waschpulver | 24.03.2013 21:17 | Hey!
Ich habe die Anweisungen schön befolgt... ;-)
2 abweichungen:
* die Option "cure" bei TDSSKiller stand nicht zur Verfügung - stattdessen habe ich "delete" gewählt.
* Combofix hat keinen Neustart erzwungen, als Abschluss wurde das Log ausgegeben. Habe dann manuell neu gestartet.
Die Symtome sind jetz eigentlich weg. Der Rechner startet in einer normalen Geschwindigkeit. Ich hoff, damit hat sichs dann! :))
Anbei noch die Logs:
TDSSKiller (2 Logs): Code:
20:21:49.0562 0460 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:21:49.0718 0460 ============================================================
20:21:49.0718 0460 Current date / time: 2013/03/24 20:21:49.0718
20:21:49.0718 0460 SystemInfo:
20:21:49.0718 0460
20:21:49.0718 0460 OS Version: 5.1.2600 ServicePack: 3.0
20:21:49.0718 0460 Product type: Workstation
20:21:49.0718 0460 ComputerName: FAMILIE-5RMVRRM
20:21:49.0718 0460 UserName: Alfred
20:21:49.0718 0460 Windows directory: C:\WINDOWS
20:21:49.0718 0460 System windows directory: C:\WINDOWS
20:21:49.0718 0460 Processor architecture: Intel x86
20:21:49.0718 0460 Number of processors: 2
20:21:49.0718 0460 Page size: 0x1000
20:21:49.0718 0460 Boot type: Normal boot
20:21:49.0718 0460 ============================================================
20:21:52.0906 0460 !crdlk
20:21:52.0921 0460 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A'
20:21:52.0921 0460 ============================================================
20:21:52.0921 0460 \Device\Harddisk0\DR0:
20:21:52.0921 0460 MBR partitions:
20:21:52.0921 0460 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x88B8F9D
20:21:52.0937 0460 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x88B901B, BlocksNum 0xA15BBE5
20:21:52.0937 0460 ============================================================
20:21:52.0953 0460 C: <-> \Device\Harddisk0\DR0\Partition1
20:21:53.0015 0460 D: <-> \Device\Harddisk0\DR0\Partition2
20:21:53.0015 0460 ============================================================
20:21:53.0015 0460 Initialize success
20:21:53.0015 0460 ============================================================
20:22:34.0796 1324 ============================================================
20:22:34.0796 1324 Scan started
20:22:34.0796 1324 Mode: Manual;
20:22:34.0796 1324 ============================================================
20:22:34.0968 1324 ================ Scan system memory ========================
20:22:34.0968 1324 System memory - ok
20:22:34.0968 1324 ================ Scan services =============================
20:22:35.0000 1324 Suspicious service (NoAccess): 1f785d9b79d933f1
20:22:35.0109 1324 [ CDAFD93CE777BABE4396781A5BAA2983 ] 1f785d9b79d933f1 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys
20:22:35.0109 1324 Suspicious file (NoAccess): C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys. md5: CDAFD93CE777BABE4396781A5BAA2983
20:22:35.0812 1324 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - infected
20:22:35.0812 1324 1f785d9b79d933f1 - detected Rootkit.Win32.Necurs.gen (0)
20:22:35.0843 1324 Abiosdsk - ok
20:22:35.0875 1324 abp480n5 - ok
20:22:35.0921 1324 [ AC407F1A62C3A300B4F2B5A9F1D55B2C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:22:35.0921 1324 ACPI - ok
20:22:35.0953 1324 [ 9E1CA3160DAFB159CA14F83B1E317F75 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:22:35.0953 1324 ACPIEC - ok
20:22:35.0968 1324 adpu160m - ok
20:22:36.0015 1324 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:22:36.0015 1324 aec - ok
20:22:36.0062 1324 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:22:36.0062 1324 AFD - ok
20:22:36.0140 1324 [ B34B1AB0A7690A0E2301FEC6D17B2FC1 ] AFS2K C:\WINDOWS\system32\drivers\AFS2K.sys
20:22:36.0140 1324 AFS2K - ok
20:22:36.0156 1324 Aha154x - ok
20:22:36.0171 1324 aic78u2 - ok
20:22:36.0187 1324 aic78xx - ok
20:22:36.0250 1324 [ 738D80CC01D7BC7584BE917B7F544394 ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:22:36.0250 1324 Alerter - ok
20:22:36.0296 1324 [ 190CD73D4984F94D823F9444980513E5 ] ALG C:\WINDOWS\System32\alg.exe
20:22:36.0296 1324 ALG - ok
20:22:36.0312 1324 AliIde - ok
20:22:36.0328 1324 amsint - ok
20:22:36.0453 1324 [ 459465DA28E49B358ECFE0D788F328F4 ] AntiVirSchedulerService C:\Programme\Avira\AntiVir Desktop\sched.exe
20:22:36.0484 1324 AntiVirSchedulerService - ok
20:22:36.0562 1324 [ BCDD17E8469D647A71B347C4B6F86685 ] AntiVirService C:\Programme\Avira\AntiVir Desktop\avguard.exe
20:22:36.0562 1324 AntiVirService - ok
20:22:36.0609 1324 [ D45960BE52C3C610D361977057F98C54 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:22:36.0609 1324 AppMgmt - ok
20:22:36.0656 1324 asc - ok
20:22:36.0671 1324 asc3350p - ok
20:22:36.0687 1324 asc3550 - ok
20:22:36.0781 1324 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
20:22:36.0781 1324 aspnet_state - ok
20:22:36.0843 1324 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:22:36.0843 1324 AsyncMac - ok
20:22:36.0875 1324 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:22:36.0875 1324 atapi - ok
20:22:36.0890 1324 Atdisk - ok
20:22:36.0953 1324 [ 89F6CB7B23111572C43F790D222C0415 ] Ati HotKey Poller C:\WINDOWS\System32\Ati2evxx.exe
20:22:36.0968 1324 Ati HotKey Poller - ok
20:22:37.0031 1324 [ B191D38D38E0ACC8CE22FA8E3D83B6B0 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe
20:22:37.0062 1324 ATI Smart - ok
20:22:37.0125 1324 [ 58F6F26083828FD18696F3592323BA21 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:22:37.0140 1324 ati2mtag - ok
20:22:37.0203 1324 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:22:37.0218 1324 Atmarpc - ok
20:22:37.0265 1324 [ 58ED0D5452DF7BE732193E7999C6B9A4 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:22:37.0281 1324 AudioSrv - ok
20:22:37.0328 1324 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:22:37.0328 1324 audstub - ok
20:22:37.0390 1324 [ A5C175039B1D6D85D0E79F5855828E4D ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
20:22:37.0390 1324 avgntflt - ok
