sommerzeit24 | 25.07.2013 14:40 | Nach Virus keine Berechtigung für externe Festplatte mehr Die Vorgeschichte: Vor ca. einem Monat habe ich bemerkt, dass mein Computer immer langsamer geworden ist. Dann ist mein Browser, Google Chrome, auch immer lahmer geworden. Ich hatte zu der Zeit Windows 7 32-bit. Es hat nicht lang gedauert und nach einem Neustart bekam ich plötzlich von McAfee eine Virenmeldung (ich habe den Namen vergessen, da ich vor einem Monat gedacht habe, das Thema wäre erledigt). Daraus wurden 20 Meldungen und bald 100. Ich habe noch versucht auf Google den Namen zu suchen und hier im Trojaner-Board herausgefunden, dass adw cleaner helfen könnte, aber der Computer war bald unbenutzbar.
Da ich sowieso keine wichtigen Dateien darauf hatte, habe ich alle Festplatten formatiert und den Computer neu aufgesetzt (das erste Mal wieder Win 7 32-bit). Bis auf meine externe Festplatte, auf der ich Fotos, Musik und andere wichtige Dinge gespeichert habe. Es ist eine Western Digital, Dateisystem NTFS, Speicherplatz 1 TB, immer über USB mit dem Computer verbunden, falls das irgendwie helfen könnte.
Danach habe ich McAfee gegen den nächstbesten Virenscanner ausgetauscht, den ich finden konnte, Bitdefender. Der hat sogar nach dem Formatieren noch irgendwas gefunden (da das schon so lange her ist, habe ich vergessen was es war. Es war dem Anschein nach eine ganz normale Datei). Seitdem bekomme ich keine Meldungen mehr, auch der Computer ist schneller geworden. Ich habe diese Woche nochmal die Festplatten formatiert, dieses Mal ein neues Windows 7 64-bit installiert (um meine RAM vollständig nutzen zu können...) und nochmal alles neu installiert.
So viel zur komplizierten Vorgeschichte. Heute ist mir aufgefallen, dass auf meiner externen Festplatte der Ordner "Musik" mit allen meinen mp3s schreibgeschützt ist. Außerdem kann ich auf ein paar Unterordner des Ordners "Musik" nicht zugreifen - die Meldung lautet dann:
"Sie verfügen momentan nicht über die Berechtigung des Zugriffs auf diesen Ordner. Klicken Sie auf fortsetzen, um dauerhaft Zugriff auf diesen Ordner zu erhalten".
Nach Klick auf fortsetzen kommt: "Der Zugriff auf diesen Ordner wurde verweigert. Sie müssen die Registerkarte Sicherheit verwenden, um Zugriff auf diesen Ordner zu erhalten".
In den Eigenschaften unter Sicherheit sind dann als Benutzer aufgezählt: mein Benutzerkonto, Administratoren-Konto meines PCs und ein fremdes Konto mit einer langen Aufzählung von Zeichen. Nach genauerer Betrachtung sah ich dann, dass ich zwar zugreifen kann auf die meisten Ordner auf meiner Festplatte, aber dass dieses komische Konto öfter mit aufgezählt wird.
Ich habe also alle Punkte des "Für alle Hilfesuchenden..." Threads befolgt. Leider kommt bei meinem Computer ein blue screen, wenn gmer fertig ist, so dass ich den Scan nicht speichern kann.
