Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Task's lassen ich nicht beenden (https://www.trojaner-board.de/107121-tasks-lassen-beenden.html)

TitanNano 28.12.2011 21:43

Task's lassen ich nicht beenden
 
Hallo,

Ich habe seit kurzem das Proben das wenn ich Programme beende, wird es zwar geschossen, der Task bleibt jedoch erhalten. Wenn ich den Task dann über den Taskmanager killen möchte passiert einfach nichts, der Task lässt sich nicht beenden. Zuerst trat das bei Skype auf, doch heute trat es auch bei Opera auf, ich wollte den Browser einfach schließen um ein Flash update zu machen doch das funktioniert eben nicht. Ich kann mir zwar nicht vorstellen, das es von einem Virus herkommt, aber ich möchte es gerne ausschließen.

Mein System:
Windows Vista 32 Bit
Service Pack 2
Prozessor AMD Athlon(tm) X2 Dual Core Procesor BE-2350 2.10 GHz
Arbeitsspeicher 2,00 GB
Avira AntiVir Personal 12.0.0.872

MfG. TitanNano

cosinus 29.12.2011 17:43

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

TitanNano 29.12.2011 18:11

ich möchte vorher noch schnell sagen, das ich mir den PC mit meinem Bruder teile. Ich habe ihm zwar verboten jegliche Keygerns und Cracks zu verwenden, kann aber nicht 100 prozentig sicher sein das er für eines seiner spiele so etwas verwendet. Ich hoffe jetzt einfach dass sich nicht so etwas im meinem System befindet.

TitanNano 29.12.2011 21:12

Hier der Malwarebytes Log:
Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2011.12.29.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Jovan :: TITAN21 [Administrator]

Schutz: Aktiviert

29.12.2011 18:14:21
mbam-log-2011-12-29 (21-09-36).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 620151
Laufzeit: 2 Stunde(n), 49 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\Software\Microsoft|setiasworld (Malware.Trace) -> Daten: fzcysnd1cpkwjmgqirauiwek3l31ypx -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Program Files\RELEVANTKNOWLEDGE (Spyware.MarketScore) -> Keine Aktion durchgeführt.

Infizierte Dateien: 4
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP61\A0010908.exe (Adware.Onlinegames) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP70\A0011958.exe (PUP.Hacktool.Patcher) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP82\A0014579.exe (PUP.Hacktool.Patcher) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP82\A0014582.exe (PUP.Hacktool.Patcher) -> Keine Aktion durchgeführt.

(Ende)

Ich hab mir mal dieses Infizierte Verzeichnis angesehen und gesehen das es leer ist (versteckte Dateien und Ordner werden angezeigt).

EDIT: Hab gesehen das ich die Funde garnicht gelöscht hatte... :( ich lass den such lauf gleich nochmal durchlaufen. Soll ich den neuen Log dann auch Posten??

cosinus 30.12.2011 00:00

Ja, das neue Log dann auch posten.
Mach auch mit ESET danach weiter

TitanNano 30.12.2011 00:07

okay, ich hab mit ESET schon mal angefangen das scannt jetzt ca. 3 Stunden auf der ersten platte (von drei) anschließend mach ich dann nochmal Malwarebytes.

TitanNano 30.12.2011 13:43

So hier nun der ESET Log:
Code:

C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll        a variant of Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll        Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe        probably a variant of Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll        Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll        Win32/Toolbar.Babylon application
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe        Win32/Adware.Toolbar.Dealio application
C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5        a variant of Win32/Adware.Toolbar.Dealio application
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP82\A0014575.exe        a variant of Win32/AutoRun.Injector.F worm
D:\Benutzer\Jovan\Desktop\Programme\Sacred 2 Tools\Sacred Tool.exe        Win32/Packed.Autoit.C.Gen application
D:\Benutzer\Jovan\Downloads\gb3-setup.exe        a variant of Win32/Toolbar.Widgi application
D:\Benutzer\Jovan\Downloads\SoftonicDownloader_fuer_lesefixpro.exe        a variant of Win32/SoftonicDownloader.A application
D:\Benutzer\Jovan\Downloads\Unlocker1.9.1.exe        Win32/Adware.ADON application

Ich hätte nun ein paar fragen dazu:

1. ESET bot mir nach dem Scan keine Möglichkeit die Funde zulöschenm, soll ich es selbst machen??

2.
Code:

D:\Benutzer\Jovan\Desktop\Programme\Sacred 2 Tools\Sacred Tool.exe        Win32/Packed.Autoit.C.Gen Application
Es handelt sich hierbei um ein Tool mit dem sich eigne Funktionen in einem Game verändern lassen (nicht zu Cheaten). Muss ich davon ausgehen das es Infizierung ist oder wird es einfach erkannt weil es in ein fremdes Programm eingreift? ich würde es gerne behalten, und es wurde auch vom Entwickler im Offiziellen Game Forum toleriert, weshalb ich denke das es kein Virus ist.

3.
Code:

D:\Benutzer\Jovan\Downloads\Unlocker1.9.1.exe        Win32/Adware.ADON application
Dieses Programm ermöglicht es den Zugriff auf eine Datei zu "lösen" wenn scheinbar kein Programm mehr drauf zugreift, Windows es aber trotzdem nicht löschen will. Muss ich es wirklich löschen oder ist das eine Fehlerkennung??

TitanNano 30.12.2011 15:49

Neuer Malwarebytes Log:
Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2011.12.29.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Jovan :: TITAN21 [Administrator]

Schutz: Deaktiviert

30.12.2011 13:28:49
mbam-log-2011-12-30 (13-28-49).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 404075
Laufzeit: 2 Stunde(n), 17 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\Software\Microsoft|setiasworld (Malware.Trace) -> Daten: fzcysnd1cpkwjmgqirauiwek3l31ypx -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Program Files\RELEVANTKNOWLEDGE (Spyware.MarketScore) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 4
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP61\A0010908.exe (Adware.Onlinegames) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP70\A0011958.exe (PUP.Hacktool.Patcher) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP82\A0014579.exe (PUP.Hacktool.Patcher) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\System Volume Information\_restore{8C553609-7F31-4532-9749-7137F161D072}\RP82\A0014582.exe (PUP.Hacktool.Patcher) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 30.12.2011 19:32

Zitat:

1. ESET bot mir nach dem Scan keine Möglichkeit die Funde zulöschenm, soll ich es selbst machen??
Was steht in meiner Anleitung? http://cheesebuerger.de/images/midi/froehlich/a048.gif

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


TitanNano 30.12.2011 22:13

Der OTL Log:

Code:

OTL logfile created on: 30.12.2011 21:49:21 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = D:\Benutzer\Jovan\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 67,72% Memory free
4,24 Gb Paging File | 2,49 Gb Available in Paging File | 58,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,53 Gb Total Space | 15,67 Gb Free Space | 21,02% Space Free | Partition Type: NTFS
Drive D: | 111,79 Gb Total Space | 52,23 Gb Free Space | 46,72% Space Free | Partition Type: NTFS
Drive E: | 931,39 Gb Total Space | 607,93 Gb Free Space | 65,27% Space Free | Partition Type: NTFS
Drive F: | 6,70 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive J: | 983,72 Mb Total Space | 283,92 Mb Free Space | 28,86% Space Free | Partition Type: FAT
 
Computer Name: TITAN21 | User Name: Jovan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - D:\Benutzer\Jovan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Opera\opera.exe (Opera Software)
PRC - E:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - E:\Programme\Steam\Steam.exe (Valve Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - E:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
PRC - C:\Programme\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - E:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - E:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - E:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - E:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - E:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - E:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\System32\vmnat.exe (VMware, Inc.)
PRC - E:\Programme\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\Programme\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
PRC - C:\Programme\Dokan\DokanLibrary\mounter.exe ()
PRC - C:\Programme\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - E:\Programme\RocketDock\RocketDock.exe ()
PRC - C:\Programme\Common Files\microsoft shared\VS7Debug\mdm.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - E:\Programme\Steam\bin\avcodec-52.dll ()
MOD - E:\Programme\Steam\bin\avformat-52.dll ()
MOD - E:\Programme\Steam\bin\avutil-50.dll ()
MOD - C:\Windows\System32\atitmpxx.dll ()
MOD - E:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - E:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\22e853d2fe1435baa459685dee7ce7b7\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5aab9bc687029a908fc01473f8e5f77b\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\8adb45c62e4c797bd4c706afe9e8bfb9\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2c472b6ac873a7ff2ebc5bb9eb0f9ce0\PresentationFramework.Classic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94f892556ec9fa7a508fc9d214ceaedf\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
MOD - E:\Programme\MonitorSwitch\MonitorSwitchDll.dll ()
MOD - e:\Programme\Unlocker\UnlockerCOM.dll ()
MOD - E:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - E:\Programme\RocketDock\RocketDock.exe ()
MOD - E:\Programme\RocketDock\RocketDock.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MBAMService) -- E:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AMD FUEL Service) -- E:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV - (AntiVirSchedulerService) -- E:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- E:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TeamViewer6) -- E:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Hamachi2Svc) -- E:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Fabs) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (MySQL51) -- C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV - (VMnetDHCP) -- C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) -- C:\Windows\System32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) -- E:\Programme\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
SRV - (ufad-ws60) -- E:\Programme\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
SRV - (DokanMounter) -- C:\Programme\Dokan\DokanLibrary\mounter.exe ()
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (HP LaserJet Service) -- C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (DfSdkS) -- E:\Programme\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe (mst software GmbH, Germany)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (VBoxDrv) -- C:\Windows\System32\drivers\VBoxDrv.sys (Oracle Corporation)
DRV - (VBoxNetFlt) -- C:\Windows\System32\drivers\VBoxNetFlt.sys (Oracle Corporation)
DRV - (VBoxUSBMon) -- C:\Windows\System32\drivers\VBoxUSBMon.sys (Oracle Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdLH3.sys (Advanced Micro Devices)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (tap0901) -- C:\Windows\System32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (vmm) -- C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (teamviewervpn) -- C:\Windows\System32\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV - (vmx86) -- C:\Windows\System32\drivers\vmx86.sys (VMware, Inc.)
DRV - (vmci) -- C:\Windows\System32\drivers\vmci.sys (VMware, Inc.)
DRV - (VMparport) -- C:\Windows\System32\drivers\vmparport.sys (VMware, Inc.)
DRV - (vmkbd) -- C:\Windows\System32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (VMnetuserif) -- C:\Windows\System32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (hcmon) -- C:\Windows\System32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMnetBridge) -- C:\Windows\System32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) -- C:\Windows\System32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (vstor2-ws60) -- E:\Programme\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (Dokan) -- C:\Windows\System32\drivers\dokan.sys (Windows (R) Win 7 DDK provider)
DRV - (NPF) -- C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (jumi) -- C:\Windows\System32\drivers\jumi.sys (Windows (R) Win 7 DDK provider)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (amdiox86) -- C:\Windows\System32\drivers\amdiox86.sys (Advanced Micro Devices)
DRV - (KUSBusByTCPMasterBus) -- C:\Windows\System32\drivers\KUSBusByTCPMasterBus.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (KUSBusByTCP) -- C:\Windows\System32\drivers\KUSBusByTCP.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (Si3114r5) -- C:\Windows\system32\drivers\si3114r5.sys (Silicon Image, Inc)
DRV - (SiFilter) -- C:\Windows\system32\drivers\siwinacc.sys (Silicon Image, Inc.)
DRV - (SiRemFil) -- C:\Windows\system32\drivers\siremfil.sys (Silicon Image, Inc.)
DRV - (AtcL001) -- C:\Windows\System32\drivers\l160x86.sys (Atheros Communications, Inc.)
DRV - (VPCNetS2) -- C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (AsIO) -- C:\Windows\System32\drivers\AsIO.sys ()
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (pfc) -- C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://startpage.com/babylon/deu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.16.101:3128
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultthis.engineName: "Freeware.de Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2736476&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.search.selectedEngine: "Google.de"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "chrome://"
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.6
FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.8.2Lite
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: googletube@googletube.com:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36605
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0b3
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: fireshot@screenshot-program.com:0.83
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: inspector@mozilla.org:2.0.8
FF - prefs.js..extensions.enabledItems: notebook@google.com:1.0.0.22
FF - prefs.js..extensions.enabledItems: omnibar@ajitk.com:0.7.2.20100912
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.11
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1a4
FF - prefs.js..extensions.enabledItems: compatibility@addons.mozilla.org:0.7
FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:7.0.3.0
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.9.3
FF - prefs.js..extensions.enabledItems: {258735dc-6743-4805-95fc-f95941fffdad}:1.3.6
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:4.1
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:4.0b
FF - prefs.js..extensions.enabledItems: {de5809e0-2b07-11dd-bd0b-0800200c9a66}:1.2.0
FF - prefs.js..extensions.enabledItems: {6e00410e-1176-11dc-8314-0800200c9a66}:1.6.2
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91
FF - prefs.js..extensions.enabledItems: {00352F14-3F76-4e4d-ACFF-9972D7E4B3B9}:0.7.2
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - prefs.js..network.proxy.backup.ftp: "192.168.178.101"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "192.168.178.101"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "192.168.178.101"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "192.168.178.101"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "192.168.16.101"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "192.168.178.101"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "192.168.16.101"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.16.101"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "192.168.16.101"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0
 
FF - user.js..browser.search.openintab: false
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\PROGRA~1\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: E:\Programme\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Programme\Adobe Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 9.0a2\extensions\\Components: E:\Programme\Aurora\components [2011.12.27 16:27:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 9.0a2\extensions\\Plugins: E:\Programme\Aurora\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: E:\Programme\Mozilla Firefox 5\components [2011.11.01 18:42:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: E:\Programme\Mozilla Firefox 5\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0b2\extensions\\Components: E:\Programme\Miramar\components [2011.11.01 18:42:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 5.0b2\extensions\\Plugins: E:\Programme\Miramar\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.1b2\extensions\\Components: C:\PROGRA~1\SEAMON~1\COMPON~1 [2011.11.01 18:42:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.1b2\extensions\\Plugins: C:\PROGRA~1\SEAMON~1\plugins [2011.11.16 21:48:33 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Aurora 10.0a2\extensions\\Components: E:\Programme\Aurora\components [2011.12.27 16:27:03 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Aurora 10.0a2\extensions\\Plugins: E:\Programme\Aurora\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Components: E:\Programme\Miramar\components [2011.11.01 18:42:33 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 6.0\extensions\\Plugins: E:\Programme\Miramar\plugins
 
