Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   FakeAlert!fakealert-REP in C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe (https://www.trojaner-board.de/102526-fakealert-fakealert-rep-c-windows-downloaded-program-files-fp_ax_cab_installer-exe.html)

Pich103 14.08.2011 15:49

FakeAlert!fakealert-REP in C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
 
Hallo liebes Trojaner-Board Team!

Ich habe heute einen Scan Mit McAfee Stinger gemacht mit fogendem Ergebnis:
Code:

McAfee(r) Labs Stinger(tm) Version 10.2.0.115 built on Jun 16 2011
Copyright (c) 2011 McAfee, Inc. All Rights Reserved.
Virus data file v1000.0000 created on Jun 16 2011.
Ready to scan for 2487 viruses, trojans and variants.

Scan initiated on Sun Aug 14 13:31:46 2011
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
    Found the FakeAlert!fakealert-REP trojan !!!
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe is infected with the FakeAlert!fakealert-REP virus !!!
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe has been deleted.
  Number of clean files: 421386
  Number of infected files: 1
  Number of files cleaned: 1

Außerdem braucht mein PC nach dem hochfahren seit ein Paar Tagen etwas länger als zuvor (ich tippe auf Rootkit).

Nun zu meinen Schutzprogrammen:

-McAfee Virus Scan Enterprise 8.7i (hab ich von einem Freund, der eine IT-Firma besitzt)
-Threat Fire
-Spybot Search&Destroy(Lässt sich nicht mehr im Administratormodus starten)
-Bit Defender Free Edition v10 (zum Wöchentlichen Test)

McAfee, Spybot und Bit Defender finden nichts, Threat Fire habe ich noch nicht probiert. Ich wollte jetzt mal die G-Data Boot CD probieren, aber ich dachte ich melde mich vorher noch bei euch.
Bitte sagt mir wenn ihr noch Logs von Malwarebytes usw. braucht...

Mit freundlichen Grüßen
Pich103
:dankeschoen:

cosinus 16.08.2011 11:55

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!


Danach OTL-Custom:


CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Pich103 16.08.2011 19:42

Hallo!
Sorry für die späte Antwort, war heute bei Bekannten. Malwarebytes findet nichts, hier der Log:

Code:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Datenbank Version: 7480

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

16.08.2011 20:20:31
mbam-log-2011-08-16 (20-20-31).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 289200
Laufzeit: 1 Stunde(n), 5 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Werde gleich noch den OTL.exe Scan machen und wenn möglich heute bzw. morgen hochladen.

Es könnte auch sein, dass mein System schon sauber ist, aber ich will am Besten auf Nummer sicher gehen.:heilig:

Bis dann,

Pich 103

Pich103 17.08.2011 07:59

Guten Morgen!

Konnte gestern den Scan nicht mehr machen, mein Bruder musste noch Kinokarten ausdrucken.

Hier die Logs, ich hoffe du kannst damit was anfangen:

OTL.Txt:
Code:

OTL logfile created on: 17.08.2011 08:27:50 - Run 1
OTL by OldTimer - Version 3.2.26.4    Folder = C:\Users\Familie Pichler\Desktop
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,83 Gb Available Physical Memory | 61,18% Memory free
6,00 Gb Paging File | 4,57 Gb Available in Paging File | 76,18% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596,07 Gb Total Space | 520,59 Gb Free Space | 87,34% Space Free | Partition Type: NTFS
 
Computer Name: PICHLER | User Name: Familie Pichler | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.08.16 19:10:55 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Familie Pichler\Desktop\OTL.exe
PRC - [2011.07.16 06:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.07.14 19:28:02 | 000,278,528 | ---- | M] (SOFTWIN S.R.L.) -- C:\Programme\Common Files\Softwin\BitDefender Update Service\livesrv.exe
PRC - [2011.07.14 19:27:57 | 000,466,944 | ---- | M] (SOFTWIN S.R.L.) -- C:\Programme\Softwin\BitDefender10\vsserv.exe
PRC - [2011.07.06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010.01.14 17:08:16 | 000,378,128 | ---- | M] (PC Tools) -- C:\Programme\ThreatFire\TFTray.exe
PRC - [2010.01.14 17:08:12 | 000,070,928 | ---- | M] (PC Tools) -- C:\Programme\ThreatFire\TFService.exe
PRC - [2009.10.26 10:20:02 | 001,499,136 | ---- | M] (Nokia) -- C:\Programme\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2009.10.21 10:24:00 | 000,272,384 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\nokiaaserver.exe
PRC - [2009.09.17 10:33:26 | 000,651,776 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.09.17 10:31:18 | 000,132,096 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.09.17 10:31:06 | 000,120,832 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.09.29 08:07:00 | 000,143,088 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2008.09.29 08:07:00 | 000,124,240 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008.09.29 08:07:00 | 000,067,904 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2008.09.29 08:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2008.09.29 08:07:00 | 000,026,672 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\mfeann.exe
PRC - [2008.09.29 08:07:00 | 000,019,456 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\EngineServer.exe
PRC - [2008.03.14 04:00:00 | 000,226,624 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008.03.14 04:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\Common Framework\FrameworkService.exe
PRC - [2006.12.20 17:33:08 | 000,081,920 | ---- | M] () -- C:\Programme\Common Files\Softwin\BitDefender Scan Server\bdss.exe
PRC - [2006.11.09 13:33:04 | 000,086,016 | ---- | M] (SOFTWIN S.R.L) -- C:\Programme\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.03.15 07:13:46 | 004,254,560 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.03.15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2009.10.21 10:24:00 | 000,272,384 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\nokiaaserver.exe
MOD - [2009.08.31 11:33:34 | 000,016,384 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\qtsecurestorage.dll
MOD - [2009.08.31 11:33:32 | 000,014,336 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\cryptodll.dll
MOD - [2009.08.31 11:33:32 | 000,013,824 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\qtsecurestorageserver.dll
MOD - [2009.08.31 11:11:16 | 000,025,088 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\wrtserviceipcserver.dll
MOD - [2009.08.24 11:29:52 | 002,013,184 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\QtCore4.dll
MOD - [2009.06.20 11:21:30 | 007,464,448 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\QtGui4.dll
MOD - [2009.06.20 11:10:32 | 000,875,520 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\QtNetwork4.dll
MOD - [2009.06.20 11:09:26 | 000,337,408 | ---- | M] () -- C:\Programme\Common Files\Nokia\NoA\QtXml4.dll
MOD - [2006.05.15 18:02:16 | 000,058,368 | ---- | M] () -- C:\Programme\Softwin\BitDefender10\bdshelxt.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.07.14 19:28:02 | 000,278,528 | ---- | M] (SOFTWIN S.R.L.) [Auto | Running] -- C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe -- (LIVESRV)
SRV - [2011.07.14 19:27:57 | 000,466,944 | ---- | M] (SOFTWIN S.R.L.) [Auto | Running] -- C:\Program Files\Softwin\BitDefender10\vsserv.exe -- (VSSERV)
SRV - [2011.07.06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010.07.31 20:30:56 | 000,057,008 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] -- C:\Program Files\F-Secure\ORSP Client\fsorsp.exe -- (FSORSPClient)
SRV - [2010.06.26 12:08:52 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.03.25 10:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.01.14 17:08:12 | 000,070,928 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\ThreatFire\TFService.exe -- (ThreatFire)
SRV - [2009.09.17 10:33:26 | 000,651,776 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2009.07.14 03:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2009.07.14 03:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2008.09.29 08:07:00 | 000,143,088 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield)
SRV - [2008.09.29 08:07:00 | 000,067,904 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2008.09.29 08:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager)
SRV - [2008.09.29 08:07:00 | 000,019,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Programme\McAfee\VirusScan Enterprise\EngineServer.exe -- (McAfeeEngineService)
SRV - [2008.03.14 04:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2006.12.20 17:33:08 | 000,081,920 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe -- (bdss)
SRV - [2006.11.09 13:33:04 | 000,086,016 | ---- | M] (SOFTWIN S.R.L) [Auto | Running] -- C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- (XCOMM)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.07.06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.02.23 16:50:44 | 000,016,184 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010.11.19 11:23:10 | 000,914,816 | ---- | M] (DiBcom SA) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mod7700.sys -- (mod7700)
DRV - [2010.04.03 22:55:32 | 011,573,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010.01.14 17:08:30 | 000,059,664 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - [2010.01.14 17:08:28 | 000,051,984 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2010.01.14 17:08:28 | 000,033,552 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2009.11.12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009.07.14 00:02:53 | 000,657,408 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr28u.sys -- (netr28u)
DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009.02.09 08:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 08:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 08:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 08:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.11.11 13:42:00 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008.11.11 13:41:00 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008.11.11 13:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008.09.29 08:07:00 | 000,340,592 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008.09.29 08:07:00 | 000,090,360 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008.09.29 08:07:00 | 000,074,648 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008.09.29 08:07:00 | 000,064,432 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2008.09.29 08:07:00 | 000,062,704 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008.09.29 08:07:00 | 000,042,424 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007.02.08 15:45:14 | 000,029,184 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dsiarhwprog.sys -- (dsiarhwprog)
DRV - [2006.12.04 16:51:44 | 000,008,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Programme\Softwin\BitDefender10\bdfdll.sys -- (bdfdll)
DRV - [2005.03.03 19:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.02.23 17:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 FE 6D 94 8D 14 CB 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "foxsearch"
FF - prefs.js..browser.search.order.1: "foxsearch"
FF - prefs.js..browser.search.selectedEngine: "foxsearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.51
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
 
FF - user.js..browser.search.selectedEngine: "foxsearch"
FF - user.js..browser.search.order.1: "foxsearch"
FF - user.js..browser.search.defaultenginename: "foxsearch"
FF - user.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2010.12.18 11:23:47 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Familie Pichler\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Familie Pichler\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files\F-Secure\NRS\litmus-ff@f-secure.com [2010.07.31 20:31:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.05.26 18:55:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.08.10 17:24:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.31 11:59:58 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.05.26 18:55:40 | 000,000,000 | ---D | M]
 
