Nabend ryder
Vielen Dank für Deine Hilfe. Bin sehr erleichtert. Ich hab die logfiles erstellt.
Ich hoffe, ich poste die richtig. Es sind drei files. Ich musste recht oft meinen Namen als Benutzer entfernen.
adwcleaner
[CODE]# AdwCleaner v2.109 - Datei am 27/01/2013 um 16:42:21 erstellt
# Aktualisiert am 26/01/2013 von Xplode
# Betriebssystem : Windows 7 Enterprise Service Pack 1 (32 bits)
# Benutzer : *** - CLT-MOB-N-1031
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\***\Downloads\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\lpk4yn2s.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\lpk4yn2s.default\bprotector_prefs.js
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Babylon
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\59558fdfb46ae546
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{991D97B8-F0D8-4EA1-9100-7A65EA2D3A63}
Schlüssel Gelöscht : HKLM\SOFTWARE\59558fdfb46ae546
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
***** [Internet Browser] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v18.0.1 (de)
Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\gmtcyi35.default\prefs.js
C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\gmtcyi35.default\user.js ... Gelöscht !
Gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true);
Gelöscht : user_pref("extensions.claro.admin", false);
Gelöscht : user_pref("extensions.claro.aflt", "babsst");
Gelöscht : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}");
Gelöscht : user_pref("extensions.claro.autoRvrt", "false");
Gelöscht : user_pref("extensions.claro.dfltLng", "en");
Gelöscht : user_pref("extensions.claro.excTlbr", false);
Gelöscht : user_pref("extensions.claro.id", "2ca60f9700000000000024770313ed71");
Gelöscht : user_pref("extensions.claro.instlDay", "15715");
Gelöscht : user_pref("extensions.claro.instlRef", "sst");
Gelöscht : user_pref("extensions.claro.prdct", "claro");
Gelöscht : user_pref("extensions.claro.prtnrId", "claro");
Gelöscht : user_pref("extensions.claro.rvrt", "false");
Gelöscht : user_pref("extensions.claro.tlbrId", "base");
Gelöscht : user_pref("extensions.claro.tlbrSrchUrl", "");
Gelöscht : user_pref("extensions.claro.vrsn", "1.8.8.5");
Gelöscht : user_pref("extensions.claro.vrsni", "1.8.8.5");
Gelöscht : user_pref("extensions.claro_i.excTlbr", false);
Gelöscht : user_pref("extensions.claro_i.newTab", false);
Gelöscht : user_pref("extensions.claro_i.smplGrp", "none");
Gelöscht : user_pref("extensions.claro_i.vrsnTs", "1.8.8.510:11:18");
Datei : C:\Users\usrn0180\AppData\Roaming\Mozilla\Firefox\Profiles\gmtcyi35.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\gmtcyi35.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\lpk4yn2s.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v [Version kann nicht ermittelt werden]
Datei : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [4651 octets] - [27/01/2013 16:42:21]
########## EOF - C:\AdwCleaner[S1].txt - [4711 octets] ##########
[CODE]
DDS Logfile:
Code:
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.9.2
Run by *** at 17:10:15 on 2013-01-27
#Option MBR scan is disabled.
Microsoft Windows 7 Enterprise 6.1.7601.1.1252.41.1031.18.2985.1570 [GMT 1:00]
.
