PUP.Conduit.Optional.A _Ordner nicht löschbar Liste der Anhänge anzeigen (Anzahl: 1) Liebes Trojaner-Board-Team,
ich konnte einen leeren Ordner "diving all" auf meinem Desktop nicht löschen. Da waren Fotos drin, die ich von einem Tauchurlaub von dem dortigen PC des Tauchclubs mitgebracht hatte.
Zudem wunderte ich mich mehr und mehr über meinen subjektiv langsamer werdenden Laptop. Ich habe Malwarebytes installiert und drüber laufen lassen. Der Schädling "HSS02.04-install-anchorfree.exe" wurde unter: Meine Dateien\Downloads gefunden. Diesen Schädling habe ich in Malwarebytes gelöscht. Bei wiederholtem Scannen mit Malwarebytes war er immer noch bzw. wieder da. Der Ordner "diving all" läßt sich nicht löschen und ist "leer" 1,57MB groß!
Wie kann ich dem Schädling endgültig den Gar aus machen und den Ordner löschen?
Vielen Dank für Eure Hilfe schon im Voraus!
Gruß JM Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:15 on 25/01/2014 (JM)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2014
Ran by JM (administrator) on ***** on 25-01-2014 13:20:27
Running from C:\Dokumente und Einstellungen\JM\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 6
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AuthenTec, Inc) C:\Programme\TrueSuite\TrueSuite.Service.exe
(AuthenTec, Inc.) C:\Programme\Fingerprint Sensor\ATService.exe
(Nero AG) C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(Alps Electric Co., Ltd.) C:\Programme\Apoint2K\Apoint.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TouchED\TouchED.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TNROTATE\TNROTATE.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TOSHIBA Zoom-Dienstprogramm\SmoothView.exe
(TOSHIBA CORPORATION) C:\Programme\TOSHIBA\Wireless Hotkey\TosHKCW.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Alps Electric Co., Ltd.) C:\Programme\Apoint2K\ApMsgFwd.exe
(Atheros Communications, Inc.) C:\Programme\Atheros\ACU.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\ThpSrv.exe
(Alps Electric Co., Ltd.) C:\Programme\Apoint2K\hidfind.exe
(Alps Electric Co., Ltd.) C:\Programme\Apoint2K\ApntEx.exe
(AuthenTec, Inc) C:\Programme\TrueSuite\TrueSuite.SysTray.exe
(AuthenTec, Inc.) C:\Programme\TrueSuite\TrueSuite.ClientAppLogonExe.exe
(shbox.de) C:\Programme\FreePDF_XP\fpassist.exe
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
() C:\WINDOWS\twain_32\Samsung\CLX6220\Scan2Pc.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\00THotkey.exe
(Apple Inc.) C:\Programme\iTunes\iTunesHelper.exe
(Anvisoft) C:\Programme\Anvisoft\Anvi Smart Defender\ASDTray.exe
(TOSHIBA CORPORATION.) C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
(TOSHIBA CORPORATION.) C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION.) C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe
(TOSHIBA CORPORATION.) C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
(Apple Inc.) C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Anvisoft) C:\Programme\Anvisoft\Anvi Smart Defender\ASDSrv.exe
(Kaspersky Lab ZAO) C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Apple Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Sun Microsystems, Inc.) C:\Programme\Java\jre6\bin\jqs.exe
(Kaspersky Lab ZAO) C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\ThpSrv.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
(TOSHIBA Corporation) C:\WINDOWS\system32\TODDSrv.exe
(TOSHIBA CORPORATION) C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
(Canon Inc.) C:\Programme\Canon\CAL\CALMAIN.exe
(Intel Corporation) C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Apple Inc.) C:\Programme\iPod\bin\iPodService.exe
(AuthenTec Inc.) C:\Programme\TrueSuite\TrueSuite.TouchControl.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Programme\Apoint2K\Apoint.exe [241664 2009-09-11] (Alps Electric Co., Ltd.)
HKLM\...\Run: [TouchED] - C:\Programme\TOSHIBA\TouchED\TouchED.exe [118784 2005-09-01] (TOSHIBA Corporation)
HKLM\...\Run: [TNRotate] - %ProgramFiles%\TOSHIBA\TNRotate\TNRotate.exe
HKLM\...\Run: [SmoothView] - C:\Programme\TOSHIBA\TOSHIBA Zoom-Dienstprogramm\SmoothView.exe [143360 2009-08-31] (TOSHIBA Corporation)
HKLM\...\Run: [TosHKCW.exe] - C:\Programme\TOSHIBA\Wireless Hotkey\TosHKCW.exe [225280 2009-07-02] (TOSHIBA CORPORATION)
HKLM\...\Run: [TUSBSleepChargeSrv] - %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
HKLM\...\Run: [DDWMon] - C:\Programme\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe [495616 2007-04-26] (TOSHIBA Corporation)
HKLM\...\Run: [IAStorIcon] - C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM\...\Run: [ITSecMng] - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
HKLM\...\Run: [ACU] - C:\Programme\Atheros\ACU.exe [471129 2009-10-07] (Atheros Communications, Inc.)