20:22:37.0437 1324 [ 37B854C7D1F477E66C5B49C7700C47CC ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
20:22:37.0453 1324 avipbb - ok
20:22:37.0500 1324 [ CC4EBA25D80DE42BBC2BF3E553219388 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
20:22:37.0500 1324 avkmgr - ok
20:22:37.0562 1324 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:22:37.0562 1324 Beep - ok
20:22:37.0625 1324 [ D6F603772A789BB3228F310D650B8BD1 ] BITS C:\WINDOWS\system32\qmgr.dll
20:22:37.0656 1324 BITS - ok
20:22:37.0750 1324 [ B42057F06BBB98B31876C0B3F2B54E33 ] Browser C:\WINDOWS\System32\browser.dll
20:22:37.0750 1324 Browser - ok
20:22:37.0781 1324 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
20:22:37.0781 1324 cbidf2k - ok
20:22:37.0812 1324 cd20xrnt - ok
20:22:37.0843 1324 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:22:37.0843 1324 Cdaudio - ok
20:22:37.0890 1324 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:22:37.0906 1324 Cdfs - ok
20:22:37.0921 1324 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:22:37.0937 1324 Cdrom - ok
20:22:37.0953 1324 Changer - ok
20:22:37.0984 1324 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:22:37.0984 1324 CiSvc - ok
20:22:38.0031 1324 [ 778A30ED3C134EB7E406AFC407E9997D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:22:38.0031 1324 ClipSrv - ok
20:22:38.0078 1324 CmdIde - ok
20:22:38.0140 1324 [ E5ADEEF2C0DB43964223F408F1FCC97E ] cmuda C:\WINDOWS\system32\drivers\cmuda.sys
20:22:38.0187 1324 cmuda - ok
20:22:38.0203 1324 COMSysApp - ok
20:22:38.0234 1324 Cpqarray - ok
20:22:38.0296 1324 [ 611F824E5C703A5A899F84C5F1699E4D ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:22:38.0296 1324 CryptSvc - ok
20:22:38.0328 1324 dac2w2k - ok
20:22:38.0343 1324 dac960nt - ok
20:22:38.0406 1324 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:22:38.0421 1324 DcomLaunch - ok
20:22:38.0484 1324 [ C29A1C9B75BA38FA37F8C44405DEC360 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:22:38.0484 1324 Dhcp - ok
20:22:38.0531 1324 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:22:38.0546 1324 Disk - ok
20:22:38.0562 1324 dmadmin - ok
20:22:38.0609 1324 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:22:38.0625 1324 dmboot - ok
20:22:38.0687 1324 [ 53720AB12B48719D00E327DA470A619A ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:22:38.0687 1324 dmio - ok
20:22:38.0734 1324 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:22:38.0734 1324 dmload - ok
20:22:38.0781 1324 [ 25C83FFBBA13B554EB6D59A9B2E2EE78 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:22:38.0781 1324 dmserver - ok
20:22:38.0812 1324 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:22:38.0812 1324 DMusic - ok
20:22:38.0859 1324 [ 407F3227AC618FD1CA54B335B083DE07 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:22:38.0859 1324 Dnscache - ok
20:22:38.0953 1324 [ 676E36C4FF5BCEA1900F44182B9723E6 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:22:38.0953 1324 Dot3svc - ok
20:22:39.0000 1324 dpti2o - ok
20:22:39.0031 1324 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:22:39.0031 1324 drmkaud - ok
20:22:39.0093 1324 [ 4E4F2FDDAB0A0736D7671134DCCE91FB ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:22:39.0093 1324 EapHost - ok
20:22:39.0171 1324 [ 877C18558D70587AA7823A1A308AC96B ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:22:39.0171 1324 ERSvc - ok
20:22:39.0234 1324 [ A3EDBE9053889FB24AB22492472B39DC ] Eventlog C:\WINDOWS\system32\services.exe
20:22:39.0234 1324 Eventlog - ok
20:22:39.0281 1324 [ AF4F6B5739D18CA7972AB53E091CBC74 ] EventSystem C:\WINDOWS\System32\es.dll
20:22:39.0296 1324 EventSystem - ok
20:22:39.0359 1324 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:22:39.0359 1324 Fastfat - ok
20:22:39.0406 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:22:39.0421 1324 FastUserSwitchingCompatibility - ok
20:22:39.0468 1324 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:22:39.0468 1324 Fdc - ok
20:22:39.0500 1324 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys
20:22:39.0500 1324 FETNDIS - ok
20:22:39.0546 1324 [ B7186B33B6CF3A23841015531E6E7D68 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
20:22:39.0546 1324 FETNDISB - ok
20:22:39.0578 1324 [ B0678A548587C5F1967B0D70BACAD6C1 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:22:39.0578 1324 Fips - ok
20:22:39.0625 1324 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:22:39.0625 1324 Flpydisk - ok
20:22:39.0687 1324 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:22:39.0687 1324 FltMgr - ok
20:22:39.0718 1324 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:22:39.0718 1324 Fs_Rec - ok
20:22:39.0750 1324 [ 8F1955CE42E1484714B542F341647778 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:22:39.0750 1324 Ftdisk - ok
20:22:39.0781 1324 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys
20:22:39.0781 1324 gameenum - ok
20:22:39.0828 1324 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:22:39.0828 1324 Gpc - ok
20:22:39.0921 1324 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Programme\Google\Update\GoogleUpdate.exe
20:22:39.0937 1324 gupdate - ok
20:22:39.0968 1324 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Programme\Google\Update\GoogleUpdate.exe
20:22:39.0968 1324 gupdatem - ok
20:22:40.0046 1324 [ CB66BF85BF599BEFD6C6A57C2E20357F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:22:40.0062 1324 helpsvc - ok
20:22:40.0078 1324 HidServ - ok
20:22:40.0125 1324 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:22:40.0125 1324 HidUsb - ok
20:22:40.0187 1324 [ ED29F14101523A6E0E808107405D452C ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:22:40.0187 1324 hkmsvc - ok
20:22:40.0234 1324 hpn - ok
20:22:40.0265 1324 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:22:40.0281 1324 HTTP - ok
20:22:40.0343 1324 [ 9E4ADB854CEBCFB81A4B36718FEECD16 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:22:40.0343 1324 HTTPFilter - ok
20:22:40.0375 1324 i2omgmt - ok
20:22:40.0390 1324 i2omp - ok