[2011.12.29 22:57:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jovan\AppData\Roaming\mozilla\Extensions
[2011.12.29 22:57:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions
[2011.12.23 22:47:23 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.11.19 19:46:25 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011.11.13 12:58:09 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.06.07 20:43:10 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2011.12.29 18:07:59 | 000,000,000 | ---D | M] (Add-on Builder Helper) -- C:\Users\Jovan\AppData\Roaming\mozilla\Firefox\Profiles\b2ukvcbi.default\extensions\jid0-t3eeRQgGANLCH9c50lPqcTDuNng@jetpack
[2011.04.04 21:12:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jovan\AppData\Roaming\mozilla\SeaMonkey\Profiles\zl98bwsr.default\extensions
[2011.04.04 21:12:05 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Jovan\AppData\Roaming\mozilla\SeaMonkey\Profiles\zl98bwsr.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2010.06.13 09:39:46 | 000,002,101 | ---- | M] () -- C:\Users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\searchplugins\googlede.xml
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE30}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{DAF44BF7-A45E-4450-979C-91CF07434C3D}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\COMPATIBILITY@ADDONS.MOZILLA.ORG.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\INSPECTOR@MOZILLA.ORG.XPI
() (No name found) -- C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\EXTENSIONS\OMNIBAR@AJITK.COM.XPI
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = E:\Programme\Adobe Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = E:\Programme\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = E:\Programme\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: ChromeAccess = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeoigbhkilbllfomkmmilbfochhlgdmh\1.6_0\
CHR - Extension: Beat the Boot (von Google) = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aidgmjkfmbhldhnhkopojimkhhhcpenl\1.0.0.1_0\
CHR - Extension: Angry Birds = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Google Text & Tabellen = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\4.9_0\
CHR - Extension: WOT = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.10_0\
CHR - Extension: Dragon Age Legends: Remix 01 = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkiinhllammkfejicmjmhnanlbifccfj\3_0\
CHR - Extension: YouTube = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Facebook = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm\1_0\
CHR - Extension: Adblock Plus f\u00FCr Google Chrome\u2122 (Beta) = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Dropbox = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnakopamhbalceiebidkekihpinoeoph\2.1_0\
CHR - Extension: Google Kalender = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.1.4_0\
CHR - Extension: TweetDeck = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl\1.1.1_0\
CHR - Extension: DropBox = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdgpbkagmklnpnondomkicjgonpfomdi\1.0_0\
CHR - Extension: Die Siedler Online = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmhcglhfdnepmdeelgjfdjckclajkha\1.0.0_0\
CHR - Extension: Die Siedler Online = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jffdjakpknfpiodfgkfmicdnkgcipbij\1.0.0_0\
CHR - Extension: Pocket Legends = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhpdbcnfpodnaefldpdohoibdajcfabp\1.7.5.3_0\
CHR - Extension: Google Talk = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd\1.2011.1207.3_0\
CHR - Extension: Google Mail = C:\Users\Jovan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll (Babylon Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] E:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] E:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] E:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TrayServer] E:\Programme\MAGIX\Video_deluxe_MX_Premium_Download-Version\Trayserver_DE.exe (MAGIX AG)
O4 - HKLM..\Run: [WinPatrol] C:\Programme\BillP Studios\WinPatrol\winpatrol.exe -expressboot File not found
O4 - HKCU..\Run: [BackgroundSwitcher] E:\Programme\John's Background Switcher\BackgroundSwitcher.exe (johnsadventures.com)
O4 - HKCU..\Run: [DU Meter] e:\Programme\DU Meter\DUMeter.exe File not found
O4 - HKCU..\Run: [MonitorSwitch] E:\Programme\MonitorSwitch\MonitorSwitch.exe (www.goldgingko.com)
O4 - HKCU..\Run: [RocketDock] E:\Programme\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [ViGlance] C:\Programme\ViGlance\ViGlance.exe (Lee-Soft.com, Lee Matthew Chantrey)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun =  [binary data]
O9 - Extra 'Tools' menuitem : Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Programme\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Programme\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D893A6ED-7C8B-4434-B976-A0975702250E}: NameServer = 192.168.178.1,192.168.16.101
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Windows\Resources\Themes\Windows 7\Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Resources\Themes\Windows 7\Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\Shell - "" = AutoRun
O33 - MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\Shell\AutoRun\command - "" = H:\TING.EXE
O33 - MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\Shell - "" = AutoRun
O33 - MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Hamachi2Svc - E:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {05466845-FF44-4671-92C1-A5FD0F9EEE1C} - Microsoft Reader
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\Windows\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.CSCD - camcodec.dll File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIV3 - DivXc32.dll File not found
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.dll (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.VMnc - C:\Windows\System32\vmnc.dll (VMware, Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\Windows\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - xvidvfw.dll File not found
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.30 19:52:41 | 000,584,192 | ---- | C] (OldTimer Tools) -- D:\Benutzer\Jovan\Desktop\OTL.exe
[2011.12.30 17:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.12.30 17:45:48 | 000,000,000 | ---D | C] -- C:\Program Files\Skype
[2011.12.30 17:45:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011.12.30 17:09:23 | 000,000,000 | R--D | C] -- C:\Users\Jovan\Documents
[2011.12.29 22:57:36 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Roaming\Macromedia
[2011.12.29 19:29:44 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Dokumente\My Cheat Tables
[2011.12.29 18:12:59 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Roaming\Malwarebytes
[2011.12.29 18:12:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.29 18:12:48 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.12.28 20:44:47 | 000,000,000 | ---D | C] -- C:\Program Files\BillP Studios
[2011.12.26 17:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SageThumbs
[2011.12.25 16:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XN Resource Editor
[2011.12.25 01:51:41 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011.12.25 01:51:01 | 000,000,000 | ---D | C] -- C:\Program Files\AMD APP
[2011.12.25 01:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2011.12.22 20:15:03 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\Borland
[2011.12.22 20:13:56 | 000,000,000 | ---D | C] -- C:\Users\Jovan\.borland
[2011.12.22 20:11:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Borland Delphi 2005
[2011.12.22 20:09:37 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Dokumente\Borland Studio-Projekte
[2011.12.22 20:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft .NET Framework SDK v1.1
[2011.12.22 20:04:23 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\ApplicationHistory
[2011.12.22 20:04:18 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\Microsoft Help
[2011.12.22 20:01:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio .NET 2003
[2011.12.22 20:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2011.12.22 19:51:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2011.12.21 18:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirRivals
[2011.12.20 17:44:11 | 000,000,000 | ---D | C] -- C:\Users\Jovan\Desktop
[2011.12.17 14:48:55 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DU Meter
[2011.12.14 18:16:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActivePerl 5.12.4 Build 1205
[2011.12.13 18:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.11 14:58:03 | 000,663,552 | ---- | C] (MAGIX AG) -- C:\Windows\System32\mgxoschk.dll
[2011.12.11 13:37:15 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Desktop\Tor Browser
[2011.12.10 23:45:55 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Dokumente\MAGIX Downloads
[2011.12.10 23:38:26 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Dokumente\MAGIX
[2011.12.10 23:37:55 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\Xara
[2011.12.10 23:37:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MAGIX Shared
[2011.12.10 23:30:17 | 000,000,000 | ---D | C] -- C:\Program Files\MAGIX
[2011.12.10 17:58:43 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Roaming\TS3Client
[2011.12.10 17:58:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2011.12.06 20:45:42 | 000,000,000 | ---D | C] -- D:\Benutzer\Jovan\Dokumente\blender
[2011.12.06 17:09:33 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\gtk-2.0
[2011.12.06 17:02:45 | 000,028,160 | ---- | C] (mst software GmbH, Germany) -- C:\Windows\System32\DfSdkBt.exe
[2011.12.06 17:02:43 | 000,000,000 | ---D | C] -- C:\Users\Jovan\AppData\Local\gegl-0.1
[2011.12.06 17:02:43 | 000,000,000 | ---D | C] -- C:\Users\Jovan\.gimp-2.7
[2011.12.03 23:17:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lionhead Studios Ltd
[2011.12.03 13:44:02 | 000,000,000 | ---D | C] -- C:\Program Files\OpenVPN
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.30 21:30:02 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.30 21:26:24 | 000,002,336 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 21:26:24 | 000,002,336 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 19:52:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- D:\Benutzer\Jovan\Desktop\OTL.exe
[2011.12.30 17:45:49 | 000,001,872 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.12.30 16:16:10 | 000,033,280 | ---- | M] () -- C:\Users\Jovan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.30 15:46:41 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\eydtvc.sys
[2011.12.30 13:26:29 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cc7ab8f1c7f6ed.job
[2011.12.30 13:25:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.29 18:12:51 | 000,000,711 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.27 21:55:46 | 000,704,148 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.12.27 21:55:46 | 000,659,308 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.12.27 21:55:46 | 000,158,844 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.12.27 21:55:46 | 000,130,848 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.12.26 22:12:59 | 000,000,000 | ---- | M] () -- C:\Users\Jovan\AppData\Local\{B1E630E0-BACD-4044-86E2-0573C5C855E3}
[2011.12.26 22:12:59 | 000,000,000 | ---- | M] () -- C:\Users\Jovan\AppData\Local\{4F70A30C-C174-423E-8CA5-43A50B9721D7}
[2011.12.26 22:09:42 | 000,053,086 | ---- | M] () -- C:\Users\Jovan\AppData\Local\recently-used.xbel
[2011.12.26 17:08:04 | 000,000,000 | ---- | M] () -- C:\Users\Jovan\AppData\Local\{DFAAA150-F15E-47F4-8539-3ADC787A5120}
[2011.12.25 17:08:03 | 000,000,000 | ---- | M] () -- C:\Users\Jovan\AppData\Local\{751098E6-739E-4A72-BE89-A4CAADFDF1D3}
[2011.12.22 20:04:24 | 000,000,093 | ---- | M] () -- C:\Users\Jovan\AppData\Local\fusioncache.dat
[2011.12.20 17:45:28 | 000,000,994 | ---- | M] () -- D:\Benutzer\Jovan\Dokumente\seil.xcf
[2011.12.14 18:48:04 | 000,000,000 | ---- | M] () -- C:\Windows\MSYS.INI
[2011.12.11 11:47:45 | 000,407,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.12.10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.12.08 19:23:21 | 000,134,856 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.12.06 19:33:06 | 000,001,812 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2011.12.05 19:41:29 | 000,000,056 | ---- | M] () -- C:\Users\Jovan\.gtk-bookmarks
[2011.12.02 20:32:34 | 000,008,105 | ---- | M] () -- D:\Benutzer\Jovan\Desktop\276990_195914143778428_246152_n.jpg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.30 17:45:49 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.12.30 15:46:41 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\eydtvc.sys
[2011.12.29 18:12:51 | 000,000,711 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.26 22:12:59 | 000,000,000 | ---- | C] () -- C:\Users\Jovan\AppData\Local\{B1E630E0-BACD-4044-86E2-0573C5C855E3}
[2011.12.26 22:12:59 | 000,000,000 | ---- | C] () -- C:\Users\Jovan\AppData\Local\{4F70A30C-C174-423E-8CA5-43A50B9721D7}
[2011.12.26 22:09:42 | 000,053,086 | ---- | C] () -- C:\Users\Jovan\AppData\Local\recently-used.xbel
[2011.12.26 17:08:04 | 000,000,000 | ---- | C] () -- C:\Users\Jovan\AppData\Local\{DFAAA150-F15E-47F4-8539-3ADC787A5120}
[2011.12.25 17:08:03 | 000,000,000 | ---- | C] () -- C:\Users\Jovan\AppData\Local\{751098E6-739E-4A72-BE89-A4CAADFDF1D3}
[2011.12.22 20:04:24 | 000,000,093 | ---- | C] () -- C:\Users\Jovan\AppData\Local\fusioncache.dat
[2011.12.20 17:45:28 | 000,000,994 | ---- | C] () -- D:\Benutzer\Jovan\Dokumente\seil.xcf
[2011.12.14 18:06:35 | 000,000,000 | ---- | C] () -- C:\Windows\MSYS.INI
[2011.12.06 17:00:18 | 000,000,695 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2011.12.05 19:41:29 | 000,000,056 | ---- | C] () -- C:\Users\Jovan\.gtk-bookmarks
[2011.12.02 20:32:32 | 000,008,105 | ---- | C] () -- D:\Benutzer\Jovan\Desktop\276990_195914143778428_246152_n.jpg
[2011.11.09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\System32\OpenVideo.dll
[2011.11.09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011.10.30 19:22:52 | 000,150,996 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2011.10.25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\System32\OVDecoder.dll
[2011.10.21 20:30:14 | 000,243,168 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.10.11 18:40:38 | 000,033,280 | ---- | C] () -- C:\Users\Jovan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011.08.26 15:42:59 | 000,000,660 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.08.23 20:03:30 | 000,000,245 | ---- | C] () -- C:\Windows\System32\regupdate.ini
[2011.08.13 20:48:31 | 000,000,132 | ---- | C] () -- C:\Windows\winamp.ini
[2011.08.02 11:31:55 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011.05.26 21:04:19 | 000,000,608 | -HS- | C] () -- C:\Windows\System32\winzvprt5.sys
[2011.05.26 21:04:19 | 000,000,250 | ---- | C] () -- C:\Windows\System32\hppfaxprinter5.ini
[2011.05.13 19:19:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.05.13 19:19:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.05.13 19:16:55 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.05.13 19:16:04 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.05.09 19:00:07 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.04.04 22:51:39 | 000,024,576 | ---- | C] () -- C:\Windows\System32\AsIO.dll
[2011.04.04 22:51:39 | 000,012,400 | ---- | C] () -- C:\Windows\System32\drivers\AsIO.sys
[2011.04.04 22:51:28 | 000,011,832 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp64.sys
[2011.04.04 22:51:28 | 000,010,216 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp32.sys
[2011.04.04 22:50:45 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2011.04.04 21:30:30 | 000,022,336 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2011.03.08 19:56:16 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2011.03.02 16:32:06 | 000,311,296 | ---- | C] () -- C:\Windows\System32\EMRegSys.dll
[2011.02.26 23:35:44 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2011.01.23 13:09:55 | 000,000,038 | ---- | C] () -- C:\Windows\camcodec100.ini
[2011.01.23 13:08:43 | 000,695,578 | ---- | C] () -- C:\Windows\System32\unins000.exe
[2011.01.23 13:08:43 | 000,001,084 | ---- | C] () -- C:\Windows\System32\unins000.dat
[2011.01.06 12:01:43 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.12.26 18:14:15 | 000,000,034 | ---- | C] () -- C:\Windows\System32\oeminfo.ini
[2010.12.03 18:13:35 | 000,023,508 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010.11.22 21:22:59 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2010.11.21 14:29:27 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.11.21 13:53:43 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.21 13:18:42 | 000,001,324 | ---- | C] () -- C:\Windows\System32\d3d9caps.dat
[2010.11.21 13:04:14 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.11.21 09:30:45 | 000,004,161 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010.07.05 13:39:12 | 000,033,792 | ---- | C] () -- C:\Windows\System32\dokan.dll
[2010.06.25 18:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2010.05.05 02:21:48 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2009.09.16 10:44:52 | 000,003,235 | ---- | C] () -- C:\Windows\System32\hptcpmon.ini
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007.04.27 08:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2006.11.02 16:42:41 | 000,704,148 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 16:42:41 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 16:42:41 | 000,158,844 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 16:42:41 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:56:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:43 | 000,407,104 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 11:33:01 | 000,659,308 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,130,848 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.02.23 16:37:18 | 000,047,104 | ---- | C] () -- C:\Windows\System32\dsfFLACEncoder.dll
[2006.02.23 15:37:06 | 000,047,616 | ---- | C] () -- C:\Windows\System32\dsfVorbisDecoder.dll
[2006.02.23 15:36:22 | 000,102,400 | ---- | C] () -- C:\Windows\System32\dsfOggDemux2.dll
[2006.02.23 15:35:56 | 000,053,248 | ---- | C] () -- C:\Windows\System32\dsfOGMDecoder.dll
[2006.02.23 15:35:44 | 000,053,248 | ---- | C] () -- C:\Windows\System32\dsfNativeFLACSource.dll
[2006.02.23 15:35:40 | 000,049,664 | ---- | C] () -- C:\Windows\System32\dsfFLACDecoder.dll
[2006.02.23 15:34:58 | 000,083,456 | ---- | C] () -- C:\Windows\System32\libFLAC++.dll
[2006.02.23 15:34:56 | 000,106,496 | ---- | C] () -- C:\Windows\System32\libFishSound.dll
[2006.02.23 15:34:38 | 000,029,696 | ---- | C] () -- C:\Windows\System32\libOOOggSeek.dll
[2006.02.23 15:34:26 | 001,108,480 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2006.02.23 15:34:16 | 000,049,152 | ---- | C] () -- C:\Windows\System32\libOOogg.dll
[2006.02.23 15:33:54 | 000,140,288 | ---- | C] () -- C:\Windows\System32\libFLAC.dll
 
========== LOP Check ==========
 
[2011.11.20 01:14:52 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\.minecraft
[2011.11.26 00:37:28 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Ashampoo
[2011.04.17 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Blender Foundation
[2011.05.13 18:03:19 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Broken Sword 2.5
[2011.05.13 23:05:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DAEMON Tools Lite
[2011.09.19 17:15:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Dropbox
[2011.10.18 16:39:20 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DVDVideoSoft
[2011.10.16 16:17:33 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.01 17:30:48 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Free Audio Editor
[2011.04.04 21:11:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\JCreator
[2011.08.26 15:40:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\johnsadventures.com
[2011.04.04 21:11:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\LibreOffice
[2011.12.10 23:38:32 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\MAGIX
[2011.10.07 16:35:02 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
[2011.09.25 08:32:22 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
[2011.10.16 11:20:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\MonitorSwitch
[2011.04.12 18:25:03 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\NCH Swift Sound
[2011.10.11 19:40:39 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Opera
[2011.04.04 21:12:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\ScummVM
[2011.04.04 21:12:17 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TeamViewer
[2011.04.04 21:12:18 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Thunderbird
[2011.12.10 23:25:52 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TS3Client
[2011.04.17 12:08:17 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TSRWorkshop
[2011.11.27 12:18:05 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\ViGlance
[2006.11.02 14:08:52 | 000,000,484 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.08.29 12:02:28 | 000,000,176 | ---- | M] () -- C:\Windows\Tasks\{20D6952E-68DE-4424-86A1-52A986B2CC2B}.job
[2011.07.12 16:07:06 | 000,000,176 | ---- | M] () -- C:\Windows\Tasks\{B668B532-98D5-494C-820D-87372AC7F773}.job
[2011.06.11 12:39:59 | 000,000,176 | ---- | M] () -- C:\Windows\Tasks\{CAF720F3-3F53-4E82-A427-E5CB36721989}.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.11.20 01:14:52 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\.minecraft
[2011.10.16 19:33:24 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Adobe
[2011.12.06 19:33:23 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Apple Computer
[2011.11.26 00:37:28 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Ashampoo
[2011.04.04 21:11:19 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\ATI
[2011.10.18 20:27:33 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Avira
[2011.04.17 11:48:13 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Blender Foundation
[2011.05.13 18:03:19 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Broken Sword 2.5
[2011.05.13 23:05:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DAEMON Tools Lite
[2011.09.19 17:15:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Dropbox
[2011.10.18 16:39:20 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DVDVideoSoft
[2011.10.16 16:17:33 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.01 17:30:48 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Free Audio Editor
[2011.04.04 21:11:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\JCreator
[2011.08.26 15:40:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\johnsadventures.com
[2011.04.04 21:11:29 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\LibreOffice
[2011.12.29 22:57:36 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Macromedia
[2011.12.10 23:38:32 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\MAGIX
[2011.12.29 18:12:59 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Malwarebytes
[2011.10.07 16:35:02 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
[2011.09.25 08:32:22 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
[2011.12.22 20:06:03 | 000,000,000 | --SD | M] -- C:\Users\Jovan\AppData\Roaming\Microsoft
[2011.06.24 12:40:44 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Microsoft Games
[2011.10.16 11:20:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\MonitorSwitch
[2011.12.29 22:57:04 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Mozilla
[2011.04.12 18:25:03 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\NCH Swift Sound
[2011.10.11 19:40:39 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Opera
[2011.04.04 21:12:08 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\ScummVM
[2011.04.04 21:12:17 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TeamViewer
[2011.04.04 21:12:18 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\Thunderbird
[2011.12.10 23:25:52 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TS3Client
[2011.04.17 12:08:17 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\TSRWorkshop
[2011.11.27 12:18:05 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\ViGlance
[2011.12.14 21:01:10 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\vlc
[2011.10.27 17:54:39 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\VMware
[2011.10.23 13:30:57 | 000,000,000 | ---D | M] -- C:\Users\Jovan\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2011.05.25 21:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jovan\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2011.05.25 21:07:18 | 000,174,784 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jovan\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2011.06.12 19:15:56 | 000,010,134 | R--- | M] () -- C:\Users\Jovan\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2010.10.31 21:31:13 | 000,188,152 | ---- | M] () -- C:\Users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\FlashGot.exe
[1 C:\Users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\*.tmp files -> C:\Users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\*.tmp -> ]
[2011.01.10 18:35:06 | 000,188,152 | ---- | M] () -- C:\Users\Jovan\AppData\Roaming\Mozilla\SeaMonkey\Profiles\zl98bwsr.default\FlashGot.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2011.04.06 17:34:31 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2011.04.06 17:34:31 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2011.04.06 17:34:31 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2011.04.05 17:11:50 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2011.04.05 17:11:53 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 08:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 10:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 10:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 09:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2011.08.20 12:00:52 | 000,443,448 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys
 
< %systemroot%\System32\config\*.sav >
[2011.04.04 21:15:26 | 006,832,128 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2011.04.04 21:15:23 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2011.04.04 21:15:26 | 000,057,344 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2011.04.04 21:15:37 | 015,519,744 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2011.04.04 21:15:38 | 006,098,944 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2011.11.10 04:12:24 | 000,466,944 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
 
<          >

< End of report >


cosinus 30.12.2011 22:49

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startpage.com/babylon/deu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.16.101
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultthis.engineName: "Freeware.de Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2736476&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:4.1
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1
FF - prefs.js..network.proxy.backup.ftp: "192.168.178.101"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "192.168.178.101"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "192.168.178.101"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "192.168.178.101"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "192.168.16.101"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "192.168.178.101"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "192.168.16.101"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.16.101"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "192.168.16.101"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll (Babylon Ltd.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\Shell - "" = AutoRun
O33 - MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\Shell\AutoRun\command - "" = H:\TING.EXE
O33 - MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\Shell - "" = AutoRun
O33 - MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
[2011.12.30 15:46:41 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\eydtvc.sys
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

TitanNano 30.12.2011 23:29

ich hab das Script wie du geschrieben hattest in OTL durchlaufen gelassen. OTL hat erst den Explorer beendet, dann eine zeit lang gearbeitet und ist am ende für ca. 3 min hängen geblieben (das Programm reagiert nicht mehr). Dann hat es sich einfach geschlossen und es ist nichts mehr passiert. nach ca. 5 min. hab ich mich im Taskmanagaer vergewissert ob es wirklich nicht mehr läuft und anschließend den PC über Strg + Alt + Entf neu gestartet. Ein Log File hab ich nie zusehen bekommen und der Ordner _OTL existiert auch nicht....

cosinus 30.12.2011 23:51

Wiederhol den Fix einfach...