HKLM\...\Run: [ThpSrv] - C:\WINDOWS\system32\thpsrv /logon
HKLM\...\Run: [TosSENotify] - C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [TWebCamera] - C:\Programme\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840 2009-12-09] (TOSHIBA CORPORATION.)
HKLM\...\Run: [SystemTray] - C:\Programme\TrueSuite\TrueSuite.SysTray.exe [619256 2009-11-18] (AuthenTec, Inc)
HKLM\...\Run: [ClientAppLogon] - C:\Programme\TrueSuite\TrueSuite.ClientAppLogonExe.exe [306936 2009-11-18] (AuthenTec, Inc.)
HKLM\...\Run: [FreePDF Assistant] - C:\Programme\FreePDF_XP\fpassist.exe [310272 2005-05-27] (shbox.de)
HKLM\...\Run: [QuickTime Task] - C:\Programme\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe [58656 2011-04-20] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung PanelMgr] - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [614400 2009-11-26] ()
HKLM\...\Run: [SCX6220_Scan2Pc] - C:\WINDOWS\Twain_32\Samsung\CLX6220\Scan2pc.exe [2042368 2011-12-02] ()
HKLM\...\Run: [6220 Scan2PC] - C:\WINDOWS\Twain_32\Samsung\CLX6220\Scan2pc.exe [2042368 2011-12-02] ()
HKLM\...\Run: [NWEReboot] - [x]
HKLM\...\Run: [00THotkey] - C:\WINDOWS\system32\00THotkey.exe [253952 2009-06-17] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Programme\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM\...\Run: [Anvi Smart Defender] - C:\Programme\Anvisoft\Anvi Smart Defender\ASDTray.exe [1636536 2013-10-21] (Anvisoft)
Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
MountPoints2: {ed8c6bd8-12c5-11e0-abb2-0026b6de09ce} - E:\DPFMate.exe
HKU\Administrator\...\Run: [TOSHIBA Online Product Information] - C:\Programme\TOSHIBA\Toshiba Online Product Information\topi.exe
HKU\Administrator\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
HKU\Administrator\...\RunOnce: [NeroHomeFirstStart] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe [ 2006-06-01] (Nero AG)
HKU\Default User\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe [ 2006-06-01] (Nero AG)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Bluetooth Manager.lnk
ShortcutTarget: Bluetooth Manager.lnk -> C:\Programme\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {c99fdc39-a1ae-4b24-8d71-e5274f8d7c54} URL = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
SearchScopes: HKCU - {c99fdc39-a1ae-4b24-8d71-e5274f8d7c54} URL = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Programme\TrueSuite\TrueSuite.IEBHO.dll (AuthenTec Inc.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo\YontooIEClient.dll (Yontoo LLC)
Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 C:\Programme\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\JM\Anwendungsdaten\Mozilla\Firefox\C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab\SafeBrowser\S-1-5-21-1583877156-3090797743-3329591833-1005\FireFox
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @canon.com/MycameraPlugin - C:\Programme\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Anti-Banner - C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2011-08-07]
FF Extension: Modul zur Link-Untersuchung - C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2011-08-07]
FF Extension: TrueSuite Website Log On - C:\Programme\Mozilla Firefox\extensions\websitelogon_toolbar@truesuite.com [2010-07-06]
FF Extension: Skype extension for Firefox - C:\Programme\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [2010-07-13]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Programme\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Programme\Java\jre6\lib\deploy\jqs\ff [2002-09-28]
FF HKLM\...\Firefox\Extensions: - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-09-07]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-09-07]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-09-07]
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-09-07]
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-09-07]
Chrome:
=======
CHR DefaultSearchURL: {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\DOKUME~1\JM\LOKALE~1\Temp\YontooLayers.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-08-14]
========================== Services (Whitelisted) =================
R2 ACS; C:\WINDOWS\system32\acs.exe [499797 2009-10-07] (Atheros)
R2 Apple Mobile Device; C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184 2012-08-11] (Apple Inc.)
R2 asdsrv; C:\Programme\Anvisoft\Anvi Smart Defender\ASDSrv.exe [742584 2013-10-21] (Anvisoft)
R2 ATService; C:\Programme\Fingerprint Sensor\atservice.exe [2034936 2009-11-16] (AuthenTec, Inc.)
R2 AVP; C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-20] (Kaspersky Lab ZAO)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [390504 2011-08-30] (Apple Inc.)
R2 CCALib8; C:\Programme\Canon\CAL\CALMAIN.exe [96334 2009-09-08] (Canon Inc.)
