBR code
14:43:27.893    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
14:43:27.996    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        90429 MB offset 20973568
14:43:28.111    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        90111 MB offset 206172160
14:43:28.371    Disk 0 scanning sectors +390719488
14:43:29.083    Disk 0 scanning C:\Windows\system32\drivers
14:44:52.696    Service scanning
14:45:28.644    Modules scanning
14:46:59.998    Disk 0 trace - called modules:
14:47:00.117    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
14:47:00.122    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x857dcac8]
14:47:00.127    3 CLASSPNP.SYS[8b449745] -> nt!IofCallDriver -> [0x85667a48]
14:47:00.133    5 acpi.sys[8ae336a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8566c5e8]
14:47:01.105    AVAST engine scan C:\Windows
14:48:16.665    AVAST engine scan C:\Windows\system32
14:59:08.812    AVAST engine scan C:\Windows\system32\drivers
14:59:29.763    AVAST engine scan C:\Users\Sandra
15:39:13.210    AVAST engine scan C:\ProgramData
15:53:30.814    Scan finished successfully
19:12:42.998    Disk 0 MBR has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\MBR.dat"
19:12:43.005    The log file has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\aswMBR.txt"


Viele Grüße Sandi

Sandi83 24.09.2012 12:46

Hallo Cosinus,

was soll ich als nächstes tun?

Bitte um Hilfe!

cosinus 24.09.2012 18:49

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

Sandi83 25.09.2012 08:26

Hallo Cosinus,

kann ich alle wichtigen Daten einfach auf eine externe Platte ziehen.
Muss ich die Daten vorher säubern?

Habe zur Zeit ja keinen funktionsfähigen Virenscanner?

Hallo,

habe in aswMBR FixMBR ausgeführt.
Ich habe nicht erkennen können ob es funktioniert hat,
Deswegen hier die Logdatei kurz nach dem ausführen des FixMBR:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-25 12:24:08
-----------------------------
12:24:08.037    OS Version: Windows 6.0.6001 Service Pack 1
12:24:08.037    Number of processors: 2 586 0xF0D
12:24:08.041    ComputerName: SANDRA-PC  UserName: Sandra
12:24:28.273    Initialize success
12:35:41.492    AVAST engine defs: 12092500
12:44:07.559    Verifying
12:44:17.586    Disk 0 Windows 600 MBR fixed successfully
12:46:26.182    Disk 0 MBR has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\MBR.dat"
12:46:26.185    The log file has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\aswMBRnachFixMBR.txt"

Dann Windows Neustart und neues Log (nach Quickscan)
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-25 12:56:12
-----------------------------
12:56:12.037    OS Version: Windows 6.0.6001 Service Pack 1
12:56:12.037    Number of processors: 2 586 0xF0D
12:56:12.040    ComputerName: SANDRA-PC  UserName: Sandra
12:56:30.808    Initialize success
12:56:47.461    AVAST engine defs: 12092500
12:57:17.244    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
12:57:17.247    Disk 0 Vendor: FUJITSU_MHY2200BH 0000000B Size: 190782MB BusType: 3
12:57:17.273    Disk 0 MBR read successfully
12:57:17.277    Disk 0 MBR scan
12:57:17.285    Disk 0 Windows VISTA default MBR code
12:57:17.293    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
12:57:17.318    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        90429 MB offset 20973568
12:57:17.344    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        90111 MB offset 206172160
12:57:17.356    Disk 0 scanning sectors +390719488
12:57:17.440    Disk 0 scanning C:\Windows\system32\drivers
12:57:33.672    Service scanning
12:58:13.577    Modules scanning
12:58:31.899    Disk 0 trace - called modules:
12:58:31.921    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
12:58:31.927    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86476ac8]
12:58:31.932    3 CLASSPNP.SYS[8b849745] -> nt!IofCallDriver -> [0x85a67a48]
12:58:31.937    5 acpi.sys[8b2336a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85a70ba0]
12:58:32.627    AVAST engine scan C:\Windows
12:58:36.422    AVAST engine scan C:\Windows\system32
13:03:09.976    AVAST engine scan C:\Windows\system32\drivers
13:03:29.560    AVAST engine scan C:\Users\Sandra
13:29:25.464    AVAST engine scan C:\ProgramData
13:38:41.494    Scan finished successfully
13:39:33.404    Disk 0 MBR has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\MBR.dat"
13:39:33.411    The log file has been saved successfully to "C:\Users\Sandra\Pictures\Desktop\Malwareangriff\aswMBR25_09_2012.txt"

Ich hoffe es war so richtig!