TitanNano 31.12.2011 00:22

diesmal hast funktioniert:
Code:

All processes killed
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: "Google" removed from browser.search.defaultenginename
Prefs.js: "Freeware.de Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2736476&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "chr-greentree_ff&type=302398" removed from browser.search.param.yahoo-fr
Prefs.js: pdfforge@mybrowserbar.com:4.1 removed from extensions.enabledItems
Prefs.js: wtxpcom@mybrowserbar.com:4.1 removed from extensions.enabledItems
Prefs.js: "192.168.178.101" removed from network.proxy.backup.ftp
Prefs.js: 3128 removed from network.proxy.backup.ftp_port
Prefs.js: "192.168.178.101" removed from network.proxy.backup.gopher
Prefs.js: 3128 removed from network.proxy.backup.gopher_port
Prefs.js: "192.168.178.101" removed from network.proxy.backup.socks
Prefs.js: 3128 removed from network.proxy.backup.socks_port
Prefs.js: "192.168.178.101" removed from network.proxy.backup.ssl
Prefs.js: 3128 removed from network.proxy.backup.ssl_port
Prefs.js: "192.168.16.101" removed from network.proxy.ftp
Prefs.js: 3128 removed from network.proxy.ftp_port
Prefs.js: "192.168.178.101" removed from network.proxy.gopher
Prefs.js: 3128 removed from network.proxy.gopher_port
Prefs.js: "192.168.16.101" removed from network.proxy.http
Prefs.js: 3128 removed from network.proxy.http_port
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "192.168.16.101" removed from network.proxy.socks
Prefs.js: 3128 removed from network.proxy.socks_port
Prefs.js: "192.168.16.101" removed from network.proxy.ssl
Prefs.js: 3128 removed from network.proxy.ssl_port
Prefs.js: 0 removed from network.proxy.type
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
File C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ not found.
File C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B0744341-96E0-4341-9ED2-8BC36CE0CCD0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0744341-96E0-4341-9ED2-8BC36CE0CCD0}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
File C:\Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File C:\AUTOEXEC.BAT not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{151f24f0-cb1c-11e0-8aed-c395a6c70c78}\ not found.
File G:\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{258a90a4-fd55-11e0-801a-005056c00008}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{258a90a4-fd55-11e0-801a-005056c00008}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{258a90a4-fd55-11e0-801a-005056c00008}\ not found.
File H:\TING.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69674fb9-c761-11e0-9c74-001e8c389122}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69674fb9-c761-11e0-9c74-001e8c389122}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69674fb9-c761-11e0-9c74-001e8c389122}\ not found.
File G:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File F:\AUTORUN.EXE not found.
File C:\Windows\System32\drivers\eydtvc.sys not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Cyrill
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User.WINDOWS
 
User: Jovan
->Temp folder emptied: 330404909 bytes
->Temporary Internet Files folder emptied: 13451848 bytes
->Java cache emptied: 4163920 bytes
->FireFox cache emptied: 88104342 bytes
->Google Chrome cache emptied: 321287975 bytes
->Apple Safari cache emptied: 1107968 bytes
->Opera cache emptied: 11009706 bytes
->Flash cache emptied: 1473 bytes
 
User: LocalService.NT-AUTORITÄT
 
User: NetworkService.NT-AUTORITÄT
 
User: Public
 
User: User
->Temp folder emptied: 20393464 bytes
->Temporary Internet Files folder emptied: 607315 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 155648 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1073327553 bytes
RecycleBin emptied: 1277 bytes
 
Total Files Cleaned = 1.778,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 12312011_001336

Files\Folders moved on Reboot...
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2128.log moved successfully.

Registry entries deleted on Reboot...


cosinus 31.12.2011 00:25

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

TitanNano 31.12.2011 00:35

Hier de Log:
Code:

00:32:20.0258 5988        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
00:32:20.0469 5988        ============================================================
00:32:20.0469 5988        Current date / time: 2011/12/31 00:32:20.0469
00:32:20.0469 5988        SystemInfo:
00:32:20.0469 5988       
00:32:20.0469 5988        OS Version: 6.0.6002 ServicePack: 2.0
00:32:20.0469 5988        Product type: Workstation
00:32:20.0469 5988        ComputerName: TITAN21
00:32:20.0470 5988        UserName: Jovan
00:32:20.0470 5988        Windows directory: C:\Windows
00:32:20.0470 5988        System windows directory: C:\Windows
00:32:20.0470 5988        Processor architecture: Intel x86
00:32:20.0470 5988        Number of processors: 2
00:32:20.0470 5988        Page size: 0x1000
00:32:20.0470 5988        Boot type: Normal boot
00:32:20.0470 5988        ============================================================
00:32:25.0923 5988        Initialize success
00:32:47.0412 5940        ============================================================
00:32:47.0412 5940        Scan started
00:32:47.0412 5940        Mode: Manual; SigCheck; TDLFS;
00:32:47.0412 5940        ============================================================
00:32:50.0773 5940        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
00:32:50.0931 5940        ACPI - ok
00:32:51.0360 5940        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
00:32:51.0558 5940        adp94xx - ok
00:32:51.0975 5940        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
00:32:52.0121 5940        adpahci - ok
00:32:52.0450 5940        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
00:32:52.0507 5940        adpu160m - ok
00:32:52.0887 5940        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
00:32:52.0911 5940        adpu320 - ok
00:32:53.0582 5940        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
00:32:53.0744 5940        AFD - ok
00:32:54.0172 5940        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
00:32:54.0208 5940        agp440 - ok
00:32:54.0536 5940        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
00:32:54.0590 5940        aic78xx - ok
00:32:55.0204 5940        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
00:32:55.0290 5940        aliide - ok
00:32:55.0688 5940        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
00:32:55.0743 5940        amdagp - ok
00:32:55.0929 5940        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
00:32:55.0973 5940        amdide - ok
00:32:56.0367 5940        amdiox86        (ff258424f0b2ef25eb98f04ee386e6e3) C:\Windows\system32\DRIVERS\amdiox86.sys
00:32:56.0456 5940        amdiox86 - ok
00:32:56.0821 5940        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
00:32:57.0080 5940        AmdK7 - ok
00:32:57.0332 5940        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
00:32:57.0532 5940        AmdK8 - ok
00:32:58.0129 5940        amdkmdag        (ab70f110143892eb41aa46500aa5cf00) C:\Windows\system32\DRIVERS\atikmdag.sys
00:32:59.0099 5940        amdkmdag - ok
00:32:59.0339 5940        amdkmdap        (32d68d05b871eed5572d0c2c764ea4ec) C:\Windows\system32\DRIVERS\atikmpag.sys
00:32:59.0528 5940        amdkmdap - ok
00:32:59.0722 5940        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
00:32:59.0771 5940        arc - ok
00:32:59.0943 5940        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
00:32:59.0990 5940        arcsas - ok
00:33:00.0139 5940        AsIO            (2b4e66fac6503494a2c6f32bb6ab3826) C:\Windows\system32\drivers\AsIO.sys
00:33:00.0154 5940        AsIO - ok
00:33:00.0357 5940        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
00:33:00.0425 5940        AsyncMac - ok
00:33:00.0861 5940        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
00:33:00.0873 5940        atapi - ok
00:33:01.0046 5940        AtcL001        (55907c61656449ca8534c323d6eabc89) C:\Windows\system32\DRIVERS\l160x86.sys
00:33:01.0122 5940        AtcL001 - ok
00:33:01.0331 5940        AtiHDAudioService (c8f5273b12cfa5c0888263e34140cb8a) C:\Windows\system32\drivers\AtihdLH3.sys
00:33:01.0354 5940        AtiHDAudioService - ok
00:33:01.0520 5940        AtiHdmiService  (5e1cbda7d52289579e25283549e99425) C:\Windows\system32\drivers\AtiHdmi.sys
00:33:01.0548 5940        AtiHdmiService - ok
00:33:01.0740 5940        avgntflt        (7713e4eb0276702faa08e52a6e23f2a6) C:\Windows\system32\DRIVERS\avgntflt.sys
00:33:01.0777 5940        avgntflt - ok
00:33:02.0047 5940        avipbb          (475fbb85956534720858ae72010c0a43) C:\Windows\system32\DRIVERS\avipbb.sys
00:33:02.0101 5940        avipbb - ok
00:33:02.0425 5940        avkmgr          (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
00:33:02.0463 5940        avkmgr - ok
00:33:02.0870 5940        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
00:33:03.0002 5940        Beep - ok
00:33:03.0301 5940        blbdrive - ok
00:33:03.0544 5940        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
00:33:03.0642 5940        bowser - ok
00:33:03.0853 5940        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
00:33:04.0013 5940        BrFiltLo - ok
00:33:04.0378 5940        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
00:33:04.0450 5940        BrFiltUp - ok
00:33:04.0753 5940        Bridge          (b1564976d98e91fc764d5dc28a0297da) C:\Windows\system32\DRIVERS\bridge.sys
00:33:04.0823 5940        Bridge - ok
00:33:04.0877 5940        BridgeMP        (b1564976d98e91fc764d5dc28a0297da) C:\Windows\system32\DRIVERS\bridge.sys
00:33:04.0900 5940        BridgeMP - ok
00:33:05.0347 5940        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
00:33:05.0456 5940        Brserid - ok
00:33:05.0752 5940        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
00:33:05.0899 5940        BrSerWdm - ok
00:33:06.0236 5940        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
00:33:06.0364 5940        BrUsbMdm - ok
00:33:06.0768 5940        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
00:33:06.0878 5940        BrUsbSer - ok
00:33:07.0193 5940        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
00:33:07.0302 5940        BTHMODEM - ok
00:33:07.0545 5940        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
00:33:07.0611 5940        cdfs - ok
00:33:07.0777 5940        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
00:33:07.0842 5940        cdrom - ok
00:33:08.0187 5940        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
00:33:08.0279 5940        circlass - ok
00:33:08.0535 5940        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
00:33:08.0587 5940        CLFS - ok
00:33:08.0890 5940        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
00:33:08.0929 5940        cmdide - ok
00:33:09.0228 5940        Compbatt        (82b8c91d327cfecf76cb58716f7d4997) C:\Windows\system32\drivers\compbatt.sys
00:33:09.0258 5940        Compbatt - ok
00:33:09.0652 5940        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
00:33:09.0669 5940        crcdisk - ok
00:33:09.0919 5940        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
00:33:10.0008 5940        Crusoe - ok
00:33:10.0284 5940        CSC            (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys
00:33:10.0419 5940        CSC - ok
00:33:10.0639 5940        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
00:33:10.0732 5940        DfsC - ok
00:33:11.0051 5940        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
00:33:11.0158 5940        disk - ok
00:33:11.0664 5940        Dokan          (73b37188b998d9c51cf2016cad0848ac) C:\Windows\system32\drivers\dokan.sys
00:33:11.0723 5940        Dokan ( UnsignedFile.Multi.Generic ) - warning
00:33:11.0723 5940        Dokan - detected UnsignedFile.Multi.Generic (1)
00:33:12.0118 5940        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
00:33:12.0185 5940        drmkaud - ok
00:33:12.0434 5940        dtsoftbus01    (c0c7ceccb6c85994c2bc92d58e52d3f2) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
00:33:12.0451 5940        dtsoftbus01 - ok
00:33:12.0857 5940        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
00:33:13.0014 5940        DXGKrnl - ok
00:33:13.0308 5940        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
00:33:13.0414 5940        E1G60 - ok
00:33:13.0680 5940        EagleNT - ok
00:33:13.0996 5940        EagleXNt - ok
00:33:14.0158 5940        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
00:33:14.0199 5940        Ecache - ok
00:33:14.0397 5940        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
00:33:14.0469 5940        elxstor - ok
00:33:14.0718 5940        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
00:33:14.0825 5940        exfat - ok
00:33:15.0026 5940        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
00:33:15.0091 5940        fastfat - ok
00:33:15.0261 5940        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
00:33:15.0312 5940        fdc - ok
00:33:15.0526 5940        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
00:33:15.0557 5940        FileInfo - ok
00:33:15.0759 5940        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
00:33:15.0830 5940        Filetrace - ok
00:33:16.0019 5940        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
00:33:16.0095 5940        flpydisk - ok
00:33:16.0276 5940        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
00:33:16.0295 5940        FltMgr - ok
00:33:16.0610 5940        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
00:33:16.0664 5940        Fs_Rec - ok
00:33:16.0842 5940        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
00:33:16.0864 5940        gagp30kx - ok
00:33:17.0040 5940        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:33:17.0068 5940        GEARAspiWDM - ok
00:33:17.0264 5940        hamachi        (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
00:33:17.0297 5940        hamachi - ok
00:33:17.0574 5940        hcmon          (51fa91bb463b15fd8eacd5045c3f2fa6) C:\Windows\system32\drivers\hcmon.sys
00:33:17.0601 5940        hcmon - ok
00:33:17.0785 5940        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
00:33:17.0891 5940        HdAudAddService - ok
00:33:18.0063 5940        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
00:33:18.0133 5940        HDAudBus - ok
00:33:18.0309 5940        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
00:33:18.0383 5940        HidBth - ok
00:33:18.0700 5940        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
00:33:18.0799 5940        HidIr - ok
00:33:18.0967 5940        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
00:33:19.0040 5940        HidUsb - ok
00:33:19.0219 5940        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
00:33:19.0239 5940        HpCISSs - ok
00:33:19.0431 5940        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
00:33:19.0636 5940        HTTP - ok
00:33:19.0814 5940        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
00:33:19.0831 5940        i2omp - ok
00:33:20.0003 5940        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
00:33:20.0062 5940        i8042prt - ok
00:33:20.0235 5940        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
00:33:20.0271 5940        iaStorV - ok
00:33:20.0451 5940        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
00:33:20.0487 5940        iirsp - ok
00:33:20.0872 5940        IntcAzAudAddService (345ac48d17f5c2f2aa1ee50d34c3978b) C:\Windows\system32\drivers\RTKVHDA.sys
00:33:21.0444 5940        IntcAzAudAddService - ok
00:33:21.0773 5940        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
00:33:21.0812 5940        intelide - ok
00:33:22.0033 5940        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
00:33:22.0118 5940        intelppm - ok
00:33:22.0416 5940        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:33:22.0478 5940        IpFilterDriver - ok
00:33:22.0778 5940        IpInIp - ok
00:33:22.0928 5940        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
00:33:23.0022 5940        IPMIDRV - ok
00:33:23.0217 5940        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
00:33:23.0248 5940        IPNAT - ok
00:33:23.0433 5940        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
00:33:23.0507 5940        IRENUM - ok
00:33:23.0710 5940        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
00:33:23.0756 5940        isapnp - ok
00:33:24.0046 5940        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
00:33:24.0064 5940        iScsiPrt - ok
00:33:24.0233 5940        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
00:33:24.0271 5940        iteatapi - ok
00:33:24.0450 5940        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
00:33:24.0468 5940        iteraid - ok
00:33:24.0666 5940        jumi            (ee894427ac0b2b2c2c8b32cb78357dae) C:\Windows\system32\DRIVERS\jumi.sys
00:33:24.0684 5940        jumi - ok
00:33:24.0896 5940        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
00:33:24.0929 5940        kbdclass - ok
00:33:25.0101 5940        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
00:33:25.0178 5940        kbdhid - ok
00:33:25.0311 5940        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
00:33:25.0392 5940        KSecDD - ok
00:33:25.0562 5940        KUSBusByTCP    (632191f9aca2df8fb478c161f51a285a) C:\Windows\system32\Drivers\KUSBusByTCP.sys
00:33:25.0596 5940        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - warning
00:33:25.0596 5940        KUSBusByTCP - detected UnsignedFile.Multi.Generic (1)
00:33:25.0824 5940        KUSBusByTCPMasterBus (32a74618edd493669b478595c2e54c62) C:\Windows\system32\Drivers\KUSBusByTCPMasterBus.sys
00:33:25.0861 5940        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - warning
00:33:25.0861 5940        KUSBusByTCPMasterBus - detected UnsignedFile.Multi.Generic (1)
00:33:26.0066 5940        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
00:33:26.0143 5940        lltdio - ok
00:33:26.0329 5940        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
00:33:26.0350 5940        LSI_FC - ok
00:33:26.0526 5940        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
00:33:26.0548 5940        LSI_SAS - ok
00:33:26.0738 5940        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
00:33:26.0822 5940        LSI_SCSI - ok
00:33:27.0137 5940        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
00:33:27.0208 5940        luafv - ok
00:33:27.0382 5940        MBAMProtector  (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys
00:33:27.0418 5940        MBAMProtector - ok
00:33:27.0599 5940        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
00:33:27.0619 5940        megasas - ok
00:33:27.0812 5940        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
00:33:27.0861 5940        Modem - ok
00:33:28.0022 5940        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
00:33:28.0072 5940        monitor - ok
00:33:28.0235 5940        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
00:33:28.0269 5940        mouclass - ok
00:33:28.0441 5940        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
00:33:28.0473 5940        mouhid - ok
00:33:28.0669 5940        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
00:33:28.0707 5940        MountMgr - ok
00:33:28.0856 5940        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
00:33:28.0878 5940        mpio - ok
00:33:29.0052 5940        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
00:33:29.0116 5940        mpsdrv - ok
00:33:29.0294 5940        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
00:33:29.0333 5940        Mraid35x - ok
00:33:29.0513 5940        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
00:33:29.0596 5940        MRxDAV - ok
00:33:29.0757 5940        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
00:33:29.0849 5940        mrxsmb - ok
00:33:30.0017 5940        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:33:30.0103 5940        mrxsmb10 - ok
00:33:30.0224 5940        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:33:30.0275 5940        mrxsmb20 - ok
00:33:30.0444 5940        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
00:33:30.0488 5940        msahci - ok
00:33:30.0685 5940        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
00:33:30.0743 5940        msdsm - ok
00:33:30.0980 5940        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
00:33:31.0064 5940        Msfs - ok
00:33:31.0316 5940        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
00:33:31.0341 5940        msisadrv - ok
00:33:31.0517 5940        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
00:33:31.0590 5940        MSKSSRV - ok
00:33:31.0811 5940        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
00:33:31.0892 5940        MSPCLOCK - ok
00:33:32.0299 5940        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
00:33:32.0354 5940        MSPQM - ok