[2010.09.13 19:36:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Extensions
[2010.07.17 13:57:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2011.05.21 12:50:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Firefox\Profiles\vk3estud.default\extensions
[2011.05.11 14:22:01 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Firefox\Profiles\vk3estud.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.12.07 19:45:03 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Firefox\Profiles\vk3estud.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.05.20 15:01:04 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Users\Familie Pichler\AppData\Roaming\mozilla\Firefox\Profiles\vk3estud.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011.05.11 14:25:49 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\FAMILIE PICHLER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VK3ESTUD.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\FAMILIE PICHLER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VK3ESTUD.DEFAULT\EXTENSIONS\CLICKCLEAN@HOTCLEANER.COM.XPI
[2011.04.14 18:40:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008.09.29 08:07:00 | 000,022,576 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2010.03.19 09:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Program Files\mozilla firefox\plugins\npmieze.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.09.13 19:41:35 | 000,000,143 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\foxsearch.src
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.02.19 14:39:27 | 000,000,735 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Programme\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Programme\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Programme\ThreatFire\TFTray.exe (PC Tools)
O4 - HKCU..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 153
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Familie Pichler\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)
MsConfig - StartUpFolder: C:^Users^Familie Pichler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -  - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: BCSSync - hkey= - key= - C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
MsConfig - StartUpReg: BDAgent - hkey= - key= - C:\Program Files\Softwin\BitDefender10\bdagent.exe (SOFTWIN S.R.L.)
MsConfig - StartUpReg: BDMCon - hkey= - key= - C:\Program Files\Softwin\BitDefender10\bdmcon.exe (SOFTWIN S.R.L.)
MsConfig - StartUpReg: dvd43 - hkey= - key= -  File not found
MsConfig - StartUpReg: GrooveMonitor - hkey= - key= -  File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: PrintDisp - hkey= - key= -  File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: VirtualCloneDrive - hkey= - key= - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: McAfeeEngineService - C:\Programme\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: vsmon - Service
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.08.16 19:12:32 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\AppData\Roaming\Malwarebytes
[2011.08.16 19:12:20 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.08.16 19:12:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.08.16 19:12:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.08.16 19:12:07 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.08.16 19:12:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.08.16 19:10:55 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Familie Pichler\Desktop\OTL.exe
[2011.08.14 13:29:14 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\Pavark
[2011.08.14 12:37:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2011.08.14 12:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2011.08.14 11:56:36 | 000,000,000 | ---D | C] -- C:\Windows\MiniDump
[2011.08.13 15:09:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011.08.13 15:09:59 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
[2011.08.12 12:49:03 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\AppData\Local\SKIDROW
[2011.08.10 17:24:26 | 000,340,592 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys
[2011.08.10 17:24:26 | 000,090,360 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys
[2011.08.10 17:24:26 | 000,074,648 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys
[2011.08.10 17:24:26 | 000,067,904 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
[2011.08.10 17:24:26 | 000,064,432 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys
[2011.08.10 17:24:26 | 000,062,704 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfetdik.sys
[2011.08.10 17:24:26 | 000,042,424 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys
[2011.08.10 17:24:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011.08.10 17:23:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2011.07.31 11:24:40 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\Mali Losinj 2.0
[2011.07.20 13:33:57 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.08.17 08:31:05 | 000,081,984 | ---- | M] () -- C:\Windows\System32\bdod.bin
[2011.08.17 08:13:09 | 000,009,920 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.17 08:13:09 | 000,009,920 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.17 08:06:01 | 000,001,160 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000UA.job
[2011.08.17 08:05:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.17 08:05:19 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2011.08.16 19:10:55 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Familie Pichler\Desktop\OTL.exe
[2011.08.15 14:52:13 | 000,726,476 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.08.15 14:52:13 | 000,676,122 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.15 14:52:13 | 000,155,048 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.08.15 14:52:13 | 000,126,636 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.08.13 19:49:31 | 000,001,132 | ---- | M] () -- C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2011.08.12 13:42:59 | 000,001,223 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\LIMBO.lnk
[2011.08.10 17:06:58 | 000,002,450 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Google Chrome.lnk
[2011.08.08 11:06:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000Core.job
[2011.07.31 12:16:07 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.07.31 11:59:59 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.07.22 10:42:58 | 007,964,786 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Alexandra Stan - Mr Saxobeat.mp3
[2011.07.22 10:41:26 | 007,371,527 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Cascada - San Francisco.mp3
[2011.07.22 10:40:26 | 008,032,161 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\David Guetta - Little Bad Girl (Feat. Taio Cruz & Ludacris).mp3
[2011.07.22 10:39:10 | 007,372,119 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Inna - Sun is Up.mp3
[2011.07.22 10:38:26 | 007,984,375 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\DJ Antoine vs. Timati feat. Kalenna - Welcome To St. Tropez.mp3
[2011.07.22 10:25:28 | 007,332,383 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Jedward - Bad Behaviour.mp3
[2011.07.20 13:57:58 | 000,003,117 | ---- | M] () -- C:\Users\Familie Pichler\Desktop\Microsoft ICE.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.08.15 14:50:32 | 011,750,500 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\The Black Eyed Peas - Don't Stop the Party (Yanis.S Remix).mp3
[2011.08.13 19:49:32 | 000,029,008 | ---- | C] () -- C:\Windows\System32\SmartDefragBootTime.exe
[2011.08.13 19:49:31 | 000,016,184 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys
[2011.08.12 13:42:59 | 000,001,223 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\LIMBO.lnk
[2011.07.22 15:05:44 | 007,371,527 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\Cascada - San Francisco.mp3
[2011.07.22 15:05:43 | 007,964,786 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\Alexandra Stan - Mr Saxobeat.mp3
[2011.07.22 15:05:43 | 007,332,383 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\Jedward - Bad Behaviour.mp3
[2011.07.22 15:05:42 | 007,372,119 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\Inna - Sun is Up.mp3
[2011.07.22 15:05:41 | 008,032,161 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\David Guetta - Little Bad Girl (Feat. Taio Cruz & Ludacris).mp3
[2011.07.22 15:05:41 | 007,984,375 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\DJ Antoine vs. Timati feat. Kalenna - Welcome To St. Tropez.mp3
[2011.07.20 13:57:58 | 000,003,117 | ---- | C] () -- C:\Users\Familie Pichler\Desktop\Microsoft ICE.lnk
[2011.05.31 18:53:39 | 000,000,620 | ---- | C] () -- C:\Windows\eReg.dat
[2011.05.21 12:21:58 | 000,081,984 | ---- | C] () -- C:\Windows\System32\bdod.bin
[2011.05.20 14:52:54 | 000,000,036 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Local\housecall.guid.cache
[2011.04.15 15:18:19 | 000,022,328 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Roaming\PnkBstrK.sys
[2011.04.15 15:18:04 | 000,107,832 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.04.15 15:17:56 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.04.12 16:53:36 | 000,000,810 | ---- | C] () -- C:\Windows\Rtcw.INI
[2011.03.26 21:07:11 | 000,000,001 | ---- | C] () -- C:\Windows\System32\SI.bin
[2011.03.20 14:47:15 | 000,000,173 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Local\msmathematics.qat.Familie Pichler
[2011.01.22 21:02:48 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2011.01.22 20:48:30 | 000,226,480 | ---- | C] () -- C:\Windows\hpoins18.dat
[2011.01.22 20:48:30 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2010.11.02 12:25:31 | 000,524,288 | ---- | C] () -- C:\Windows\System32\PrtPass.exe
[2010.11.02 12:25:30 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2010.10.02 15:50:41 | 000,000,080 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.10.02 13:05:40 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.09.10 16:19:13 | 000,000,600 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Local\PUTTY.RND
[2010.09.10 15:27:21 | 000,007,606 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Local\Resmon.ResmonCfg
[2010.09.10 09:38:44 | 000,000,600 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Roaming\winscp.rnd
[2010.08.03 14:31:43 | 000,000,911 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Roaming\burnaware.ini
[2010.08.02 13:29:42 | 000,000,008 | -HS- | C] () -- C:\Users\Familie Pichler\AppData\Local\systemCurUses
[2010.08.02 13:29:41 | 000,000,006 | -HS- | C] () -- C:\Users\Familie Pichler\AppData\Local\systemHdID
[2010.07.21 19:05:18 | 000,005,120 | ---- | C] () -- C:\Users\Familie Pichler\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.16 18:51:48 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009.08.03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.08.03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009.07.14 10:47:43 | 000,726,476 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,155,048 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,407,240 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,676,122 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,126,636 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2007.01.31 14:50:32 | 000,913,408 | ---- | C] () -- C:\Windows\System32\xreglib.dll
[2006.07.20 22:07:50 | 000,053,248 | ---- | C] () -- C:\Windows\System32\PhysXLoader.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2006.07.10 18:54:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
 
========== LOP Check ==========
 
[2010.12.30 19:05:06 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\aicon
[2011.01.29 13:55:12 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\AntiBrowserSpy 2009
[2011.01.19 21:07:20 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Audacity
[2011.05.21 12:22:50 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Bitdefender
[2010.07.23 16:48:27 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Bump Technologies, Inc
[2010.07.16 18:52:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Canneverbe Limited
[2011.07.01 16:01:33 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Canon
[2010.12.07 19:45:02 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.12.07 19:52:41 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Free Audio Editor
[2010.09.08 11:36:29 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\FreeFixer
[2010.09.16 15:17:26 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\FreeFLVConverter
[2010.09.11 14:09:43 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Get from YouTube
[2010.09.13 19:42:46 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\GrabPro
[2010.06.26 13:35:53 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Groove Games
[2011.02.05 21:11:56 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\gsmartcontrol
[2011.07.09 19:51:33 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\gtk-2.0
[2010.10.09 13:39:38 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Gutscheinmieze
[2011.05.21 19:36:42 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\IObit
[2011.06.11 11:25:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Mp3tag
[2011.06.25 13:23:49 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Nokia
[2010.12.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Notepad++
[2010.09.14 16:23:20 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Orbit
[2011.06.25 13:23:45 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\PC Suite
[2010.09.13 19:48:09 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\ProgSense
[2011.08.13 18:10:18 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\QuickScan
[2010.10.09 10:42:56 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\QuickStoresToolbar
[2010.07.13 13:18:27 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\SharePod
[2011.07.08 13:18:12 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\TeamViewer
[2011.02.19 14:07:25 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\TuneUp Software
[2010.08.12 11:06:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Uniblue
[2011.01.07 11:17:44 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\WindSolutions
[2010.11.02 11:42:40 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\XMedia Recode
[2011.01.17 20:44:43 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Youtube Downloader HD
[2011.06.23 11:18:39 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.06.26 13:05:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Adobe
[2010.12.30 19:05:06 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\aicon
[2011.01.29 13:55:12 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\AntiBrowserSpy 2009
[2010.07.15 16:59:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Apple Computer
[2011.01.19 21:07:20 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Audacity
[2011.05.21 12:22:50 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Bitdefender
[2010.07.23 16:48:27 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Bump Technologies, Inc
[2010.07.16 18:52:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Canneverbe Limited
[2011.07.01 16:01:33 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Canon
[2011.07.01 15:56:27 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\CANON INC
[2010.07.23 19:06:15 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\DivX
[2010.12.07 19:45:02 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.12.07 19:52:41 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Free Audio Editor
[2010.09.08 11:36:29 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\FreeFixer
[2010.09.16 15:17:26 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\FreeFLVConverter
[2010.09.11 14:09:43 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Get from YouTube
[2010.09.13 19:42:46 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\GrabPro
[2010.06.26 13:35:53 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Groove Games
[2011.02.05 21:11:56 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\gsmartcontrol
[2011.07.09 19:51:33 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\gtk-2.0
[2010.10.09 13:39:38 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Gutscheinmieze
[2010.08.24 18:12:25 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\HP
[2011.01.23 15:54:01 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\HpUpdate
[2010.06.25 19:14:48 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Identities
[2011.05.21 19:36:42 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\IObit
[2010.06.26 13:05:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Macromedia
[2011.08.16 19:12:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Media Center Programs
[2010.11.15 22:11:31 | 000,000,000 | --SD | M] -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft
[2010.06.26 11:47:16 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Mozilla
[2011.06.11 11:25:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Mp3tag
[2011.06.25 13:23:49 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Nokia
[2010.12.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Notepad++
[2011.02.03 20:26:49 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\NVIDIA
[2010.09.14 16:23:20 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Orbit
[2011.06.25 13:23:45 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\PC Suite
[2010.09.13 19:48:09 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\ProgSense
[2011.08.13 18:10:18 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\QuickScan
[2010.10.09 10:42:56 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\QuickStoresToolbar
[2010.07.13 13:18:27 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\SharePod
[2011.08.03 15:48:00 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Skype
[2011.02.16 22:18:38 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\skypePM
[2011.07.08 13:18:12 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\TeamViewer
[2011.02.19 14:07:25 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\TuneUp Software
[2010.08.12 11:06:28 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Uniblue
[2011.06.26 17:50:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\vlc
[2011.01.07 11:17:44 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\WindSolutions
[2010.07.08 15:09:59 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\WinRAR
[2010.11.02 11:42:40 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\XMedia Recode
[2011.01.17 20:44:43 | 000,000,000 | ---D | M] -- C:\Users\Familie Pichler\AppData\Roaming\Youtube Downloader HD
 