20:22:40.0437 1324 [ E283B97CFBEB86C1D86BAED5F7846A92 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:22:40.0453 1324 i8042prt - ok
20:22:40.0468 1324 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:22:40.0468 1324 Imapi - ok
20:22:40.0515 1324 [ D4B413AA210C21E46AEDD2BA5B68D38E ] ImapiService C:\WINDOWS\System32\imapi.exe
20:22:40.0515 1324 ImapiService - ok
20:22:40.0609 1324 ini910u - ok
20:22:40.0640 1324 IntelIde - ok
20:22:40.0703 1324 [ 4C7D2750158ED6E7AD642D97BFFAE351 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:22:40.0703 1324 intelppm - ok
20:22:40.0734 1324 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:22:40.0734 1324 ip6fw - ok
20:22:40.0781 1324 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:22:40.0796 1324 IpFilterDriver - ok
20:22:40.0828 1324 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:22:40.0828 1324 IpInIp - ok
20:22:40.0859 1324 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:22:40.0859 1324 IpNat - ok
20:22:40.0906 1324 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:22:40.0906 1324 IPSec - ok
20:22:40.0937 1324 [ ACA5E7B54409F9CB5EED97ED0C81120E ] irda C:\WINDOWS\system32\DRIVERS\irda.sys
20:22:40.0937 1324 irda - ok
20:22:40.0953 1324 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:22:40.0953 1324 IRENUM - ok
20:22:41.0000 1324 [ 2EFE1DB1EC58A26B0C14BFDA122E246F ] Irmon C:\WINDOWS\System32\irmon.dll
20:22:41.0000 1324 Irmon - ok
20:22:41.0031 1324 [ 0501F0B9AB08425F8C0EACBDCC04AA32 ] irsir C:\WINDOWS\system32\DRIVERS\irsir.sys
20:22:41.0031 1324 irsir - ok
20:22:41.0078 1324 [ 6DFB88F64135C525433E87648BDA30DE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:22:41.0078 1324 isapnp - ok
20:22:41.0125 1324 [ 1704D8C4C8807B889E43C649B478A452 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:22:41.0125 1324 Kbdclass - ok
20:22:41.0140 1324 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:22:41.0140 1324 kmixer - ok
20:22:41.0171 1324 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:22:41.0171 1324 KSecDD - ok
20:22:41.0265 1324 [ 2BBDCB79900990F0716DFCB714E72DE7 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:22:41.0265 1324 lanmanserver - ok
20:22:41.0328 1324 [ 1869B14B06B44B44AF70548E1EA3303F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:22:41.0343 1324 lanmanworkstation - ok
20:22:41.0390 1324 lbrtfdc - ok
20:22:41.0437 1324 [ 636714B7D43C8D0C80449123FD266920 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:22:41.0437 1324 LmHosts - ok
20:22:41.0515 1324 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
20:22:41.0531 1324 MDM - ok
20:22:41.0593 1324 [ B7550A7107281D170CE85524B1488C98 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:22:41.0593 1324 Messenger - ok
20:22:41.0625 1324 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:22:41.0625 1324 mnmdd - ok
20:22:41.0656 1324 [ C2F1D365FD96791B037EE504868065D3 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
20:22:41.0671 1324 mnmsrvc - ok
20:22:41.0718 1324 [ 6FB74EBD4EC57A6F1781DE3852CC3362 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:22:41.0734 1324 Modem - ok
20:22:41.0781 1324 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys
20:22:41.0781 1324 MODEMCSA - ok
20:22:41.0812 1324 [ B24CE8005DEAB254C0251E15CB71D802 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:22:41.0812 1324 Mouclass - ok
20:22:41.0859 1324 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:22:41.0859 1324 MountMgr - ok
20:22:41.0937 1324 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
20:22:41.0937 1324 MozillaMaintenance - ok
20:22:41.0968 1324 mraid35x - ok
20:22:42.0031 1324 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:22:42.0031 1324 MRxDAV - ok
20:22:42.0078 1324 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:22:42.0093 1324 MRxSmb - ok
20:22:42.0156 1324 [ 35A031AF38C55F92D28AA03EE9F12CC9 ] MSDTC C:\WINDOWS\System32\msdtc.exe
20:22:42.0156 1324 MSDTC - ok
20:22:42.0187 1324 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:22:42.0187 1324 Msfs - ok
20:22:42.0218 1324 MSIServer - ok
20:22:42.0250 1324 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:22:42.0250 1324 MSKSSRV - ok
20:22:42.0281 1324 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:22:42.0281 1324 MSPCLOCK - ok
20:22:42.0328 1324 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:22:42.0328 1324 MSPQM - ok
20:22:42.0390 1324 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:22:42.0390 1324 mssmbios - ok
20:22:42.0437 1324 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys
20:22:42.0437 1324 ms_mpu401 - ok
20:22:42.0484 1324 [ 6433EC4BCE450447C7947F6181A9E268 ] Mtlmnt5 C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
20:22:42.0500 1324 Mtlmnt5 - ok
20:22:42.0562 1324 [ 30B87862B93574A20D78E1FF63C88694 ] Mtlstrm C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
20:22:42.0609 1324 Mtlstrm - ok
20:22:42.0687 1324 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:22:42.0687 1324 Mup - ok
20:22:42.0734 1324 [ 46BB15AE2AC7D025D6D2567B876817BD ] napagent C:\WINDOWS\System32\qagentrt.dll
20:22:42.0765 1324 napagent - ok
20:22:42.0828 1324 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:22:42.0828 1324 NDIS - ok
20:22:42.0859 1324 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:22:42.0859 1324 NdisTapi - ok
20:22:42.0890 1324 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:22:42.0890 1324 Ndisuio - ok
20:22:42.0921 1324 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:22:42.0937 1324 NdisWan - ok
20:22:42.0984 1324 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:22:42.0984 1324 NDProxy - ok
20:22:43.0015 1324 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:22:43.0015 1324 NetBIOS - ok
20:22:43.0031 1324 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:22:43.0046 1324 NetBT - ok
20:22:43.0093 1324 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDE C:\WINDOWS\system32\netdde.exe
20:22:43.0093 1324 NetDDE - ok