00:33:32.0590 5940        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
00:33:32.0629 5940        MsRPC - ok
00:33:32.0830 5940        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
00:33:32.0840 5940        mssmbios - ok
00:33:33.0015 5940        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
00:33:33.0061 5940        MSTEE - ok
00:33:33.0228 5940        MTsensor        (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys
00:33:33.0278 5940        MTsensor - ok
00:33:33.0446 5940        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
00:33:33.0475 5940        Mup - ok
00:33:33.0663 5940        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
00:33:33.0711 5940        NativeWifiP - ok
00:33:33.0917 5940        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
00:33:33.0969 5940        NDIS - ok
00:33:34.0140 5940        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
00:33:34.0194 5940        NdisTapi - ok
00:33:34.0359 5940        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
00:33:34.0432 5940        Ndisuio - ok
00:33:34.0621 5940        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
00:33:34.0693 5940        NdisWan - ok
00:33:34.0870 5940        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
00:33:34.0910 5940        NDProxy - ok
00:33:35.0087 5940        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
00:33:35.0156 5940        NetBIOS - ok
00:33:35.0376 5940        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
00:33:35.0464 5940        netbt - ok
00:33:35.0701 5940        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
00:33:35.0728 5940        nfrd960 - ok
00:33:35.0966 5940        NPF            (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys
00:33:35.0986 5940        NPF - ok
00:33:36.0182 5940        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
00:33:36.0238 5940        Npfs - ok
00:33:36.0435 5940        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
00:33:36.0523 5940        nsiproxy - ok
00:33:36.0731 5940        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
00:33:36.0953 5940        Ntfs - ok
00:33:37.0140 5940        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
00:33:37.0254 5940        ntrigdigi - ok
00:33:37.0566 5940        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
00:33:37.0633 5940        Null - ok
00:33:37.0830 5940        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
00:33:37.0877 5940        nvraid - ok
00:33:38.0062 5940        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
00:33:38.0101 5940        nvstor - ok
00:33:38.0269 5940        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
00:33:38.0291 5940        nv_agp - ok
00:33:38.0432 5940        NwlnkFlt - ok
00:33:38.0578 5940        NwlnkFwd - ok
00:33:38.0743 5940        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
00:33:38.0860 5940        ohci1394 - ok
00:33:39.0036 5940        Parport        (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
00:33:39.0110 5940        Parport - ok
00:33:39.0277 5940        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
00:33:39.0308 5940        partmgr - ok
00:33:39.0475 5940        Parvdm          (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
00:33:39.0539 5940        Parvdm - ok
00:33:39.0722 5940        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
00:33:39.0738 5940        pci - ok
00:33:39.0911 5940        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
00:33:39.0941 5940        pciide - ok
00:33:40.0103 5940        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
00:33:40.0131 5940        pcmcia - ok
00:33:40.0313 5940        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
00:33:40.0540 5940        PEAUTH - ok
00:33:40.0749 5940        pfc            (f2b3785d7282bac66d4b644fc88749f0) C:\Windows\system32\drivers\pfc.sys
00:33:40.0800 5940        pfc ( UnsignedFile.Multi.Generic ) - warning
00:33:40.0800 5940        pfc - detected UnsignedFile.Multi.Generic (1)
00:33:41.0004 5940        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
00:33:41.0057 5940        PptpMiniport - ok
00:33:41.0230 5940        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
00:33:41.0328 5940        Processor - ok
00:33:41.0509 5940        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
00:33:41.0574 5940        PSched - ok
00:33:41.0751 5940        PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
00:33:41.0770 5940        PxHelp20 - ok
00:33:41.0959 5940        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
00:33:42.0100 5940        ql2300 - ok
00:33:42.0272 5940        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
00:33:42.0325 5940        ql40xx - ok
00:33:42.0500 5940        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
00:33:42.0655 5940        QWAVEdrv - ok
00:33:42.0843 5940        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
00:33:42.0878 5940        RasAcd - ok
00:33:43.0080 5940        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
00:33:43.0160 5940        Rasl2tp - ok
00:33:43.0344 5940        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
00:33:43.0413 5940        RasPppoe - ok
00:33:43.0627 5940        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
00:33:43.0655 5940        RasSstp - ok
00:33:43.0866 5940        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
00:33:44.0110 5940        rdbss - ok
00:33:44.0399 5940        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
00:33:44.0471 5940        RDPCDD - ok
00:33:44.0718 5940        rdpdr          (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys
00:33:44.0881 5940        rdpdr - ok
00:33:45.0122 5940        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
00:33:45.0185 5940        RDPENCDD - ok
00:33:45.0480 5940        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
00:33:45.0708 5940        RDPWD - ok
00:33:45.0968 5940        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
00:33:46.0022 5940        rspndr - ok
00:33:46.0195 5940        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
00:33:46.0217 5940        sbp2port - ok
00:33:46.0408 5940        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
00:33:46.0514 5940        secdrv - ok
00:33:46.0702 5940        Serenum        (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
00:33:46.0780 5940        Serenum - ok
00:33:46.0975 5940        Serial          (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
00:33:47.0039 5940        Serial - ok
00:33:47.0194 5940        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
00:33:47.0246 5940        sermouse - ok
00:33:47.0443 5940        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
00:33:47.0539 5940        sffdisk - ok
00:33:47.0710 5940        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
00:33:47.0812 5940        sffp_mmc - ok
00:33:48.0008 5940        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
00:33:48.0120 5940        sffp_sd - ok
00:33:48.0324 5940        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
00:33:48.0395 5940        sfloppy - ok
00:33:48.0615 5940        Si3114r5        (09889d435edc82435b18c7c311fe5721) C:\Windows\system32\drivers\si3114r5.sys
00:33:48.0631 5940        Si3114r5 - ok
00:33:48.0893 5940        SiFilter        (46b92189fe4db53a09e3a0099aa3084c) C:\Windows\system32\drivers\siwinacc.sys
00:33:48.0945 5940        SiFilter - ok
00:33:49.0134 5940        SiRemFil        (b688378d258d1ecce4768cdb55d48d92) C:\Windows\system32\drivers\siremfil.sys
00:33:49.0166 5940        SiRemFil - ok
00:33:49.0360 5940        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
00:33:49.0398 5940        sisagp - ok
00:33:49.0580 5940        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
00:33:49.0599 5940        SiSRaid2 - ok
00:33:49.0785 5940        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
00:33:49.0853 5940        SiSRaid4 - ok
00:33:50.0063 5940        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
00:33:50.0099 5940        Smb - ok
00:33:50.0271 5940        snpstd - ok
00:33:50.0451 5940        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
00:33:50.0477 5940        spldr - ok
00:33:50.0671 5940        sptd            (8ea0fd60a5b047e0c734d51aace531c9) C:\Windows\System32\Drivers\sptd.sys
00:33:50.0671 5940        Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 8ea0fd60a5b047e0c734d51aace531c9
00:33:50.0694 5940        sptd ( LockedFile.Multi.Generic ) - warning
00:33:50.0695 5940        sptd - detected LockedFile.Multi.Generic (1)
00:33:50.0938 5940        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
00:33:51.0094 5940        srv - ok
00:33:51.0264 5940        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
00:33:51.0371 5940        srv2 - ok
00:33:51.0556 5940        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
00:33:51.0628 5940        srvnet - ok
00:33:51.0822 5940        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
00:33:51.0852 5940        ssmdrv - ok
00:33:52.0090 5940        StillCam        (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
00:33:52.0125 5940        StillCam - ok
00:33:52.0294 5940        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
00:33:52.0312 5940        swenum - ok
00:33:52.0496 5940        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
00:33:52.0536 5940        Symc8xx - ok
00:33:52.0718 5940        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
00:33:52.0745 5940        Sym_hi - ok
00:33:52.0940 5940        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
00:33:52.0959 5940        Sym_u3 - ok
00:33:53.0140 5940        tap0901        (98a1e6bc9f766b0b0a5bf00af847ef20) C:\Windows\system32\DRIVERS\tap0901.sys
00:33:53.0193 5940        tap0901 - ok
00:33:53.0379 5940        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
00:33:53.0505 5940        Tcpip - ok
00:33:53.0737 5940        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
00:33:53.0826 5940        Tcpip6 - ok
00:33:53.0990 5940        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
00:33:54.0066 5940        tcpipreg - ok
00:33:54.0248 5940        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
00:33:54.0303 5940        TDPIPE - ok
00:33:54.0476 5940        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
00:33:54.0539 5940        TDTCP - ok
00:33:54.0722 5940        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
00:33:54.0806 5940        tdx - ok
00:33:55.0020 5940        teamviewervpn  (9101fffcfccd1a30e870a5b8a9091b10) C:\Windows\system32\DRIVERS\teamviewervpn.sys
00:33:55.0086 5940        teamviewervpn - ok
00:33:55.0252 5940        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
00:33:55.0277 5940        TermDD - ok
00:33:55.0482 5940        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
00:33:55.0550 5940        tssecsrv - ok
00:33:55.0779 5940        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
00:33:55.0864 5940        tunmp - ok
00:33:56.0032 5940        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
00:33:56.0050 5940        tunnel - ok
00:33:56.0242 5940        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
00:33:56.0290 5940        uagp35 - ok
00:33:56.0470 5940        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
00:33:56.0574 5940        udfs - ok
00:33:56.0794 5940        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
00:33:56.0815 5940        uliagpkx - ok
00:33:56.0984 5940        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
00:33:57.0048 5940        uliahci - ok
00:33:57.0186 5940        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
00:33:57.0237 5940        UlSata - ok
00:33:57.0417 5940        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
00:33:57.0442 5940        ulsata2 - ok
00:33:57.0618 5940        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
00:33:57.0716 5940        umbus - ok
00:33:57.0779 5940        UnlockerDriver5 (bb879dcfd22926efbeb3298129898cbb) e:\Programme\Unlocker\UnlockerDriver5.sys
00:33:57.0822 5940        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
00:33:57.0823 5940        UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
00:33:57.0996 5940        USBAAPL        (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
00:33:58.0066 5940        USBAAPL - ok
00:33:58.0241 5940        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
00:33:58.0314 5940        usbaudio - ok
00:33:58.0494 5940        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
00:33:58.0584 5940        usbccgp - ok
00:33:58.0767 5940        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
00:33:58.0896 5940        usbcir - ok
00:33:59.0071 5940        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
00:33:59.0122 5940        usbehci - ok
00:33:59.0294 5940        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
00:33:59.0386 5940        usbhub - ok
00:33:59.0549 5940        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
00:33:59.0581 5940        usbohci - ok
00:33:59.0751 5940        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
00:33:59.0826 5940        usbprint - ok
00:34:00.0009 5940        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:34:00.0032 5940        USBSTOR - ok
00:34:00.0217 5940        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
00:34:00.0288 5940        usbuhci - ok
00:34:00.0506 5940        VBoxDrv        (103b23ec82c08fc4bdbc369552ffab2a) C:\Windows\system32\DRIVERS\VBoxDrv.sys
00:34:00.0599 5940        VBoxDrv - ok
00:34:00.0767 5940        VBoxNetAdp      (226cd9e42be28a84ec56430fbb57224f) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
00:34:00.0789 5940        VBoxNetAdp - ok
00:34:00.0949 5940        VBoxNetFlt      (0a5d6512dcb14135a388d0e7e69e01bb) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
00:34:00.0995 5940        VBoxNetFlt - ok
00:34:01.0253 5940        VBoxUSBMon      (96a478edfb1fbf1fc663beb09b4175a8) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
00:34:01.0349 5940        VBoxUSBMon - ok
00:34:01.0580 5940        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
00:34:01.0697 5940        vga - ok
00:34:01.0860 5940        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
00:34:01.0909 5940        VgaSave - ok
00:34:02.0082 5940        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
00:34:02.0103 5940        viaagp - ok
00:34:02.0286 5940        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
00:34:02.0363 5940        ViaC7 - ok
00:34:02.0561 5940        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
00:34:02.0581 5940        viaide - ok
00:34:02.0808 5940        vmci            (6f5d703bf312cb6cda78948763cb1e0d) C:\Windows\system32\Drivers\vmci.sys
00:34:02.0843 5940        vmci - ok
00:34:03.0006 5940        vmkbd          (27df4aece721961f9c9064a31790f2ea) C:\Windows\system32\drivers\VMkbd.sys
00:34:03.0022 5940        vmkbd - ok
00:34:03.0187 5940        vmm            (817da66b1b889fad1dbf669e0e2f3228) C:\Windows\system32\Drivers\vmm.sys
00:34:03.0207 5940        vmm - ok
00:34:03.0370 5940        VMnetAdapter    (e41704d8149992107b333cc7a52c07cc) C:\Windows\system32\DRIVERS\vmnetadapter.sys
00:34:03.0406 5940        VMnetAdapter - ok
00:34:03.0722 5940        VMnetBridge    (462f2a31ea8b87a28962aca998df1869) C:\Windows\system32\DRIVERS\vmnetbridge.sys
00:34:03.0755 5940        VMnetBridge - ok
00:34:03.0925 5940        VMnetuserif    (ea10f0c9333388d2ecc4068efb8c366d) C:\Windows\system32\drivers\vmnetuserif.sys
00:34:03.0950 5940        VMnetuserif - ok
00:34:04.0125 5940        VMparport      (311e4d0703f53faf7e7a5b3a2641d4fa) C:\Windows\system32\Drivers\VMparport.sys
00:34:04.0162 5940        VMparport - ok
00:34:04.0379 5940        vmx86          (35dc7079a413484423750db5d40b8ea6) C:\Windows\system32\Drivers\vmx86.sys
00:34:04.0547 5940        vmx86 - ok
00:34:04.0704 5940        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
00:34:04.0725 5940        volmgr - ok
00:34:04.0907 5940        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
00:34:04.0987 5940        volmgrx - ok
00:34:05.0192 5940        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
00:34:05.0286 5940        volsnap - ok
00:34:05.0513 5940        VPCNetS2        (2abe8281db609d8bb1bd1b2f93800d5f) C:\Windows\system32\DRIVERS\VMNetSrv.sys
00:34:05.0534 5940        VPCNetS2 - ok
00:34:05.0713 5940        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
00:34:05.0734 5940        vsmraid - ok
00:34:05.0788 5940        vstor2-ws60    (98929c5c5314c4c048e2f60492c26723) E:\Programme\VMware\VMware Player\vstor2-ws60.sys
00:34:05.0825 5940        vstor2-ws60 - ok
00:34:06.0034 5940        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
00:34:06.0137 5940        WacomPen - ok
00:34:06.0404 5940        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:34:06.0556 5940        Wanarp - ok
00:34:06.0596 5940        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:34:06.0623 5940        Wanarpv6 - ok
00:34:06.0829 5940        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
00:34:06.0857 5940        Wd - ok
00:34:07.0053 5940        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
00:34:07.0140 5940        Wdf01000 - ok
00:34:07.0408 5940        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
00:34:07.0482 5940        WmiAcpi - ok
00:34:07.0668 5940        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
00:34:07.0737 5940        WpdUsb - ok
00:34:07.0953 5940        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
00:34:08.0023 5940        ws2ifsl - ok
00:34:08.0280 5940        WSDPrintDevice  (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
00:34:08.0329 5940        WSDPrintDevice - ok
00:34:08.0527 5940        WudfPf          (13b5f255e90624a5ba0441d39cfb6be2) C:\Windows\system32\DRIVERS\WudfPf.sys
00:34:08.0594 5940        WudfPf - ok
00:34:08.0781 5940        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
00:34:08.0831 5940        WUDFRd - ok
00:34:08.0931 5940        XDva388 - ok
00:34:09.0009 5940        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
00:34:09.0067 5940        \Device\Harddisk0\DR0 - ok
00:34:09.0179 5940        MBR (0x1B8)    (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR2
00:34:09.0245 5940        \Device\Harddisk2\DR2 - ok
00:34:09.0265 5940        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
00:34:09.0307 5940        \Device\Harddisk1\DR1 ( TDSS File System ) - warning
00:34:09.0307 5940        \Device\Harddisk1\DR1 - detected TDSS File System (1)
00:34:09.0317 5940        MBR (0x1B8)    (65e858a8a0293be11a920b0bc99d695e) \Device\Harddisk3\DR3
00:34:10.0150 5940        \Device\Harddisk3\DR3 - ok
00:34:10.0156 5940        Boot (0x1200)  (b1e27aa018409de6bfd73f8afb883a65) \Device\Harddisk0\DR0\Partition0
00:34:10.0156 5940        \Device\Harddisk0\DR0\Partition0 - ok
00:34:10.0184 5940        Boot (0x1200)  (f8f14c5cab9c47583f1d5ef92ce8e6b6) \Device\Harddisk0\DR0\Partition1
00:34:10.0185 5940        \Device\Harddisk0\DR0\Partition1 - ok
00:34:10.0191 5940        Boot (0x1200)  (f109a278b35a02ec96b150cd4dffc89e) \Device\Harddisk2\DR2\Partition0
00:34:10.0191 5940        \Device\Harddisk2\DR2\Partition0 - ok
00:34:10.0213 5940        Boot (0x1200)  (8f7140eaa4a9a5749fdd82db7baa8307) \Device\Harddisk1\DR1\Partition0
00:34:10.0213 5940        \Device\Harddisk1\DR1\Partition0 - ok
00:34:10.0223 5940        Boot (0x1200)  (29da36f4271c988087019cd666b1936c) \Device\Harddisk3\DR3\Partition0
00:34:10.0224 5940        \Device\Harddisk3\DR3\Partition0 - ok
00:34:10.0224 5940        ============================================================
00:34:10.0224 5940        Scan finished
00:34:10.0224 5940        ============================================================
00:34:10.0244 4452        Detected object count: 7
00:34:10.0244 4452        Actual detected object count: 7
00:34:37.0035 4452        Dokan ( UnsignedFile.Multi.Generic ) - skipped by user
00:34:37.0035 4452        Dokan ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:34:37.0036 4452        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - skipped by user
00:34:37.0036 4452        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:34:37.0039 4452        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - skipped by user
00:34:37.0039 4452        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:34:37.0043 4452        pfc ( UnsignedFile.Multi.Generic ) - skipped by user
00:34:37.0043 4452        pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:34:37.0046 4452        sptd ( LockedFile.Multi.Generic ) - skipped by user
00:34:37.0046 4452        sptd ( LockedFile.Multi.Generic ) - User select action: Skip
00:34:37.0050 4452        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
00:34:37.0050 4452        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:34:37.0053 4452        \Device\Harddisk1\DR1 ( TDSS File System ) - skipped by user
00:34:37.0054 4452        \Device\Harddisk1\DR1 ( TDSS File System ) - User select action: Skip