< %APPDATA%\*.exe /s >
[2010.06.10 14:19:22 | 000,825,856 | ---- | M] (Synatix GmbH) -- C:\Users\Familie Pichler\AppData\Roaming\Gutscheinmieze\uninstall.exe
[2011.07.20 13:33:57 | 000,043,385 | R--- | M] () -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Installer\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}\_112D608FD02CD87FDC7735.exe
[2011.07.20 13:33:57 | 000,043,385 | R--- | M] () -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Installer\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}\_1A508631B9BA7A5663EE5C.exe
[2011.07.20 13:33:57 | 000,032,579 | R--- | M] () -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Installer\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}\_853F67D554F05449430E7E.exe
[2011.05.19 18:49:30 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2010.03.10 15:13:58 | 000,045,304 | ---- | M] (Andreas Breitschopp - Softwareentwicklung und -vertrieb) -- C:\Users\Familie Pichler\AppData\Roaming\QuickStoresToolbar\Update.exe
[2010.08.12 11:03:58 | 005,276,088 | ---- | M] (Uniblue Systems Ltd                                        ) -- C:\Users\Familie Pichler\AppData\Roaming\Uniblue\SpeedUpMyPC\_temp\ub.exe
[2011.04.02 09:50:24 | 003,461,672 | ---- | M] (WindSolutions) -- C:\Users\Familie Pichler\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
[2011.05.19 18:03:54 | 007,594,104 | ---- | M] (WindSolutions) -- C:\Users\Familie Pichler\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransManager.exe
[2011.01.07 11:17:38 | 004,508,864 | ---- | M] (WindSolutions) -- C:\Users\Familie Pichler\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransTuneSwift.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll

Im nächtsen Posting gehts weiter!

Hoffe dass du was findest, und wenn nicht ist's natürlich noch besser! :lach:

Ich geh dann mal frühstcken, Bis bald! :kaffee:

Pich103 17.08.2011 08:01

Teil 2 (OTL.Txt):
Code:

< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 08:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 07:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:E8BE05FA

< End of report >

und dann noch Extras.Txt:

Code:

OTL Extras logfile created on: 17.08.2011 08:27:50 - Run 1
OTL by OldTimer - Version 3.2.26.4    Folder = C:\Users\Familie Pichler\Desktop
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,83 Gb Available Physical Memory | 61,18% Memory free
6,00 Gb Paging File | 4,57 Gb Available in Paging File | 76,18% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596,07 Gb Total Space | 520,59 Gb Free Space | 87,34% Space Free | Partition Type: NTFS
 
Computer Name: PICHLER | User Name: Familie Pichler | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [explore] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{1597D0AE-34A7-4A8B-A395-2E30EB745470}" = Nokia Connectivity Cable Driver
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}" = c3100_Help
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 20
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{354038F6-0A35-4C55-A80B-F86C4C1A6D38}" = C3100
"{35A81F0A-A1CA-458D-8FCD-7D838E3D95FF}" = Microsoft WorldWide Telescope
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}" = Microsoft Image Composite Editor
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{702563CE-516C-40CF-B69C-A4E2A8FC8F14}" = OviMPlatform
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 2.9.7
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D6B740F-D9A2-45A6-BDC4-0A453D499FE6}" = PC Connectivity Solution
"{A638557B-1F13-40A0-9627-C892FBCA6960}" = McAfee Agent
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.5 - Deutsch
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF595D08-64AC-428B-8FB8-EEC70CCB8803}" = Ovi Desktop Sync Engine
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7D38898-283C-4720-BF42-4ABC90375904}" = System Requirements Lab CYRI
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BDF62CC9-FE60-4F9D-8194-8EB7E6E1412D}" = BitDefender Free Edition v10
"{C38D079C-950D-4F18-BF7B-CE58DE86D3BD}" = Image Resizer Powertoy Clone for Windows
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C5089197-5B15-44AD-B0FC-2E94EE9ECB63}" = WinSysClean X
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D6E0EB79-CB6B-4540-9FC1-3D215CE25AD4}" = Nokia Ovi Suite
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"1489-3350-5074-6281" = JDownloader 0.9
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AGEIA PhysX v2.5.0" = AGEIA PhysX v2.5.0
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow Launcher
"Canon MOV Decoder" = Canon MOV Decoder
"CCleaner" = CCleaner
"Desperados - Ein Wild West Abenteuer 1.01" = Desperados - Ein Wild West Abenteuer 1.01
"Free Audio Dub_is1" = Free Audio Dub version 1.7.8.426
"GimpLqRPlugIn" = GIMP LqR Plug-In
"GML Matting_is1" = GML Matting 0.3
"GrowCut3_is1" = GrowCut 3.0.1
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.1.1800
"MapUtility" = Canon Utilities Map Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 4.0.1 (x86 de)" = Mozilla Firefox 4.0.1 (x86 de)
"Mp3tag" = Mp3tag v2.48
"MyCamera" = Canon Utilities MyCamera
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"Nokia Ovi Suite" = Nokia Ovi Suite
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PhotoStitch" = Canon Utilities PhotoStitch
"Return to Castle Wolfenstein" = Return to Castle Wolfenstein
"Shop for HP Supplies" = Shop for HP Supplies
"Smart Defrag 2_is1" = Smart Defrag 2
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.20
"Uninstall_is1" = Uninstall 1.0.0.1
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.7
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"WinSysClean X" = WinSysClean X
"XMedia Recode" = XMedia Recode 2.3.1.3
"Youtube Downloader HD_is1" = Youtube Downloader HD v. 2.2.2
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CopyTrans Suite" = Nur Deinstallierung der CopyTrans Suite möglich.
"GeoGebra WebStart" = GeoGebra WebStart
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 28.03.2011 05:58:18 | Computer Name = Pichler | Source = Windows Backup | ID = 4103
Description =
 
Error - 13.04.2011 13:38:14 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WolfSP.exe, Version: 0.0.0.0, Zeitstempel:
 0x3cd036dd  Name des fehlerhaften Moduls: cgamex86.dll, Version: 0.0.0.0, Zeitstempel:
 0x3cd0369e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000369b  ID des fehlerhaften Prozesses:
 0xaf4  Startzeit der fehlerhaften Anwendung: 0x01cbfa0188492f40  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Return to Castle Wolfenstein\WolfSP.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Return to Castle Wolfenstein\cgamex86.dll  Berichtskennung:
 ced64790-65f4-11e0-ae20-40618601b217
 
Error - 13.04.2011 13:39:07 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WolfSP.exe, Version: 0.0.0.0, Zeitstempel:
 0x3cd036dd  Name des fehlerhaften Moduls: cgamex86.dll, Version: 0.0.0.0, Zeitstempel:
 0x3cd0369e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000369b  ID des fehlerhaften Prozesses:
 0x1070  Startzeit der fehlerhaften Anwendung: 0x01cbfa01a2fef400  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Return to Castle Wolfenstein\WolfSP.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Return to Castle Wolfenstein\cgamex86.dll  Berichtskennung:
 edfe3380-65f4-11e0-ae20-40618601b217
 
Error - 13.04.2011 13:41:00 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WolfSP.exe, Version: 0.0.0.0, Zeitstempel:
 0x3cd036dd  Name des fehlerhaften Moduls: cgamex86.dll, Version: 0.0.0.0, Zeitstempel:
 0x3cd0369e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000369b  ID des fehlerhaften Prozesses:
 0x924  Startzeit der fehlerhaften Anwendung: 0x01cbfa01e9db5580  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Return to Castle Wolfenstein\WolfSP.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Return to Castle Wolfenstein\cgamex86.dll  Berichtskennung:
 315e9570-65f5-11e0-ae20-40618601b217
 
Error - 13.04.2011 13:51:28 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WolfSP.exe, Version: 0.0.0.0, Zeitstempel:
 0x3cd036dd  Name des fehlerhaften Moduls: qagamex86.dll, Version: 0.0.0.0, Zeitstempel:
 0x3cd036b1  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0001fa29  ID des fehlerhaften Prozesses:
 0xbc0  Startzeit der fehlerhaften Anwendung: 0x01cbfa021d4b3610  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Return to Castle Wolfenstein\WolfSP.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Return to Castle Wolfenstein\qagamex86.dll  Berichtskennung:
 a82b67e0-65f6-11e0-ae20-40618601b217
 
Error - 13.04.2011 13:53:51 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WolfSP.exe, Version: 0.0.0.0, Zeitstempel:
 0x3cd036dd  Name des fehlerhaften Moduls: cgamex86.dll, Version: 0.0.0.0, Zeitstempel:
 0x3cd0369e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000369b  ID des fehlerhaften Prozesses:
 0xbe4  Startzeit der fehlerhaften Anwendung: 0x01cbfa03b2ffce90  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Return to Castle Wolfenstein\WolfSP.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Return to Castle Wolfenstein\cgamex86.dll  Berichtskennung:
 fcfd45e0-65f6-11e0-ae20-40618601b217
 
Error - 14.04.2011 15:28:09 | Computer Name = Pichler | Source = Windows Search Service | ID = 3007
Description =
 
Error - 15.04.2011 09:12:36 | Computer Name = Pichler | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: TFService.exe, Version: 4.10.1.14,
 Zeitstempel: 0x4b4fa1c8  Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.4927,
 Zeitstempel: 0x4a2752ff  Ausnahmecode: 0xc000000d  Fehleroffset: 0x00014ba1  ID des fehlerhaften
 Prozesses: 0x184  Startzeit der fehlerhaften Anwendung: 0x01cbfb6e8192a1e0  Pfad der
 fehlerhaften Anwendung: C:\Program Files\ThreatFire\TFService.exe  Pfad des fehlerhaften
 Moduls: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5\MSVCR80.dll
Berichtskennung:
 078d3ee0-6762-11e0-bdee-40618601b217
 
Error - 15.04.2011 09:13:24 | Computer Name = Pichler | Source = VSS | ID = 8194
Description =
 
Error - 19.04.2011 07:23:07 | Computer Name = Pichler | Source = McLogEvent | ID = 259
Description = Der Scan hat Entdeckungen gefunden. Scan-Modul der Version 5400.1158
 DAT-Version 6320.
 
[ System Events ]
Error - 16.08.2011 14:49:01 | Computer Name = Pichler | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
 
Error - 16.08.2011 14:49:18 | Computer Name = Pichler | Source = ipnathlp | ID = 34001
Description =
 
Error - 17.08.2011 02:05:13 | Computer Name = Pichler | Source = Application Popup | ID = 875
Description = Treiber sfdrv01.sys konnte nicht geladen werden.
 
Error - 17.08.2011 02:06:08 | Computer Name = Pichler | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  sfdrv01
 
Error - 17.08.2011 02:06:08 | Computer Name = Pichler | Source = Application Popup | ID = 875
Description = Treiber bdfdll.sys konnte nicht geladen werden.
 