Hier ist das File von OTL: Code:
OTL logfile created on: 25.07.2013 09:55:00 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\xxxx\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,99 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,33% Memory free
7,98 Gb Paging File | 6,44 Gb Available in Paging File | 80,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 910,41 Gb Total Space | 872,00 Gb Free Space | 95,78% Space Free | Partition Type: NTFS
Drive D: | 20,00 Gb Total Space | 15,47 Gb Free Space | 77,34% Space Free | Partition Type: NTFS
Drive F: | 614,91 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive J: | 930,86 Gb Total Space | 89,37 Gb Free Space | 9,60% Space Free | Partition Type: NTFS
Computer Name: xxxx-PC | User Name: xxxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.07.25 09:15:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xxxx\Desktop\OTL.exe
PRC - [2013.07.23 11:28:11 | 000,217,992 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
PRC - [2013.06.08 14:11:48 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2007.09.04 15:14:04 | 000,974,848 | ---- | M] (Hama GmbH & Co KG) -- C:\Program Files (x86)\Hama\Common\RaUI.exe
========== Modules (No Company Name) ==========
MOD - [2013.06.08 14:11:48 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
========== Services (SafeList) ==========
SRV:64bit: - [2013.07.08 12:22:19 | 000,064,224 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe -- (gzserv)
SRV:64bit: - [2013.03.29 03:34:18 | 000,241,152 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013.07.24 12:57:32 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2013.07.23 11:21:57 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.07.23 13:03:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013.05.28 12:12:19 | 000,382,536 | ---- | M] (BitDefender S.R.L.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\trufos.sys -- (trufos)
DRV:64bit: - [2013.04.22 13:21:00 | 000,148,696 | ---- | M] (BitDefender LLC) [File_System | System | Running] -- C:\Windows\SysNative\drivers\gzflt.sys -- (gzflt)
DRV:64bit: - [2013.04.17 14:59:58 | 000,593,144 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\avckf.sys -- (avckf)
DRV:64bit: - [2013.04.17 14:59:56 | 000,718,840 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avc3.sys -- (avc3)
DRV:64bit: - [2013.03.29 04:35:02 | 011,658,752 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.03.29 03:09:44 | 000,581,120 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.02.14 13:41:10 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.06.10 22:35:36 | 000,867,328 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28ux.sys -- (netr28ux)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2013.04.17 17:18:57 | 000,121,928 | ---- | M] (Bitdefender SRL) [Kernel | System | Running] -- C:\Programme\Bitdefender\Antivirus Free Edition\bdfwfpf.sys -- (bdfwfpf)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 97 9B D3 81 87 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Pinterest button = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfjhllmkehmdajjlkolhdjjlfcmmlpl\6.4_0\
CHR - Extension: AdBlock = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.2_0\
CHR - Extension: Evernote Web = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0\
CHR - Extension: Evernote Web Clipper = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.9.19_0\
CHR - Extension: Google Mail = C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\xxxx\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.186.211.21 195.34.133.21
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{80C728CC-B826-4B28-8D4A-1CF42CB2DAD4}: DhcpNameServer = 212.186.211.21 195.34.133.21
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.18 23:12:18 | 000,000,088 | ---- | M] () - F:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.25 09:37:47 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.07.25 09:15:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\xxxx\Desktop\OTL.exe
[2013.07.25 08:33:02 | 000,000,000 | ---D | C] -- C:\Users\xxxx\Desktop\Programme
[2013.07.25 08:27:18 | 000,000,000 | ---D | C] -- C:\ProgramData\GZ
[2013.07.25 08:13:19 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.07.25 07:44:38 | 000,000,000 | ---D | C] -- C:\FRST
[2013.07.25 07:05:40 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2013.07.25 07:05:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2013.07.24 12:57:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone
[2013.07.24 12:56:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Rosetta Stone
[2013.07.24 12:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rosetta Stone
[2013.07.24 12:39:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GPLGS
[2013.07.24 12:39:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
[2013.07.24 12:39:18 | 000,000,000 | ---D | C] -- C:\ProgramData\APN
[2013.07.24 12:39:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acro Software
[2013.07.24 12:39:00 | 000,489,392 | ---- | C] (Ask Partner Network) -- C:\Users\xxxx\Documents\APNSetup.exe
[2013.07.23 17:46:02 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2013.07.23 17:45:56 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Adobe
[2013.07.23 17:32:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2013.07.23 17:28:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2013.07.23 17:23:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2013.07.23 17:23:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2013.07.23 17:22:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2013.07.23 17:09:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hama Wireless LAN
[2013.07.23 17:09:08 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2013.07.23 17:09:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hama