cosinus 31.12.2011 15:17

Das TDSS File System bitte mit dem TDSS-Killer löschen lassen, starte Windows danach neu und mach ein neues Log mit diesem Tool. Poste es wieder mit CODE-Tags umschlossen.

TitanNano 31.12.2011 15:32

also noch mal scannen, dann Funde entfernen und dann noch mal scannen??

cosinus 02.01.2012 10:23

Ja aber bitte nur das TDSS File System löschen!!

TitanNano 02.01.2012 17:51

Code:

17:47:42.0511 4320        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
17:47:43.0660 4320        ============================================================
17:47:43.0661 4320        Current date / time: 2012/01/02 17:47:43.0660
17:47:43.0661 4320        SystemInfo:
17:47:43.0661 4320       
17:47:43.0661 4320        OS Version: 6.0.6002 ServicePack: 2.0
17:47:43.0661 4320        Product type: Workstation
17:47:43.0661 4320        ComputerName: TITAN21
17:47:43.0661 4320        UserName: Jovan
17:47:43.0661 4320        Windows directory: C:\Windows
17:47:43.0661 4320        System windows directory: C:\Windows
17:47:43.0661 4320        Processor architecture: Intel x86
17:47:43.0661 4320        Number of processors: 2
17:47:43.0661 4320        Page size: 0x1000
17:47:43.0661 4320        Boot type: Normal boot
17:47:43.0661 4320        ============================================================
17:47:46.0358 4320        Initialize success
17:47:58.0459 3252        ============================================================
17:47:58.0459 3252        Scan started
17:47:58.0459 3252        Mode: Manual; SigCheck; TDLFS;
17:47:58.0459 3252        ============================================================
17:48:01.0337 3252        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
17:48:01.0529 3252        ACPI - ok
17:48:02.0171 3252        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
17:48:02.0406 3252        adp94xx - ok
17:48:03.0128 3252        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
17:48:03.0315 3252        adpahci - ok
17:48:03.0752 3252        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
17:48:03.0784 3252        adpu160m - ok
17:48:04.0323 3252        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
17:48:04.0365 3252        adpu320 - ok
17:48:05.0085 3252        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
17:48:05.0329 3252        AFD - ok
17:48:05.0599 3252        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
17:48:05.0724 3252        agp440 - ok
17:48:06.0130 3252        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
17:48:06.0188 3252        aic78xx - ok
17:48:06.0599 3252        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
17:48:06.0637 3252        aliide - ok
17:48:07.0157 3252        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
17:48:07.0186 3252        amdagp - ok
17:48:07.0673 3252        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
17:48:07.0688 3252        amdide - ok
17:48:08.0256 3252        amdiox86        (ff258424f0b2ef25eb98f04ee386e6e3) C:\Windows\system32\DRIVERS\amdiox86.sys
17:48:08.0385 3252        amdiox86 - ok
17:48:08.0872 3252        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
17:48:09.0157 3252        AmdK7 - ok
17:48:09.0479 3252        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
17:48:10.0001 3252        AmdK8 - ok
17:48:11.0330 3252        amdkmdag        (ab70f110143892eb41aa46500aa5cf00) C:\Windows\system32\DRIVERS\atikmdag.sys
17:48:14.0778 3252        amdkmdag - ok
17:48:15.0525 3252        amdkmdap        (32d68d05b871eed5572d0c2c764ea4ec) C:\Windows\system32\DRIVERS\atikmpag.sys
17:48:15.0970 3252        amdkmdap - ok
17:48:16.0573 3252        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
17:48:17.0804 3252        arc - ok
17:48:18.0591 3252        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
17:48:18.0653 3252        arcsas - ok
17:48:19.0369 3252        AsIO            (2b4e66fac6503494a2c6f32bb6ab3826) C:\Windows\system32\drivers\AsIO.sys
17:48:19.0588 3252        AsIO - ok
17:48:19.0978 3252        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
17:48:20.0270 3252        AsyncMac - ok
17:48:21.0089 3252        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
17:48:21.0100 3252        atapi - ok
17:48:22.0230 3252        AtcL001        (55907c61656449ca8534c323d6eabc89) C:\Windows\system32\DRIVERS\l160x86.sys
17:48:22.0978 3252        AtcL001 - ok
17:48:23.0722 3252        AtiHDAudioService (c8f5273b12cfa5c0888263e34140cb8a) C:\Windows\system32\drivers\AtihdLH3.sys
17:48:23.0797 3252        AtiHDAudioService - ok
17:48:24.0617 3252        AtiHdmiService  (5e1cbda7d52289579e25283549e99425) C:\Windows\system32\drivers\AtiHdmi.sys
17:48:25.0759 3252        AtiHdmiService - ok
17:48:26.0891 3252        avgntflt        (7713e4eb0276702faa08e52a6e23f2a6) C:\Windows\system32\DRIVERS\avgntflt.sys
17:48:27.0037 3252        avgntflt - ok
17:48:28.0021 3252        avipbb          (475fbb85956534720858ae72010c0a43) C:\Windows\system32\DRIVERS\avipbb.sys
17:48:28.0335 3252        avipbb - ok
17:48:29.0332 3252        avkmgr          (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
17:48:29.0388 3252        avkmgr - ok
17:48:30.0152 3252        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
17:48:30.0358 3252        Beep - ok
17:48:31.0173 3252        blbdrive - ok
17:48:32.0156 3252        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
17:48:32.0219 3252        bowser - ok
17:48:32.0748 3252        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
17:48:34.0356 3252        BrFiltLo - ok
17:48:34.0679 3252        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
17:48:34.0759 3252        BrFiltUp - ok
17:48:35.0494 3252        Bridge          (b1564976d98e91fc764d5dc28a0297da) C:\Windows\system32\DRIVERS\bridge.sys
17:48:35.0590 3252        Bridge - ok
17:48:35.0669 3252        BridgeMP        (b1564976d98e91fc764d5dc28a0297da) C:\Windows\system32\DRIVERS\bridge.sys
17:48:35.0693 3252        BridgeMP - ok
17:48:36.0346 3252        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
17:48:36.0457 3252        Brserid - ok
17:48:36.0843 3252        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
17:48:37.0001 3252        BrSerWdm - ok
17:48:37.0410 3252        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
17:48:37.0578 3252        BrUsbMdm - ok
17:48:38.0059 3252        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
17:48:38.0438 3252        BrUsbSer - ok
17:48:38.0700 3252        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
17:48:38.0772 3252        BTHMODEM - ok
17:48:39.0451 3252        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
17:48:39.0793 3252        cdfs - ok
17:48:40.0432 3252        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
17:48:40.0548 3252        cdrom - ok
17:48:41.0249 3252        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
17:48:41.0424 3252        circlass - ok
17:48:41.0972 3252        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
17:48:42.0433 3252        CLFS - ok
17:48:42.0959 3252        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
17:48:43.0008 3252        cmdide - ok
17:48:43.0580 3252        Compbatt        (82b8c91d327cfecf76cb58716f7d4997) C:\Windows\system32\drivers\compbatt.sys
17:48:43.0659 3252        Compbatt - ok
17:48:44.0112 3252        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
17:48:44.0235 3252        crcdisk - ok
17:48:44.0787 3252        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
17:48:44.0899 3252        Crusoe - ok
17:48:45.0700 3252        CSC            (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys
17:48:45.0927 3252        CSC - ok
17:48:46.0555 3252        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
17:48:46.0780 3252        DfsC - ok
17:48:47.0232 3252        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
17:48:47.0283 3252        disk - ok
17:48:47.0862 3252        Dokan          (73b37188b998d9c51cf2016cad0848ac) C:\Windows\system32\drivers\dokan.sys
17:48:47.0914 3252        Dokan ( UnsignedFile.Multi.Generic ) - warning
17:48:47.0914 3252        Dokan - detected UnsignedFile.Multi.Generic (1)
17:48:48.0358 3252        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
17:48:48.0509 3252        drmkaud - ok
17:48:49.0073 3252        dtsoftbus01    (c0c7ceccb6c85994c2bc92d58e52d3f2) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
17:48:49.0089 3252        dtsoftbus01 - ok
17:48:50.0029 3252        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
17:48:50.0103 3252        DXGKrnl - ok
17:48:51.0004 3252        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
17:48:51.0141 3252        E1G60 - ok
17:48:51.0309 3252        EagleNT - ok
17:48:51.0708 3252        EagleXNt - ok
17:48:51.0987 3252        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
17:48:52.0059 3252        Ecache - ok
17:48:52.0717 3252        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
17:48:52.0779 3252        elxstor - ok
17:48:53.0320 3252        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
17:48:53.0410 3252        exfat - ok
17:48:54.0186 3252        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
17:48:54.0317 3252        fastfat - ok
17:48:54.0879 3252        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
17:48:54.0946 3252        fdc - ok
17:48:55.0351 3252        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
17:48:55.0422 3252        FileInfo - ok
17:48:55.0917 3252        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
17:48:55.0996 3252        Filetrace - ok
17:48:56.0376 3252        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
17:48:56.0511 3252        flpydisk - ok
17:48:57.0099 3252        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
17:48:57.0113 3252        FltMgr - ok
17:48:57.0408 3252        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
17:48:57.0470 3252        Fs_Rec - ok
17:48:58.0123 3252        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
17:48:58.0197 3252        gagp30kx - ok
17:48:58.0396 3252        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:48:58.0411 3252        GEARAspiWDM - ok
17:48:59.0060 3252        hamachi        (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
17:48:59.0075 3252        hamachi - ok
17:48:59.0462 3252        hcmon          (51fa91bb463b15fd8eacd5045c3f2fa6) C:\Windows\system32\drivers\hcmon.sys
17:48:59.0477 3252        hcmon - ok
17:49:00.0214 3252        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
17:49:00.0370 3252        HdAudAddService - ok
17:49:00.0958 3252        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
17:49:01.0178 3252        HDAudBus - ok
17:49:01.0411 3252        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
17:49:01.0485 3252        HidBth - ok
17:49:01.0911 3252        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
17:49:02.0013 3252        HidIr - ok
17:49:02.0378 3252        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
17:49:02.0485 3252        HidUsb - ok
17:49:02.0888 3252        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
17:49:03.0164 3252        HpCISSs - ok
17:49:03.0673 3252        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
17:49:04.0503 3252        HTTP - ok
17:49:05.0055 3252        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
17:49:05.0169 3252        i2omp - ok
17:49:05.0601 3252        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
17:49:05.0668 3252        i8042prt - ok
17:49:06.0266 3252        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
17:49:06.0297 3252        iaStorV - ok
17:49:06.0756 3252        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
17:49:06.0792 3252        iirsp - ok
17:49:07.0922 3252        IntcAzAudAddService (345ac48d17f5c2f2aa1ee50d34c3978b) C:\Windows\system32\drivers\RTKVHDA.sys
17:49:08.0612 3252        IntcAzAudAddService - ok
17:49:08.0885 3252        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
17:49:08.0920 3252        intelide - ok
17:49:09.0611 3252        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
17:49:09.0780 3252        intelppm - ok
17:49:10.0251 3252        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:49:10.0433 3252        IpFilterDriver - ok
17:49:10.0780 3252        IpInIp - ok
17:49:11.0072 3252        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
17:49:11.0157 3252        IPMIDRV - ok
17:49:11.0743 3252        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
17:49:11.0772 3252        IPNAT - ok
17:49:12.0600 3252        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
17:49:12.0705 3252        IRENUM - ok
17:49:13.0142 3252        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
17:49:13.0202 3252        isapnp - ok
17:49:13.0578 3252        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
17:49:13.0593 3252        iScsiPrt - ok
17:49:14.0048 3252        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
17:49:14.0108 3252        iteatapi - ok
17:49:14.0856 3252        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
17:49:14.0893 3252        iteraid - ok
17:49:15.0454 3252        jumi            (ee894427ac0b2b2c2c8b32cb78357dae) C:\Windows\system32\DRIVERS\jumi.sys
17:49:15.0516 3252        jumi - ok
17:49:15.0926 3252        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
17:49:15.0959 3252        kbdclass - ok
17:49:16.0438 3252        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
17:49:16.0598 3252        kbdhid - ok
17:49:16.0898 3252        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
17:49:16.0954 3252        KSecDD - ok
17:49:17.0673 3252        KUSBusByTCP    (632191f9aca2df8fb478c161f51a285a) C:\Windows\system32\Drivers\KUSBusByTCP.sys
17:49:17.0857 3252        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - warning
17:49:17.0857 3252        KUSBusByTCP - detected UnsignedFile.Multi.Generic (1)
17:49:18.0326 3252        KUSBusByTCPMasterBus (32a74618edd493669b478595c2e54c62) C:\Windows\system32\Drivers\KUSBusByTCPMasterBus.sys
17:49:18.0463 3252        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - warning
17:49:18.0463 3252        KUSBusByTCPMasterBus - detected UnsignedFile.Multi.Generic (1)
17:49:19.0084 3252        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
17:49:19.0270 3252        lltdio - ok
17:49:19.0962 3252        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
17:49:19.0997 3252        LSI_FC - ok
17:49:20.0309 3252        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
17:49:20.0363 3252        LSI_SAS - ok
17:49:21.0053 3252        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
17:49:21.0223 3252        LSI_SCSI - ok
17:49:21.0726 3252        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
17:49:22.0006 3252        luafv - ok
17:49:22.0296 3252        MBAMProtector  (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys
17:49:22.0431 3252        MBAMProtector - ok
17:49:23.0013 3252        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
17:49:23.0110 3252        megasas - ok
17:49:23.0425 3252        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
17:49:23.0499 3252        Modem - ok
17:49:24.0259 3252        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
17:49:24.0311 3252        monitor - ok
17:49:25.0079 3252        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
17:49:25.0167 3252        mouclass - ok
17:49:25.0476 3252        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
17:49:25.0528 3252        mouhid - ok
17:49:26.0146 3252        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
17:49:26.0246 3252        MountMgr - ok
17:49:27.0023 3252        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
17:49:27.0116 3252        mpio - ok
17:49:28.0066 3252        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
17:49:28.0123 3252        mpsdrv - ok
17:49:28.0442 3252        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
17:49:28.0499 3252        Mraid35x - ok
17:49:29.0120 3252        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
17:49:29.0263 3252        MRxDAV - ok
17:49:29.0670 3252        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:49:30.0036 3252        mrxsmb - ok
17:49:30.0471 3252        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:49:30.0590 3252        mrxsmb10 - ok
17:49:30.0985 3252        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:49:31.0170 3252        mrxsmb20 - ok
17:49:31.0347 3252        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
17:49:31.0365 3252        msahci - ok
17:49:31.0555 3252        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
17:49:31.0610 3252        msdsm - ok
17:49:31.0924 3252        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
17:49:32.0132 3252        Msfs - ok
17:49:32.0336 3252        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
17:49:32.0370 3252        msisadrv - ok
17:49:32.0603 3252        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
17:49:32.0663 3252        MSKSSRV - ok
17:49:33.0329 3252        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
17:49:33.0474 3252        MSPCLOCK - ok
17:49:33.0734 3252        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
17:49:33.0890 3252        MSPQM - ok
17:49:34.0341 3252        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
17:49:34.0373 3252        MsRPC - ok
17:49:34.0540 3252        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
17:49:34.0553 3252        mssmbios - ok
17:49:34.0883 3252        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
17:49:35.0003 3252        MSTEE - ok
17:49:35.0371 3252        MTsensor        (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys
17:49:35.0475 3252        MTsensor - ok
17:49:35.0729 3252        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
17:49:35.0790 3252        Mup - ok
17:49:36.0330 3252        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
17:49:36.0387 3252        NativeWifiP - ok
17:49:36.0683 3252        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
17:49:36.0721 3252        NDIS - ok
17:49:37.0106 3252        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
17:49:37.0196 3252        NdisTapi - ok
17:49:37.0492 3252        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
17:49:37.0575 3252        Ndisuio - ok
17:49:37.0787 3252        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
17:49:37.0900 3252        NdisWan - ok
17:49:38.0477 3252        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
17:49:38.0602 3252        NDProxy - ok
17:49:38.0960 3252        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
17:49:39.0295 3252        NetBIOS - ok
17:49:39.0889 3252        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
17:49:40.0079 3252        netbt - ok
17:49:40.0547 3252        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
17:49:40.0622 3252        nfrd960 - ok
17:49:40.0829 3252        NPF            (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys
17:49:40.0880 3252        NPF - ok
17:49:41.0053 3252        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
17:49:41.0106 3252        Npfs - ok
17:49:41.0581 3252        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
17:49:41.0634 3252        nsiproxy - ok
17:49:41.0918 3252        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
17:49:42.0163 3252        Ntfs - ok
17:49:42.0627 3252        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
17:49:42.0713 3252        ntrigdigi - ok
17:49:42.0961 3252        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
17:49:42.0999 3252        Null - ok
17:49:43.0183 3252        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
17:49:43.0227 3252        nvraid - ok
17:49:43.0731 3252        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
17:49:44.0009 3252        nvstor - ok
17:49:44.0188 3252        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
17:49:44.0230 3252        nv_agp - ok
17:49:44.0655 3252        NwlnkFlt - ok
17:49:44.0797 3252        NwlnkFwd - ok
17:49:44.0995 3252        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
17:49:45.0073 3252        ohci1394 - ok
17:49:45.0304 3252        Parport        (8a79fdf04a73428597e2caf9d0d67850) C:\Windows\system32\DRIVERS\parport.sys
17:49:45.0514 3252        Parport - ok
17:49:45.0755 3252        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
17:49:45.0863 3252        partmgr - ok
17:49:46.0026 3252        Parvdm          (6c580025c81caf3ae9e3617c22cad00e) C:\Windows\system32\DRIVERS\parvdm.sys
17:49:46.0092 3252        Parvdm - ok
17:49:46.0282 3252        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
17:49:46.0295 3252        pci - ok
17:49:46.0886 3252        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
17:49:46.0904 3252        pciide - ok
17:49:47.0087 3252        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
17:49:47.0112 3252        pcmcia - ok
17:49:47.0314 3252        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
17:49:48.0049 3252        PEAUTH - ok
17:49:48.0323 3252        pfc            (f2b3785d7282bac66d4b644fc88749f0) C:\Windows\system32\drivers\pfc.sys
17:49:48.0366 3252        pfc ( UnsignedFile.Multi.Generic ) - warning
17:49:48.0366 3252        pfc - detected UnsignedFile.Multi.Generic (1)
17:49:49.0161 3252        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
17:49:49.0200 3252        PptpMiniport - ok
17:49:49.0411 3252        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
17:49:49.0481 3252        Processor - ok
17:49:50.0015 3252        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
17:49:50.0074 3252        PSched - ok
17:49:50.0315 3252        PxHelp20        (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
17:49:50.0335 3252        PxHelp20 - ok
17:49:50.0532 3252        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
17:49:51.0059 3252        ql2300 - ok
17:49:51.0234 3252        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
17:49:51.0286 3252        ql40xx - ok
17:49:51.0464 3252        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
17:49:51.0552 3252        QWAVEdrv - ok
17:49:51.0932 3252        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
17:49:51.0981 3252        RasAcd - ok
17:49:52.0201 3252        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:49:52.0310 3252        Rasl2tp - ok
17:49:52.0499 3252        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
17:49:52.0561 3252        RasPppoe - ok
17:49:52.0974 3252        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
17:49:53.0132 3252        RasSstp - ok
17:49:53.0341 3252        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
17:49:53.0429 3252        rdbss - ok
17:49:53.0595 3252        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:49:53.0667 3252        RDPCDD - ok
17:49:54.0138 3252        rdpdr          (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys
17:49:54.0312 3252        rdpdr - ok
17:49:54.0494 3252        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
17:49:54.0567 3252        RDPENCDD - ok
17:49:54.0811 3252        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
17:49:55.0024 3252        RDPWD - ok
17:49:55.0323 3252        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
17:49:55.0426 3252        rspndr - ok
17:49:55.0600 3252        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
17:49:55.0643 3252        sbp2port - ok
17:49:56.0237 3252        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
17:49:56.0309 3252        secdrv - ok
17:49:56.0514 3252        Serenum        (ce9ec966638ef0b10b864ddedf62a099) C:\Windows\system32\DRIVERS\serenum.sys
17:49:56.0576 3252        Serenum - ok
17:49:56.0738 3252        Serial          (6d663022db3e7058907784ae14b69898) C:\Windows\system32\DRIVERS\serial.sys
17:49:56.0807 3252        Serial - ok
17:49:57.0273 3252        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
17:49:57.0318 3252        sermouse - ok
17:49:57.0505 3252        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
17:49:57.0603 3252        sffdisk - ok
17:49:57.0798 3252        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
17:49:57.0907 3252        sffp_mmc - ok
17:49:58.0478 3252        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
17:49:58.0614 3252        sffp_sd - ok
17:49:59.0326 3252        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
17:49:59.0434 3252        sfloppy - ok
17:49:59.0634 3252        Si3114r5        (09889d435edc82435b18c7c311fe5721) C:\Windows\system32\drivers\si3114r5.sys
17:49:59.0653 3252        Si3114r5 - ok
17:49:59.0928 3252        SiFilter        (46b92189fe4db53a09e3a0099aa3084c) C:\Windows\system32\drivers\siwinacc.sys
17:50:00.0069 3252        SiFilter - ok
17:50:00.0729 3252        SiRemFil        (b688378d258d1ecce4768cdb55d48d92) C:\Windows\system32\drivers\siremfil.sys
17:50:00.0752 3252        SiRemFil - ok
17:50:01.0394 3252        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
17:50:01.0417 3252        sisagp - ok
17:50:01.0880 3252        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
17:50:01.0977 3252        SiSRaid2 - ok
17:50:02.0908 3252        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
17:50:02.0982 3252        SiSRaid4 - ok
17:50:03.0652 3252        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
17:50:03.0835 3252        Smb - ok
17:50:04.0569 3252        snpstd - ok
17:50:05.0287 3252        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
17:50:05.0437 3252        spldr - ok
17:50:06.0788 3252        sptd            (8ea0fd60a5b047e0c734d51aace531c9) C:\Windows\System32\Drivers\sptd.sys
17:50:06.0788 3252        Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 8ea0fd60a5b047e0c734d51aace531c9
17:50:06.0978 3252        sptd ( LockedFile.Multi.Generic ) - warning
17:50:06.0978 3252        sptd - detected LockedFile.Multi.Generic (1)
17:50:07.0895 3252        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
17:50:08.0543 3252        srv - ok
17:50:09.0984 3252        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
17:50:10.0382 3252        srv2 - ok
17:50:11.0682 3252        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
17:50:11.0914 3252        srvnet - ok
17:50:12.0967 3252        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
17:50:13.0081 3252        ssmdrv - ok
17:50:13.0614 3252        StillCam        (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
17:50:13.0639 3252        StillCam - ok
17:50:14.0226 3252        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
17:50:14.0245 3252        swenum - ok
17:50:14.0485 3252        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
17:50:14.0537 3252        Symc8xx - ok
17:50:15.0130 3252        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
17:50:15.0176 3252        Sym_hi - ok
17:50:15.0362 3252        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
17:50:15.0381 3252        Sym_u3 - ok
17:50:15.0578 3252        tap0901        (98a1e6bc9f766b0b0a5bf00af847ef20) C:\Windows\system32\DRIVERS\tap0901.sys
17:50:15.0649 3252        tap0901 - ok
17:50:16.0209 3252        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
17:50:16.0416 3252        Tcpip - ok
17:50:16.0600 3252        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
17:50:16.0665 3252        Tcpip6 - ok
17:50:16.0986 3252        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
17:50:17.0153 3252        tcpipreg - ok
17:50:17.0336 3252        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
17:50:17.0368 3252        TDPIPE - ok
17:50:17.0547 3252        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
17:50:17.0618 3252        TDTCP - ok
17:50:17.0868 3252        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
17:50:18.0085 3252        tdx - ok
17:50:18.0490 3252        teamviewervpn  (9101fffcfccd1a30e870a5b8a9091b10) C:\Windows\system32\DRIVERS\teamviewervpn.sys
17:50:18.0571 3252        teamviewervpn - ok
17:50:18.0739 3252        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
17:50:18.0773 3252        TermDD - ok
17:50:19.0393 3252        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:50:19.0469 3252        tssecsrv - ok
17:50:19.0632 3252        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
17:50:19.0709 3252        tunmp - ok
17:50:20.0126 3252        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
17:50:20.0163 3252        tunnel - ok
17:50:20.0419 3252        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
17:50:20.0463 3252        uagp35 - ok
17:50:20.0681 3252        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
17:50:20.0761 3252        udfs - ok
17:50:21.0178 3252        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
17:50:21.0401 3252        uliagpkx - ok
17:50:21.0618 3252        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
17:50:21.0682 3252        uliahci - ok
17:50:21.0954 3252        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
17:50:22.0000 3252        UlSata - ok
17:50:22.0510 3252        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
17:50:22.0545 3252        ulsata2 - ok
17:50:22.0751 3252        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
17:50:22.0830 3252        umbus - ok
17:50:22.0983 3252        UnlockerDriver5 (bb879dcfd22926efbeb3298129898cbb) e:\Programme\Unlocker\UnlockerDriver5.sys
17:50:23.0256 3252        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
17:50:23.0256 3252        UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
17:50:23.0737 3252        USBAAPL        (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
17:50:23.0832 3252        USBAAPL - ok
17:50:23.0999 3252        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
17:50:24.0072 3252        usbaudio - ok
17:50:24.0293 3252        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
17:50:24.0516 3252        usbccgp - ok
17:50:24.0791 3252        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
17:50:25.0042 3252        usbcir - ok
17:50:25.0200 3252        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
17:50:25.0254 3252        usbehci - ok
17:50:25.0817 3252        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
17:50:25.0883 3252        usbhub - ok
17:50:26.0055 3252        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
17:50:26.0080 3252        usbohci - ok
17:50:26.0242 3252        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
17:50:26.0291 3252        usbprint - ok
17:50:26.0896 3252        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:50:26.0935 3252        USBSTOR - ok
17:50:27.0115 3252        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
17:50:27.0224 3252        usbuhci - ok
17:50:27.0769 3252        VBoxDrv        (103b23ec82c08fc4bdbc369552ffab2a) C:\Windows\system32\DRIVERS\VBoxDrv.sys
17:50:27.0850 3252        VBoxDrv - ok
17:50:28.0022 3252        VBoxNetAdp      (226cd9e42be28a84ec56430fbb57224f) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
17:50:28.0053 3252        VBoxNetAdp - ok
17:50:28.0221 3252        VBoxNetFlt      (0a5d6512dcb14135a388d0e7e69e01bb) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
17:50:28.0258 3252        VBoxNetFlt - ok
17:50:28.0591 3252        VBoxUSBMon      (96a478edfb1fbf1fc663beb09b4175a8) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
17:50:28.0722 3252        VBoxUSBMon - ok
17:50:29.0018 3252        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
17:50:29.0122 3252        vga - ok
17:50:29.0291 3252        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
17:50:29.0337 3252        VgaSave - ok
17:50:29.0869 3252        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
17:50:29.0888 3252        viaagp - ok
17:50:30.0065 3252        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
17:50:30.0178 3252        ViaC7 - ok
17:50:30.0373 3252        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
17:50:30.0411 3252        viaide - ok
17:50:31.0028 3252        vmci            (6f5d703bf312cb6cda78948763cb1e0d) C:\Windows\system32\Drivers\vmci.sys
17:50:31.0063 3252        vmci - ok
17:50:31.0226 3252        vmkbd          (27df4aece721961f9c9064a31790f2ea) C:\Windows\system32\drivers\VMkbd.sys
17:50:31.0241 3252        vmkbd - ok
17:50:31.0414 3252        vmm            (817da66b1b889fad1dbf669e0e2f3228) C:\Windows\system32\Drivers\vmm.sys
17:50:31.0436 3252        vmm - ok
17:50:31.0732 3252        VMnetAdapter    (e41704d8149992107b333cc7a52c07cc) C:\Windows\system32\DRIVERS\vmnetadapter.sys
17:50:31.0758 3252        VMnetAdapter - ok
17:50:32.0158 3252        VMnetBridge    (462f2a31ea8b87a28962aca998df1869) C:\Windows\system32\DRIVERS\vmnetbridge.sys
17:50:32.0194 3252        VMnetBridge - ok
17:50:32.0362 3252        VMnetuserif    (ea10f0c9333388d2ecc4068efb8c366d) C:\Windows\system32\drivers\vmnetuserif.sys
17:50:32.0392 3252        VMnetuserif - ok
17:50:32.0570 3252        VMparport      (311e4d0703f53faf7e7a5b3a2641d4fa) C:\Windows\system32\Drivers\VMparport.sys
17:50:32.0606 3252        VMparport - ok
17:50:33.0058 3252        vmx86          (35dc7079a413484423750db5d40b8ea6) C:\Windows\system32\Drivers\vmx86.sys
17:50:33.0178 3252        vmx86 - ok
17:50:33.0332 3252        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
17:50:33.0352 3252        volmgr - ok
17:50:33.0535 3252        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
17:50:33.0598 3252        volmgrx - ok
17:50:34.0111 3252        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
17:50:34.0308 3252        volsnap - ok
17:50:34.0499 3252        VPCNetS2        (2abe8281db609d8bb1bd1b2f93800d5f) C:\Windows\system32\DRIVERS\VMNetSrv.sys
17:50:34.0518 3252        VPCNetS2 - ok
17:50:34.0707 3252        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
17:50:34.0795 3252        vsmraid - ok
17:50:34.0917 3252        vstor2-ws60    (98929c5c5314c4c048e2f60492c26723) E:\Programme\VMware\VMware Player\vstor2-ws60.sys
17:50:35.0002 3252        vstor2-ws60 - ok
17:50:35.0211 3252        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
17:50:35.0305 3252        WacomPen - ok
17:50:35.0490 3252        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:50:35.0549 3252        Wanarp - ok
17:50:35.0590 3252        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:50:35.0611 3252        Wanarpv6 - ok
17:50:36.0123 3252        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
17:50:36.0148 3252        Wd - ok
17:50:36.0339 3252        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
17:50:36.0457 3252        Wdf01000 - ok
17:50:36.0719 3252        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
17:50:36.0782 3252        WmiAcpi - ok
17:50:37.0194 3252        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
17:50:37.0239 3252        WpdUsb - ok
17:50:37.0409 3252        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
17:50:37.0481 3252        ws2ifsl - ok
17:50:37.0649 3252        WSDPrintDevice  (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
17:50:37.0687 3252        WSDPrintDevice - ok
17:50:38.0262 3252        WudfPf          (13b5f255e90624a5ba0441d39cfb6be2) C:\Windows\system32\DRIVERS\WudfPf.sys
17:50:38.0338 3252        WudfPf - ok
17:50:38.0524 3252        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:50:38.0569 3252        WUDFRd - ok
17:50:38.0674 3252        XDva388 - ok
17:50:38.0742 3252        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
17:50:38.0809 3252        \Device\Harddisk0\DR0 - ok
17:50:38.0832 3252        MBR (0x1B8)    (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR2
17:50:38.0882 3252        \Device\Harddisk2\DR2 - ok
17:50:38.0925 3252        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
17:50:39.0266 3252        \Device\Harddisk1\DR1 - ok
17:50:39.0274 3252        MBR (0x1B8)    (65e858a8a0293be11a920b0bc99d695e) \Device\Harddisk3\DR3
17:50:39.0843 3252        \Device\Harddisk3\DR3 - ok
17:50:39.0848 3252        Boot (0x1200)  (b1e27aa018409de6bfd73f8afb883a65) \Device\Harddisk0\DR0\Partition0
17:50:39.0848 3252        \Device\Harddisk0\DR0\Partition0 - ok
17:50:39.0876 3252        Boot (0x1200)  (f8f14c5cab9c47583f1d5ef92ce8e6b6) \Device\Harddisk0\DR0\Partition1
17:50:39.0877 3252        \Device\Harddisk0\DR0\Partition1 - ok
17:50:39.0881 3252        Boot (0x1200)  (f109a278b35a02ec96b150cd4dffc89e) \Device\Harddisk2\DR2\Partition0
17:50:39.0884 3252        \Device\Harddisk2\DR2\Partition0 - ok
17:50:39.0931 3252        Boot (0x1200)  (8f7140eaa4a9a5749fdd82db7baa8307) \Device\Harddisk1\DR1\Partition0
17:50:39.0946 3252        \Device\Harddisk1\DR1\Partition0 - ok
17:50:39.0955 3252        Boot (0x1200)  (29da36f4271c988087019cd666b1936c) \Device\Harddisk3\DR3\Partition0
17:50:39.0956 3252        \Device\Harddisk3\DR3\Partition0 - ok
17:50:39.0956 3252        ============================================================
17:50:39.0956 3252        Scan finished
17:50:39.0956 3252        ============================================================
17:50:39.0979 5560        Detected object count: 6
17:50:39.0979 5560        Actual detected object count: 6
17:50:52.0271 5560        Dokan ( UnsignedFile.Multi.Generic ) - skipped by user
17:50:52.0271 5560        Dokan ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:50:52.0271 5560        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - skipped by user
17:50:52.0271 5560        KUSBusByTCP ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:50:52.0271 5560        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - skipped by user
17:50:52.0271 5560        KUSBusByTCPMasterBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:50:52.0272 5560        pfc ( UnsignedFile.Multi.Generic ) - skipped by user
17:50:52.0272 5560        pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:50:52.0272 5560        sptd ( LockedFile.Multi.Generic ) - skipped by user
17:50:52.0272 5560        sptd ( LockedFile.Multi.Generic ) - User select action: Skip
17:50:52.0272 5560        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
17:50:52.0272 5560        UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 02.01.2012 20:51