Irgendetwas hat sich verstellt, den jetzt meldet sich immer die Benutzerkontensteuerung.
Unter Systemsteuerung ist aber kein Haken drin!

Ich müsste eine dringende Onlineüberweisung tätigen. Ist das jetzt schon wieder ohne Gefahr möglich?

Viele Grüße
Sandi

cosinus 25.09.2012 12:53

Ja, aber bitte nur Datendateien, keine Programme, Spiele oder Setups!

Sandi83 25.09.2012 13:25

Hallo Cosinus,

habe Daten gesichert und in aswMBR FixMBR ausgeführt.

Logdateien habe ich schon gepostet.

cosinus 25.09.2012 14:52

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Sandi83 26.09.2012 09:10

Hallo

hier die Logdateien:

Malewarebytes:
Code:


Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.25.10

Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 8.0.6001.19088
Sandra :: SANDRA-PC [Administrator]

Schutz: Aktiviert

25.09.2012 18:41:05
mbam-log-2012-09-25 (18-41-05).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 449961
Laufzeit: 2 Stunde(n), 10 Minute(n), 30 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

SUPERAntiSpyware:

Code:


SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/26/2012 at 01:45 AM

Application Version : 5.5.1016

Core Rules Database Version : 9290
Trace Rules Database Version: 7102

Scan type      : Complete Scan
Total Scan Time : 03:14:33

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 1 (Build 6.00.6001)
UAC On - Administrator

Memory items scanned      : 971
Memory threats detected  : 0
Registry items scanned    : 39072
Registry threats detected : 0
File items scanned        : 191035
File threats detected    : 383