[2013.07.23 16:40:02 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\ATI
[2013.07.23 16:40:02 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\ATI
[2013.07.23 16:40:02 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013.07.23 14:09:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2013.07.23 13:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2013.07.23 13:42:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013.07.23 13:42:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2013.07.23 13:42:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2013.07.23 13:42:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013.07.23 13:41:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2013.07.23 13:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013.07.23 13:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2013.07.23 13:39:53 | 000,000,000 | ---D | C] -- C:\AMD
[2013.07.23 13:34:02 | 000,000,000 | ---D | C] -- C:\Medion
[2013.07.23 13:22:27 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2013.07.23 13:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013.07.23 13:21:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.07.23 13:21:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.07.23 13:11:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.07.23 13:11:11 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2013.07.23 13:05:52 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.07.23 13:04:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2013.07.23 13:03:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2013.07.23 13:03:55 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\DAEMON Tools Lite
[2013.07.23 13:03:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2013.07.23 13:02:54 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2013.07.23 13:02:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.07.23 13:02:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2013.07.23 12:40:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack
[2013.07.23 12:40:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\C2MP
[2013.07.23 12:33:55 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\vlc
[2013.07.23 12:17:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013.07.23 12:13:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013.07.23 12:13:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2013.07.23 12:11:37 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\uTorrent
[2013.07.23 11:36:40 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013.07.23 11:32:48 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\OpenOffice.org
[2013.07.23 11:30:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.07.23 11:29:28 | 000,000,000 | --SD | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2013.07.23 11:28:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice.org 3
[2013.07.23 11:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013.07.23 11:28:07 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Google
[2013.07.23 11:27:57 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Deployment
[2013.07.23 11:27:57 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Apps
[2013.07.23 11:25:15 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013.07.23 11:22:14 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Dropbox
[2013.07.23 11:22:03 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Macromedia
[2013.07.23 11:22:03 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Adobe
[2013.07.23 11:21:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2013.07.23 11:21:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2013.07.23 11:03:11 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013.07.23 11:00:15 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Dropbox
[2013.07.23 10:54:54 | 000,261,056 | ---- | C] (BitDefender) -- C:\Windows\SysNative\drivers\avchv.sys
[2013.07.23 10:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
[2013.07.23 10:53:47 | 000,718,840 | ---- | C] (BitDefender) -- C:\Windows\SysNative\drivers\avc3.sys
[2013.07.23 10:53:47 | 000,593,144 | ---- | C] (BitDefender) -- C:\Windows\SysNative\drivers\avckf.sys
[2013.07.23 10:52:43 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\QuickScan
[2013.07.23 10:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\Bitdefender
[2013.07.23 10:52:30 | 000,148,696 | ---- | C] (BitDefender LLC) -- C:\Windows\SysNative\drivers\gzflt.sys
[2013.07.23 10:52:29 | 000,382,536 | ---- | C] (BitDefender S.R.L.) -- C:\Windows\SysNative\drivers\trufos.sys
[2013.07.23 10:48:12 | 000,000,000 | R--D | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.07.23 10:48:12 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Searches
[2013.07.23 10:48:12 | 000,000,000 | R--D | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.07.23 10:47:48 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Identities
[2013.07.23 10:47:41 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Contacts
[2013.07.23 10:47:39 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\VirtualStore
[2013.07.23 10:47:33 | 000,000,000 | --SD | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Videos
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Saved Games
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Pictures
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Music
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Links
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Favorites
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Downloads
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Documents
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\Desktop
[2013.07.23 10:47:33 | 000,000,000 | R--D | C] -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Vorlagen