AV: Sophos Anti-Virus *Enabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Sophos Anti-Virus *Enabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\IDT\WDM\STacSV.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\aestsrv.exe
C:\Windows\system32\Empirum\EmpirumRCHost.exe
C:\Windows\system32\Empirum\Eris.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Empirum\EmpirumRemoteSettings.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\System32\Empirum\ERIS_UI.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\dradio-Recorder\phonostarTimer.exe
C:\Program Files\Citrix\ICA Client\PNAMAIN.EXE
C:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\Empirum\eris_ui.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k regsvc
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = Preserve
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [dradio-RecorderTimer] c:\program files\dradio-recorder\phonostarTimer.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [erisui] "c:\windows\system32\empirum\eris_ui" /hide
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [cryptocardRdpM2Mreg] rdpM2M.vbs
mRun: [Sophos AutoUpdate Monitor] c:\program files\sophos\autoupdate\almon.exe
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [DivXMediaServer] c:\program files\divx\divx media server\DivXMediaServer.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empiru~1.lnk - c:\windows\system32\empirum\EmpInventory.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\online~1.lnk - c:\windows\installer\{7681a1a9-d865-4dc0-a319-41a49f5e78db}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableInstallerDetection = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableSecureUIAPaths = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: dontdisplaylastusername = dword:1
mPolicies-System: SoftwareSASGeneration = dword:3
mPolicies-Windows\System: UseOEMBackground = dword:1
mPolicies-Windows\System: AddAdminGroupToRUP = dword:1
mPolicies-Windows\System: SlowLinkDetectEnabled = dword:0
mPolicies-Windows\System: UserPolicyMode = dword:1
IE: An vorhandene PDF-Datei anfügen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
TCP: NameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
TCP: Interfaces\{63D5BE52-6DFC-4872-8969-6B9EBA002FBD} : DHCPNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
TCP: Interfaces\{63D5BE52-6DFC-4872-8969-6B9EBA002FBD}\7457563747 : DHCPNameServer = 130.238.96.1 130.238.98.11
TCP: Interfaces\{A4E085BB-9FDD-4057-922D-3D720C717789} : DHCPNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs= c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: NukeOnDelete - c:\program files\empirum\packages\nukeondelete\1.0\NukeOnDelete.vbs
mASetup: UserRegistry - c:\program files\initbuild\userregistry\UserRegistry.vbs
mASetup: ZHAWMobileUser - c:\program files\initmobile\initmobileuser\InitMobile_User.vbs
mASetup: {CD9F3105-0DF6-4D56-BFB1-759DEDB864CC} - msiexec.exe -fu {CD9F3105-0DF6-4D56-BFB1-759DEDB864CC} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\***\appdata\roaming\mozilla\firefox\profiles\gmtcyi35.default\
FF - plugin: c:\progra~1\micros~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2011-10-25 20328]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\drivers\stdcfltn.sys [2011-10-25 17648]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-4-16 65584]
R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\drivers\savonaccess.sys [2012-7-30 123680]
R1 SKMScan;SKMScan;c:\windows\system32\drivers\skmscan.sys [2012-7-30 31736]
R2 AESTFilters;Andrea ST Filters Service;c:\program files\idt\wdm\AEstSrv.exe [2011-10-25 81920]
R2 EmpirumRC_Service;Empirum Remote Control Service;c:\windows\system32\empirum\EmpirumRCHost.exe [2011-10-25 893952]
R2 ERIS;Empirum Remote Installation Service;c:\windows\system32\empirum\ERIS.exe [2011-10-25 220568]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-1-24 398184]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-1-24 682344]
R2 SAVAdminService;Sophos Anti-Virus Statusreporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2012-12-5 216640]
R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2012-7-30 139840]
R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2012-9-21 289856]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2012-8-8 232512]
R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2012-9-21 818240]
R2 Sophos Web Control Service;Sophos Web Control Service;c:\program files\sophos\sophos anti-virus\web control\swc_service.exe [2012-7-30 357400]
R2 swi_service;Sophos Web Intelligence Service;c:\program files\sophos\sophos anti-virus\web intelligence\swi_service.exe [2012-12-5 2869824]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2010-5-5 583360]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2011-10-25 43888]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2011-10-25 33832]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-1-24 21104]
R3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2011-10-25 41088]
R3 NETwNs32;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 32-Bit;c:\windows\system32\drivers\NETwNs32.sys [2011-10-25 7434240]
R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\o2mdfw7.sys [2011-10-25 60904]
R3 O2SDJRDR;O2SDJRDR;c:\windows\system32\drivers\o2sdjw7.sys [2011-10-25 63848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-10-19 160944]
S2 swi_update;Sophos Web Intelligence Update;c:\programdata\sophos\web intelligence\swi_update.exe [2012-7-30 1459264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\drivers\d554gps.sys [2011-10-25 87592]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-12 62464]
S3 ecnssndis; Mobile Broadband Driver;c:\windows\system32\drivers\wwanuss.sys [2011-10-25 23592]
S3 ecnssndisfltr; Mobile Broadband Driver Filter;c:\windows\system32\drivers\wwanussf.sys [2011-10-25 26152]
S3 Mbm3CBus;Dell Wireless 5530 HSPA Mini-Card Device (WDM);c:\windows\system32\drivers\Mbm3CBus.sys [2011-10-25 361032]
S3 Mbm3DevMt;Dell Wireless HSPA Mini-Card Device Management Driver (WDM);c:\windows\system32\drivers\Mbm3DevMt.sys [2011-10-25 396872]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2011-10-25 62208]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2011-10-25 141568]
S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\drivers\O2MDRw7.sys [2011-10-25 62440]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-12-19 14848]
S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [2012-7-30 33696]
S3 StorSvc;Speicherdienst;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2011-4-12 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-12-19 24064]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-12-19 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-12-19 27136]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2011-4-12 112640]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2012-5-11 22536]
.