20:22:43.0125 1324 [ 8ACE4251BFFD09CE75679FE940E996CC ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:22:43.0140 1324 NetDDEdsdm - ok
20:22:43.0171 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] Netlogon C:\WINDOWS\System32\lsass.exe
20:22:43.0187 1324 Netlogon - ok
20:22:43.0234 1324 [ E6D88F1F6745BF00B57E7855A2AB696C ] Netman C:\WINDOWS\System32\netman.dll
20:22:43.0234 1324 Netman - ok
20:22:43.0296 1324 [ F1B67B6B0751AE0E6E964B02821206A3 ] Nla C:\WINDOWS\System32\mswsock.dll
20:22:43.0312 1324 Nla - ok
20:22:43.0375 1324 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:22:43.0375 1324 Npfs - ok
20:22:43.0406 1324 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:22:43.0421 1324 Ntfs - ok
20:22:43.0453 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
20:22:43.0453 1324 NtLmSsp - ok
20:22:43.0531 1324 [ 56AF4064996FA5BAC9C449B1514B4770 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:22:43.0546 1324 NtmsSvc - ok
20:22:43.0625 1324 [ 576B34CEAE5B7E5D9FD2775E93B3DB53 ] NtMtlFax C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
20:22:43.0625 1324 NtMtlFax - ok
20:22:43.0687 1324 [ A568B9A9FFE2D9387222A5C90F86D731 ] NTSIM C:\WINDOWS\System32\ntsim.sys
20:22:43.0687 1324 NTSIM - ok
20:22:43.0734 1324 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
20:22:43.0734 1324 Null - ok
20:22:43.0781 1324 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:22:43.0781 1324 NwlnkFlt - ok
20:22:43.0812 1324 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:22:43.0812 1324 NwlnkFwd - ok
20:22:43.0859 1324 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
20:22:43.0859 1324 ose - ok
20:22:43.0953 1324 [ F84785660305B9B903FB3BCA8BA29837 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
20:22:43.0953 1324 Parport - ok
20:22:43.0984 1324 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:22:43.0984 1324 PartMgr - ok
20:22:44.0015 1324 [ C2BF987829099A3EAA2CA6A0A90ECB4F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:22:44.0031 1324 ParVdm - ok
20:22:44.0078 1324 [ 387E8DEDC343AA2D1EFBC30580273ACD ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:22:44.0093 1324 PCI - ok
20:22:44.0109 1324 PCIDump - ok
20:22:44.0140 1324 [ 59BA86D9A61CBCF4DF8E598C331F5B82 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:22:44.0140 1324 PCIIde - ok
20:22:44.0171 1324 [ A2A966B77D61847D61A3051DF87C8C97 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:22:44.0171 1324 Pcmcia - ok
20:22:44.0218 1324 PDCOMP - ok
20:22:44.0234 1324 PDFRAME - ok
20:22:44.0250 1324 PDRELI - ok
20:22:44.0281 1324 PDRFRAME - ok
20:22:44.0296 1324 perc2 - ok
20:22:44.0312 1324 perc2hib - ok
20:22:44.0406 1324 [ 2ABA2F545B35F9C6CC2CFC4E1D539A80 ] PLCNDIS5 C:\WINDOWS\system32\plcndis5.sys
20:22:44.0406 1324 PLCNDIS5 - ok
20:22:44.0437 1324 [ A3EDBE9053889FB24AB22492472B39DC ] PlugPlay C:\WINDOWS\system32\services.exe
20:22:44.0437 1324 PlugPlay - ok
20:22:44.0453 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] PolicyAgent C:\WINDOWS\System32\lsass.exe
20:22:44.0453 1324 PolicyAgent - ok
20:22:44.0515 1324 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:22:44.0515 1324 PptpMiniport - ok
20:22:44.0546 1324 [ 2CB55427C58679F49AD600FCCBA76360 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
20:22:44.0546 1324 Processor - ok
20:22:44.0562 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:22:44.0578 1324 ProtectedStorage - ok
20:22:44.0593 1324 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:22:44.0593 1324 PSched - ok
20:22:44.0640 1324 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:22:44.0640 1324 Ptilink - ok
20:22:44.0687 1324 ql1080 - ok
20:22:44.0703 1324 Ql10wnt - ok
20:22:44.0718 1324 ql12160 - ok
20:22:44.0750 1324 ql1240 - ok
20:22:44.0765 1324 ql1280 - ok
20:22:44.0781 1324 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:22:44.0781 1324 RasAcd - ok
20:22:44.0843 1324 [ F5BA6CACCDB66C8F048E867563203246 ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:22:44.0843 1324 RasAuto - ok
20:22:44.0875 1324 [ 0207D26DDF796A193CCD9F83047BB5FC ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys
20:22:44.0875 1324 Rasirda - ok
20:22:44.0921 1324 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:22:44.0937 1324 Rasl2tp - ok
20:22:44.0984 1324 [ F9A7B66EA345726EDB5862A46B1ECCD5 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:22:45.0000 1324 RasMan - ok
20:22:45.0015 1324 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:22:45.0015 1324 RasPppoe - ok
20:22:45.0062 1324 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:22:45.0062 1324 Raspti - ok
20:22:45.0093 1324 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:22:45.0093 1324 Rdbss - ok
20:22:45.0125 1324 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:22:45.0125 1324 RDPCDD - ok
20:22:45.0156 1324 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:22:45.0156 1324 rdpdr - ok
20:22:45.0218 1324 [ 5B3055DAA788BD688594D2F5981F2A83 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:22:45.0234 1324 RDPWD - ok
20:22:45.0265 1324 [ 263AF18AF0F3DB99F574C95F284CCEC9 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:22:45.0281 1324 RDSessMgr - ok
20:22:45.0343 1324 [ 41315D97BB319BD5B5E1B367570E7B3C ] RecAgent C:\WINDOWS\system32\DRIVERS\RecAgent.sys
20:22:45.0343 1324 RecAgent - ok
20:22:45.0390 1324 [ ED761D453856F795A7FE056E42C36365 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:22:45.0390 1324 redbook - ok
20:22:45.0453 1324 [ 0E97EC96D6942CEEC2D188CC2EB69A01 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:22:45.0453 1324 RemoteAccess - ok
20:22:45.0500 1324 [ E4CD1F3D84E1C2CA0B8CF7501E201593 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:22:45.0515 1324 RemoteRegistry - ok
20:22:45.0546 1324 [ 2A02E21867497DF20B8FC95631395169 ] RpcLocator C:\WINDOWS\System32\locator.exe
20:22:45.0546 1324 RpcLocator - ok
20:22:45.0609 1324 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B ] RpcSs C:\WINDOWS\system32\rpcss.dll
20:22:45.0609 1324 RpcSs - ok