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\AppData\Local\Verlauf
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\AppData\Local\Temporary Internet Files
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Startmenü
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\SendTo
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Recent
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Netzwerkumgebung
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Lokale Einstellungen
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Documents\Eigene Videos
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Documents\Eigene Musik
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Eigene Dateien
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Documents\Eigene Bilder
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Druckumgebung
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Cookies
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\AppData\Local\Anwendungsdaten
[2013.07.23 10:47:33 | 000,000,000 | -HSD | C] -- C:\Users\xxxx\Anwendungsdaten
[2013.07.23 10:47:33 | 000,000,000 | -H-D | C] -- C:\Users\xxxx\AppData
[2013.07.23 10:47:33 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Temp
[2013.07.23 10:47:33 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Local\Microsoft
[2013.07.23 10:47:33 | 000,000,000 | ---D | C] -- C:\Users\xxxx\AppData\Roaming\Media Center Programs
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Programme
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2013.07.23 10:47:23 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2013.07.23 10:47:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2013.07.23 10:47:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2013.07.23 10:47:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2013.07.23 10:47:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2013.07.23 10:47:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2013.07.23 10:42:05 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013.07.23 10:37:57 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013.07.23 10:37:14 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2013.07.25 09:50:51 | 000,020,656 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.25 09:50:51 | 000,020,656 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.25 09:49:16 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.25 09:48:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.25 09:48:20 | 3214,233,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.25 09:46:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.25 09:35:44 | 000,377,856 | ---- | M] () -- C:\Users\xxxx\Desktop\gmer_2.1.19163.exe
[2013.07.25 09:33:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.25 09:15:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xxxx\Desktop\OTL.exe
[2013.07.25 09:14:43 | 000,000,168 | ---- | M] () -- C:\Users\xxxx\defogger_reenable
[2013.07.25 09:13:41 | 000,050,477 | ---- | M] () -- C:\Users\xxxx\Desktop\Defogger.exe
[2013.07.25 07:56:09 | 000,000,512 | ---- | M] () -- C:\Users\xxxx\Documents\MBR.dat
[2013.07.25 07:14:31 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.25 07:14:31 | 000,696,620 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.07.25 07:14:31 | 000,651,938 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.25 07:14:31 | 000,147,916 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.07.25 07:14:31 | 000,120,870 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.25 07:08:49 | 002,222,528 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.07.24 20:38:34 | 001,588,762 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.07.24 19:58:25 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.07.24 19:58:25 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013.07.23 17:09:09 | 000,001,966 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk
[2013.07.23 13:58:30 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2013.07.23 13:03:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2013.07.23 12:40:50 | 000,001,873 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
[2013.07.23 11:32:58 | 000,001,235 | ---- | M] () -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2013.07.23 11:03:39 | 000,001,049 | ---- | M] () -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.07.23 10:54:54 | 000,261,056 | ---- | M] (BitDefender) -- C:\Windows\SysNative\drivers\avchv.sys
[2013.07.23 10:54:11 | 000,006,188 | ---- | M] () -- C:\ProgramData\1374569535.3584.bin
[2013.07.23 10:53:59 | 000,083,593 | ---- | M] () -- C:\ProgramData\1374569535.3880.bin
[2013.07.23 10:53:59 | 000,034,634 | ---- | M] () -- C:\ProgramData\1374569535.4012.bin
[2013.07.23 10:53:59 | 000,018,238 | ---- | M] () -- C:\ProgramData\1374569535.3916.bin
[2013.07.23 10:53:59 | 000,013,051 | ---- | M] () -- C:\ProgramData\1374569535.404.bin
[2013.07.23 10:53:49 | 000,012,247 | ---- | M] () -- C:\ProgramData\1374569535.3876.bin
[2013.07.23 10:53:49 | 000,001,420 | ---- | M] () -- C:\ProgramData\1374569535.3644.bin
[2013.07.23 10:52:54 | 000,004,420 | ---- | M] () -- C:\ProgramData\1374569535.3920.bin
[2013.07.23 10:42:56 | 000,159,772 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013.07.23 10:42:56 | 000,159,772 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013.07.23 10:39:49 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
========== Files Created - No Company Name ==========
[2013.07.25 09:35:44 | 000,377,856 | ---- | C] () -- C:\Users\xxxx\Desktop\gmer_2.1.19163.exe
[2013.07.25 09:14:43 | 000,000,168 | ---- | C] () -- C:\Users\xxxx\defogger_reenable
[2013.07.25 09:13:41 | 000,050,477 | ---- | C] () -- C:\Users\xxxx\Desktop\Defogger.exe
[2013.07.25 07:56:09 | 000,000,512 | ---- | C] () -- C:\Users\xxxx\Documents\MBR.dat