Error - 17.08.2011 02:06:08 | Computer Name = Pichler | Source = Service Control Manager | ID = 7000
Description = Der Dienst "bdfdll" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%1275
 
Error - 17.08.2011 02:06:09 | Computer Name = Pichler | Source = Service Control Manager | ID = 7000
Description = Der Dienst "BDFsDrv" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 17.08.2011 02:06:09 | Computer Name = Pichler | Source = Service Control Manager | ID = 7000
Description = Der Dienst "BDRsDrv" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 17.08.2011 02:32:44 | Computer Name = Pichler | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
 
Error - 17.08.2011 02:32:49 | Computer Name = Pichler | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
 
 
< End of report >


cosinus 17.08.2011 10:29

Führe auch bitte ESET aus, danach sehen wir weiter.


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

n.

Pich103 17.08.2011 12:10

Liste der Anhänge anzeigen (Anzahl: 2)
Hallo!
Ich habe mit ESET Online Scanner so meine Probleme. Wenn ich die Stelle erreiche, wo er die Datenbank updatet, kommt eine Fehlermeldung:
"Can not get update. Is Proxy Fixed?"

Habe es jetzt schon mit IE9, Firefox und Chrome versucht, immer das selbe. :confused:

Hast du eine Idee, was das Problem sein könnte?

MFG Pich103

PS: Ich hänge noch 2 Screenshots von den Fenstern an, eines vor der Meldung und eins mit.

cosinus 17.08.2011 13:51

Prüfen => http://www.trojaner-board.de/94344-p...n-pruefen.html

Pich103 17.08.2011 14:31

Liste der Anhänge anzeigen (Anzahl: 2)
Hab ich, aber bei den Proxy Einstellungen Stimmt alles. Und das Internet funktioniert ja überall anders auch.

cosinus 17.08.2011 15:04

Du hast den Browser für ESET per Rechtsklick als Admin ausgeführt?

Pich103 17.08.2011 16:05

Ja hab ich auch gemacht. Keine Ahnung warum es nicht Funktioniert...:confused:
Und auf meinem Laptop mit Win7 64Bit Funktioniert's auch.... (hab auf dem Stand PC Win7 32 Bit)

cosinus 17.08.2011 21:07

Hast du beide Browser probiert oder nur einen?

Pich103 18.08.2011 08:23

:singsing:Habe es jetzt nochmal probiert mit IE und siehe da... es FUNKTIONIERT!
Werde nachher das Ergebnis posten.

Pich103 18.08.2011 11:36

Oh... 7 Funde!

Code:

ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
esets_scanner_update returned -1 esets_gle=12
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=acb141828105b54f92a5e878477b0864
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-08-18 10:17:26
# local_time=2011-08-18 12:17:26 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=512 16777215 100 0 7826633 7826633 0 0
# compatibility_mode=768 16777215 100 0 35061278 35061278 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 68583 66092745 0 0
# compatibility_mode=8192 67108863 100 0 72186 72186 0 0
# scanned=144272
# found=7
# cleaned=0
# scan_time=8644
C:\Users\Familie Pichler\AppData\Roaming\Uniblue\SpeedUpMyPC\_temp\ub.exe        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Familie Pichler\Downloads\cdbxp_setup_4.3.8.2568.exe        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I
F:\PICHLER\Backup Set 2011-02-03 181353\Backup Files 2011-02-03 181353\Backup files 2.zip        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I
F:\PICHLER\Backup Set 2011-02-03 181353\Backup Files 2011-02-03 181353\Backup files 4.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 6.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 7.zip        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 8.zip        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I

Die Infektionen sehen meiner Meinung nach aber sehr verdächtig im Bezug auf Fehlalarm aus...

Hatte mal SpeedUpMyPC installiert, und da könnten noch Reste vorhanden sein.
Und einen Virus im CD Burner XP Setup kann ich mir auch nicht vorstellen, der ist von Chip.de

Es sind nur eigentlich 2 Viren: Win32/SpeedUpMyPC und Win32/OpenCandy.

Warum in meinen Backupfiles auf der externen Platte auch welche angezeigt werden ist mir unklar.:confused:

cosinus 18.08.2011 12:01

Das sind "halbe" Fehlalarme, die Setups und Backupsets sind eigentlich sauber, aber können Adware-Bestandteile enthalten. Lass von Uniblue die Finger, das ist allerfeinstes Schlangenöl!

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
[2011.08.12 12:49:03 | 000,000,000 | ---D | C] -- C:\Users\Familie Pichler\AppData\Local\SKIDROW
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:E8BE05FA
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Pich103 18.08.2011 16:42

So, habe den Fix gemacht, hier das Ergebnis:

Code:

========== OTL ==========
C:\Users\Familie Pichler\AppData\Local\SKIDROW\620\Storage folder moved successfully.
C:\Users\Familie Pichler\AppData\Local\SKIDROW\620 folder moved successfully.
C:\Users\Familie Pichler\AppData\Local\SKIDROW\48000\Storage folder moved successfully.
C:\Users\Familie Pichler\AppData\Local\SKIDROW\48000 folder moved successfully.
C:\Users\Familie Pichler\AppData\Local\SKIDROW folder moved successfully.
Unable to delete ADS C:\ProgramData\TEMP:E8BE05FA .
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.26.4 log created on 08182011_173516

Ich glaube es hat funktioniert! :applaus:

cosinus 19.08.2011 13:55

Ich brauch den Quarantäneordner von OTL. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen!
2.) Ordner MovedFiles in C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html
4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Pich103 19.08.2011 14:43

Hallo Arne!

Wollte die Datei Moved Files.zip hochladen doch dann kam diese Meldung:

Datei: Moved Files.zip empfangen

Fehler: Die Dateien konnten nicht empfangen werden.Bitte melden sie sich im Forum.

Sind sie nun hochgeladen oder nicht?:glaskugel:

cosinus 19.08.2011 17:07

Nein die Datei fehlt. Warum weiß ich nicht.
Lad sie hier hoch und verlink es => File-Upload.net - Ihr kostenloser File Hoster!

Pich103 20.08.2011 10:34

Ok, jetzt hat es Funktioniert.

Hier der Link:
Code:

hxxp://www.file-upload.net/download-3675978/Moved-Files.zip.html
Hab gegooglet, und SKIDROW ist anscheinend irgendwas illegales, doch ich hab nie was illegales oder gar gecractes installiert. :aufsmaul:

Die xx in hxxp:// kommen automatisch. Das musst du in der Adresszeile noch in tt ändern.

cosinus 21.08.2011 13:05

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://www.trojaner-board.de/attachm...rnen-start.png


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Pich103 22.08.2011 11:22

Hier der Log von TDSSKiller (er hat nichts Gefunden! :wtf:):

Code:

2011/08/22 12:18:36.0385 5316        TCPIP6          (c2daaeb48f3a47c410b041a0d2382ee1) C:\Windows\system32\DRIVERS\tcpip.sys
2011/08/22 12:18:36.0416 5316        tcpipreg        (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/08/22 12:18:36.0432 5316        TDPIPE          (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/08/22 12:18:36.0448 5316        TDTCP          (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/08/22 12:18:36.0479 5316        tdx            (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/08/22 12:18:36.0494 5316        TermDD          (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/08/22 12:18:36.0572 5316        TfFsMon        (95746e5b1473432f3d9458940dba6e3a) C:\Windows\system32\drivers\TfFsMon.sys
2011/08/22 12:18:36.0604 5316        TfNetMon        (02ffdd873e31c5c2d57ca87d11ec36af) C:\Windows\system32\drivers\TfNetMon.sys
2011/08/22 12:18:36.0650 5316        TfSysMon        (f8bd92251ab439383c051ce907d78cce) C:\Windows\system32\drivers\TfSysMon.sys
2011/08/22 12:18:36.0697 5316        tssecsrv        (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/08/22 12:18:36.0728 5316        tunnel          (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/08/22 12:18:36.0744 5316        uagp35          (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/08/22 12:18:36.0760 5316        udfs            (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/08/22 12:18:36.0806 5316        uliagpkx        (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/08/22 12:18:36.0822 5316        umbus          (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/08/22 12:18:36.0853 5316        UmPass          (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/08/22 12:18:36.0916 5316        upperdev        (587e643a4e2ffd9a00f114b057ceb773) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
2011/08/22 12:18:36.0947 5316        USBAAPL        (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys
2011/08/22 12:18:36.0978 5316        usbbus          (9419faac6552a51542dbba02971c841c) C:\Windows\system32\DRIVERS\lgusbbus.sys
2011/08/22 12:18:37.0009 5316        usbccgp        (c31ae588e403042632dc796cf09e30b0) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/08/22 12:18:37.0025 5316        usbcir          (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/08/22 12:18:37.0072 5316        UsbDiag        (c0a466fa4ffec464320e159bc1bbdc0c) C:\Windows\system32\DRIVERS\lgusbdiag.sys
2011/08/22 12:18:37.0150 5316        usbehci        (e4c436d914768ce965d5e659ba7eebd8) C:\Windows\system32\DRIVERS\usbehci.sys
2011/08/22 12:18:37.0228 5316        usbhub          (bdcd7156ec37448f08633fd899823620) C:\Windows\system32\DRIVERS\usbhub.sys
2011/08/22 12:18:37.0274 5316        USBModem        (f74a54774a9b0afeb3c40adec68aa600) C:\Windows\system32\DRIVERS\lgusbmodem.sys
2011/08/22 12:18:37.0306 5316        usbohci        (eb2d819a639015253c871cda09d91d58) C:\Windows\system32\DRIVERS\usbohci.sys
2011/08/22 12:18:37.0321 5316        usbprint        (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/08/22 12:18:37.0352 5316        usbscan        (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/08/22 12:18:37.0415 5316        usbser          (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys
2011/08/22 12:18:37.0446 5316        UsbserFilt      (fca6a196d47cb972a0e4adc0db9cd17c) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
2011/08/22 12:18:37.0477 5316        USBSTOR        (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/08/22 12:18:37.0508 5316        usbuhci        (22480bf4e5a09192e5e30ba4dde79fa4) C:\Windows\system32\drivers\usbuhci.sys
2011/08/22 12:18:37.0571 5316        VClone          (fce98c43b5c5db8e0da8ea0e2b45e044) C:\Windows\system32\DRIVERS\VClone.sys
2011/08/22 12:18:37.0602 5316        vdrvroot        (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/08/22 12:18:37.0618 5316        vga            (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/08/22 12:18:37.0649 5316        VgaSave        (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/08/22 12:18:37.0664 5316        vhdmp          (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/08/22 12:18:37.0696 5316        viaagp          (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/08/22 12:18:37.0711 5316        ViaC7          (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/08/22 12:18:37.0727 5316        viaide          (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/08/22 12:18:37.0758 5316        volmgr          (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/08/22 12:18:37.0774 5316        volmgrx        (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/08/22 12:18:37.0805 5316        volsnap        (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/08/22 12:18:37.0836 5316        vsmraid        (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/08/22 12:18:37.0867 5316        vwifibus        (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
2011/08/22 12:18:37.0898 5316        vwififlt        (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
2011/08/22 12:18:37.0930 5316        WacomPen        (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/08/22 12:18:37.0961 5316        WANARP          (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/22 12:18:37.0976 5316        Wanarpv6        (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/22 12:18:38.0023 5316        Wd              (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/08/22 12:18:38.0039 5316        Wdf01000        (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/08/22 12:18:38.0117 5316        WfpLwf          (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/08/22 12:18:38.0132 5316        WIMMount        (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/08/22 12:18:38.0226 5316        WinUsb          (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/08/22 12:18:38.0257 5316        WmiAcpi        (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/08/22 12:18:38.0288 5316        ws2ifsl        (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/08/22 12:18:38.0335 5316        WudfPf          (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/08/22 12:18:38.0366 5316        WUDFRd          (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/08/22 12:18:38.0429 5316        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/08/22 12:18:38.0444 5316        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
2011/08/22 12:18:38.0460 5316        Boot (0x1200)  (7e0afe512f23aa30d13268fa04207a1b) \Device\Harddisk0\DR0\Partition0
2011/08/22 12:18:38.0476 5316        Boot (0x1200)  (11b5d2ba8f5353bfb40d147e96db90d1) \Device\Harddisk0\DR0\Partition1
2011/08/22 12:18:38.0491 5316        Boot (0x1200)  (e470bdd5a55b593c63000d43186e2161) \Device\Harddisk1\DR1\Partition0
2011/08/22 12:18:38.0491 5316        ================================================================================
2011/08/22 12:18:38.0491 5316        Scan finished
2011/08/22 12:18:38.0491 5316        ================================================================================
2011/08/22 12:18:38.0507 4676        Detected object count: 0
2011/08/22 12:18:38.0507 4676        Actual detected object count: 0