Adware.Tracking Cookie
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@2o7[1].txt [ /2o7 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@2o7[2].txt [ /2o7 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@a.revenuemax[1].txt [ /a.revenuemax ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@accounts.google[2].txt [ /accounts.google ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@accounts.youtube[1].txt [ /accounts.youtube ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@accounts.youtube[2].txt [ /accounts.youtube ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@accounts.youtube[3].txt [ /accounts.youtube ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.123-template[1].txt [ /ad.123-template ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.360yield[2].txt [ /ad.360yield ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.ad-srv[1].txt [ /ad.ad-srv ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.ad-srv[2].txt [ /ad.ad-srv ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.adc-serv[2].txt [ /ad.adc-serv ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.adnet[1].txt [ /ad.adnet ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.adnet[2].txt [ /ad.adnet ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.dyntracker[1].txt [ /ad.dyntracker ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.dyntracker[3].txt [ /ad.dyntracker ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.yieldmanager[3].txt [ /ad.yieldmanager ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.zanox[2].txt [ /ad.zanox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.zanox[3].txt [ /ad.zanox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad.zanox[4].txt [ /ad.zanox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad1.adfarm1.adition[1].txt [ /ad1.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad2.adfarm1.adition[1].txt [ /ad2.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad2.adfarm1.adition[2].txt [ /ad2.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad2.adfarm1.adition[3].txt [ /ad2.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad2.adfarm1.adition[4].txt [ /ad2.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad3.adfarm1.adition[2].txt [ /ad3.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad3.adfarm1.adition[3].txt [ /ad3.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad4.adfarm1.adition[1].txt [ /ad4.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad4.adfarm1.adition[2].txt [ /ad4.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad4.adfarm1.adition[3].txt [ /ad4.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ad4.adfarm1.adition[5].txt [ /ad4.adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adbrite[1].txt [ /adbrite ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adbrite[3].txt [ /adbrite ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[1].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[2].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[3].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[4].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[5].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[6].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[7].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adfarm1.adition[9].txt [ /adfarm1.adition ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adformdsp[1].txt [ /adformdsp ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adform[1].txt [ /adform ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adnetwork[1].txt [ /adnetwork ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.1a-infosysteme[1].txt [ /ads.1a-infosysteme ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.blackfling[1].txt [ /ads.blackfling ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.crakmedia[2].txt [ /ads.crakmedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.creative-serving[1].txt [ /ads.creative-serving ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.getyourguide[2].txt [ /ads.getyourguide ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.jinkads[1].txt [ /ads.jinkads ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.trafficjunky[1].txt [ /ads.trafficjunky ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.undertone[2].txt [ /ads.undertone ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads.unister-gmbh[1].txt [ /ads.unister-gmbh ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ads2.zeusclicks[1].txt [ /ads2.zeusclicks ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adserve.f-flirts[2].txt [ /adserve.f-flirts ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adserver.mediadomain-verlag[2].txt [ /adserver.mediadomain-verlag ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adtech[1].txt [ /adtech ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adtech[2].txt [ /adtech ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adtech[3].txt [ /adtech ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adultfriendfinder[1].txt [ /adultfriendfinder ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adultfriendfinder[2].txt [ /adultfriendfinder ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adv1.rack-media[2].txt [ /adv1.rack-media ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@advertising[1].txt [ /advertising ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adviva[1].txt [ /adviva ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adviva[2].txt [ /adviva ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adx.chip[2].txt [ /adx.chip ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@adxpansion[2].txt [ /adxpansion ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@amazon-adsystem[1].txt [ /amazon-adsystem ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@apmebf[1].txt [ /apmebf ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@apmebf[2].txt [ /apmebf ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@at.atwola[1].txt [ /at.atwola ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@atdmt[1].txt [ /atdmt ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@atdmt[2].txt [ /atdmt ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@atdmt[4].txt [ /atdmt ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@bannerboard[1].txt [ /bannerboard ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@bs.serving-sys[2].txt [ /bs.serving-sys ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@burstnet[1].txt [ /burstnet ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@c.atdmt[2].txt [ /c.atdmt ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@c.atdmt[3].txt [ /c.atdmt ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@casalemedia[2].txt [ /casalemedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@collective-media[1].txt [ /collective-media ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[10].