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

TitanNano 02.01.2012 21:27

Code:

ComboFix 12-01-02.01 - Jovan 02.01.2012  21:05:05.1.2 - x86
Microsoft® Windows Vista™ Business  6.0.6002.2.1252.49.1031.18.2047.1096 [GMT 1:00]
ausgeführt von:: d:\benutzer\Jovan\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0407.exe
c:\windows\system32\shsvcs.dll.vgorg
c:\windows\system32\themeui.dll.vgorg
c:\windows\system32\uxtheme.dll.vgorg
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-02 bis 2012-01-02  ))))))))))))))))))))))))))))))
.
.
2012-01-02 20:17 . 2012-01-02 20:17        --------        d-----w-        c:\users\Jovan\AppData\Local\temp
2012-01-02 16:45 . 2012-01-02 16:45        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{52BDA092-9A86-4AC2-9580-29A6C8ECA708}\offreg.dll
2012-01-01 12:34 . 2012-01-01 12:34        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\Imperium Romanum
2012-01-01 12:27 . 2012-01-01 12:27        --------        d-----w-        c:\users\User\AppData\Roaming\Imperium Romanum
2011-12-30 16:45 . 2011-12-30 16:45        --------        d-----w-        c:\program files\Skype
2011-12-30 16:45 . 2011-12-30 16:45        --------        d-----w-        c:\programdata\Skype
2011-12-29 17:12 . 2011-12-29 17:12        --------        d-----w-        c:\users\Jovan\AppData\Roaming\Malwarebytes
2011-12-29 17:12 . 2011-12-10 14:24        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-28 19:44 . 2011-12-28 19:44        --------        d-----w-        c:\program files\BillP Studios
2011-12-27 17:27 . 2011-12-27 17:27        --------        d-----w-        c:\users\Cyrill\AppData\Local\Apple
2011-12-27 08:55 . 2012-01-01 15:38        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\Skype
2011-12-25 00:51 . 2011-12-25 00:51        --------        d-----w-        c:\programdata\ATI
2011-12-25 00:51 . 2011-12-25 00:51        --------        d-----w-        c:\program files\AMD APP
2011-12-22 19:15 . 2011-12-22 19:15        --------        d-----w-        c:\users\Jovan\AppData\Local\Borland
2011-12-22 19:13 . 2011-12-30 23:23        --------        d-----w-        c:\users\Jovan\.borland
2011-12-22 19:04 . 2011-12-22 19:12        --------        d-----w-        c:\users\Jovan\AppData\Local\ApplicationHistory
2011-12-22 19:04 . 2011-12-22 19:04        --------        d-----w-        c:\users\Jovan\AppData\Local\Microsoft Help
2011-12-22 19:01 . 2011-12-22 19:01        --------        d-----w-        c:\program files\Microsoft Visual Studio .NET 2003
2011-12-22 19:01 . 2011-12-22 19:13        --------        d-----w-        c:\programdata\Microsoft Help
2011-12-22 18:51 . 2011-12-22 18:51        --------        d-----w-        c:\windows\system32\URTTEMP
2011-12-21 17:58 . 2011-12-19 13:11        158512        ----a-w-        c:\windows\system32\drivers\VBoxDrv.sys
2011-12-21 17:57 . 2011-12-19 13:11        91440        ----a-w-        c:\windows\system32\drivers\VBoxUSBMon.sys
2011-12-19 13:12 . 2011-12-19 13:12        104752        ----a-w-        c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 13:11 . 2011-12-19 13:11        116016        ----a-w-        c:\windows\system32\drivers\VBoxNetFlt.sys
2011-12-19 13:11 . 2011-12-19 13:11        135472        ----a-w-        c:\windows\system32\VBoxNetFltNobj.dll
2011-12-16 17:23 . 2011-12-16 17:23        --------        d-----w-        c:\users\Cyrill\AppData\Local\Warner Bros. Interactive Entertainment
2011-12-16 15:11 . 2011-12-16 15:11        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\WB Games
2011-12-11 13:58 . 2007-01-04 11:02        663552        ----a-w-        c:\windows\system32\mgxoschk.dll
2011-12-10 22:37 . 2011-12-10 22:37        --------        d-----w-        c:\users\Jovan\AppData\Local\Xara
2011-12-10 22:37 . 2011-12-10 22:37        --------        d-----w-        c:\program files\Common Files\MAGIX Shared
2011-12-10 22:30 . 2011-12-10 22:30        --------        d-----w-        c:\program files\MAGIX
2011-12-10 16:58 . 2011-12-10 22:25        --------        d-----w-        c:\users\Jovan\AppData\Roaming\TS3Client
2011-12-09 16:47 . 2011-12-09 17:42        --------        d-----w-        c:\users\Cyrill\AppData\Local\gtk-2.0
2011-12-09 16:44 . 2011-12-09 17:56        --------        d-----w-        c:\users\Cyrill\.gimp-2.7
2011-12-09 16:44 . 2011-12-09 16:44        --------        d-----w-        c:\users\Cyrill\AppData\Local\gegl-0.1
2011-12-06 16:09 . 2011-12-18 18:43        --------        d-----w-        c:\users\Jovan\AppData\Local\gtk-2.0
2011-12-06 16:02 . 2009-08-24 21:08        28160        ----a-w-        c:\windows\system32\DfSdkBt.exe
2011-12-06 16:02 . 2011-12-30 22:30        --------        d-----w-        c:\users\Jovan\.gimp-2.7
2011-12-06 16:02 . 2011-12-06 16:02        --------        d-----w-        c:\users\Jovan\AppData\Local\gegl-0.1
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-08 18:23 . 2011-10-18 19:26        134856        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-11-12 12:36 . 2011-05-30 15:35        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 03:44 . 2011-11-10 03:44        8913920        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-11-10 03:17 . 2011-11-10 03:17        159744        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-11-10 03:16 . 2010-05-05 02:19        774656        ----a-w-        c:\windows\system32\aticfx32.dll
2011-11-10 03:12 . 2011-11-10 03:12        466944        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-11-10 03:11 . 2011-11-10 03:11        417792        ----a-w-        c:\windows\system32\atieclxx.exe
2011-11-10 03:11 . 2011-11-10 03:11        176128        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-11-10 03:10 . 2011-11-10 03:10        163840        ----a-w-        c:\windows\system32\atitmmxx.dll
2011-11-10 03:09 . 2011-11-10 03:09        360448        ----a-w-        c:\windows\system32\atipdlxx.dll
2011-11-10 03:09 . 2011-11-10 03:09        278528        ----a-w-        c:\windows\system32\Oemdspif.dll
2011-11-10 03:09 . 2011-11-10 03:09        20992        ----a-w-        c:\windows\system32\atimuixx.dll
2011-11-10 03:09 . 2011-11-10 03:09        43520        ----a-w-        c:\windows\system32\ati2edxx.dll
2011-11-10 03:06 . 2011-11-10 03:06        6077952        ----a-w-        c:\windows\system32\atidxx32.dll
2011-11-10 02:58 . 2011-11-10 02:58        18996224        ----a-w-        c:\windows\system32\atioglxx.dll
2011-11-10 02:40 . 2011-11-10 02:40        1828864        ----a-w-        c:\windows\system32\atiumdmv.dll
2011-11-10 02:34 . 2011-11-10 02:34        46080        ----a-w-        c:\windows\system32\aticalrt.dll
2011-11-10 02:34 . 2011-11-10 02:34        44032        ----a-w-        c:\windows\system32\aticalcl.dll
2011-11-10 02:33 . 2010-05-05 01:41        5852672        ----a-w-        c:\windows\system32\atiumdag.dll
2011-11-10 02:29 . 2011-11-10 02:29        11300864        ----a-w-        c:\windows\system32\aticaldd.dll
2011-11-10 02:29 . 2010-05-05 01:19        4200960        ----a-w-        c:\windows\system32\atiumdva.dll
2011-11-10 02:18 . 2011-04-05 15:27        51200        ----a-w-        c:\windows\system32\coinst.dll
2011-11-10 02:13 . 2011-11-10 02:13        348160        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-11-10 02:13 . 2011-11-10 02:13        14336        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-11-10 02:12 . 2011-11-10 02:12        32768        ----a-w-        c:\windows\system32\atigktxx.dll
2011-11-10 02:12 . 2011-11-10 02:12        263680        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-11-10 02:11 . 2011-11-10 02:11        32256        ----a-w-        c:\windows\system32\atiuxpag.dll
2011-11-10 02:11 . 2010-05-05 01:22        29184        ----a-w-        c:\windows\system32\atiu9pag.dll
2011-11-10 02:11 . 2011-11-10 02:11        53760        ----a-w-        c:\windows\system32\atimpc32.dll
2011-11-10 02:11 . 2011-11-10 02:11        53760        ----a-w-        c:\windows\system32\amdpcom32.dll
2011-11-10 02:11 . 2010-05-05 01:21        37376        ----a-w-        c:\windows\system32\atitmpxx.dll
2011-11-10 02:10 . 2011-11-10 02:10        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-11-09 21:39 . 2011-11-09 21:39        59904        ----a-w-        c:\windows\system32\OpenVideo.dll
2011-11-09 21:39 . 2011-11-09 21:39        54784        ----a-w-        c:\windows\system32\OVDecode.dll
2011-11-09 21:38 . 2011-11-09 21:38        14375936        ----a-w-        c:\windows\system32\amdocl.dll
2011-11-09 21:37 . 2011-11-09 21:37        44032        ----a-w-        c:\windows\system32\OpenCL.dll
2011-10-30 18:48 . 2011-04-05 15:30        319456        ----a-w-        c:\windows\DIFxAPI.dll
2011-10-25 20:21 . 2011-10-25 20:21        56832        ----a-w-        c:\windows\system32\OVDecoder.dll
2011-10-24 13:29 . 2011-10-24 13:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-21 19:16 . 2011-10-21 19:16        1843200        ----a-w-        c:\windows\system32\SlotMaximizerBe.dll
2011-10-21 19:15 . 2011-10-21 19:15        104448        ----a-w-        c:\windows\system32\SlotMaximizerAg.dll
2011-10-18 18:53 . 2011-10-30 18:23        3546664        ----a-w-        c:\windows\system32\drivers\RTKVHDA.sys
2011-10-18 17:10 . 2011-10-30 18:23        83048        ----a-w-        c:\windows\system32\RtkCoInst.dll
2011-10-18 14:57 . 2011-10-30 18:23        58264        ----a-w-        c:\windows\system32\TepeqAPO.dll
2011-10-18 12:47 . 2011-10-30 18:23        1329768        ----a-w-        c:\windows\system32\RtkApoApi.dll
2011-10-18 10:05 . 2011-10-30 18:23        2276968        ----a-w-        c:\windows\system32\RtkPgExt.dll
2011-10-17 17:40 . 2011-10-17 17:40        82960        ----a-w-        c:\windows\system32\drivers\AtihdLH3.sys
2011-10-17 16:30 . 2011-10-30 18:23        4238440        ----a-w-        c:\windows\system32\RtkAPO.dll
2011-10-14 12:43 . 2011-10-30 18:22        1873920        ----a-w-        c:\windows\system32\RCoRes.dat
2011-10-11 13:00 . 2011-10-18 19:26        74640        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2011-10-11 13:00 . 2011-10-18 19:26        36000        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2011-10-07 03:48 . 2011-11-18 14:33        6668624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{52BDA092-9A86-4AC2-9580-29A6C8ECA708}\mpengine.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="e:\programme\RocketDock\RocketDock.exe" [2007-09-02 495616]
"BackgroundSwitcher"="e:\programme\John's Background Switcher\BackgroundSwitcher.exe" [2011-07-07 119104]
"MonitorSwitch"="e:\programme\MonitorSwitch\MonitorSwitch.exe" [2011-07-06 696320]
"ViGlance"="c:\program files\ViGlance\ViGlance.exe" [2011-10-21 446464]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Skype"="c:\programme\Skype\Phone\Skype.exe" [2011-11-09 17049736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-05 59240]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-10-17 11430504]
"avgnt"="e:\programme\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"TrayServer"="e:\programme\MAGIX\Video_deluxe_MX_Premium_Download-Version\TrayServer_de.exe" [2008-08-07 90112]
"iTunesHelper"="e:\programme\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"StartCCC"="e:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-11-09 343168]
"Malwarebytes' Anti-Malware"="e:\programme\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileAssociate"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1708537768-1659004503-725345543-1009]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DokanMounter;DokanMounter;c:\program files\Dokan\DokanLibrary\mounter.exe [2010-07-05 11776]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R2 MySQL51;MySQL51;c:\program files\MySQL\MySQL Server 5.5\bin\mysqld --defaults-file=c:\program files\MySQL\MySQL Server 5.5\my.ini MySQL51 [x]
R3 DfSdkS;Defragmentation-Service;e:\programme\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 jumi;%Jumi%;c:\windows\system32\DRIVERS\jumi.sys [2010-06-03 13112]
R3 KUSBusByTCP;KUSBusByTCP;c:\windows\system32\Drivers\KUSBusByTCP.sys [2009-12-18 88064]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
R3 XDva388;XDva388;c:\windows\system32\XDva388.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-11 36000]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 158512]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 91440]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-11-10 176128]
S2 AMD FUEL Service;AMD FUEL Service;e:\programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-11-09 291840]
S2 AntiVirSchedulerService;Avira Planer;e:\programme\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys [2010-07-05 84992]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-05-24 1840128]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;e:\programme\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 1361288]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
S2 MBAMService;MBAMService;e:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 TeamViewer6;TeamViewer 6;e:\programme\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-17 2358656]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2011-03-25 70768]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-03-25 539248]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-11-10 8913920]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-11-10 263680]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2008-11-12 46592]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-10-17 82960]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-20 232512]
S3 KUSBusByTCPMasterBus;Master Bus of Kernel USB Software Bus by TCP;c:\windows\system32\Drivers\KUSBusByTCPMasterBus.sys [2009-12-18 60672]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 25088]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 116016]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 46961904
*Deregistered* - 46961904
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork        REG_MULTI_SZ          PLA DPS BFE mpssvc
dot3svc        REG_MULTI_SZ          dot3svc
eapsvcs        REG_MULTI_SZ          eaphost
WudfServiceGroup        REG_MULTI_SZ          WUDFSvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-29 c:\windows\Tasks\AdobeAAMUpdater-1.0-TITAN21-Jovan.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-05-11 00:25]
.
2012-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc7ab8f1c7f6ed.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 18:47]
.
2012-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 18:47]
.
2011-08-29 c:\windows\Tasks\{20D6952E-68DE-4424-86A1-52A986B2CC2B}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
2011-07-12 c:\windows\Tasks\{B668B532-98D5-494C-820D-87372AC7F773}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
2011-06-11 c:\windows\Tasks\{CAF720F3-3F53-4E82-A427-E5CB36721989}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
IE: {{20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - c:\windows\system32\mscoree.DLL
LSP: e:\programme\VMware\VMware Player\vsocklib.dll
TCP: Interfaces\{D893A6ED-7C8B-4434-B976-A0975702250E}: NameServer = 192.168.178.1,192.168.16.101
FF - ProfilePath - c:\users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google.de
FF - prefs.js: browser.startup.homepage - chrome://
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 2
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - true
.
.
------- Dateityp-Verknüpfung -------
.
.scr=SageThumbsImage.scr
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-DU Meter - e:\programme\DU Meter\DUMeter.exe
HKLM-Run-WinPatrol - c:\programme\BillP Studios\WinPatrol\winpatrol.exe
AddRemove-69083DC58646DE46A09847A522A1CC487F918039 - c:\progra~1\DIFX\270581~1\dpinst32.exe
AddRemove-9722CA1E8F72F362E93CBEC75A707FDABFC8D880 - c:\progra~1\DIFX\270581~1\dpinst32.exe
AddRemove-EAX Unified - c:\program files\Creative\EAX Unified\Uninst.isu
AddRemove-Memento Mori_is1 - d:\games\Memento Mori\unins000.exe
AddRemove-Mozilla Firefox 4.0 (x86 de) - c:\program files\Mozilla Firefox 4.0\uninstall\helper.exe
AddRemove-No23 Recorder - c:\programdata\Caphyon\Advanced Installer\{6DED41BC-C9EF-4330-B4E5-46CB2C5C6E2D}\No23 Recorder.exe
AddRemove-No23Live - c:\programdata\Caphyon\Advanced Installer\{6A1482E0-7119-4A66-BBF1-FFD95A6BA16C}\No23Live.exe
AddRemove-NVIDIA Drivers - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-S4Uninst - c:\windows\IsUn0407.exe
AddRemove-UnZip-5.51_is1 - e:\programme\MinGW\uninstall\unins001.exe
AddRemove-ViSploreBeta1 - c:\progra~1\ViSplore\KillMe.exe
AddRemove-Wget-1.11.4-1_is1 - e:\programme\MinGW\uninstall\unins000.exe
AddRemove-xSIMS_NRaas_MasterController - d:\benutzer\Jovan\Electronic Arts\Die Sims 3\Mods\xSIMS_UnInstaller_for_NRaas_MasterController.exe
AddRemove-Mozilla Firefox 4.0.1 (x86 de) - c:\program files\Mozilla Firefox 4.0\uninstall\helper.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-02 21:17
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MySQL51]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.5\my.ini\" MySQL51"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1708537768-1659004503-725345543-1009\Software\SecuROM\License information*]
"datasecu"=hex:4e,02,fb,03,b7,83,48,b4,91,d8,67,01,d4,95,79,c5,a4,e4,cd,3f,d7,
  86,b0,42,3a,ee,91,df,86,4e,2d,24,39,84,70,f2,22,f9,d7,78,91,c4,cd,69,5c,cf,\
"rkeysecu"=hex:c4,b1,33,40,0f,ad,de,9b,22,45,e3,64,83,36,1d,d8
.
Zeit der Fertigstellung: 2012-01-02  21:22:21
ComboFix-quarantined-files.txt  2012-01-02 20:22
.
Vor Suchlauf: 6 Verzeichnis(se), 18.496.614.400 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 23.893.360.640 Bytes frei
.
- - End Of File - - FB17FB127CCB843722251C200C987C93


cosinus 02.01.2012 22:07

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

File::
c:\windows\system32\XDva388.sys

Driver::
XDva388