Ich glaube ich bin wieder sauber, was meinst du? :huepp:

cosinus 22.08.2011 12:03

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Pich103 23.08.2011 13:27

So, nach der Haarsträubenden Aktion mit ComboFix :killpc: hab ich endlich die Log-Datei:daumenhoc:

Code:

ComboFix 11-08-23.01 - Familie Pichler 23.08.2011  13:59:09.1.4 - x86
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.43.1031.18.3071.2251 [GMT 2:00]
ausgeführt von:: c:\users\Familie Pichler\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Familie Pichler\AppData\Roaming\aicon
c:\users\Familie Pichler\AppData\Roaming\aicon\aicon.ini
c:\users\Wallpaper\10.jpg
c:\users\Wallpaper\11.jpg
c:\windows\system32\Cache
c:\windows\system32\logs
F:\autorun.inf
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-07-23 bis 2011-08-23  ))))))))))))))))))))))))))))))
.
.
2011-08-23 12:12 . 2011-08-23 12:13        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\temp
2011-08-23 12:12 . 2011-08-23 12:12        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-08-23 10:08 . 2011-08-12 02:44        7152464        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F85841D-093A-4691-825D-3336F5016214}\mpengine.dll
2011-08-22 10:26 . 2009-06-30 08:37        28552        ----a-w-        c:\windows\system32\drivers\pavboot.sys
2011-08-22 10:26 . 2011-08-22 10:26        --------        d-----w-        c:\program files\Panda Security
2011-08-20 14:26 . 2011-08-20 14:26        --------        d-----w-        c:\program files\Alex Feinman
2011-08-19 13:59 . 2011-08-19 13:59        --------        d-----w-        c:\users\Familie Pichler\AppData\Roaming\bizarre creations
2011-08-19 13:58 . 2008-10-15 04:22        452440        ----a-w-        c:\windows\system32\d3dx10_40.dll
2011-08-19 13:58 . 2008-10-15 04:22        2036576        ----a-w-        c:\windows\system32\D3DCompiler_40.dll
2011-08-19 13:58 . 2008-10-15 04:22        4379984        ----a-w-        c:\windows\system32\D3DX9_40.dll
2011-08-19 13:47 . 2011-08-19 13:47        --------        d-----w-        c:\program files\Activision
2011-08-18 16:03 . 2011-08-18 16:03        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\SKIDROW
2011-08-18 15:43 . 2011-08-18 15:43        --------        d-----w-        c:\program files\Sandboxie
2011-08-18 15:35 . 2011-08-18 15:35        --------        d-----w-        C:\_OTL
2011-08-18 10:55 . 2011-08-18 15:34        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\Spoon
2011-08-18 10:55 . 2011-08-18 10:55        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\Xenocode
2011-08-17 10:50 . 2011-08-17 10:50        --------        d-----w-        c:\program files\ESET
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\users\Familie Pichler\AppData\Roaming\Malwarebytes
2011-08-16 17:12 . 2011-07-06 17:52        41272        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\programdata\Malwarebytes
2011-08-16 17:12 . 2011-07-06 17:52        22712        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-08-14 11:29 . 2011-08-14 11:29        --------        d-----w-        c:\users\Familie Pichler\Pavark
2011-08-14 10:37 . 2011-08-14 10:37        --------        d-----w-        c:\program files\Sophos
2011-08-13 17:49 . 2011-02-23 14:50        29008        ----a-w-        c:\windows\system32\SmartDefragBootTime.exe
2011-08-13 17:49 . 2011-02-23 14:50        16184        ----a-w-        c:\windows\system32\drivers\SmartDefragDriver.sys
2011-08-13 13:09 . 2011-08-13 13:09        --------        d-----w-        c:\program files\Elaborate Bytes
2011-08-10 15:24 . 2008-09-29 06:07        22576        ----a-w-        c:\program files\Mozilla Firefox\components\Scriptff.dll
2011-08-10 15:24 . 2008-09-29 06:07        90360        ----a-w-        c:\windows\system32\drivers\mfeavfk.sys
2011-08-10 15:24 . 2008-09-29 06:07        74648        ----a-w-        c:\windows\system32\drivers\mfeapfk.sys
2011-08-10 15:24 . 2008-09-29 06:07        67904        ----a-w-        c:\windows\system32\mfevtps.exe
2011-08-10 15:24 . 2008-09-29 06:07        64432        ----a-w-        c:\windows\system32\drivers\mferkdet.sys
2011-08-10 15:24 . 2008-09-29 06:07        62704        ----a-w-        c:\windows\system32\drivers\mfetdik.sys
2011-08-10 15:24 . 2008-09-29 06:07        42424        ----a-w-        c:\windows\system32\drivers\mfebopk.sys
2011-08-10 15:24 . 2008-09-29 06:07        340592        ----a-w-        c:\windows\system32\drivers\mfehidk.sys
2011-08-10 15:23 . 2011-08-10 15:23        --------        d-----w-        c:\program files\Common Files\McAfee
2011-07-31 09:24 . 2011-07-31 16:37        --------        d-----w-        c:\users\Familie Pichler\Mali Losinj 2.0
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-11 02:37 . 2011-07-14 17:28        2332672        ----a-w-        c:\windows\system32\win32k.sys
2011-04-14 16:40 . 2011-05-11 12:25        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
2008-09-29 06:07 . 2011-08-10 15:24        22576        ----a-w-        c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-01 401728]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-06-17 412432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2010-01-14 378128]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Familie Pichler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk]
path=c:\users\Familie Pichler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
backup=c:\windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59        937920        ----a-r-        c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02        37296        ----a-w-        c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54        91520        ----a-w-        c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
2007-03-26 13:49        69632        ----a-w-        c:\program files\Softwin\BitDefender10\bdagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
2007-04-02 14:48        290816        ----a-w-        c:\program files\Softwin\BitDefender10\bdmcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 14:08        421160        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38        421888        ----a-w-        c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2011-03-07 13:33        89456        ----a-w-        c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"Google Update"="c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"PDFPrint"=c:\program files\PDF24\pdf24.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 dsiarhwprog;dsiarhwprog;c:\windows\system32\Drivers\dsiarhwprog.sys [2007-02-08 29184]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure\ORSP Client\fsorsp.exe [2010-07-31 57008]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\6DA2.tmp [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2008-09-29 64432]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-26 1343400]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-01-14 51984]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-01-14 59664]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [2008-09-29 19456]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2008-09-29 67904]
S2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 netr28u;RT2870-USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-01-14 33552]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - PAVBOOT
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
iissvcs        REG_MULTI_SZ          w3svc was
apphost        REG_MULTI_SZ          apphostsvc
HPService        REG_MULTI_SZ          HPSLPSVC
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2011-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000Core.job
- c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 17:41]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000UA.job
- c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 17:41]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.at/
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Free YouTube to MP3 Converter - c:\users\Familie Pichler\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Familie Pichler\AppData\Roaming\Mozilla\Firefox\Profiles\vk3estud.default\
FF - prefs.js: browser.search.selectedEngine - foxsearch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
FF - prefs.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.search.selectedEngine - foxsearch
FF - user.js: browser.search.order.1 - foxsearch
FF - user.js: browser.search.defaultenginename - foxsearch
FF - user.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - user.js: privacy.item.cookies - false
FF - user.js: privacy.sanitize.promptOnSanitize - false
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-dvd43 - c:\program files\dvd43\dvd43_tray.exe
MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
MSConfigStartUp-PrintDisp - c:\windows\system32\PrintDisp.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\6DA2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}"=hex:51,66,7a,6c,4c,1d,38,12,fa,ba,fe,
  14,ca,09,99,06,d1,80,b1,aa,66,b7,bd,1b
"{265EEE8E-3228-44D3-AEA5-F7FDF5860049}"=hex:51,66,7a,6c,4c,1d,38,12,e0,ed,4d,
  22,1a,7c,bd,01,d1,b3,b4,bd,f0,d8,44,5d
"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,
  07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
  1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
  76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,
  79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
  94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
  b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{C6867EB7-8350-4856-877F-93CF8AE3DC9C}"=hex:51,66,7a,6c,4c,1d,38,12,d9,7d,95,
  c2,62,cd,38,0d,f8,69,d0,8f,8f,bd,98,88
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
  df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,
  fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
  2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,
  51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:00,56,ab,27,45,5f,cc,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(608)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'lsass.exe'(568)
c:\program files\ThreatFire\TFWAH.dll
.
Zeit der Fertigstellung: 2011-08-23  14:20:23
ComboFix-quarantined-files.txt  2011-08-23 12:20
.
Vor Suchlauf: 17 Verzeichnis(se), 541.222.436.864 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 540.902.621.184 Bytes frei
.
- - End Of File - - EF782FC276ACE4A9CCC3C53BA0BFD6E4

LG
Pich103

Ach ja und ich habe gestern noch einen Scan mit PANDA Active Scan 2.0 gemacht, der sagt: IHR PC IST ZURZEIT NICHT INFIZIERT.

cosinus 23.08.2011 14:27

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.


Code:

Folder::
c:\users\Familie Pichler\AppData\Local\SKIDROW

File::
c:\windows\system32\Drivers\dsiarhwprog.sys

Driver::
dsiarhwprog

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Pich103 24.08.2011 14:48

Also den Schritt begreif ich nicht. Wenn ich die CFScript.txt auf ComboFix.exe ziehe, installiert er ja wieder das Programm.:wtf: Ist das so richtig? Denn auch in dem blauen Feld steht dann ja auch nix anderes...:uglyhammer:

cosinus 24.08.2011 15:01

CF wird nicht installiert! CF wird erneut gestartet und nimmt als weitere Option das Script in der CFscript.txt!

Pich103 26.08.2011 10:29

Oh, danke.:stirn: Werde es jetzt nochmal probieren, und außerdem hab ich in den nächsten Tagen wieder mehr Zeit für den PC.