20:22:45.0656 1324 [ 4BDD71B4B521521499DFD14735C4F398 ] RSVP C:\WINDOWS\System32\rsvp.exe
20:22:45.0656 1324 RSVP - ok
20:22:45.0703 1324 [ AFB8261B56CBA0D86AEB6DF682AF9785 ] SamSs C:\WINDOWS\system32\lsass.exe
20:22:45.0703 1324 SamSs - ok
20:22:45.0750 1324 [ DCEC079FAD95D36C8DD5CB6D779DFE32 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:22:45.0750 1324 SCardSvr - ok
20:22:45.0812 1324 [ A050194A44D7FA8D7186ED2F4E8367AE ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:22:45.0828 1324 Schedule - ok
20:22:45.0906 1324 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:22:45.0906 1324 Secdrv - ok
20:22:45.0953 1324 [ BEE4CFD1D48C23B44CF4B974B0B79B2B ] seclogon C:\WINDOWS\System32\seclogon.dll
20:22:45.0953 1324 seclogon - ok
20:22:46.0015 1324 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3 ] SENS C:\WINDOWS\system32\sens.dll
20:22:46.0015 1324 SENS - ok
20:22:46.0062 1324 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:22:46.0062 1324 serenum - ok
20:22:46.0109 1324 [ CF24EB4F0412C82BCD1F4F35A025E31D ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:22:46.0109 1324 Serial - ok
20:22:46.0140 1324 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:22:46.0140 1324 Sfloppy - ok
20:22:46.0203 1324 [ CAD058D5F8B889A87CA3EB3CF624DCEF ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:22:46.0203 1324 SharedAccess - ok
20:22:46.0296 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:22:46.0296 1324 ShellHWDetection - ok
20:22:46.0312 1324 Simbad - ok
20:22:46.0375 1324 [ F3A4AB7230646941D41A9E2E754F047A ] Slnt7554 C:\WINDOWS\system32\DRIVERS\slnt7554.sys
20:22:46.0390 1324 Slnt7554 - ok
20:22:46.0437 1324 [ F06507086FF9BFDBCF3C5098A4848B5D ] SlNtHal C:\WINDOWS\system32\DRIVERS\Slnthal.sys
20:22:46.0437 1324 SlNtHal - ok
20:22:46.0453 1324 SLService - ok
20:22:46.0500 1324 [ CD4F4CEE4481E11BDA806A9366785A1D ] SlWdmSup C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
20:22:46.0500 1324 SlWdmSup - ok
20:22:46.0531 1324 Sparrow - ok
20:22:46.0578 1324 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:22:46.0578 1324 splitter - ok
20:22:46.0625 1324 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:22:46.0625 1324 Spooler - ok
20:22:46.0640 1324 [ 50FA898F8C032796D3B1B9951BB5A90F ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:22:46.0656 1324 sr - ok
20:22:46.0703 1324 [ FE77A85495065F3AD59C5C65B6C54182 ] srservice C:\WINDOWS\System32\srsvc.dll
20:22:46.0703 1324 srservice - ok
20:22:46.0781 1324 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:22:46.0796 1324 Srv - ok
20:22:46.0843 1324 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:22:46.0843 1324 SSDPSRV - ok
20:22:46.0921 1324 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
20:22:46.0921 1324 ssmdrv - ok
20:22:46.0968 1324 [ BC2C5985611C5356B24AEB370953DED9 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:22:47.0000 1324 stisvc - ok
20:22:47.0046 1324 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:22:47.0046 1324 swenum - ok
20:22:47.0078 1324 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:22:47.0078 1324 swmidi - ok
20:22:47.0093 1324 SwPrv - ok
20:22:47.0125 1324 symc810 - ok
20:22:47.0156 1324 symc8xx - ok
20:22:47.0171 1324 sym_hi - ok
20:22:47.0218 1324 sym_u3 - ok
20:22:47.0265 1324 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:22:47.0265 1324 sysaudio - ok
20:22:47.0312 1324 [ 2903FFFA2523926D6219428040DCE6B9 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:22:47.0312 1324 SysmonLog - ok
20:22:47.0375 1324 [ 05903CAC4B98908D55EA5774775B382E ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:22:47.0390 1324 TapiSrv - ok
20:22:47.0453 1324 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:22:47.0468 1324 Tcpip - ok
20:22:47.0515 1324 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:22:47.0515 1324 TDPIPE - ok
20:22:47.0562 1324 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:22:47.0562 1324 TDTCP - ok
20:22:47.0609 1324 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:22:47.0609 1324 TermDD - ok
20:22:47.0671 1324 [ B7DE02C863D8F5A005A7BF375375A6A4 ] TermService C:\WINDOWS\System32\termsrv.dll
20:22:47.0703 1324 TermService - ok
20:22:47.0750 1324 [ 2DB7D303C36DDD055215052F118E8E75 ] Themes C:\WINDOWS\System32\shsvcs.dll
20:22:47.0750 1324 Themes - ok
20:22:47.0796 1324 [ 03681A1CE77F51586903869A5AB1DEAB ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
20:22:47.0796 1324 TlntSvr - ok
20:22:47.0843 1324 TosIde - ok
20:22:47.0890 1324 [ 626504572B175867F30F3215C04B3E2F ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:22:47.0906 1324 TrkWks - ok
20:22:47.0937 1324 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:22:47.0937 1324 Udfs - ok
20:22:47.0953 1324 ultra - ok
20:22:48.0000 1324 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:22:48.0015 1324 Update - ok
20:22:48.0093 1324 [ 1DFD8975D8C89214B98D9387C1125B49 ] upnphost C:\WINDOWS\System32\upnphost.dll
20:22:48.0109 1324 upnphost - ok
20:22:48.0140 1324 [ 9B11E6118958E63E1FEF129466E2BDA7 ] UPS C:\WINDOWS\System32\ups.exe
20:22:48.0140 1324 UPS - ok
20:22:48.0203 1324 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:22:48.0203 1324 usbccgp - ok
20:22:48.0250 1324 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:22:48.0250 1324 usbehci - ok
20:22:48.0296 1324 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:22:48.0296 1324 usbhub - ok
20:22:48.0343 1324 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:22:48.0359 1324 usbscan - ok
20:22:48.0390 1324 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:22:48.0390 1324 USBSTOR - ok
20:22:48.0468 1324 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:22:48.0468 1324 usbuhci - ok
20:22:48.0500 1324 [ BEE793D4A059CAEA55D6AC20E19B3A8F ] USB_RNDIS C:\WINDOWS\system32\DRIVERS\usb8023.sys
20:22:48.0500 1324 USB_RNDIS - ok
20:22:48.0531 1324 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:22:48.0531 1324 VgaSave - ok
20:22:48.0593 1324 [ 4B039BBD037B01F5DB5A144C837F283A ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys
20:22:48.0593 1324 viaagp1 - ok
20:22:48.0640 1324 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
20:22:48.0640 1324 ViaIde - ok
20:22:48.0687 1324 [ A5A712F4E880874A477AF790B5186E1D ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:22:48.0687 1324 VolSnap - ok
20:22:48.0734 1324 [ 68F106273BE29E7B7EF8266977268E78 ] VSS C:\WINDOWS\System32\vssvc.exe
20:22:48.0750 1324 VSS - ok
20:22:48.0828 1324 [ 7B353059E665F8B7AD2BBEAEF597CF45 ] W32Time C:\WINDOWS\System32\w32time.dll
20:22:48.0828 1324 W32Time - ok
20:22:48.0875 1324 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:22:48.0875 1324 Wanarp - ok
20:22:48.0890 1324 WDICA - ok
20:22:48.0921 1324 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:22:48.0921 1324 wdmaud - ok
20:22:48.0984 1324 [ 81727C9873E3905A2FFC1EBD07265002 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:22:48.0984 1324 WebClient - ok
20:22:49.0062 1324 [ 6F3F3973D97714CC5F906A19FE883729 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:22:49.0062 1324 winmgmt - ok
20:22:49.0156 1324 [ 6E18978B749F0696A774DE3F2CB142DD ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
20:22:49.0156 1324 WmdmPmSN - ok
20:22:49.0250 1324 [ FFA4D901D46D07A5BAB2D8307FBB51A6 ] Wmi C:\WINDOWS\System32\advapi32.dll
20:22:49.0281 1324 Wmi - ok
20:22:49.0359 1324 [ 93908111BA57A6E60EC2FA2DE202105C ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
20:22:49.0359 1324 WmiApSrv - ok
20:22:49.0421 1324 [ 300B3E84FAF1A5C1F791C159BA28035D ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:22:49.0437 1324 wscsvc - ok
20:22:49.0484 1324 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:22:49.0484 1324 wuauserv - ok
20:22:49.0531 1324 [ C4F109C005F6725162D2D12CA751E4A7 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:22:49.0562 1324 WZCSVC - ok
20:22:49.0625 1324 [ 0ADA34871A2E1CD2CAAFED1237A47750 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:22:49.0640 1324 xmlprov - ok
20:22:49.0687 1324 ================ Scan global ===============================
20:22:49.0750 1324 [ 2C60091CA5F67C3032EAB3B30390C27F ] C:\WINDOWS\system32\basesrv.dll
20:22:49.0781 1324 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
20:22:49.0812 1324 [ A28CE25B59C90E12743001A1F2AE3613 ] C:\WINDOWS\system32\winsrv.dll
20:22:49.0843 1324 [ A3EDBE9053889FB24AB22492472B39DC ] C:\WINDOWS\system32\services.exe
20:22:49.0843 1324 [Global] - ok
20:22:49.0843 1324 ================ Scan MBR ==================================
20:22:49.0875 1324 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0
20:22:50.0031 1324 \Device\Harddisk0\DR0 - ok
20:22:50.0031 1324 ================ Scan VBR ==================================
20:22:50.0031 1324 [ 419E0E86CCAEA9B1007E36922D127ADB ] \Device\Harddisk0\DR0\Partition1
20:22:50.0046 1324 \Device\Harddisk0\DR0\Partition1 - ok
20:22:50.0062 1324 [ 3A078522B2D615653713BB15F22B968C ] \Device\Harddisk0\DR0\Partition2
20:22:50.0062 1324 \Device\Harddisk0\DR0\Partition2 - ok
20:22:50.0062 1324 ============================================================
20:22:50.0062 1324 Scan finished
20:22:50.0062 1324 ============================================================
20:22:50.0203 1564 Detected object count: 1
20:22:50.0203 1564 Actual detected object count: 1
20:24:54.0203 1564 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys - copied to quarantine
20:24:54.0218 1564 HKLM\SYSTEM\ControlSet001\services\1f785d9b79d933f1 - will be deleted on reboot
20:24:54.0265 1564 HKLM\SYSTEM\ControlSet002\services\1f785d9b79d933f1 - will be deleted on reboot
20:24:54.0421 1564 C:\WINDOWS\System32\Drivers\1f785d9b79d933f1.sys - will be deleted on reboot
20:24:54.0421 1564 1f785d9b79d933f1 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
20:26:14.0046 1532 Deinitialize success Code:
20:27:54.0843 0352 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:27:55.0500 0352 ============================================================
20:27:55.0500 0352 Current date / time: 2013/03/24 20:27:55.0500
20:27:55.0500 0352 SystemInfo:
20:27:55.0500 0352
20:27:55.0500 0352 OS Version: 5.1.2600 ServicePack: 3.0
20:27:55.0500 0352 Product type: Workstation
20:27:55.0500 0352 ComputerName: FAMILIE-5RMVRRM
20:27:55.0500 0352 UserName: Alfred
20:27:55.0500 0352 Windows directory: C:\WINDOWS
20:27:55.0500 0352 System windows directory: C:\WINDOWS
20:27:55.0500 0352 Processor architecture: Intel x86
20:27:55.0500 0352 Number of processors: 2
20:27:55.0500 0352 Page size: 0x1000
20:27:55.0500 0352 Boot type: Normal boot
20:27:55.0500 0352 ============================================================
20:27:58.0906 0352 BG loaded
20:28:02.0671 0352 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
20:28:02.0687 0352 ============================================================
20:28:02.0687 0352 \Device\Harddisk0\DR0:
20:28:02.0687 0352 MBR partitions:
20:28:02.0687 0352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x88B8F9D
20:28:02.0734 0352 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x88B901B, BlocksNum 0xA15BBE5
20:28:02.0734 0352 ============================================================
20:28:02.0812 0352 C: <-> \Device\Harddisk0\DR0\Partition1
20:28:02.0921 0352 D: <-> \Device\Harddisk0\DR0\Partition2
20:28:02.0921 0352 ============================================================
20:28:02.0921 0352 Initialize success
20:28:02.0921 0352 ============================================================
20:32:38.0218 1324 Deinitialize success ComboFix: Code:
ComboFix 13-03-24.03 - Alfred 24.03.2013 20:41:36.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.511.122 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Alfred\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Alfred\pl468q4scf.exe
c:\dokumente und einstellungen\Alfred\WINDOWS
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\SET1A.tmp
c:\windows\system32\SET1B.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 ))))))))))))))))))))))))))))))
.