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[11].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[1].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[2].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[3].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[4].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[5].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[6].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[7].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[8].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@doubleclick[9].txt [ /doubleclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@eaeacom.112.2o7[2].txt [ /eaeacom.112.2o7 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@eas.apm.emediate[1].txt [ /eas.apm.emediate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@eas.apm.emediate[2].txt [ /eas.apm.emediate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@eas.apm.emediate[3].txt [ /eas.apm.emediate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[1].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[2].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[3].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[4].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[5].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ehg-foxsports.hitbox[6].txt [ /ehg-foxsports.hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ero-advertising[1].txt [ /ero-advertising ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ero-advertising[3].txt [ /ero-advertising ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@etargetnet[2].txt [ /etargetnet ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@exoclick[2].txt [ /exoclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@fastclick[1].txt [ /fastclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@fastclick[3].txt [ /fastclick ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@hertz.122.2o7[1].txt [ /hertz.122.2o7 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@histats[1].txt [ /histats ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@histats[2].txt [ /histats ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@hitbox[1].txt [ /hitbox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@im.banner.t-online[2].txt [ /im.banner.t-online ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@im.banner.t-online[3].txt [ /im.banner.t-online ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@insightexpressai[1].txt [ /insightexpressai ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@invitemedia[1].txt [ /invitemedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@invitemedia[2].txt [ /invitemedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@kursnet-finden.arbeitsagentur[1].txt [ /kursnet-finden.arbeitsagentur ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@lfstmedia[1].txt [ /lfstmedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@liveperson[1].txt [ /liveperson ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@liveperson[3].txt [ /liveperson ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@lucidmedia[1].txt [ /lucidmedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@media.photobucket[2].txt [ /media.photobucket ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@media6degrees[2].txt [ /media6degrees ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@mediaplex[1].txt [ /mediaplex ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@mediaplex[3].txt [ /mediaplex ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ox-d.adnetxchange[2].txt [ /ox-d.adnetxchange ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ox-d.secure-clicks[2].txt [ /ox-d.secure-clicks ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@partners.webmasterplan[2].txt [ /partners.webmasterplan ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@quartermedia[2].txt [ /quartermedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@questionmarket[1].txt [ /questionmarket ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@revsci[1].txt [ /revsci ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@revsci[3].txt [ /revsci ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ru4[2].txt [ /ru4 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@server.adformdsp[1].txt [ /server.adformdsp ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@server.iad.liveperson[1].txt [ /server.iad.liveperson ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@serving-sys[1].txt [ /serving-sys ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@serving-sys[3].txt [ /serving-sys ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@sk.search.etargetnet[2].txt [ /sk.search.etargetnet ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@smartadserver[1].txt [ /smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@smartadserver[2].txt [ /smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@smartadserver[3].txt [ /smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@sonyeurope.112.2o7[1].txt [ /sonyeurope.112.2o7 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@statcounter[1].txt [ /statcounter ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@stats.goomradio[2].txt [ /stats.goomradio ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@statse.webtrendslive[2].txt [ /statse.webtrendslive ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@syndication.traffichaus[1].txt [ /syndication.traffichaus ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tomtailor.dyntracker[2].txt [ /tomtailor.dyntracker ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@toplist[1].txt [ /toplist ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@toplist[2].txt [ /toplist ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@track.adform[2].txt [ /track.adform ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@track.zalando[1].txt [ /track.zalando ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tracker.vinsight[2].txt [ /tracker.vinsight ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tracking.quisma[1].txt [ /tracking.quisma ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tracking.quisma[2].txt [ /tracking.quisma ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tradedoubler[2].txt [ /tradedoubler ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tradedoubler[3].txt [ /tradedoubler ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@traffictrack[2].txt [ /traffictrack ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@tribalfusion[1].txt [ /tribalfusion ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@unister-adservices[1].txt [ /unister-adservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@unitymediaforum[1].txt [ /unitymediaforum ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@unitymedia[2].txt [ /unitymedia ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@webmasterplan[1].txt [ /webmasterplan ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@webmasterplan[3].txt [ /webmasterplan ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ww251.smartadserver[1].txt [ /ww251.smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@ww251.smartadserver[2].txt [ /ww251.smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.active-tracking[2].txt [ /www.active-tracking ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.etracker[1].txt [ /www.etracker ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.fpctraffic2[1].txt [ /www.fpctraffic2 ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.googleadservices[1].txt [ /www.googleadservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.googleadservices[2].txt [ /www.googleadservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.googleadservices[3].txt [ /www.googleadservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.googleadservices[4].txt [ /www.googleadservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.googleadservices[7].txt [ /www.googleadservices ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.zanox-affiliate[2].txt [ /www.zanox-affiliate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www4.smartadserver[2].txt [ /www4.smartadserver ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@xiti[2].txt [ /xiti ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@yadro[2].txt [ /yadro ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@yieldmanager[1].txt [ /yieldmanager ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@zanox-affiliate[1].txt [ /zanox-affiliate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@zanox-affiliate[2].txt [ /zanox-affiliate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@zanox-affiliate[3].txt [ /zanox-affiliate ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@zanox[1].txt [ /zanox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@zanox[2].txt [ /zanox ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@uk.sitestat[1].txt [ /uk.sitestat.com ]
        C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Cookies\sandra@de.sitestat[1].txt [ /de.sitestat.com ]
        C:\USERS\NEROMEDIAHOMEUSER.4\AppData\Roaming\Microsoft\Windows\Cookies\neromediahomeuser.4@zdf[4].txt [ Cookie:neromediahomeuser.4@zdf.de/ ]
        C:\USERS\NEROMEDIAHOMEUSER.4\Cookies\neromediahomeuser.4@zdf[4].txt [ Cookie:neromediahomeuser.4@zdf.de/ ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@clkads[1].txt [ Cookie:sandra@clkads.com/adServe/banners ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@gallys.gfrevenge[2].txt [ Cookie:sandra@gallys.gfrevenge.com/vbanners/ ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.google[3].txt [ Cookie:sandra@www.google.com/insights/search ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@google[6].txt [ Cookie:sandra@google.com/accounts/ ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.google[2].txt [ Cookie:sandra@www.google.de/accounts ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\sandra@www.google[1].txt [ Cookie:sandra@www.google.com/accounts ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\Low\sandra@mediaplex[1].txt [ Cookie:sandra@mediaplex.com/ ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\Low\sandra@apmebf[1].txt [ Cookie:sandra@apmebf.com/ ]
        C:\USERS\SANDRA\AppData\Roaming\Microsoft\Windows\Cookies\Low\sandra@atdmt[2].txt [ Cookie:sandra@atdmt.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@clkads[1].txt [ Cookie:sandra@clkads.com/adServe/banners ]
        C:\USERS\SANDRA\Cookies\sandra@imrworldwide[2].txt [ Cookie:sandra@imrworldwide.com/cgi-bin ]
        C:\USERS\SANDRA\Cookies\sandra@mediaplex[3].txt [ Cookie:sandra@mediaplex.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@liveperson[3].txt [ Cookie:sandra@liveperson.net/hc/11042824 ]
        C:\USERS\SANDRA\Cookies\sandra@www.googleadservices[2].txt [ Cookie:sandra@www.googleadservices.com/pagead/conversion/1030004439/ ]
        C:\USERS\SANDRA\Cookies\sandra@xiti[2].txt [ Cookie:sandra@xiti.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@lucidmedia[1].txt [ Cookie:sandra@lucidmedia.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@gallys.gfrevenge[2].txt [ Cookie:sandra@gallys.gfrevenge.com/vbanners/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.zanox-affiliate[2].txt [ Cookie:sandra@www.zanox-affiliate.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@casalemedia[2].txt [ Cookie:sandra@casalemedia.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@tradedoubler[3].txt [ Cookie:sandra@tradedoubler.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ad2.adfarm1.adition[1].txt [ Cookie:sandra@ad2.adfarm1.adition.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ehg-foxsports.hitbox[2].txt [ Cookie:sandra@ehg-foxsports.hitbox.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@collective-media[1].txt [ Cookie:sandra@collective-media.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@amazon-adsystem[1].txt [ Cookie:sandra@amazon-adsystem.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@hitbox[1].txt [ Cookie:sandra@hitbox.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@unister-adservices[1].txt [ Cookie:sandra@unister-adservices.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ad.yieldmanager[3].txt [ Cookie:sandra@ad.yieldmanager.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@kursnet-finden.arbeitsagentur[1].txt [ Cookie:sandra@kursnet-finden.arbeitsagentur.de/kurs/ ]
        C:\USERS\SANDRA\Cookies\sandra@apmebf[2].txt [ Cookie:sandra@apmebf.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@advertising[1].txt [ Cookie:sandra@advertising.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@server.iad.liveperson[1].txt [ Cookie:sandra@server.iad.liveperson.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@adserve.f-flirts[2].txt [ Cookie:sandra@adserve.f-flirts.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@traffictrack[2].txt [ Cookie:sandra@traffictrack.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@ox-d.secure-clicks[2].txt [ Cookie:sandra@ox-d.secure-clicks.org/ ]
        C:\USERS\SANDRA\Cookies\sandra@atdmt[4].txt [ Cookie:sandra@atdmt.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@uk.sitestat[1].txt [ Cookie:sandra@uk.sitestat.com/isango/isango/ ]