R2 CFSvcs; C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2005-01-17] (TOSHIBA CORPORATION)
R2 FPLService; C:\Programme\TrueSuite\TrueSuite.Service.exe [108280 2009-11-18] (AuthenTec, Inc)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2010-08-23] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2010-08-23] (Google Inc.)
R2 IAStorDataMgrSvc; C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [13336 2009-10-02] (Intel Corporation)
S3 IDriverT; c:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation)
R2 InCDsrv; C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe [800768 2006-05-30] (Nero AG)
R3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [553440 2012-12-12] (Apple Inc.)
R2 JavaQuickStarterService; C:\Programme\Java\jre6\bin\jqs.exe [152984 2002-09-28] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [441136 2006-10-26] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
S4 Tmesrv; C:\Programme\TOSHIBA\TME3\Tmesrv31.exe [118784 2009-11-20] (TOSHIBA)
R2 TNaviSrv; C:\Programme\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2009-11-12] (TOSHIBA Corporation)
R2 TOSHIBA Bluetooth Service; C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [148848 2009-10-21] (TOSHIBA CORPORATION)
R3 TOSHIBA HDD SSD Alert Service; C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2009-11-05] (TOSHIBA Corporation)
S2 UNS; C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation)
S2 LMS; C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [x]
==================== Drivers (Whitelisted) ====================
S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.)
R1 asdrm; C:\Windows\System32\DRIVERS\asdrm.sys [16208 2013-10-15] (Anvisoft)
R2 asdrs; C:\WINDOWS\system32\DRIVERS\asdrs.sys [22864 2013-10-15] (Anvisoft)
R1 asdws; C:\Windows\System32\DRIVERS\asdws.sys [14160 2013-10-15] ()
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 e1kexpress; C:\Windows\System32\DRIVERS\e1k5132.sys [160424 2009-09-23] (Intel Corporation)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49664 2005-10-28] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-28] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2005-10-28] (HP)
R3 IFXTPM; C:\Windows\System32\DRIVERS\IFXTPM.SYS [44800 2007-12-18] (Infineon Technologies AG)
R4 InCDfs; C:\Windows\System32\drivers\InCDFs.sys [102656 2006-05-30] (Nero AG)
R1 InCDPass; C:\Windows\System32\drivers\InCDPass.sys [29568 2006-05-30] (Nero AG)
U1 InCDrec; C:\Windows\System32\Drivers\InCDrec.sys [9984 2006-05-30] (Nero AG)
R1 incdrm; C:\Windows\System32\drivers\InCDRm.sys [33792 2006-05-30] (Nero AG)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-11-07] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [573536 2013-12-23] (Kaspersky Lab ZAO)
R3 klim5; C:\Windows\System32\DRIVERS\klim5.sys [36448 2013-04-19] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [24160 2013-10-20] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [24672 2013-10-20] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2014-01-25] (Malwarebytes Corporation)
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 Netdevio; C:\Windows\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.)
S3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [57576 2009-10-12] (NVIDIA Corporation)
R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
R2 risdpcie; C:\Windows\System32\DRIVERS\risdpe86.sys [49152 2009-07-28] (REDC)
R2 rixdpcie; C:\Windows\System32\DRIVERS\rixdpe86.sys [38400 2009-07-04] (REDC)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25984 2009-11-20] (The OpenVPN Project)
S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [32768 2011-05-25] (AnchorFree Inc)
R2 tdudf; C:\Windows\System32\DRIVERS\tdudf.sys [105856 2007-03-26] (TOSHIBA Corporation)
R1 TMEI3E; C:\Windows\System32\Drivers\TMEI3E.SYS [5888 2004-06-16] (Toshiba Corporation)
R2 trudf; C:\Windows\System32\DRIVERS\trudf.sys [134016 2007-02-19] (TOSHIBA Corporation)
R3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [58208 2009-03-16] (Atheros Communications, Inc.)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys [x]
S4 IntelIde; No ImagePath
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [93280 2013-06-08] (Kaspersky Lab ZAO)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-25 13:20 - 2014-01-25 13:21 - 00026209 _____ C:\Dokumente und Einstellungen\JM\Desktop\FRST.txt
2014-01-25 13:17 - 2014-01-25 13:17 - 00000000 ____D C:\FRST
2014-01-25 13:16 - 2014-01-25 13:16 - 01222144 _____ (Farbar) C:\Dokumente und Einstellungen\JM\Desktop\FRST.exe