=============== Created Last 30 ================
.
2013-01-24 12:06:55 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-24 12:06:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-19 19:37:27 -------- d-----w- c:\users\***\appdata\local\Zattoo
2013-01-19 19:37:22 -------- d-----w- c:\program files\Zattoo4
2013-01-10 20:12:18 -------- d-----w- c:\users\***\appdata\roaming\Malwarebytes
2013-01-10 20:12:06 -------- d-----w- c:\programdata\Malwarebytes
2013-01-10 20:11:47 -------- d-----w- c:\users\***\appdata\local\Programs
2013-01-10 19:09:59 -------- d-----w- c:\users\***\appdata\local\Macromedia
2013-01-10 19:08:39 -------- d-----w- c:\users\***\appdata\local\Mozilla
2013-01-10 16:33:52 -------- d-----w- c:\users\***\appdata\local\Sophos
.
==================== Find3M ====================
.
2012-12-19 10:45:29 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-19 10:44:51 376832 ----a-w- c:\windows\system32\dpnet.dll
2012-12-19 10:44:31 981504 ----a-w- c:\windows\system32\wininet.dll
2012-12-19 10:44:31 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-19 10:39:51 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-19 10:39:51 295424 ----a-w- c:\windows\system32\atmfd.dll
2012-12-19 10:39:40 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-12-19 10:37:25 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-12-19 10:37:25 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-12-19 10:37:25 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-12-19 10:37:25 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-12-19 10:37:25 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-12-19 10:37:25 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-12-19 10:37:25 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-12-19 10:33:41 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-12-19 10:33:41 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-12-19 10:33:15 2560 ----a-w- c:\windows\system32\drivers\de-de\wdf01000.sys.mui
2012-12-19 10:33:14 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-12-19 10:33:14 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-12-19 10:33:14 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-12-19 10:32:41 78336 ----a-w- c:\windows\system32\synceng.dll
2012-12-19 10:32:01 52224 ----a-w- c:\windows\system32\nlaapi.dll
2012-12-19 10:32:01 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-12-19 10:32:01 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-12-19 10:32:01 242176 ----a-w- c:\windows\system32\nlasvc.dll
2012-12-19 10:32:01 18944 ----a-w- c:\windows\system32\netevent.dll
2012-12-19 10:32:01 175104 ----a-w- c:\windows\system32\netcorehc.dll
2012-12-19 10:32:01 156672 ----a-w- c:\windows\system32\ncsi.dll
2012-12-19 10:32:01 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-12-19 10:30:02 369856 ----a-w- c:\windows\system32\drivers\cng.sys
2012-12-19 10:30:02 247808 ----a-w- c:\windows\system32\schannel.dll
2012-12-19 10:30:02 220160 ----a-w- c:\windows\system32\ncrypt.dll
2012-12-19 10:30:02 136560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-12-19 10:30:02 1039360 ----a-w- c:\windows\system32\lsasrv.dll
2012-11-29 18:07:14 30744 ----a-w- c:\windows\system32\SophosBootTasks.exe
2012-11-01 15:29:44 542208 ----a-w- c:\windows\system32\kerberos.dll
2012-11-01 15:29:35 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-11-01 15:29:22 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-11-01 15:29:22 1159680 ----a-w- c:\windows\system32\crypt32.dll
2012-11-01 15:29:22 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-11-01 15:26:11 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-11-01 15:25:55 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-11-01 15:25:55 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-11-01 15:23:59 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
.
============= FINISH: 17:10:50.36 ===============
--- --- ---
attach
Code:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Enterprise
Boot Device: \Device\HarddiskVolume1
Install Date: 25.10.2011 10:57:21
System Uptime: 27.01.2013 17:05:27 (0 hours ago)
.