.
2013-03-24 19:29 . 2013-03-24 19:31 -------- d-----w- c:\windows\LastGood
2013-03-24 19:24 . 2013-03-24 19:24 -------- d-----w- C:\TDSSKiller_Quarantine
2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\dokumente und einstellungen\Alfred\Anwendungsdaten\Malwarebytes
2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2013-03-23 10:48 . 2013-03-23 10:48 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware
2013-03-23 10:48 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-24 10:36 . 2006-02-14 14:33 1409 ----a-w- c:\windows\QTFont.for
2012-12-30 07:45 . 2012-09-30 08:43 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-12-30 07:45 . 2012-09-30 08:43 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-12-30 07:45 . 2012-09-30 08:43 134336 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-20 09:46 . 2009-06-20 09:44 53634800 ----a-w- c:\programme\ExcelViewer.exe
2013-03-07 14:30 . 2013-03-09 11:28 263064 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 339968]
"ISUSPM Startup"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-02-14 77824]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-15 196608]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-02-15 385248]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\programme\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 ----a-w- c:\programme\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-17 09:42 69632 ----a-w- c:\programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\devolo\\informer\\devinf.exe"=
"c:\\Programme\\aon\\aonController\\aonController.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\aon\\aonInstaller\\Installer.exe"=
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [30.09.2012 09:43 36552]
R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [30.09.2012 09:43 86752]
R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\plcndis5.sys [17.05.2004 11:21 17280]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [04.08.2004 06:41 224888]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 00848729
*NewlyCreated* - 31272864
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
*NewlyCreated* - AVKMGR
*NewlyCreated* - SSMDRV
*Deregistered* - 00848729
*Deregistered* - 31272864
.
Inhalt des "geplante Tasks" Ordners
.
2013-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2011-12-26 15:26]
.
2013-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2011-12-26 15:26]
.
2013-03-24 c:\windows\Tasks\User_Feed_Synchronization-{92EA0041-BA85-4B6E-A2C1-892B498D1258}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.telekom.at
mWindow Title = UTA Telekom AG
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: uni-graz.at
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\dokumente und einstellungen\Alfred\Anwendungsdaten\Mozilla\Firefox\Profiles\d7ywe9b3.default-1364029350796\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-E06DXLRD_1476890 - c:\programme\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-NWEReboot - (no file)
SafeBoot-00848729.sys
MSConfigStartUp-E06DXLRD_720156 - c:\programme\Microsoft Encarta\Encarta 2006 Enzyklopaedie DVD\EDICT.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-03-24 20:49
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0f,7e,39,c6,ed,4e,3b,47,b3,60,7f,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0f,7e,39,c6,ed,4e,3b,47,b3,60,7f,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(676)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2013-03-24 20:52:30
ComboFix-quarantined-files.txt 2013-03-24 19:52
.
Vor Suchlauf: 8 Verzeichnis(se), 59.617.886.208 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 60.130.217.984 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 9E3026E4117384DE9C52C0ABFFC14035 OTL: Code:
OTL logfile created on: 24.03.2013 21:01:52 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Alfred\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
511,23 Mb Total Physical Memory | 124,53 Mb Available Physical Memory | 24,36% Memory free
1,22 Gb Paging File | 0,80 Gb Available in Paging File | 65,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 68,36 Gb Total Space | 56,03 Gb Free Space | 81,97% Space Free | Partition Type: NTFS
Drive D: | 80,68 Gb Total Space | 77,19 Gb Free Space | 95,67% Space Free | Partition Type: NTFS
Computer Name: FAMILIE-5RMVRRM | User Name: Alfred | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\qttask.exe (Apple Computer, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\WINDOWS\system32\slserv.exe (Smart Link)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP)
========== Modules (No Company Name) ==========
MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\ati2evxx.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()
========== Services (SafeList) ==========
SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SLService) -- C:\WINDOWS\System32\slserv.exe (Smart Link)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOKUME~1\Alfred\LOKALE~1\Temp\catchme.sys File not found
DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (AFS2K) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (Mtlstrm) -- C:\WINDOWS\system32\drivers\mtlstrm.sys ( )
DRV - (Mtlmnt5) -- C:\WINDOWS\system32\drivers\mtlmnt5.sys ( )
DRV - (Slnt7554) -- C:\WINDOWS\system32\drivers\slnt7554.sys ( )
DRV - (SlNtHal) -- C:\WINDOWS\system32\drivers\slnthal.sys ( )
DRV - (RecAgent) -- C:\WINDOWS\system32\drivers\RecAgent.sys ( )
DRV - (SlWdmSup) -- C:\WINDOWS\system32\drivers\slwdmsup.sys ( )
DRV - (NtMtlFax) -- C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (PLCNDIS5) -- C:\WINDOWS\system32\plcndis5.sys (Intellon, Inc.)