2014-01-25 13:15 - 2014-01-25 13:15 - 00000466 _____ C:\Dokumente und Einstellungen\JM\Desktop\defogger_disable.log
2014-01-25 13:15 - 2014-01-25 13:15 - 00000000 _____ C:\Dokumente und Einstellungen\JM\defogger_reenable
2014-01-25 13:10 - 2014-01-25 13:10 - 00050477 _____ C:\Dokumente und Einstellungen\JM\Desktop\Defogger.exe
2014-01-25 12:47 - 2014-01-25 12:47 - 00000000 ____D C:\WINDOWS\LastGood
2014-01-25 12:33 - 2014-01-25 13:11 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Eigene Dateien\ADAC
2014-01-25 10:01 - 2014-01-25 10:01 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2014-01-23 21:08 - 2014-01-25 12:48 - 00005006 _____ C:\WINDOWS\setupapi.log
2014-01-23 17:27 - 2014-01-23 17:27 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Anwendungsdaten\Malwarebytes
2014-01-23 17:26 - 2014-01-23 17:26 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2014-01-23 17:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-27 09:05 - 2013-12-27 14:46 - 01163264 _____ C:\WINDOWS\system32\㩣摜歯浵湥整甠摮攠湩瑳汥畬杮湥慜汬甠敳獲慜睮湥畤杮摳瑡湥歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯慤
==================== One Month Modified Files and Folders =======
2014-01-25 13:21 - 2014-01-25 13:20 - 00026209 _____ C:\Dokumente und Einstellungen\JM\Desktop\FRST.txt
2014-01-25 13:17 - 2014-01-25 13:17 - 00000000 ____D C:\FRST
2014-01-25 13:16 - 2014-01-25 13:16 - 01222144 _____ (Farbar) C:\Dokumente und Einstellungen\JM\Desktop\FRST.exe
2014-01-25 13:16 - 2010-07-06 10:21 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
2014-01-25 13:15 - 2014-01-25 13:15 - 00000466 _____ C:\Dokumente und Einstellungen\JM\Desktop\defogger_disable.log
2014-01-25 13:15 - 2014-01-25 13:15 - 00000000 _____ C:\Dokumente und Einstellungen\JM\defogger_reenable
2014-01-25 13:15 - 2010-07-05 19:28 - 00000000 ____D C:\Dokumente und Einstellungen\JM
2014-01-25 13:12 - 2002-09-28 02:17 - 00000315 _____ C:\WINDOWS\wiadebug.log
2014-01-25 13:11 - 2014-01-25 12:33 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Eigene Dateien\ADAC
2014-01-25 13:10 - 2014-01-25 13:10 - 00050477 _____ C:\Dokumente und Einstellungen\JM\Desktop\Defogger.exe
2014-01-25 12:48 - 2014-01-23 21:08 - 00005006 _____ C:\WINDOWS\setupapi.log
2014-01-25 12:48 - 2002-09-28 03:13 - 00000000 ____D C:\WINDOWS\Help
2014-01-25 12:48 - 2002-09-28 01:19 - 01497440 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-25 12:47 - 2014-01-25 12:47 - 00000000 ____D C:\WINDOWS\LastGood
2014-01-25 12:46 - 2010-08-23 15:51 - 00001082 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-25 12:20 - 2010-07-06 15:54 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Eigene Dateien\Kündigung O2
2014-01-25 12:14 - 2013-12-23 22:08 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Desktop\diving all
2014-01-25 12:08 - 2010-07-06 19:00 - 00000116 _____ C:\WINDOWS\NeroDigital.ini
2014-01-25 10:01 - 2014-01-25 10:01 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2014-01-25 09:54 - 2010-08-23 15:51 - 00001078 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-25 09:54 - 2009-12-16 09:20 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-25 09:54 - 2002-09-28 02:17 - 00000050 _____ C:\WINDOWS\wiaservc.log
2014-01-25 09:54 - 2002-09-28 01:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-23 21:25 - 2013-09-07 08:14 - 00268218 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
2014-01-23 21:25 - 2010-07-05 19:28 - 00000300 ___SH C:\Dokumente und Einstellungen\JM\ntuser.ini
2014-01-23 21:25 - 2010-07-05 16:56 - 00524288 _____ C:\WINDOWS\system32\config\ACS.evt
2014-01-23 21:25 - 2002-09-28 01:22 - 00032530 _____ C:\WINDOWS\SchedLgU.Txt
2014-01-23 21:02 - 2013-09-07 16:27 - 00268218 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-1583877156-3090797743-3329591833-1005-0.dat
2014-01-23 17:27 - 2014-01-23 17:27 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Anwendungsdaten\Malwarebytes
2014-01-23 17:26 - 2014-01-23 17:26 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
2014-01-23 17:26 - 2014-01-23 17:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2014-01-23 17:26 - 2002-09-28 02:16 - 00000000 ___RD C:\Programme
2014-01-23 17:26 - 2002-09-28 02:16 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2014-01-12 12:01 - 2010-11-30 15:52 - 00000000 ___RD C:\Dokumente und Einstellungen\JM\Eigene Dateien\Eigene Bilder
2014-01-11 10:16 - 2010-07-06 11:11 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\FreePDF