Motherboard: Dell Inc. | | 032T9K
Processor: Intel(R) Core(TM) i5-2540M CPU @ 2.60GHz | CPU 1 | 780/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 458 GiB total, 368.329 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
PNP Device ID: ROOT\NET\0000
Service: vpnva
.
==== System Restore Points ===================
.
RP72: 04.12.2012 16:28:54 - Geplanter Prüfpunkt
RP73: 13.12.2012 13:21:41 - Geplanter Prüfpunkt
RP74: 19.12.2012 11:28:35 - Windows Modules Installer
RP75: 03.01.2013 09:22:10 - Geplanter Prüfpunkt
RP76: 10.01.2013 18:51:30 - Geplanter Prüfpunkt
RP77: 18.01.2013 11:38:59 - Geplanter Prüfpunkt
RP78: 27.01.2013 00:47:28 - Geplanter Prüfpunkt
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
7-Zip 465 4.65.00.0
7-Zip 9.20
Acrobat Pro 10.1
Adobe Acrobat Pro 9.3.3
Adobe Acrobat X Pro - English, Français, Deutsch
Adobe Flash Player 10 ActiveX 10.3.181.34
Adobe Flash Player 11.5.502.110 MUL x86 001
Adobe Shockwave Player 11.5
Anti Virus 1.0
AnyConnect VPN Client 2.5
Apple Application Support
Cisco AnyConnect VPN Client
Citrix Online Plug-in
Citrix Online Plug-in (DV)
Citrix Online Plug-in (HDX)
Citrix Online Plug-in (PNA)
Citrix Online Plug-in (SSON)
Citrix Online Plug-in (USB)
Citrix Online Plug-in (Web)
CRYPTOCard BlackShield ID Cisco AnyConnect
CRYPTOCard BlackShield ID Software Tools
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell Touchpad
DeptN ChangePW zAdmin 1.0
dradio-Recorder Version 3.02.6
Empirum Agent 14.2
Empirum Remote Control Host 3.3
Enterprise Library 5.0 - April 2010 - GAC
FireFox 15.0
Flash Player 11.5
Flash Player Plugin 10.0
InitBuild 1.0
InitMobile 1.0
ISI ResearchSoft - Export Helper
Java 7 Update 9
Java Auto Updater
JAVA JRE 7.X
KB2444677 1.0
KB2744842 1.0
Malwarebytes Anti-Malware Version 1.70.0.1100
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile DEU Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended DEU Language Pack
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010
Microsoft Office Excel MUI (German) 2010
Microsoft Office Groove MUI (German) 2010
Microsoft Office InfoPath MUI (German) 2010
Microsoft Office OneNote MUI (German) 2010
Microsoft Office Outlook MUI (German) 2010
Microsoft Office PowerPoint MUI (German) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Project MUI (German) 2010
Microsoft Office Project Professional 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Italian) 2010
Microsoft Office Proofing (German) 2010
Microsoft Office Publisher MUI (German) 2010
Microsoft Office Shared MUI (German) 2010
Microsoft Office Visio 2010
Microsoft Office Visio MUI (German) 2010
Microsoft Office Word MUI (German) 2010
Microsoft Project 2010 Service Pack 1 (SP1)
Microsoft Project Professional 2010
Microsoft Silverlight
Microsoft Visio 2010 Service Pack 1 (SP1)
Microsoft Visio Premium 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 18.0.1 (x86 de)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NukeOnDelete 1.0
Office Professional 14.0
Office Professional Servicepack All 1.0
Office Professional Update 14.0
Outlook Profile Fix 1.0
PM2Client 14.2
PM2ClientFix 2.0
Project 14.0
QuickTime
QuickTime 7.7.2
Reference Manager 12 Professional Edition
RootCA 1.0
RStudio
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
Shockwave Player 11.5
Silverlight 4.0
Skype™ 6.0
Sophos Anti-Virus
Sophos AutoUpdate
Sophos Remote Management System
swMSM
Tinn-R 2.4.0.1
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
VC80CRTRedist - 8.0.50727.6195
Visio 14.0
Visual C++ 9.0 CRT (x86) WinSXS MSM
VLC 1.1.7
VLC 2.0.2
VLC media player 2.0.2
Windows ServicePack 1.0
ZHAW ICA Client 12.0
.
==== End Of File ===========================
Nochmals Danke,
S