Pich103 26.08.2011 11:42

Der ComboFix Log:

Code:

ComboFix 11-08-25.05 - Familie Pichler 26.08.2011  12:15:04.2.4 - x86
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.43.1031.18.3071.1778 [GMT 2:00]
ausgeführt von:: c:\users\Familie Pichler\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Familie Pichler\Desktop\CFScript.txt.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
FILE ::
"c:\windows\system32\Drivers\dsiarhwprog.sys"
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Familie Pichler\AppData\Local\SKIDROW
c:\users\Familie Pichler\AppData\Local\SKIDROW\48000\Storage\savegame.txt
c:\windows\system32\Drivers\dsiarhwprog.sys
.
.
(((((((((((((((((((((((((((((((((((((((  Treiber/Dienste  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_dsiarhwprog
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-07-26 bis 2011-08-26  ))))))))))))))))))))))))))))))
.
.
2011-08-26 10:29 . 2011-08-26 10:33        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\temp
2011-08-26 10:29 . 2011-08-26 10:29        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-08-24 13:38 . 2011-07-09 04:30        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-08-23 10:08 . 2011-08-12 02:44        7152464        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F85841D-093A-4691-825D-3336F5016214}\mpengine.dll
2011-08-22 10:26 . 2009-06-30 08:37        28552        ----a-w-        c:\windows\system32\drivers\pavboot.sys
2011-08-22 10:26 . 2011-08-22 10:26        --------        d-----w-        c:\program files\Panda Security
2011-08-20 14:26 . 2011-08-20 14:26        --------        d-----w-        c:\program files\Alex Feinman
2011-08-19 13:59 . 2011-08-19 13:59        --------        d-----w-        c:\users\Familie Pichler\AppData\Roaming\bizarre creations
2011-08-19 13:58 . 2008-10-15 04:22        452440        ----a-w-        c:\windows\system32\d3dx10_40.dll
2011-08-19 13:58 . 2008-10-15 04:22        2036576        ----a-w-        c:\windows\system32\D3DCompiler_40.dll
2011-08-19 13:58 . 2008-10-15 04:22        4379984        ----a-w-        c:\windows\system32\D3DX9_40.dll
2011-08-19 13:47 . 2011-08-19 13:47        --------        d-----w-        c:\program files\Activision
2011-08-18 15:43 . 2011-08-18 15:43        --------        d-----w-        c:\program files\Sandboxie
2011-08-18 15:35 . 2011-08-18 15:35        --------        d-----w-        C:\_OTL
2011-08-18 10:55 . 2011-08-18 15:34        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\Spoon
2011-08-18 10:55 . 2011-08-18 10:55        --------        d-----w-        c:\users\Familie Pichler\AppData\Local\Xenocode
2011-08-17 10:50 . 2011-08-17 10:50        --------        d-----w-        c:\program files\ESET
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\users\Familie Pichler\AppData\Roaming\Malwarebytes
2011-08-16 17:12 . 2011-07-06 17:52        41272        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\programdata\Malwarebytes
2011-08-16 17:12 . 2011-07-06 17:52        22712        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-08-16 17:12 . 2011-08-16 17:12        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-08-14 11:29 . 2011-08-14 11:29        --------        d-----w-        c:\users\Familie Pichler\Pavark
2011-08-14 10:37 . 2011-08-14 10:37        --------        d-----w-        c:\program files\Sophos
2011-08-13 17:49 . 2011-02-23 14:50        29008        ----a-w-        c:\windows\system32\SmartDefragBootTime.exe
2011-08-13 17:49 . 2011-02-23 14:50        16184        ----a-w-        c:\windows\system32\drivers\SmartDefragDriver.sys
2011-08-13 13:09 . 2011-08-13 13:09        --------        d-----w-        c:\program files\Elaborate Bytes
2011-08-10 15:24 . 2008-09-29 06:07        22576        ----a-w-        c:\program files\Mozilla Firefox\components\Scriptff.dll
2011-08-10 15:24 . 2008-09-29 06:07        90360        ----a-w-        c:\windows\system32\drivers\mfeavfk.sys
2011-08-10 15:24 . 2008-09-29 06:07        74648        ----a-w-        c:\windows\system32\drivers\mfeapfk.sys
2011-08-10 15:24 . 2008-09-29 06:07        67904        ----a-w-        c:\windows\system32\mfevtps.exe
2011-08-10 15:24 . 2008-09-29 06:07        64432        ----a-w-        c:\windows\system32\drivers\mferkdet.sys
2011-08-10 15:24 . 2008-09-29 06:07        62704        ----a-w-        c:\windows\system32\drivers\mfetdik.sys
2011-08-10 15:24 . 2008-09-29 06:07        42424        ----a-w-        c:\windows\system32\drivers\mfebopk.sys
2011-08-10 15:24 . 2008-09-29 06:07        340592        ----a-w-        c:\windows\system32\drivers\mfehidk.sys
2011-08-10 15:23 . 2011-08-10 15:23        --------        d-----w-        c:\program files\Common Files\McAfee
2011-07-31 09:24 . 2011-07-31 16:37        --------        d-----w-        c:\users\Familie Pichler\Mali Losinj 2.0
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-11 02:37 . 2011-07-14 17:28        2332672        ----a-w-        c:\windows\system32\win32k.sys
2011-04-14 16:40 . 2011-05-11 12:25        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
2008-09-29 06:07 . 2011-08-10 15:24        22576        ----a-w-        c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-01 401728]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-06-17 412432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2010-01-14 378128]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Familie Pichler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk]
path=c:\users\Familie Pichler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
backup=c:\windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59        937920        ----a-r-        c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02        37296        ----a-w-        c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54        91520        ----a-w-        c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
2007-03-26 13:49        69632        ----a-w-        c:\program files\Softwin\BitDefender10\bdagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
2007-04-02 14:48        290816        ----a-w-        c:\program files\Softwin\BitDefender10\bdmcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 14:08        421160        ----a-w-        c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38        421888        ----a-w-        c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2011-03-07 13:33        89456        ----a-w-        c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"Google Update"="c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"PDFPrint"=c:\program files\PDF24\pdf24.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure\ORSP Client\fsorsp.exe [2010-07-31 57008]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\6DA2.tmp [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2008-09-29 64432]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-26 1343400]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-01-14 51984]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-01-14 59664]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [2008-09-29 19456]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2008-09-29 67904]
S2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 netr28u;RT2870-USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-01-14 33552]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
iissvcs        REG_MULTI_SZ          w3svc was
apphost        REG_MULTI_SZ          apphostsvc
HPService        REG_MULTI_SZ          HPSLPSVC
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2011-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000Core.job
- c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 17:41]
.
2011-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000UA.job
- c:\users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 17:41]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.at/
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Free YouTube to MP3 Converter - c:\users\Familie Pichler\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Familie Pichler\AppData\Roaming\Mozilla\Firefox\Profiles\vk3estud.default\
FF - prefs.js: browser.search.selectedEngine - foxsearch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
FF - prefs.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.search.selectedEngine - foxsearch
FF - user.js: browser.search.order.1 - foxsearch
FF - user.js: browser.search.defaultenginename - foxsearch
FF - user.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - user.js: privacy.item.cookies - false
FF - user.js: privacy.sanitize.promptOnSanitize - false
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\6DA2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}"=hex:51,66,7a,6c,4c,1d,38,12,fa,ba,fe,
  14,ca,09,99,06,d1,80,b1,aa,66,b7,bd,1b
"{265EEE8E-3228-44D3-AEA5-F7FDF5860049}"=hex:51,66,7a,6c,4c,1d,38,12,e0,ed,4d,
  22,1a,7c,bd,01,d1,b3,b4,bd,f0,d8,44,5d
"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,
  07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
  1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
  76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,
  79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
  94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
  b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{C6867EB7-8350-4856-877F-93CF8AE3DC9C}"=hex:51,66,7a,6c,4c,1d,38,12,d9,7d,95,
  c2,62,cd,38,0d,f8,69,d0,8f,8f,bd,98,88
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
  df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,
  fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
  2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,
  51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:00,56,ab,27,45,5f,cc,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(640)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'lsass.exe'(572)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'Explorer.exe'(1432)
c:\program files\ThreatFire\TfWah.dll
c:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll
c:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\msi.dll
c:\windows\system32\MPR.dll
c:\windows\system32\WINSPOOL.DRV
c:\windows\system32\taskschd.dll
c:\windows\system32\FXSAPI.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\program files\ThreatFire\TFService.exe
c:\program files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
c:\program files\Softwin\BitDefender10\vsserv.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-08-26  12:40:42 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-08-26 10:40
ComboFix2.txt  2011-08-23 12:20
.
Vor Suchlauf: 21 Verzeichnis(se), 540.283.449.344 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 539.913.818.112 Bytes frei
.
- - End Of File - - 9299C5AFC7CB4E99907C01362BE5DC7D


cosinus 26.08.2011 12:38

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!


Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


Pich103 27.08.2011 14:13

GMER ist während des Scans abgestürzt, werde jetzt noch OSAM probieren.

Pich103 28.08.2011 09:46

OSAM Log:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 10:46:05 on 28.08.2011

OS: Windows 7 Home Premium Edition (Build 7600), 32-bit
Default Browser: Google Inc. Google Chrome 0.0.0.0

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000Core.job" - "Google Inc." - C:\Users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-3068468112-1341261719-3374128048-1000UA.job" - "Google Inc." - C:\Users\Familie Pichler\AppData\Local\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"PhysX.cpl" - ? - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"bdfdll" (bdfdll) - ? - C:\Program Files\Softwin\BitDefender10\bdfdll.sys  (File found, but it contains no detailed information)
"BDFsDrv" (BDFsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys  (File not found)
"BDRsDrv" (BDRsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys  (File not found)
"catchme" (catchme) - ? - C:\Users\FAMILI~1\AppData\Local\Temp\catchme.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"McAfee Inc. mfeapfk" (mfeapfk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfeapfk.sys
"McAfee Inc. mfeavfk" (mfeavfk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfeavfk.sys
"McAfee Inc. mfebopk" (mfebopk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfebopk.sys
"McAfee Inc. mfehidk" (mfehidk) - "McAfee, Inc." - C:\Windows\System32\drivers\mfehidk.sys
"McAfee Inc. mferkdet" (mferkdet) - "McAfee, Inc." - C:\Windows\System32\drivers\mferkdet.sys
"McAfee Inc. mfetdik" (mfetdik) - "McAfee, Inc." - C:\Windows\System32\drivers\mfetdik.sys
"MEMSWEEP2" (MEMSWEEP2) - ? - C:\Windows\system32\6DA2.tmp  (File not found)
"pavboot" (pavboot) - "Panda Security, S.L." - C:\Windows\System32\drivers\pavboot.sys
"SbieDrv" (SbieDrv) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieDrv.sys
"SmartDefragDriver" (SmartDefragDriver) - ? - C:\Windows\System32\Drivers\SmartDefragDriver.sys  (File found, but it contains no detailed information)
"StarForce Protection Environment Driver (version 1.x)" (sfdrv01) - "Protection Technology" - C:\Windows\System32\drivers\sfdrv01.sys
"StarForce Protection Helper Driver (version 2.x)" (sfhlp02) - "Protection Technology" - C:\Windows\System32\drivers\sfhlp02.sys
"StarOpen" (StarOpen) - ? - C:\Windows\system32\drivers\StarOpen.sys  (File found, but it contains no detailed information)
"TfFsMon" (TfFsMon) - "PC Tools" - C:\Windows\System32\drivers\TfFsMon.sys
"TfNetMon" (TfNetMon) - "PC Tools" - C:\Windows\system32\drivers\TfNetMon.sys
"TfSysMon" (TfSysMon) - "PC Tools" - C:\Windows\System32\drivers\TfSysMon.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{34F4B935-17DC-4885-8BC9-CCD1ADF42F93} "CISORecorderContextMenu Object" - "Alex Feinman" - C:\Program Files\Alex Feinman\ISO Recorder\ISORecorder.dll
{4CF20B46-D006-4B90-A64B-DBAA9470EFBE} "ContextMenuHandler Class" - "Brice Lambson" - C:\Program Files\Image Resizer\ImageResizer.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{1AC77AE9-9EC6-405A-9F9B-C06AB3C10B71} "Microsoft Image Composite Editor" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLSHEXT.DLL
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}" - ? -  (File not found | COM-object registry key not found)
<binary data> "{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{9191F686-7F0A-441D-8A98-2FE3AC1BD913} "ActiveScan 2.0 Installer Class" - "Panda Security" - C:\Windows\Downloaded Program Files\as2stubie.dll / hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10l.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - ? -  (File not found | COM-object registry key not found)
{DDE87865-83C5-48c4-8357-2F5B1AA84522} "HP Smart Web Printing ein- oder ausblenden" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{265EEE8E-3228-44D3-AEA5-F7FDF5860049} "Browsing Protection Toolbar" - "F-Secure Corporation" - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} "{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{C6867EB7-8350-4856-877F-93CF8AE3DC9C} "Browsing Protection Class" - "F-Secure Corporation" - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{0347C33E-8762-4905-BF09-768834316C61} "HP Print Enhancer" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} "HP Smart BHO Class" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} "scriptproxy" - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Familie Pichler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"NokiaOviSuite2" - "Nokia" - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
"SandboxieControl" - "SANDBOXIE L.T.D" - "C:\Program Files\Sandboxie\SbieCtrl.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"ShStatEXE" - "McAfee, Inc." - "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
"ThreatFire" - "PC Tools" - C:\Program Files\ThreatFire\TFTray.exe