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

TitanNano 02.01.2012 23:08

Code:

ComboFix 12-01-02.01 - Jovan 02.01.2012  22:36:27.2.2 - x86
Microsoft® Windows Vista™ Business  6.0.6002.2.1252.49.1031.18.2047.1215 [GMT 1:00]
ausgeführt von:: d:\benutzer\Jovan\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: d:\benutzer\Jovan\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\XDva388.sys"
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((  Treiber/Dienste  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA388
-------\Service_XDva388
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-02 bis 2012-01-02  ))))))))))))))))))))))))))))))
.
.
2012-01-02 21:54 . 2012-01-02 21:54        0        ---ha-w-        c:\users\Jovan\AppData\Local\BITC89C.tmp
2012-01-02 21:54 . 2012-01-02 21:54        0        ---ha-w-        c:\users\Jovan\AppData\Local\BITC570.tmp
2012-01-02 21:51 . 2012-01-02 21:51        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{52BDA092-9A86-4AC2-9580-29A6C8ECA708}\offreg.dll
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\users\User\AppData\Local\temp
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\users\Cyrill\AppData\Local\temp
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\dokumente und einstellungen\NetworkService.NT-AUTORITÄT\Lokale Einstellungen\Anwendungsdaten\temp        ERROR(0x00000005)
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\dokumente und einstellungen\LocalService.NT-AUTORITÄT\Lokale Einstellungen\Anwendungsdaten\temp        ERROR(0x00000005)
2012-01-02 21:47 . 2012-01-02 21:47        --------        d-----w-        c:\dokumente und einstellungen\Default User.WINDOWS\Lokale Einstellungen\Anwendungsdaten\temp        ERROR(0x00000005)
2012-01-02 20:22 . 2012-01-02 21:53        --------        d-----w-        c:\users\Jovan\AppData\Local\temp
2012-01-01 12:34 . 2012-01-01 12:34        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\Imperium Romanum
2012-01-01 12:27 . 2012-01-01 12:27        --------        d-----w-        c:\users\User\AppData\Roaming\Imperium Romanum
2011-12-30 16:45 . 2011-12-30 16:45        --------        d-----w-        c:\program files\Skype
2011-12-30 16:45 . 2011-12-30 16:45        --------        d-----w-        c:\programdata\Skype
2011-12-29 17:12 . 2011-12-29 17:12        --------        d-----w-        c:\users\Jovan\AppData\Roaming\Malwarebytes
2011-12-29 17:12 . 2011-12-10 14:24        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-28 19:44 . 2011-12-28 19:44        --------        d-----w-        c:\program files\BillP Studios
2011-12-27 17:27 . 2011-12-27 17:27        --------        d-----w-        c:\users\Cyrill\AppData\Local\Apple
2011-12-27 08:55 . 2012-01-01 15:38        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\Skype
2011-12-25 00:51 . 2011-12-25 00:51        --------        d-----w-        c:\programdata\ATI
2011-12-25 00:51 . 2011-12-25 00:51        --------        d-----w-        c:\program files\AMD APP
2011-12-22 19:15 . 2011-12-22 19:15        --------        d-----w-        c:\users\Jovan\AppData\Local\Borland
2011-12-22 19:13 . 2011-12-30 23:23        --------        d-----w-        c:\users\Jovan\.borland
2011-12-22 19:04 . 2011-12-22 19:12        --------        d-----w-        c:\users\Jovan\AppData\Local\ApplicationHistory
2011-12-22 19:04 . 2011-12-22 19:04        --------        d-----w-        c:\users\Jovan\AppData\Local\Microsoft Help
2011-12-22 19:01 . 2011-12-22 19:01        --------        d-----w-        c:\program files\Microsoft Visual Studio .NET 2003
2011-12-22 19:01 . 2011-12-22 19:13        --------        d-----w-        c:\programdata\Microsoft Help
2011-12-21 17:58 . 2011-12-19 13:11        158512        ----a-w-        c:\windows\system32\drivers\VBoxDrv.sys
2011-12-21 17:57 . 2011-12-19 13:11        91440        ----a-w-        c:\windows\system32\drivers\VBoxUSBMon.sys
2011-12-19 13:12 . 2011-12-19 13:12        104752        ----a-w-        c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 13:11 . 2011-12-19 13:11        116016        ----a-w-        c:\windows\system32\drivers\VBoxNetFlt.sys
2011-12-16 17:23 . 2011-12-16 17:23        --------        d-----w-        c:\users\Cyrill\AppData\Local\Warner Bros. Interactive Entertainment
2011-12-16 15:11 . 2011-12-16 15:11        --------        d-----w-        c:\users\Cyrill\AppData\Roaming\WB Games
2011-12-11 13:58 . 2007-01-04 11:02        663552        ----a-w-        c:\windows\system32\mgxoschk.dll
2011-12-10 22:37 . 2011-12-10 22:37        --------        d-----w-        c:\users\Jovan\AppData\Local\Xara
2011-12-10 22:37 . 2011-12-10 22:37        --------        d-----w-        c:\program files\Common Files\MAGIX Shared
2011-12-10 22:30 . 2011-12-10 22:30        --------        d-----w-        c:\program files\MAGIX
2011-12-10 16:58 . 2011-12-10 22:25        --------        d-----w-        c:\users\Jovan\AppData\Roaming\TS3Client
2011-12-09 16:47 . 2011-12-09 17:42        --------        d-----w-        c:\users\Cyrill\AppData\Local\gtk-2.0
2011-12-09 16:44 . 2011-12-09 17:56        --------        d-----w-        c:\users\Cyrill\.gimp-2.7
2011-12-09 16:44 . 2011-12-09 16:44        --------        d-----w-        c:\users\Cyrill\AppData\Local\gegl-0.1
2011-12-06 16:09 . 2011-12-18 18:43        --------        d-----w-        c:\users\Jovan\AppData\Local\gtk-2.0
2011-12-06 16:02 . 2009-08-24 21:08        28160        ----a-w-        c:\windows\system32\DfSdkBt.exe
2011-12-06 16:02 . 2011-12-30 22:30        --------        d-----w-        c:\users\Jovan\.gimp-2.7
2011-12-06 16:02 . 2011-12-06 16:02        --------        d-----w-        c:\users\Jovan\AppData\Local\gegl-0.1
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 13:11 . 2011-12-19 13:11        135472        ----a-w-        c:\windows\system32\VBoxNetFltNobj.dll
2011-12-08 18:23 . 2011-10-18 19:26        134856        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-11-12 12:36 . 2011-05-30 15:35        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 03:44 . 2011-11-10 03:44        8913920        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2011-11-10 03:17 . 2011-11-10 03:17        159744        ----a-w-        c:\windows\system32\atiapfxx.exe
2011-11-10 03:16 . 2010-05-05 02:19        774656        ----a-w-        c:\windows\system32\aticfx32.dll
2011-11-10 03:12 . 2011-11-10 03:12        466944        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2011-11-10 03:11 . 2011-11-10 03:11        417792        ----a-w-        c:\windows\system32\atieclxx.exe
2011-11-10 03:11 . 2011-11-10 03:11        176128        ----a-w-        c:\windows\system32\atiesrxx.exe
2011-11-10 03:10 . 2011-11-10 03:10        163840        ----a-w-        c:\windows\system32\atitmmxx.dll
2011-11-10 03:09 . 2011-11-10 03:09        360448        ----a-w-        c:\windows\system32\atipdlxx.dll
2011-11-10 03:09 . 2011-11-10 03:09        278528        ----a-w-        c:\windows\system32\Oemdspif.dll
2011-11-10 03:09 . 2011-11-10 03:09        20992        ----a-w-        c:\windows\system32\atimuixx.dll
2011-11-10 03:09 . 2011-11-10 03:09        43520        ----a-w-        c:\windows\system32\ati2edxx.dll
2011-11-10 03:06 . 2011-11-10 03:06        6077952        ----a-w-        c:\windows\system32\atidxx32.dll
2011-11-10 02:58 . 2011-11-10 02:58        18996224        ----a-w-        c:\windows\system32\atioglxx.dll
2011-11-10 02:40 . 2011-11-10 02:40        1828864        ----a-w-        c:\windows\system32\atiumdmv.dll
2011-11-10 02:34 . 2011-11-10 02:34        46080        ----a-w-        c:\windows\system32\aticalrt.dll
2011-11-10 02:34 . 2011-11-10 02:34        44032        ----a-w-        c:\windows\system32\aticalcl.dll
2011-11-10 02:33 . 2010-05-05 01:41        5852672        ----a-w-        c:\windows\system32\atiumdag.dll
2011-11-10 02:29 . 2011-11-10 02:29        11300864        ----a-w-        c:\windows\system32\aticaldd.dll
2011-11-10 02:29 . 2010-05-05 01:19        4200960        ----a-w-        c:\windows\system32\atiumdva.dll
2011-11-10 02:18 . 2011-04-05 15:27        51200        ----a-w-        c:\windows\system32\coinst.dll
2011-11-10 02:13 . 2011-11-10 02:13        348160        ----a-w-        c:\windows\system32\atiadlxx.dll
2011-11-10 02:13 . 2011-11-10 02:13        14336        ----a-w-        c:\windows\system32\atiglpxx.dll
2011-11-10 02:12 . 2011-11-10 02:12        32768        ----a-w-        c:\windows\system32\atigktxx.dll
2011-11-10 02:12 . 2011-11-10 02:12        263680        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2011-11-10 02:11 . 2011-11-10 02:11        32256        ----a-w-        c:\windows\system32\atiuxpag.dll
2011-11-10 02:11 . 2010-05-05 01:22        29184        ----a-w-        c:\windows\system32\atiu9pag.dll
2011-11-10 02:11 . 2011-11-10 02:11        53760        ----a-w-        c:\windows\system32\atimpc32.dll
2011-11-10 02:11 . 2011-11-10 02:11        53760        ----a-w-        c:\windows\system32\amdpcom32.dll
2011-11-10 02:11 . 2010-05-05 01:21        37376        ----a-w-        c:\windows\system32\atitmpxx.dll
2011-11-10 02:10 . 2011-11-10 02:10        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2011-11-09 21:39 . 2011-11-09 21:39        59904        ----a-w-        c:\windows\system32\OpenVideo.dll
2011-11-09 21:39 . 2011-11-09 21:39        54784        ----a-w-        c:\windows\system32\OVDecode.dll
2011-11-09 21:38 . 2011-11-09 21:38        14375936        ----a-w-        c:\windows\system32\amdocl.dll
2011-11-09 21:37 . 2011-11-09 21:37        44032        ----a-w-        c:\windows\system32\OpenCL.dll
2011-10-30 18:48 . 2011-04-05 15:30        319456        ----a-w-        c:\windows\DIFxAPI.dll
2011-10-25 20:21 . 2011-10-25 20:21        56832        ----a-w-        c:\windows\system32\OVDecoder.dll
2011-10-24 13:29 . 2011-10-24 13:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-21 19:16 . 2011-10-21 19:16        1843200        ----a-w-        c:\windows\system32\SlotMaximizerBe.dll
2011-10-21 19:15 . 2011-10-21 19:15        104448        ----a-w-        c:\windows\system32\SlotMaximizerAg.dll
2011-10-18 18:53 . 2011-10-30 18:23        3546664        ----a-w-        c:\windows\system32\drivers\RTKVHDA.sys
2011-10-18 17:10 . 2011-10-30 18:23        83048        ----a-w-        c:\windows\system32\RtkCoInst.dll
2011-10-18 14:57 . 2011-10-30 18:23        58264        ----a-w-        c:\windows\system32\TepeqAPO.dll
2011-10-18 12:47 . 2011-10-30 18:23        1329768        ----a-w-        c:\windows\system32\RtkApoApi.dll
2011-10-18 10:05 . 2011-10-30 18:23        2276968        ----a-w-        c:\windows\system32\RtkPgExt.dll
2011-10-17 17:40 . 2011-10-17 17:40        82960        ----a-w-        c:\windows\system32\drivers\AtihdLH3.sys
2011-10-17 16:30 . 2011-10-30 18:23        4238440        ----a-w-        c:\windows\system32\RtkAPO.dll
2011-10-14 12:43 . 2011-10-30 18:22        1873920        ----a-w-        c:\windows\system32\RCoRes.dat
2011-10-11 13:00 . 2011-10-18 19:26        74640        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2011-10-11 13:00 . 2011-10-18 19:26        36000        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2011-10-07 03:48 . 2011-11-18 14:33        6668624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{52BDA092-9A86-4AC2-9580-29A6C8ECA708}\mpengine.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12        94208        ----a-w-        c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="e:\programme\RocketDock\RocketDock.exe" [2007-09-02 495616]
"BackgroundSwitcher"="e:\programme\John's Background Switcher\BackgroundSwitcher.exe" [2011-07-07 119104]
"MonitorSwitch"="e:\programme\MonitorSwitch\MonitorSwitch.exe" [2011-07-06 696320]
"ViGlance"="c:\program files\ViGlance\ViGlance.exe" [2011-10-21 446464]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Skype"="c:\programme\Skype\Phone\Skype.exe" [2011-11-09 17049736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-05 59240]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-10-17 11430504]
"avgnt"="e:\programme\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"TrayServer"="e:\programme\MAGIX\Video_deluxe_MX_Premium_Download-Version\TrayServer_de.exe" [2008-08-07 90112]
"iTunesHelper"="e:\programme\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"StartCCC"="e:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-11-09 343168]
"Malwarebytes' Anti-Malware"="e:\programme\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileAssociate"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1708537768-1659004503-725345543-1009]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R2 MySQL51;MySQL51;c:\program files\MySQL\MySQL Server 5.5\bin\mysqld --defaults-file=c:\program files\MySQL\MySQL Server 5.5\my.ini MySQL51 [x]
R3 DfSdkS;Defragmentation-Service;e:\programme\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 136176]
R3 jumi;%Jumi%;c:\windows\system32\DRIVERS\jumi.sys [2010-06-03 13112]
R3 KUSBusByTCP;KUSBusByTCP;c:\windows\system32\Drivers\KUSBusByTCP.sys [2009-12-18 88064]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-11 36000]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 158512]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 91440]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-11-10 176128]
S2 AMD FUEL Service;AMD FUEL Service;e:\programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-11-09 291840]
S2 AntiVirSchedulerService;Avira Planer;e:\programme\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys [2010-07-05 84992]
S2 DokanMounter;DokanMounter;c:\program files\Dokan\DokanLibrary\mounter.exe [2010-07-05 11776]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-05-24 1840128]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;e:\programme\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 1361288]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
S2 MBAMService;MBAMService;e:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 TeamViewer6;TeamViewer 6;e:\programme\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-17 2358656]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2011-03-25 70768]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-03-25 539248]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-11-10 8913920]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-11-10 263680]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2008-11-12 46592]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-10-17 82960]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-20 232512]
S3 KUSBusByTCPMasterBus;Master Bus of Kernel USB Software Bus by TCP;c:\windows\system32\Drivers\KUSBusByTCPMasterBus.sys [2009-12-18 60672]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 25088]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 116016]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork        REG_MULTI_SZ          PLA DPS BFE mpssvc
dot3svc        REG_MULTI_SZ          dot3svc
eapsvcs        REG_MULTI_SZ          eaphost
WudfServiceGroup        REG_MULTI_SZ          WUDFSvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2011-05-29 c:\windows\Tasks\AdobeAAMUpdater-1.0-TITAN21-Jovan.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-05-11 00:25]
.
2012-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc7ab8f1c7f6ed.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 18:47]
.
2012-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 18:47]
.
2011-08-29 c:\windows\Tasks\{20D6952E-68DE-4424-86A1-52A986B2CC2B}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
2011-07-12 c:\windows\Tasks\{B668B532-98D5-494C-820D-87372AC7F773}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
2011-06-11 c:\windows\Tasks\{CAF720F3-3F53-4E82-A427-E5CB36721989}.job
- c:\progra~1\Skype\Phone\Skype.exe [2011-11-09 13:42]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
IE: {{20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - c:\windows\system32\mscoree.DLL
LSP: e:\programme\VMware\VMware Player\vsocklib.dll
TCP: Interfaces\{D893A6ED-7C8B-4434-B976-A0975702250E}: NameServer = 192.168.178.1,192.168.16.101
FF - ProfilePath - c:\users\Jovan\AppData\Roaming\Mozilla\Firefox\Profiles\b2ukvcbi.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google.de
FF - prefs.js: browser.startup.homepage - chrome://
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 2
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - true
.
.
**************************************************************************
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MySQL51]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.5\my.ini\" MySQL51"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1708537768-1659004503-725345543-1009\Software\SecuROM\License information*]
"datasecu"=hex:4e,02,fb,03,b7,83,48,b4,91,d8,67,01,d4,95,79,c5,a4,e4,cd,3f,d7,
  86,b0,42,3a,ee,91,df,86,4e,2d,24,39,84,70,f2,22,f9,d7,78,91,c4,cd,69,5c,cf,\
"rkeysecu"=hex:c4,b1,33,40,0f,ad,de,9b,22,45,e3,64,83,36,1d,d8
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2728)
c:\users\Jovan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
j:\virtualpc\VPCShExH.DLL
.
------------------------ Weitere laufende Prozesse ------------------------
.
e:\programme\Avira\AntiVir Desktop\avguard.exe
e:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\atieclxx.exe
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\vmnat.exe
c:\windows\system32\vmnetdhcp.exe
e:\programme\VMware\VMware Player\vmware-authd.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\Taskmgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-01-02  23:05:31 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-01-02 22:03
ComboFix2.txt  2012-01-02 20:22
.
Vor Suchlauf: 9 Verzeichnis(se), 23.804.411.904 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 23.766.806.528 Bytes frei
.
- - End Of File - - 0BEA4053344FB4EF30F7BD9E1B34E5D4