[2013.07.24 20:06:25 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.07.24 19:58:25 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.07.24 19:58:25 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013.07.24 19:27:46 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.07.24 12:39:19 | 000,087,152 | ---- | C] () -- C:\Windows\SysNative\cpwmon64.dll
[2013.07.24 12:34:23 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013.07.23 17:09:09 | 000,001,966 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk
[2013.07.23 14:12:00 | 001,588,762 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.07.23 13:58:30 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.07.23 12:40:50 | 000,001,873 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
[2013.07.23 11:32:58 | 000,001,235 | ---- | C] () -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2013.07.23 11:28:16 | 000,001,108 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.23 11:28:14 | 000,001,104 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.23 11:21:58 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.23 11:03:39 | 000,001,049 | ---- | C] () -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.07.23 10:53:47 | 000,001,420 | ---- | C] () -- C:\ProgramData\1374569535.3644.bin
[2013.07.23 10:52:34 | 000,083,593 | ---- | C] () -- C:\ProgramData\1374569535.3880.bin
[2013.07.23 10:52:34 | 000,012,247 | ---- | C] () -- C:\ProgramData\1374569535.3876.bin
[2013.07.23 10:52:34 | 000,004,420 | ---- | C] () -- C:\ProgramData\1374569535.3920.bin
[2013.07.23 10:52:29 | 000,018,238 | ---- | C] () -- C:\ProgramData\1374569535.3916.bin
[2013.07.23 10:52:18 | 000,013,051 | ---- | C] () -- C:\ProgramData\1374569535.404.bin
[2013.07.23 10:52:18 | 000,006,188 | ---- | C] () -- C:\ProgramData\1374569535.3584.bin
[2013.07.23 10:52:15 | 000,034,634 | ---- | C] () -- C:\ProgramData\1374569535.4012.bin
[2013.07.23 10:49:52 | 000,001,421 | ---- | C] () -- C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.07.23 10:42:46 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013.07.23 10:42:45 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013.07.23 10:39:49 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.07.23 10:37:14 | 3214,233,600 | -HS- | C] () -- C:\hiberfil.sys
[2013.06.08 14:11:48 | 000,039,896 | ---- | C] () -- C:\Windows\SysWow64\DiscHandler.exe
[2013.06.08 13:54:10 | 003,915,776 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2013.06.08 13:53:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013.06.08 13:52:30 | 000,271,360 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2013.06.08 13:52:12 | 000,157,184 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2013.06.08 13:52:10 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2013.06.08 13:52:10 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2013.06.08 13:52:08 | 001,525,760 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2013.06.08 13:52:08 | 000,211,968 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2013.06.08 13:52:08 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2013.06.08 13:52:06 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2013.05.20 17:43:32 | 000,446,128 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2013.05.20 17:43:32 | 000,280,624 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-52.dll
[2013.05.20 17:43:32 | 000,190,640 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2013.05.20 17:43:32 | 000,172,216 | ---- | C] () -- C:\Windows\SysWow64\avresample-lav-1.dll
[2013.05.20 17:43:30 | 007,856,976 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2013.05.20 17:43:30 | 001,315,240 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-55.dll
[2013.05.20 17:43:30 | 000,202,344 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-3.dll
[2013.03.29 04:13:14 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.03.29 04:13:12 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.03.29 03:38:08 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.03.29 03:38:08 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.11.27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.09.30 00:47:28 | 000,000,178 | ---- | C] () -- C:\Windows\SysWow64\Formats.ini
[2011.12.07 21:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\Lagarith.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.09.08 16:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
[2011.09.08 16:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
[2011.09.08 16:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
[2011.09.08 16:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
[2011.09.08 16:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
[2011.09.08 16:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
[2011.09.08 16:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
[2011.09.08 16:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
[2011.09.08 15:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
[2011.09.08 15:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.07.25 08:15:24 | 000,000,000 | ---D | M] -- C:\Users\xxxx\AppData\Roaming\DAEMON Tools Lite
[2013.07.25 09:49:49 | 000,000,000 | ---D | M] -- C:\Users\xxxx\AppData\Roaming\Dropbox
[2013.07.23 11:32:48 | 000,000,000 | ---D | M] -- C:\Users\xxxx\AppData\Roaming\OpenOffice.org
[2013.07.23 10:52:43 | 000,000,000 | ---D | M] -- C:\Users\xxxx\AppData\Roaming\QuickScan
[2013.07.25 08:15:24 | 000,000,000 | ---D | M] -- C:\Users\xxxx\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report > Es war natürlich blöd, dass ich den Namen des Virus oder was es war nicht aufgeschrieben habe, aber der Fehler ist passiert. Ich bedanke mich schon einmal im Vorhinein für jegliche Hilfe!
Ich werde erst am Samstag Nachmittag bis Abend Zugang zu meinem Computer haben, antworten kann ich inzwischen auch von anderen Computern. |