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"BitDefender Communicator" (XCOMM) - "SOFTWIN S.R.L" - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
"BitDefender Desktop Update Service" (LIVESRV) - "SOFTWIN S.R.L." - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
"BitDefender Scan Server" (bdss) - ? - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe  (File found, but it contains no detailed information)
"BitDefender Virus Shield" (VSSERV) - "SOFTWIN S.R.L." - C:\Program Files\Softwin\BitDefender10\vsserv.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"F-Secure ORSP Client" (FSORSPClient) - "F-Secure Corporation" - C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"HP Network Devices Support" (HPSLPSVC) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"McAfee Engine Service" (McAfeeEngineService) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
"McAfee Framework-Dienst" (McAfeeFramework) - "McAfee, Inc." - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
"McAfee McShield" (McShield) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
"McAfee Task Manager" (McTaskManager) - "McAfee, Inc." - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
"McAfee Validation Trust Protection Service" (mfevtp) - "McAfee, Inc." - C:\Windows\system32\mfevtps.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Sandboxie Service" (SbieSvc) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieSvc.exe
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
"ThreatFire" (ThreatFire) - "PC Tools" - C:\Program Files\ThreatFire\TFService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 28.08.2011 14:25

Ok, und was ist mit aswMBR?

Pich103 28.08.2011 16:18

Ist abgestürzt, danach für ca. 2 sec Bluescreen und reboot. :balla:

cosinus 28.08.2011 16:21

Hm, das ist selten bei aswMBR :(

Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

Pich103 30.08.2011 10:41

Habe heute den ganzen Tag frei, und ich werd mich mehr dem Forum widmen.
Sorry dass ich in den letzten Tagen so nachlässig war.:heulen:

Ich werde gleich mal MBRCheck durchlaufen lassen und dann nochmal das mit Avast!.

Pich103 30.08.2011 10:44

Das ging ja schnell, hier der Log:

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows 7 Home Premium Edition
Windows Information:                (build 7600), 32-bit
Base Board Manufacturer:        MEDIONPC
BIOS Manufacturer:                American Megatrends Inc.
System Manufacturer:                MEDIONPC
System Product Name:                MS-7366
Logical Drives Mask:                0x000001fc

Kernel Drivers (total 196):
  0x82E15000 \SystemRoot\system32\ntkrnlpa.exe
  0x83225000 \SystemRoot\system32\halmacpi.dll
  0x80BA0000 \SystemRoot\system32\kdcom.dll
  0x8381A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x83892000 \SystemRoot\system32\PSHED.dll
  0x838A3000 \SystemRoot\system32\BOOTVID.dll
  0x838AB000 \SystemRoot\system32\CLFS.SYS
  0x838ED000 \SystemRoot\system32\CI.dll
  0x83A2C000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x83A9D000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x83AAB000 \SystemRoot\system32\DRIVERS\ACPI.sys
  0x83AF3000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
  0x83AFC000 \SystemRoot\system32\DRIVERS\msisadrv.sys
  0x83B04000 \SystemRoot\system32\DRIVERS\pci.sys
  0x83B2E000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
  0x83B39000 \SystemRoot\System32\drivers\partmgr.sys
  0x83B4A000 \SystemRoot\system32\DRIVERS\volmgr.sys
  0x83B5A000 \SystemRoot\System32\drivers\volmgrx.sys
  0x83BA5000 \SystemRoot\System32\drivers\mountmgr.sys
  0x83BBB000 \SystemRoot\system32\drivers\pavboot.sys
  0x83BC1000 \SystemRoot\system32\DRIVERS\atapi.sys
  0x83BCA000 \SystemRoot\system32\DRIVERS\ataport.SYS
  0x83BED000 \SystemRoot\system32\DRIVERS\msahci.sys
  0x83A00000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
  0x83A0E000 \SystemRoot\system32\drivers\amdxata.sys
  0x83998000 \SystemRoot\system32\drivers\fltmgr.sys
  0x83A17000 \SystemRoot\system32\drivers\fileinfo.sys
  0x839CC000 \SystemRoot\system32\drivers\TfFsMon.sys
  0x839DD000 \SystemRoot\system32\drivers\TfSysMon.sys
  0x8B220000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8B34F000 \SystemRoot\System32\Drivers\msrpc.sys
  0x8B37A000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x8B38D000 \SystemRoot\System32\Drivers\cng.sys
  0x8B3EA000 \SystemRoot\System32\drivers\pcw.sys
  0x8B200000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x8B404000 \SystemRoot\system32\drivers\ndis.sys
  0x8B4BB000 \SystemRoot\system32\drivers\NETIO.SYS
  0x8B4F9000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x8B625000 \SystemRoot\System32\drivers\tcpip.sys
  0x8B76E000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x8B79F000 \SystemRoot\system32\DRIVERS\volsnap.sys
  0x8B7DE000 \SystemRoot\System32\Drivers\spldr.sys
  0x8B7E6000 \SystemRoot\System32\Drivers\SmartDefragDriver.sys
  0x8B7ED000 \SystemRoot\System32\drivers\sfhlp02.sys
  0x8B51E000 \SystemRoot\System32\drivers\rdyboost.sys
  0x8B611000 \SystemRoot\System32\Drivers\mup.sys
  0x8B54B000 \SystemRoot\system32\drivers\mfehidk.sys
  0x8B7F5000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x8B59D000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x8B5CF000 \SystemRoot\system32\DRIVERS\disk.sys
  0x8B829000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x8B881000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x8B8A0000 \SystemRoot\System32\Drivers\Null.SYS
  0x8B8A7000 \SystemRoot\System32\Drivers\Beep.SYS
  0x8B8AE000 \SystemRoot\System32\drivers\vga.sys
  0x8B8BA000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x8B8DB000 \SystemRoot\System32\drivers\watchdog.sys
  0x8B8E8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x8B8F0000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x8B8F8000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x8B900000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x8B90B000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x8B919000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x8B930000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x8B93B000 \SystemRoot\system32\drivers\mfetdik.sys
  0x8B949000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x8B97B000 \SystemRoot\system32\drivers\afd.sys
  0x8B9D5000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x8B9DC000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x8B800000 \SystemRoot\system32\DRIVERS\vwififlt.sys
  0x8B811000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x8B5E0000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x8B600000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x90C04000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x90C45000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x90C4F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x90C59000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
  0x90C63000 \SystemRoot\System32\drivers\discache.sys
  0x90C6F000 \SystemRoot\System32\Drivers\dfsc.sys
  0x90C87000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x90C95000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x90CB6000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x90CC8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
  0x90CE0000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x90CED000 \SystemRoot\system32\DRIVERS\usbohci.sys
  0x90CF7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x90D42000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x90D51000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x9262A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
  0x93132000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
  0x93134000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x90D70000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x90DA9000 \SystemRoot\system32\DRIVERS\1394ohci.sys
  0x931EB000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
  0x9843C000 \SystemRoot\system32\DRIVERS\nvm62x32.sys
  0x98491000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
  0x9849A000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
  0x984B7000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x984C9000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x984E1000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x984EC000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x9850E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x98526000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x9853D000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x98554000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x98561000 \SystemRoot\system32\DRIVERS\VClone.sys
  0x9856D000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
  0x98593000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x98595000 \SystemRoot\system32\DRIVERS\ks.sys
  0x985C9000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x99621000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x99665000 \SystemRoot\system32\drivers\HdAudio.sys
  0x996B5000 \SystemRoot\system32\drivers\portcls.sys
  0x996E4000 \SystemRoot\system32\drivers\drmk.sys
  0x996FD000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x82950000 \SystemRoot\System32\win32k.sys
  0x9970E000 \SystemRoot\System32\drivers\Dxapi.sys
  0x99718000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x99725000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x99730000 \SystemRoot\System32\Drivers\dump_msahci.sys
  0x9973A000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x9974B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
  0x99762000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x99764000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x82BB0000 \SystemRoot\System32\TSDDD.dll
  0x9976F000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x9977A000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x9978D000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x82BE0000 \SystemRoot\System32\cdd.dll
  0x99794000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x9979F000 \SystemRoot\system32\drivers\luafv.sys
  0x997BA000 \SystemRoot\system32\drivers\WudfPf.sys
  0x997D4000 \??\C:\Program Files\Sandboxie\SbieDrv.sys
  0x9C02F000 \SystemRoot\system32\DRIVERS\netr28u.sys
  0x9C0D8000 \SystemRoot\system32\DRIVERS\vwifibus.sys
  0x9C0E2000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x9C0F2000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x9C138000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x9C148000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x9C15B000 \SystemRoot\system32\drivers\HTTP.sys
  0x9C1E0000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x9C000000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x985D7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x98400000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x9C012000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0xA1635000 \SystemRoot\system32\drivers\peauth.sys
  0xA16CC000 \SystemRoot\System32\Drivers\secdrv.SYS
  0xA16D6000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0xA16F7000 \SystemRoot\System32\drivers\tcpipreg.sys
  0xA1704000 \SystemRoot\System32\DRIVERS\srv2.sys
  0xA1753000 \SystemRoot\System32\DRIVERS\srv.sys
  0xA17A5000 \SystemRoot\System32\drivers\ipnat.sys
  0xA17CB000 \SystemRoot\system32\drivers\mfebopk.sys
  0xA17D4000 \SystemRoot\system32\drivers\mfeapfk.sys
  0xA17E5000 \SystemRoot\system32\drivers\mfeavfk.sys
  0xA1607000 \??\C:\Windows\system32\drivers\TfNetMon.sys
  0xA1621000 \??\C:\Windows\system32\drivers\mbam.sys
  0x76F80000 \Windows\System32\ntdll.dll
  0x476C0000 \Windows\System32\smss.exe
  0x771C0000 \Windows\System32\apisetschema.dll
  0x00020000 \Windows\System32\autochk.exe
  0x76DE0000 \Windows\System32\setupapi.dll
  0x77150000 \Windows\System32\difxapi.dll
  0x76D30000 \Windows\System32\rpcrt4.dll
  0x77110000 \Windows\System32\ws2_32.dll
  0x76C60000 \Windows\System32\msctf.dll
  0x770F0000 \Windows\System32\sechost.dll
  0x76BD0000 \Windows\System32\clbcatq.dll
  0x770E0000 \Windows\System32\normaliz.dll
  0x76B80000 \Windows\System32\Wldap32.dll
  0x76A20000 \Windows\System32\ole32.dll
  0x769A0000 \Windows\System32\comdlg32.dll
  0x76950000 \Windows\System32\gdi32.dll
  0x76870000 \Windows\System32\kernel32.dll
  0x76760000 \Windows\System32\urlmon.dll
  0x766B0000 \Windows\System32\msvcrt.dll
  0x76620000 \Windows\System32\oleaut32.dll
  0x765F0000 \Windows\System32\imagehlp.dll
  0x770D0000 \Windows\System32\lpk.dll
  0x76550000 \Windows\System32\advapi32.dll
  0x76390000 \Windows\System32\iertutil.dll
  0x762C0000 \Windows\System32\user32.dll
  0x76220000 \Windows\System32\usp10.dll
  0x76100000 \Windows\System32\wininet.dll
  0x760E0000 \Windows\System32\imm32.dll
  0x76080000 \Windows\System32\shlwapi.dll
  0x770C0000 \Windows\System32\nsi.dll
  0x76070000 \Windows\System32\psapi.dll
  0x75420000 \Windows\System32\shell32.dll
  0x75390000 \Windows\System32\comctl32.dll
  0x75360000 \Windows\System32\cfgmgr32.dll
  0x75330000 \Windows\System32\wintrust.dll
  0x75310000 \Windows\System32\devobj.dll
  0x751F0000 \Windows\System32\crypt32.dll
  0x751A0000 \Windows\System32\KernelBase.dll
  0x75190000 \Windows\System32\msasn1.dll