DRV - (viaagp1) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (irsir) -- C:\WINDOWS\system32\drivers\irsir.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.telekom.at
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes,DefaultScope = {99968DBC-2B29-494F-A050-29B9BDB22FCF}
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\SearchScopes\{99968DBC-2B29-494F-A050-29B9BDB22FCF}: "URL" = hxxp://www.google.at/search?hl=de&q={searchTerms}&meta=
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.23 10:04:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.03.09 12:28:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.03.23 10:07:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
[2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions
[2010.04.24 15:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.03.23 10:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2013.03.07 16:45:15 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 16:45:15 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2013.03.07 16:45:15 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 16:45:15 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 16:45:15 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 16:45:15 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2013.03.24 20:49:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {147D6308-0614-4112-89B1-31402F9B82C4} - No CLSID value found.
O3 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe (Apple Computer, Inc.)
O4 - HKU\S-1-5-21-436374069-1614895754-839522115-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-436374069-1614895754-839522115-1003\..Trusted Domains: uni-graz.at ([]https in Vertrauenswürdige Sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1348999421515 (WUWebControl Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CD0B796-8D2C-433B-8D55-EB74130C2239}: DhcpNameServer = 195.34.133.21 195.34.133.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B10F9BE5-DA3F-4B17-9954-DED73D9F9628}: DhcpNameServer = 195.34.133.21 195.34.133.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D3D40258-515E-4126-B155-DCCACE2B1CF7}: DhcpNameServer = 10.0.0.138 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3A5CA91-A3DF-4D41-9D1D-F3B6AE8ADCEF}: DhcpNameServer = 195.34.133.21 195.34.133.22
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.02.13 17:03:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.24 20:52:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013.03.24 20:36:08 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.03.24 20:34:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.03.24 20:34:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.03.24 20:34:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.03.24 20:34:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.03.24 20:34:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.24 20:34:02 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Alfred\Startmenü\Programme\Verwaltung
[2013.03.24 20:34:02 | 000,000,000 | R--D | C] -- d:\Eigene Videos
[2013.03.24 20:33:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.03.24 20:25:53 | 005,044,071 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\Alfred\Desktop\ComboFix.exe
[2013.03.24 20:24:54 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013.03.24 08:39:53 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Alfred\Desktop\tdsskiller.exe
[2013.03.24 08:38:36 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\Alfred\Desktop\aswMBR.exe
[2013.03.23 12:28:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe
[2013.03.23 12:26:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Desktop\LOGS
[2013.03.23 11:48:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Malwarebytes
[2013.03.23 11:48:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2013.03.23 11:48:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2013.03.23 11:48:15 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013.03.23 11:48:15 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2013.03.23 10:16:16 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira
[2013.03.09 12:28:08 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2009.06.20 10:44:29 | 053,634,800 | ---- | C] (Microsoft Corporation) -- C:\Programme\ExcelViewer.exe
[1 d:\*.tmp files -> d:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.24 21:03:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{92EA0041-BA85-4B6E-A2C1-892B498D1258}.job
[2013.03.24 20:58:23 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2013.03.24 20:58:14 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.24 20:58:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.03.24 20:52:39 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2013.03.24 20:49:34 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.03.24 20:36:18 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.03.24 20:25:42 | 005,044,071 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\Alfred\Desktop\ComboFix.exe
[2013.03.24 20:13:00 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.24 08:39:30 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\Alfred\Desktop\tdsskiller.exe
[2013.03.24 08:38:18 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Dokumente und Einstellungen\Alfred\Desktop\aswMBR.exe
[2013.03.23 12:28:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Alfred\Desktop\OTL.exe
[2013.03.23 12:25:36 | 000,609,993 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe
[2013.03.23 11:48:18 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.23 10:16:16 | 000,001,677 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk
[2013.03.23 10:07:36 | 000,001,638 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk
[2013.03.23 10:05:01 | 000,000,702 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.03.23 09:52:22 | 000,002,509 | ---- | M] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\Microsoft Office Word 2003.lnk
[2013.03.06 17:56:09 | 000,000,278 | ---- | M] () -- C:\WINDOWS\hpqcopy.INI
[2013.03.01 11:47:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[1 d:\*.tmp files -> d:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.24 20:36:17 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.03.24 20:36:11 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.03.24 20:34:30 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.03.24 20:34:30 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.03.24 20:34:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.03.24 20:34:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.03.24 20:34:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.03.23 12:26:00 | 000,609,993 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Desktop\adwcleaner.exe
[2013.03.23 11:48:18 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.23 10:05:01 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2012.09.30 12:20:55 | 000,292,480 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.02.16 11:32:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010.03.09 17:01:04 | 000,000,082 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\default.pls
[2006.07.09 10:13:00 | 000,038,451 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Microsoft Excel.ADR
[2006.07.09 10:05:13 | 000,009,354 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Tabulatorgetrennte Werte (Windows).EML
[2006.07.09 06:51:20 | 000,045,424 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\IMG_3054[2].jpg
[2006.02.14 15:08:14 | 000,000,139 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006.02.14 12:49:18 | 000,007,680 | ---- | C] () -- C:\Dokumente und Einstellungen\Alfred\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006.02.14 12:29:00 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 03:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2006.02.19 20:25:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Alawar
[2007.07.25 10:09:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\AUTOSICH
[2008.11.07 19:41:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\mquadr.at
[2011.01.17 18:03:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Ordner HP Share-to-Web
[2010.04.24 15:18:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Alfred\Anwendungsdaten\Thunderbird
[2008.11.07 19:41:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\m2backup
[2008.11.07 19:41:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mquadr.at
[2006.02.28 16:41:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSScanAppDataDir
[2009.08.05 11:33:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PCSettings
[2008.11.07 19:39:23 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{0AB34A1C-91C1-45BB-8B32-A0746A30DC96}
[2008.11.07 19:38:47 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{C3358ED5-0ADD-4BA0-8F60-B5A7CD34BD14}
========== Purity Check ==========
< End of report > |