        C:\USERS\SANDRA\Cookies\sandra@doubleclick[9].txt [ Cookie:sandra@doubleclick.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.usenext[2].txt [ Cookie:sandra@www.usenext.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@im.banner.t-online[3].txt [ Cookie:sandra@im.banner.t-online.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@ad3.adfarm1.adition[3].txt [ Cookie:sandra@ad3.adfarm1.adition.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@2o7[1].txt [ Cookie:sandra@2o7.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@webmasterplan[1].txt [ Cookie:sandra@webmasterplan.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@revsci[3].txt [ Cookie:sandra@revsci.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@tribalfusion[1].txt [ Cookie:sandra@tribalfusion.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@questionmarket[1].txt [ Cookie:sandra@questionmarket.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.google[3].txt [ Cookie:sandra@www.google.com/insights/search ]
        C:\USERS\SANDRA\Cookies\sandra@www.googleadservices[3].txt [ Cookie:sandra@www.googleadservices.com/pagead/conversion/1069787306/ ]
        C:\USERS\SANDRA\Cookies\sandra@invitemedia[2].txt [ Cookie:sandra@invitemedia.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@adform[1].txt [ Cookie:sandra@adform.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@ad.adnet[1].txt [ Cookie:sandra@ad.adnet.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@track.adform[2].txt [ Cookie:sandra@track.adform.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@a.revenuemax[1].txt [ Cookie:sandra@a.revenuemax.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@tracking.quisma[2].txt [ Cookie:sandra@tracking.quisma.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ads.trafficjunky[1].txt [ Cookie:sandra@ads.trafficjunky.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@de.sitestat[1].txt [ Cookie:sandra@de.sitestat.com/is24-community/is24-community/ ]
        C:\USERS\SANDRA\Cookies\sandra@eaeacom.112.2o7[2].txt [ Cookie:sandra@eaeacom.112.2o7.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@adviva[2].txt [ Cookie:sandra@adviva.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@sonyeurope.112.2o7[1].txt [ Cookie:sandra@sonyeurope.112.2o7.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@ru4[2].txt [ Cookie:sandra@ru4.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@adformdsp[1].txt [ Cookie:sandra@adformdsp.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@server.adformdsp[1].txt [ Cookie:sandra@server.adformdsp.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@adultfriendfinder[1].txt [ Cookie:sandra@adultfriendfinder.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ox-d.adnetxchange[2].txt [ Cookie:sandra@ox-d.adnetxchange.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@sk.search.etargetnet[2].txt [ Cookie:sandra@sk.search.etargetnet.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@adbrite[3].txt [ Cookie:sandra@adbrite.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@histats[2].txt [ Cookie:sandra@histats.com/stats/ ]
        C:\USERS\SANDRA\Cookies\sandra@ads2.zeusclicks[1].txt [ Cookie:sandra@ads2.zeusclicks.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@serving-sys[3].txt [ Cookie:sandra@serving-sys.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@quartermedia[2].txt [ Cookie:sandra@quartermedia.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@liveperson[1].txt [ Cookie:sandra@liveperson.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@burstnet[1].txt [ Cookie:sandra@burstnet.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@hertz.122.2o7[1].txt [ Cookie:sandra@hertz.122.2o7.net/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.googleadservices[1].txt [ Cookie:sandra@www.googleadservices.com/pagead/conversion/1068627716/ ]
        C:\USERS\SANDRA\Cookies\sandra@statse.webtrendslive[2].txt [ Cookie:sandra@statse.webtrendslive.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@statcounter[1].txt [ Cookie:sandra@statcounter.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@media.photobucket[2].txt [ Cookie:sandra@media.photobucket.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@histats[1].txt [ Cookie:sandra@histats.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@ad.dyntracker[3].txt [ Cookie:sandra@ad.dyntracker.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.googleadservices[7].txt [ Cookie:sandra@www.googleadservices.com/pagead/conversion/995553404/ ]
        C:\USERS\SANDRA\Cookies\sandra@adxpansion[2].txt [ Cookie:sandra@adxpansion.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@invitemedia[1].txt [ Cookie:sandra@invitemedia.com/ ]
        C:\USERS\SANDRA\Cookies\sandra@tracker.vinsight[2].txt [ Cookie:sandra@tracker.vinsight.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@adtech[3].txt [ Cookie:sandra@adtech.de/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.googleadservices[4].txt [ Cookie:sandra@www.googleadservices.com/pagead/conversion/1064217298/ ]
        C:\USERS\SANDRA\Cookies\sandra@google[6].txt [ Cookie:sandra@google.com/accounts/ ]
        C:\USERS\SANDRA\Cookies\sandra@www.google[2].txt [ Cookie:sandra@www.google.de/accounts ]
        C:\USERS\SANDRA\Cookies\sandra@www.google[1].txt [ Cookie:sandra@www.google.com/accounts ]
        C:\USERS\SANDRA\Cookies\sandra@stats.goomradio[2].txt [ Cookie:sandra@stats.goomradio.com/player/ ]
        .doubleclick.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .aok.122.2o7.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradetracker.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ec-track.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.mindshare.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kaspersky.122.2o7.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tomtailor.dyntracker.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.googleadservices.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kontera.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        server.adformdsp.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adformdsp.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx2.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracker.vinsight.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tribalfusion.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        C:\USERS\SANDRA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SANDRA@C.ATDMT[2].TXT [ /C.ATDMT ]
        C:\USERS\SANDRA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\SANDRA@SERVING-SYS[1].TXT [ /SERVING-SYS ]