Processes (total 72):
      0 System Idle Process
      4 System
    292 C:\Windows\System32\smss.exe
    444 C:\Windows\System32\csrss.exe
    500 C:\Windows\System32\wininit.exe
    508 C:\Windows\System32\csrss.exe
    556 C:\Windows\System32\services.exe
    568 C:\Windows\System32\lsass.exe
    580 C:\Windows\System32\lsm.exe
    684 C:\Windows\System32\winlogon.exe
    716 C:\Windows\System32\svchost.exe
    788 C:\Windows\System32\svchost.exe
    888 C:\Windows\System32\svchost.exe
    924 C:\Windows\System32\svchost.exe
    968 C:\Windows\System32\svchost.exe
    1040 C:\Windows\System32\audiodg.exe
    1104 C:\Windows\System32\svchost.exe
    1152 C:\Program Files\Sandboxie\SbieSvc.exe
    1280 C:\Windows\System32\svchost.exe
    1472 C:\Windows\System32\spoolsv.exe
    1500 C:\Windows\System32\svchost.exe
    1588 C:\Windows\System32\svchost.exe
    1628 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1732 C:\Program Files\Bonjour\mDNSResponder.exe
    1780 C:\Windows\System32\svchost.exe
    1804 C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
    1824 C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    1936 C:\Windows\System32\dwm.exe
    1964 C:\Windows\explorer.exe
    2040 C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    332 C:\Windows\System32\mfevtps.exe
    624 C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
    440 C:\Windows\System32\svchost.exe
    1524 C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
    2068 C:\Windows\System32\svchost.exe
    2104 C:\Windows\System32\svchost.exe
    2200 C:\Program Files\ThreatFire\TFService.exe
    2248 C:\Windows\System32\svchost.exe
    2304 C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
    2348 C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    2464 C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
    2476 C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
    2488 C:\Windows\System32\conhost.exe
    2600 C:\Program Files\ThreatFire\TFTray.exe
    2620 C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
    2668 C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
    3004 C:\Program Files\Sandboxie\SbieCtrl.exe
    3088 C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
    3520 C:\Program Files\Softwin\BitDefender10\vsserv.exe
    3572 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    3624 C:\Windows\System32\alg.exe
    3652 C:\Windows\System32\svchost.exe
    3748 C:\Windows\System32\SearchIndexer.exe
    3864 C:\Windows\System32\svchost.exe
    3872 C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    3960 C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    4072 C:\Program Files\Windows Media Player\wmpnetwk.exe
    2336 C:\Program Files\Windows Media Player\wmpnscfg.exe
    4680 C:\Windows\System32\svchost.exe
    4952 C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
    5352 C:\Windows\System32\SearchProtocolHost.exe
    4360 C:\Program Files\iPod\bin\iPodService.exe
    5100 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    3156 C:\Windows\System32\svchost.exe
    3112 C:\Windows\servicing\TrustedInstaller.exe
    4004 C:\Windows\System32\SearchProtocolHost.exe
    1872 C:\Windows\System32\VSSVC.exe
    3020 C:\Windows\System32\svchost.exe
    912 C:\Windows\System32\SearchFilterHost.exe
    4100 C:\Users\Familie Pichler\Desktop\MBRCheck.exe
    5800 C:\Windows\System32\conhost.exe
    3500 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000  (NTFS)
\\.\F: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000  (NTFS)

PhysicalDrive0 Model Number: WDCWD6400AACS-00G8B1, Rev: 05.04C05
PhysicalDrive1 Model Number: WDC WD15EARS-00MVWB0, Rev: 51.0

      Size  Device Name          MBR Status
  --------------------------------------------
    596 GB  \\.\PhysicalDrive0  Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
  1397 GB  \\.\PhysicalDrive1  RE: Windows 7 MBR code detected
            SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!


cosinus 30.08.2011 10:54

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Pich103 30.08.2011 11:13

Ok, werd' ich auch noch machen!

Übrigens: der Quich Scan mit aswMBR hat Funktioniert!:daumenhoc

Der Log:

Code:

aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-08-30 11:51:11
-----------------------------
11:51:11.164    OS Version: Windows 6.1.7600
11:51:11.164    Number of processors: 4 586 0x170A
11:51:11.164    ComputerName: PICHLER  UserName:
11:51:12.583    Initialize success
11:58:22.473    AVAST engine defs: 11083000
11:58:28.057    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
11:58:28.057    Disk 0 Vendor: WDC_WD6400AACS-00G8B1 05.04C05 Size: 610480MB BusType: 11
11:58:30.085    Disk 0 MBR read successfully
11:58:30.085    Disk 0 MBR scan
11:58:30.085    Disk 0 Windows 7 default MBR code
11:58:30.085    Disk 0 scanning sectors +1250260992
11:58:30.163    Disk 0 scanning C:\Windows\system32\drivers
11:58:36.559    Service scanning
11:58:37.870    Modules scanning
11:58:42.893    Disk 0 trace - called modules:
11:58:42.924    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys
11:58:42.924    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86631ac8]
11:58:42.924    3 CLASSPNP.SYS[8b82d59e] -> nt!IofCallDriver -> [0x864c7c10]
11:58:42.940    5 ACPI.sys[83ab43b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x860fb030]
11:58:44.703    AVAST engine scan C:\Windows
11:58:47.448    AVAST engine scan C:\Windows\system32
12:00:11.376    AVAST engine scan C:\Windows\system32\drivers
12:00:19.067    AVAST engine scan C:\Users\Familie Pichler
12:06:18.694    AVAST engine scan C:\ProgramData
12:07:14.979    Scan finished successfully
12:09:20.574    Disk 0 MBR has been saved successfully to "C:\Users\Familie Pichler\Desktop\MBR.dat"
12:09:20.574    The log file has been saved successfully to "C:\Users\Familie Pichler\Desktop\aswMBR.txt"


Pich103 30.08.2011 11:48

Malwarebytes:

Code:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Datenbank Version: 7609

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

30.08.2011 12:47:15
mbam-log-2011-08-30 (12-47-15).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 299058
Laufzeit: 30 Minute(n), 43 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Pich103 31.08.2011 14:45

Na toll, gestern Internertausfall, heute so viel zu tun...:headbang: Kann die Scans erst morgen machen, Sorry.

Pich103 01.09.2011 14:09

Endlich der SUPERAntiSpyware Log:

Code:

SUPERAntiSpyware Scann-Protokoll
hxxp://www.superantispyware.com

Generiert 09/01/2011 bei 02:27 PM

Version der Applikation : 5.0.1118

Version der Kern-Datenbank : 7630
Version der Spur-Datenbank : 5442

Scan Art      : kompletter Scann
Totale Scann-Zeit : 01:10:00

Operating System Information
Windows 7 Home Premium 32-bit (Build 6.01.7600)
UAC On - Administrator

Gescannte Speicherelemente  : 746
Erfasste Speicher-Bedrohungen  : 0
Gescannte Register-Elemente  : 38608
Erfasste Register-Bedrohungen  : 0
Gescannte Datei-Elemente    : 125676
Erfasste Datei-Elemente  : 0

Werde jetzt noch den ESET online Scan Machen und den Log posten wenn er fertig ist. :daumenhoc

Pich103 01.09.2011 16:02

ESET Log:

Code:

ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
esets_scanner_update returned -1 esets_gle=12
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=acb141828105b54f92a5e878477b0864
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-08-18 10:17:26
# local_time=2011-08-18 12:17:26 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=512 16777215 100 0 7826633 7826633 0 0
# compatibility_mode=768 16777215 100 0 35061278 35061278 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 68583 66092745 0 0
# compatibility_mode=8192 67108863 100 0 72186 72186 0 0
# scanned=144272
# found=7
# cleaned=0
# scan_time=8644
C:\Users\Familie Pichler\AppData\Roaming\Uniblue\SpeedUpMyPC\_temp\ub.exe        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Familie Pichler\Downloads\cdbxp_setup_4.3.8.2568.exe        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I
F:\PICHLER\Backup Set 2011-02-03 181353\Backup Files 2011-02-03 181353\Backup files 2.zip        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I
F:\PICHLER\Backup Set 2011-02-03 181353\Backup Files 2011-02-03 181353\Backup files 4.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 6.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 7.zip        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I
F:\SEBASTIAN\Backup Set 2011-02-06 174809\Backup Files 2011-02-06 174809\Backup files 8.zip        Win32/OpenCandy application (unable to clean)        00000000000000000000000000000000        I
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=acb141828105b54f92a5e878477b0864
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-01 02:54:47
# local_time=2011-09-01 04:54:47 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=512 16777215 100 0 9056142 9056142 0 0
# compatibility_mode=768 16777215 100 0 36290787 36290787 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 186285 67322254 0 0
# compatibility_mode=8192 67108863 100 0 1301695 1301695 0 0
# scanned=134801
# found=2
# cleaned=0
# scan_time=5377
C:\Users\Familie Pichler\AppData\Roaming\Uniblue\SpeedUpMyPC\_temp\ub.exe        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I
F:\PICHLER\Backup Set 2011-08-29 093749\Backup Files 2011-08-29 093749\Backup files 2.zip        Win32/SpeedUpMyPC application (unable to clean)        00000000000000000000000000000000        I


cosinus 01.09.2011 16:08

Uniblue ist unnützes Schöangenöl, aber kein wirklicher Schädling, daher kann man das vernachlässigen.
Rechner soweit wieder im Lot?

Pich103 02.09.2011 08:56

Ja, hab ihn gestern noch Defragmentiert und jetzt lauft er wieder wie ne 1. :applaus:

cosinus 02.09.2011 09:24

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:49 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19