2014-01-09 17:02 - 2010-07-06 10:04 - 00102912 _____ C:\Dokumente und Einstellungen\JM\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-05 11:29 - 2011-09-11 09:34 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Eigene Dateien\Haus Eybacherstrasse 5
2014-01-04 14:10 - 2010-07-06 15:59 - 00000000 ____D C:\Dokumente und Einstellungen\JM\Eigene Dateien\Pau Verschiedene
2014-01-04 12:53 - 2002-09-28 02:16 - 01246892 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-31 17:13 - 2010-07-06 06:51 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-12-27 14:46 - 2013-12-27 09:05 - 01163264 _____ C:\WINDOWS\system32\㩣摜歯浵湥整甠摮攠湩瑳汥畬杮湥慜汬甠敳獲慜睮湥畤杮摳瑡湥歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯慤
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2009-12-16 09:20] - [2008-04-14 13:00] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2009-12-16 09:20] - [2008-04-14 13:00] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2009-12-16 09:20] - [2008-04-14 13:00] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2009-12-16 09:20] - [2009-02-09 12:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2009-12-16 09:20] - [2008-04-14 13:00] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2009-12-16 09:20] - [2008-04-14 13:00] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\rpcss.dll
[2009-12-16 09:20] - [2009-02-09 11:51] - 0401408 ____A (Microsoft Corporation) 3127afbf2c1ed0ab14a1bbb7aaecb85b
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys
[2009-12-16 09:20] - [2008-04-14 13:00] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2014
Ran by JM at 2014-01-25 13:21:23
Running from C:\Dokumente und Einstellungen\JM\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Internet Security (Disabled - Up to date) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security (Disabled) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
==================== Installed Programs ======================
Adobe Flash Player 10 Plugin (Version: 10.1.53.64 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (Version: 9.0.28.0 - Adobe Systems, Inc.)
Adobe Reader X (10.1.2) - Deutsch (Version: 10.1.2 - Adobe Systems Incorporated)
AFPL Ghostscript 8.54 (Version: - )
AFPL Ghostscript Fonts (Version: - )
AiO_Scan_CDA (Version: 51.0.230.000 - Hewlett-Packard) Hidden
ALPS Touch Pad Driver (Version: 7.5.303.213 - ALPS ELECTRIC CO., LTD.)
Anvi Smart Defender 1.9.3 (Version: 1.9.3 - Anvisoft)
Apple Application Support (Version: 2.3.2 - Apple Inc.)
Apple Mobile Device Support (Version: 6.0.1.3 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Utility (Version: - Atheros)
Atheros Driver Installation Program (Version: 5.0 - Atheros)
AuthenTec TrueSuite (Version: 3.0.1.42 - AuthenTec, Inc.)
Bluetooth Stack for Windows by Toshiba (Version: v7.10.01(T) - TOSHIBA CORPORATION)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Canon Camera Access Library (Version: 8.5.0.2 - Canon Inc.)
CANON iMAGE GATEWAY Task for ZoomBrowser EX (Version: 1.7.2.11 - Canon Inc.)
Canon Internet Library for ZoomBrowser EX (Version: 1.6.3.9 - Canon Inc.)
Canon iP2600 series (Version: - )
Canon MOV Decoder (Version: 1.5.0.7 - Canon Inc.)
Canon MOV Encoder (Version: 1.3.0.3 - Canon Inc.)
Canon MovieEdit Task for ZoomBrowser EX (Version: 3.4.0.8 - Canon Inc.)
Canon Utilities CameraWindow (Version: 7.4.0.7 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (Version: 8.1.0.11 - Canon Inc.)
Canon Utilities Movie Uploader for YouTube (Version: 1.0.0.11 - Canon Inc.)
Canon Utilities MyCamera (Version: 7.3.0.5 - Canon Inc.)
Canon Utilities PhotoStitch (Version: 3.1.22.46 - Canon Inc.)
Canon Utilities ZoomBrowser EX (Version: 6.5.0.14 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (Version: 1.3.0.4 - Canon Inc.)
CCleaner (Version: 2.33 - Piriform)
Deinstallationsprogamm für TOSHIBA Mobile Extension3 (Version: - ) Hidden
FreePDF XP (Remove only) (Version: - )
Google Earth (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
iDRS(tm) OCR Software by I.R.I.S (Version: 1.00.13.00 - Samsung Electronics Co., Ltd.)
Image Resizer Powertoy for Windows XP (Version: 1.00.0001 - Microsoft Corporation)
Intel(R) Graphics Media Accelerator Driver (Version: 6.14.10.5179 - Intel Corporation)
Intel(R) Management Engine Components (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Network Connections Drivers (Version: 14.5 - Intel)
Intel(R) Rapid Storage Technology (Version: 9.5.0.1037 - Intel Corporation)
iTunes (Version: 11.0.1.12 - Apple Inc.)
Java(TM) 6 Update 14 (Version: 6.0.140 - Sun Microsystems, Inc.)