Mit den Cookies habe ich jetzt noch nichts gemacht.

cosinus 26.09.2012 15:28

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Sandi83 26.09.2012 16:25

Es funktioniert alles sehr gut, aber ich habe noch kein richtiges Sicherheitskonzept.

Firewall und Virenscanner.
Vorgehen beim Surfen(welcher Browser).
Umgang mit Updates

Entfernung alter Software.

Hast Du da für mich noch Tipps!

Was ist mit den Dateien, die in der Quarantäne stehen.
Über den TDSS-Killer hatte ich doch aus versehen Dateien in die Quarantäne geschoben, die wir wieder herstellen wollten.

Beim ESSET Online Scanner wurden damals 6 Dateien gefunden.
Der Haken bei Remove sollte ja nicht gesetzt werden.
Sind die Dateien über die anderen Werkzeuge entfernt worden oder noch da und werden nur nicht angezeigt?

Ist hier noch etwas zu tun?

cosinus 27.09.2012 10:56

Zitat:

aber ich habe noch kein richtiges Sicherheitskonzept.
Lies mal diesen Artikel => http://www.trojaner-board.de/96344-a...tml#post627442

Kurz erläutert in meinen Worten:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?


Zitat:

Was ist mit den Dateien, die in der Quarantäne stehen.

Was habt ihr alle immer nur mit der Quarantäne? :wtf:
Überleg doch mal was eine Quarantäne ist. Ob da die schädliche Datei drinbleibt oder nicht, das hat keine Auswirkungen. Schädlinge in der Quarantäne können nichts mehr anrichten, sie sind dort isoliert. Du solltest grundsätzlich mit der Quarantäne arbeiten, denn falls der Virenscanner durch einen Fehlalarm was wichtiges löscht, kannst Du notfalls noch über die Quarantäne an die Datei ran.

Zitat:

Über den TDSS-Killer hatte ich doch aus versehen Dateien in die Quarantäne geschoben, die wir wieder herstellen wollten.
Was gibt es denn dazu wiederherzustellen? Ich hab doch erwähnt, dass die Dateien nur in die Quarantäne kopiert wurden, da wurde nichts verschoben! Es gab auch keinen Anlass irgendetwas zu machen weil die Dateien legitim sind, du hattest ja da auf Grund eines Bedienfehlers die Dateien in die Q kopiert!

Zitat:

Beim ESSET Online Scanner wurden damals 6 Dateien gefunden.
Der Haken bei Remove sollte ja nicht gesetzt werden.
Sind die Dateien über die anderen Werkzeuge entfernt worden oder noch da und werden nur nicht angezeigt?
Was weg sollte hab ich entfernt mit OTL, ist jetzt also in der Q von OTL

Sandi83 28.09.2012 17:02

Hallo Cosinus,

vielen Dank für Deine Hilfe!

Abschließend habe ich noch eine Frage zur Vorgehensweise!

Muss ich erst die Softwarehelfer Malewarebytes, Gmer, usw. alle entfernen (über die Systemsteuerung) und dann meine Updates machen?

T-Online 6.0 macht mir Probleme, bekomme ich nicht über die Systemsteuerung weg.
Hast Du schon Erfahrungen gemacht.

Dann mache ich mich über die Sicherheitseinstellungen und hoffe dann verschont zu bleiben!

Viele Grüße
Sandi

cosinus 28.09.2012 19:04

Versuch mal T-Online damit zu entfernen => http://filepony.de/download-revo_uninstaller/

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Sandi83 29.09.2012 20:14

Hallo Cosinus,

leider hat der Revo Uninstaller nichts gebracht. Es wurden zwar einige Dateien und Registryeinträge gelöscht, aber unter C: sind die T-Online Ordner immer noch da!

Im Revo Uninstaller und unter der Systemsteuerung finde ich T-Online dafür nicht mehr!
Kann ich die Dateien jetzt einfach löschen?
Kannst Du mir bitte helfen?

Beim Updaten der Software habe ich mit dem Microsoft XML Core Services Probleme.
Es würde ein Dienst dd verwendet werden.

Viele Grüße
Sandi

Hallo Cosinus,

nach Beendigung einiger Programme in der Autostart, konnte ich die MS XML Core Services updaten!

cosinus 01.10.2012 12:11

Zitat:

aber unter C: sind die T-Online Ordner immer noch da!
Und? Dann verschiebt man sie eben manuell in einen Ordner wie zB C:\tmp und wenn alles noch läuft wie vorher dann löscht man sie komplett!


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:13 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55