Kaspersky Internet Security 2012 (Version: 12.0.0.374 - Kaspersky Lab)
Kaspersky Internet Security 2012 (Version: 12.0.0.374 - Kaspersky Lab) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Version: - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Standard Edition 2003 (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Software Update for Web Folders (German) 12 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft User-Mode Driver Framework Feature Pack 1.0 (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation)
MobileMe Control Panel (Version: 3.1.6.0 - Apple Inc.)
Mozilla Firefox 17.0.1 (x86 de) (Version: 17.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
Nero 7 Essentials (Version: 7.01.4237 - Nero AG)
NVIDIA Drivers (Version: 1.10 - NVIDIA Corporation)
OpenVPN Tap Adapter 9.0 (Version: - )
PVS 2.000 (Vollversion) (Version: - )
QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
QuickTime (Version: 7.69.80.9 - Apple Inc.)
Realtek High Definition Audio Driver (Version: 5.10.0.5972 - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (Version: - )
RICOH R5U230 Media Driver ver.2.07.03.02 (Version: 2.07.03.02 - RICOH)
Scan (Version: 6.0.0.0 - Hewlett-Packard) Hidden
Skype™ 3.5 (Version: 3.5.229 - Skype Technologies S.A.)
TOSHIBA 180 Degrees Rotation Utility (Version: 1.2.0.0 - TOSHIBA Corporation)
TOSHIBA 180 Degrees Rotation Utility (Version: 1.2.0.0 - TOSHIBA Corporation) Hidden
TOSHIBA Assist (Version: - )
TOSHIBA Benutzerhandbücher (Version: 7.52 - TOSHIBA)
TOSHIBA ConfigFree (Version: 5.90.17 - )
TOSHIBA Controls (Version: v3.37.4310 - TOSHIBA Corporation)
TOSHIBA Controls (Version: v3.37.4310 - TOSHIBA Corporation) Hidden
TOSHIBA Dienstprogramme (Version: 4.30.24 - TOSHIBA)
TOSHIBA Direct Disc Writer (Version: 1.1.0.0b - TOSHIBA Corporation)
TOSHIBA Disc Creator (Version: 2.1.0.2 - TOSHIBA Corporation)
TOSHIBA Display Devices Change Utility (Version: - )
TOSHIBA DVD PLAYER (Version: 2.50.1.05-A - TOSHIBA Corporation)
TOSHIBA HDD Protection (Version: 2.3.0.0 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (Version: 3.1.0.4 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (Version: 3.1.0.4 - TOSHIBA Corporation) Hidden
TOSHIBA Hotkey Utility for Display Devices (Version: - )
TOSHIBA Mobile Extension3 (Version: 3.91.00.XP - TOSHIBA)
TOSHIBA Password Utility (Version: 2.01.10 - TOSHIBA) Hidden
TOSHIBA Passwort-Utility (Version: 2.01.10 - TOSHIBA)
TOSHIBA PC Diagnostic Tool (Version: 3.2.15 - TOSHIBA) Hidden
TOSHIBA PC-Diagnose-Tool (Version: 3.2.15 - TOSHIBA)
TOSHIBA Power Saver (Version: 7.13.04 - )
TOSHIBA Power Saver (Version: 7.13.04 - ) Hidden
TOSHIBA Sicherheits-Assistent (Version: 1.2.1 - TOSHIBA)
TOSHIBA Touchpad Ein/Aus Utility V2.5.1.0 (Version: 2.5.1.0 - TOSHIBA)
TOSHIBA USB Sleep and Charge Utility (Version: 1.3.2.0 - TOSHIBA Corporation)
TOSHIBA Utilities (Version: 4.30.24 - TOSHIBA) Hidden
TOSHIBA Web Camera Application (Version: 1.1.2.8 - TOSHIBA Corporation)
TOSHIBA Zoom-Dienstprogramm (Version: 2.0.0.25 - TOSHIBA)
TSOL Pro 4.5 (Version: TSOL Pro 4.5 - Dr. Valentin EnergieSoftware GmbH)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
Valentin Meteo Data 1.0.26 (Version: - Dr. Valentin EnergieSoftware GmbH)
VizadooCAD 2.3 start (Version: - )
VLC media player 1.1.4 (Version: 1.1.4 - VideoLAN)
Wartung Samsung CLX-6220 Series (Version: - Samsung Electronics Co.,Ltd)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Media Format 11 runtime (Version: - )
Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden
Windows Media Player 10 (Version: - )
WinRAR (Version: - )
Wireless Hotkey (Version: 3.0.0.9 - TOSHIBA)
XML Paper Specification Shared Components Language Pack 1.0 (Version: - Microsoft Corporation) Hidden
==================== Restore Points =========================
07-09-2013 07:07:31 First Restore Point
15-09-2013 06:36:23 Systemprüfpunkt
20-10-2013 07:56:24 Systemprüfpunkt
02-11-2013 10:44:55 Systemprüfpunkt
09-11-2013 12:44:17 Systemprüfpunkt
12-11-2013 09:30:17 Systemprüfpunkt
24-12-2013 09:16:46 Systemprüfpunkt
27-12-2013 09:52:52 Systemprüfpunkt
02-01-2014 09:00:42 Systemprüfpunkt
04-01-2014 11:51:41 Systemprüfpunkt
19-01-2014 10:46:37 Systemprüfpunkt
23-01-2014 16:53:48 Systemprüfpunkt
25-01-2014 10:27:16 Systemprüfpunkt
==================== Hosts content: ==========================
2009-12-16 09:20 - 2012-03-16 09:27 - 00000923 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Programme\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Programme\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Programme\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Registrierungserinnerung 1.job => C:\WINDOWS\system32\OOBE\oobebaln.exe
Task: C:\WINDOWS\Tasks\Registrierungserinnerung 2.job => C:\WINDOWS\system32\OOBE\oobebaln.exe
==================== Loaded Modules (whitelisted) =============
2010-07-06 11:11 - 2005-01-06 17:33 - 00116224 _____ () C:\WINDOWS\system32\redmonnt.dll
2012-12-19 18:49 - 2009-05-29 01:33 - 00026624 _____ () C:\WINDOWS\system32\ssy2cl3.dll
2013-01-07 10:25 - 2009-05-29 18:37 - 00026624 _____ () C:\WINDOWS\system32\ssy2ml3.dll
2012-12-19 18:49 - 2009-11-25 11:56 - 00495616 _____ () C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ssy2cdu.dll
2012-01-03 14:10 - 2012-01-03 14:10 - 00301056 _____ () C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU
2011-01-11 05:17 - 2010-03-15 11:28 - 00141824 _____ () C:\Programme\WinRAR\rarext.dll
2009-12-16 09:20 - 2008-04-14 13:00 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2012-12-19 18:25 - 2009-08-14 08:53 - 01384520 _____ () C:\WINDOWS\Twain_32\Samsung\CLX6220\ssole.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\zlib1.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\libxml2.dll
2013-10-15 04:06 - 2013-10-15 04:06 - 00785128 _____ () C:\Programme\Anvisoft\Anvi Smart Defender\sqlite3.dll
2013-06-17 11:35 - 2013-06-17 11:35 - 00478400 _____ () C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 13:52 - 2013-05-08 13:52 - 01270464 _____ () C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2010-07-05 16:45 - 2009-10-02 12:18 - 00058880 _____ () C:\Programme\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2009-11-05 08:14 - 2009-11-05 08:14 - 00079192 _____ () C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
2012-12-20 09:36 - 2012-11-29 09:26 - 02397152 _____ () C:\Programme\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/12/2014 11:42:45 AM) (Source: Application Hang) (User: )
Description: Stillstehende Anwendung explorer.exe, Version 6.0.2900.5512, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error: (01/12/2014 11:41:06 AM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung explorer.exe, Version 6.0.2900.5512, fehlgeschlagenes Modul comctl32.dll, Version 6.0.2900.5512, Fehleradresse 0x0006d6b0.
Das medienspezifische Ereignis für [explorer.exe!ws!] wird verarbeitet.
Error: (01/12/2014 11:38:37 AM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung drwtsn32.exe, Version 5.1.2600.0, fehlgeschlagenes Modul dbghelp.dll, Version 5.1.2600.5512, Fehleradresse 0x0001295d.
Das medienspezifische Ereignis für [drwtsn32.exe!ws!] wird verarbeitet.
Error: (01/12/2014 11:38:09 AM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung explorer.exe, Version 6.0.2900.5512, fehlgeschlagenes Modul comctl32.dll, Version 6.0.2900.5512, Fehleradresse 0x0006d6b0.
Das medienspezifische Ereignis für [explorer.exe!ws!] wird verarbeitet.
Error: (12/23/2013 09:08:11 PM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung applemobilebackup.exe, Version 17.1140.1.4, fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0001a81f.
Das medienspezifische Ereignis für [applemobilebackup.exe!ws!] wird verarbeitet.
Error: (12/23/2013 08:09:42 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT)
Description: Produkt: Google Earth -- Fehler 1406.Wert konnte nicht unter den Schlüssel \Software\Classes\Google Earth.kmzfile\shell\Open\command geschrieben werden. Systemfehler . Überprüfen Sie, ob Sie ausreichende Zugriffsrechte auf diesen Schlüssel besitzen, oder setzen Sie sich mit Ihrem Supportpersonal in Verbindung.
Error: (10/20/2013 08:14:05 AM) (Source: MsiInstaller) (User: NT-AUTORITÄT)
Description: Product: Google Update Helper -- Error 1704. An installation for Kaspersky Internet Security is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?
Error: (07/20/2013 07:56:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 31203
Error: (07/20/2013 07:56:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 31203
Error: (07/20/2013 07:56:58 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (01/25/2014 00:48:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%2147942405
Error: (01/25/2014 09:55:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/25/2014 09:55:03 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management & Security Application User Notification Service" ist vom Dienst "Intel(R) Management and Security Application Local Management Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%2
Error: (01/25/2014 09:55:03 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/25/2014 09:55:03 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/23/2014 09:06:24 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/23/2014 09:03:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management & Security Application User Notification Service" ist vom Dienst "Intel(R) Management and Security Application Local Management Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%2
Error: (01/23/2014 09:03:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/23/2014 09:03:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (01/23/2014 05:20:37 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (01/29/2013 09:41:59 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 11154 seconds with 3660 seconds of active time. This session ended with a crash.
Error: (04/06/2011 07:49:29 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 190 seconds with 0 seconds of active time. This session ended with a crash.
Error: (03/31/2011 10:53:40 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6281 seconds with 4140 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 2928.35 MB
Available physical RAM: 1626.54 MB
Total Pagefile: 4808.27 MB
Available Pagefile: 3397.34 MB
Total Virtual: 2047.88 MB
Available Virtual: 1978.43 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:298.09 GB) (Free:8.1 GB) NTFS ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 298 GB) (Disk ID: DD451EAB)
Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
GMER 2.1.19355 - hxxp://www.gmer.net
Rootkit scan 2014-01-25 14:07:54
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB3O 298,09GB
Running: gmer.exe; Driver: C:\DOKUME~1\JM\LOKALE~1\Temp\kxtdypow.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwAdjustPrivilegesToken [0x94DC2A16]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwConnectPort [0x94D72EC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateProcess [0x94DC46D6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateProcessEx [0x94DC49BE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateSection [0x94DC5A74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateThread [0x94DC4FB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDebugActiveProcess [0x94DC4576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDeleteKey [0x94D707EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDeleteValueKey [0x94D71FD6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDeviceIoControlFile [0x94D633BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDuplicateObject [0x94DC2B58]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwEnumerateKey [0x94D717E2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwEnumerateValueKey [0x94D72176]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwLoadDriver [0x94DC2684]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwLoadKey [0x94D71326]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwLoadKey2 [0x94D7157E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwMapViewOfSection [0x94DC582C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenProcess [0x94DC40B2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenSection [0x94DC5CA4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenThread [0x94DC4CAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueryKey [0x94D70622]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueryMultipleValueKey [0x94D71DE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueryValueKey [0x94D71BD8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueueApcThread [0x94DC56E0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwRenameKey [0x94D70902]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwReplaceKey [0x94D70F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwRequestWaitReplyPort [0x94D730CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwRestoreKey [0x94D7117A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwResumeThread [0x94DC53FC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSaveKey [0x94D70AA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSaveKeyEx [0x94D70C3C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSaveMergedKeys [0x94D70DD8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSecureConnectPort [0x94D72FC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetContextThread [0x94DC5562]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetInformationToken [0x94D637D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetSystemInformation [0x94DC29BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetValueKey [0x94D719A2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSuspendProcess [0x94DC42BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSuspendThread [0x94DC529E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSystemDebugControl [0x94D637E6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwTerminateProcess [0x94DC441C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwTerminateThread [0x94DC4EAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwUnmapViewOfSection [0x94DC5DAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwWriteVirtualMemory [0x94DC5B36]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2D48 805045E4 12 Bytes [84, 26, DC, 94, 26, 13, D7, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2EFC 80504798 20 Bytes [FC, 53, DC, 94, A6, 0A, D7, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2FB8 80504854 12 Bytes [BA, 42, DC, 94, 9E, 52, DC, ...]
.text C:\WINDOWS\system32\drivers\tos_sps32.sys section is writeable [0xB96F4480, 0x3C939, 0xE8000020]
.dsrt C:\WINDOWS\system32\drivers\tos_sps32.sys unknown last section [0xB9735900, 0x3CA, 0x48000040]
---- User code sections - GMER 2.1 ----
.text C:\Programme\Mozilla Firefox\firefox.exe[2512] ntdll.dll!LdrLoadDll 7C9263C3 5 Bytes JMP 01604470 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2512] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 0185047C C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2512] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 01850459 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2512] kernel32.dll!ValidateLocale + B130 7C844958 7 Bytes JMP 0160F972 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2512] GDI32.dll!SetDIBitsToDevice + 20A 77EF9E14 7 Bytes JMP 018503DA C:\Programme\Mozilla Firefox\xul.dll
---- Devices - GMER 2.1 ----
Device Ntfs.sys
Device Udfs.SYS
AttachedDevice \Driver\Tcpip \Device\Ip kltdi.sys
AttachedDevice \Driver\Tcpip \Device\Tcp kltdi.sys
AttachedDevice \Driver\Tcpip \Device\Udp kltdi.sys
AttachedDevice \Driver\Tcpip \Device\RawIp kltdi.sys
Device mrxsmb.sys
Device InCDFs.sys
---- EOF - GMER 2.1 ---- --- --- --- |