cosinus 02.01.2012 23:10

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


TitanNano 03.01.2012 01:10

GMER:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-01-03 01:09:36
Windows 6.0.6002 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2 ST380215A rev.3.AAD
Running: whwo3pd5.exe; Driver: C:\Users\Jovan\AppData\Local\Temp\awldipow.sys


---- System - GMER 1.0.15 ----

SSDT            897F2076                                                                                                ZwCreateSection
SSDT            897F2080                                                                                                ZwRequestWaitReplyPort
SSDT            897F207B                                                                                                ZwSetContextThread
SSDT            897F2085                                                                                                ZwSetSecurityObject
SSDT            897F208A                                                                                                ZwSystemDebugControl
SSDT            897F2017                                                                                                ZwTerminateProcess

INT 0x52        ?                                                                                                      86996CB8
INT 0x62        ?                                                                                                      84C4BCB8
INT 0x72        ?                                                                                                      84C4CCB8
INT 0x82        ?                                                                                                      84C4CCB8
INT 0x92        ?                                                                                                      84C4CCB8
INT 0x93        ?                                                                                                      86996CB8
INT 0xA3        ?                                                                                                      86996CB8
INT 0xB3        ?                                                                                                      86996CB8

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!KeSetEvent + 215                                                                          82ABB998 4 Bytes  [76, 20, 7F, 89] {JBE 0x22; JG 0xffffffffffffff8d}
.text          ntkrnlpa.exe!KeSetEvent + 539                                                                          82ABBCBC 4 Bytes  [80, 20, 7F, 89]
.text          ntkrnlpa.exe!KeSetEvent + 56D                                                                          82ABBCF0 4 Bytes  [7B, 20, 7F, 89] {JNP 0x22; JG 0xffffffffffffff8d}
.text          ntkrnlpa.exe!KeSetEvent + 5D1                                                                          82ABBD54 4 Bytes  [85, 20, 7F, 89] {TEST [EAX], ESP; JG 0xffffffffffffff8d}
.text          ntkrnlpa.exe!KeSetEvent + 619                                                                          82ABBD9C 4 Bytes  [8A, 20, 7F, 89] {MOV AH, [EAX]; JG 0xffffffffffffff8d}
.text          ...                                                                                                   
.text          sptd.sys                                                                                                80602000 32 Bytes  [C0, CE, DC, 82, 06, 61, DD, ...]
.text          sptd.sys                                                                                                80602024 104 Bytes  [EA, D3, A4, 82, 41, CB, AF, ...]
.text          sptd.sys                                                                                                8060208D 103 Bytes  [81, A5, 82, 81, CB, AB, 82, ...]
.text          sptd.sys                                                                                                806020F5 23 Bytes  [48, A5, 82, F0, E2, A2, 82, ...]
.text          sptd.sys                                                                                                8060210D 191 Bytes  [4A, A5, 82, 1C, 03, AC, 82, ...]
.text          ...                                                                                                   
.sptd2          C:\Windows\System32\Drivers\sptd.sys                                                                    entry point in ".sptd2" section [0x806AC9E3]
?              C:\Windows\System32\Drivers\sptd.sys                                                                    Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                                                section is writeable [0x8EE04000, 0x3BEEC5, 0xE8000020]
.text          USBPORT.SYS!DllUnload                                                                                  8F7E941B 5 Bytes  JMP 869961C8

---- User code sections - GMER 1.0.15 ----

.text          E:\Programme\Aurora\plugin-container.exe[3012] USER32.dll!SetWindowLongA                                7628E7CD 5 Bytes  JMP 5F260E8D E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\plugin-container.exe[3012] USER32.dll!SetWindowLongW                                762913B4 5 Bytes  JMP 5F260E1F E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\plugin-container.exe[3012] USER32.dll!GetWindowInfo                                7629428E 5 Bytes  JMP 5F02AA81 E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\plugin-container.exe[3012] USER32.dll!TrackPopupMenu                                762A14F3 5 Bytes  JMP 5F02B03E E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\firefox.exe[4372] ntdll.dll!LdrLoadDll                                              777893A8 5 Bytes  JMP 5EEB6640 E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\firefox.exe[4372] kernel32.dll!MapViewOfFile                                        775768F0 5 Bytes  JMP 5F0EB536 E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\firefox.exe[4372] kernel32.dll!VirtualAlloc                                        7757AD55 5 Bytes  JMP 5F0EB55D E:\Programme\Aurora\xul.dll (Mozilla Foundation)
.text          E:\Programme\Aurora\firefox.exe[4372] GDI32.dll!CreateDIBSection                                        778E7461 5 Bytes  JMP 5F0EB4C0 E:\Programme\Aurora\xul.dll (Mozilla Foundation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                              [80603EEE] \SystemRoot\System32\Drivers\sptd.sys
IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong]                              [8060420E] \SystemRoot\System32\Drivers\sptd.sys
IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                [8060370C] \SystemRoot\System32\Drivers\sptd.sys
IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                        [806040CC] \SystemRoot\System32\Drivers\sptd.sys
IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort]                              [80603832] \SystemRoot\System32\Drivers\sptd.sys
IAT            \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                        [806038F0] \SystemRoot\System32\Drivers\sptd.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                  [74207817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                    [7425A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                [7420BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]          [741FF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                    [742075E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                [741FE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]    [74238395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]        [7420DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                [741FFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                [741FFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                  [741F71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]          [7428CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]            [7422C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                [741FD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                          [741F6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                        [741F687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2776] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]            [74202AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                  84C541E8

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                  siwinacc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

Device          \FileSystem\fastfat \FatCdrom                                                                          872321E8
Device          \Driver\netbt \Device\NetBT_Tcpip_{DD323DD6-5A13-4785-AC8E-E8EF90402433}                                86FD3430
Device          \Driver\netbt \Device\NetBT_Tcpip_{A6B29388-BD01-4EA9-BC68-30DB9FDE7B17}                                86FD3430

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application@Sources                                    WSH?WMIAdapter?WMI.NET Provider Extension?WmdmPmSN?WinMgmt?Winlogon?Windows Product Activation?Windows 3.1 Migration?WebClient?VSSetup?VSS?VBRuntime?Userinit?Userenv?System.ServiceModel.Install 3.0.0.0?System.ServiceModel 4.0.0.0?System.ServiceModel 3.0.0.0?System.Runtime.Serialization 4.0.0.0?System.Runtime.Serialization 3.0.0.0?System.IO.Log 4.0.0.0?System.IO.Log 3.0.0.0?System.IdentityModel 4.0.0.0?System.IdentityModel 3.0.0.0?SysmonLog?Starter?SpoolerCtrs?Software Restriction Policies?Software Installation?ServiceModel Audit 4.0.0.0?ServiceModel Audit 3.0.0.0?SecurityCenter?SclgNtfy?SceSrv?SceCli?safrslv?SAFrdms?RPC?Remote Assistance?PerfProc?PerfOS?PerfNet?Perfmon?Perflib?PerfDisk?Perfctrs?Offline Files?Oakley?ntbackup?MSSQLSERVER/MSDE?MSSHA?MsiInstaller?MSDTC Client?MSDTC?mnmsrvc?Microsoft.Transactions.Bridge 4.0.0.0?Microsoft.Transactions.Bridge 3.0.0.0?Microsoft WSE 3.0?Microsoft H.323 Telephony Service Provider?Microsoft (R) Visual C# 2005 Compiler?LoadPerf?KOCH Protect?JavaQuickStarterService?idsvc
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                      771343423
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                      285507792
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                       
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                    E:\Programme\DAEMON Tools Lite\
Reg            HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                    0x00 0x00 0x00 0x00 ...
Reg            HKLM\SYSTEM\ControlSet004\Services\Eventlog\Application@Sources                                        WSH?WMIAdapter?WMI.NET Provider Extension?WmdmPmSN?WinMgmt?Winlogon?Windows Product Activation?Windows 3.1 Migration?WebClient?VSSetup?VSS?VBRuntime?Userinit?Userenv?System.ServiceModel.Install 3.0.0.0?System.ServiceModel 4.0.0.0?System.ServiceModel 3.0.0.0?System.Runtime.Serialization 4.0.0.0?System.Runtime.Serialization 3.0.0.0?System.IO.Log 4.0.0.0?System.IO.Log 3.0.0.0?System.IdentityModel 4.0.0.0?System.IdentityModel 3.0.0.0?SysmonLog?Starter?SpoolerCtrs?Software Restriction Policies?Software Installation?ServiceModel Audit 4.0.0.0?ServiceModel Audit 3.0.0.0?SecurityCenter?SclgNtfy?SceSrv?SceCli?safrslv?SAFrdms?RPC?Remote Assistance?PerfProc?PerfOS?PerfNet?Perfmon?Perflib?PerfDisk?Perfctrs?Offline Files?Oakley?ntbackup?MSSQLSERVER/MSDE?MSSHA?MsiInstaller?MSDTC Client?MSDTC?mnmsrvc?Microsoft.Transactions.Bridge 4.0.0.0?Microsoft.Transactions.Bridge 3.0.0.0?Microsoft WSE 3.0?Microsoft H.323 Telephony Service Provider?Microsoft (R) Visual C# 2005 Compiler?LoadPerf?KOCH Protect?JavaQuickStarterService?idsvc
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlId  454
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex@CheckPointNumber                      1
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455                           
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@CrawlType                  2
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@InProgress                1
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@DoneAddingCrawlSeeds      1
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@LogName                    C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl455.gthr
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@CheckPoint                0x82 0x00 0x00 0x00 ...
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@IsCatalogLevel            0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@LogStartAddId              2
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@SuccessfulTransactions    0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@ErrorTransactions          0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@WarningTransactions        0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@ExcludedTransactions      0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@RetryTransactions          0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@KilobytesCrawled          0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@Modified                  0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@UnvisitedItems            0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\455@ForcedFullCrawl            0
Reg            HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2@CrawlNumberInProgress    455

---- EOF - GMER 1.0.15 ----


TitanNano 04.01.2012 23:44

OSAM:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 23:43:02 on 04.01.2012

OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Aurora 11.0a2

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Personal" - ? - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl  (File not found)
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
"SageThumbs Shell Extension" - "CherubicSoft" - E:\Programme\SageThumbs\32\SageThumbs.dll

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"%Jumi%" (jumi) - "Windows (R) Win 7 DDK provider" - C:\Windows\System32\DRIVERS\jumi.sys
"AsIO" (AsIO) - ? - C:\Windows\System32\drivers\AsIO.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Dokan" (Dokan) - "Windows (R) Win 7 DDK provider" - C:\Windows\system32\drivers\dokan.sys
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys  (File not found)
"EagleXNt" (EagleXNt) - ? - C:\Windows\system32\drivers\EagleXNt.sys  (File not found)
"GEAR ASPI Filter Driver" (GEARAspiWDM) - "GEAR Software Inc." - C:\Windows\System32\DRIVERS\GEARAspiWDM.sys
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"KUSBusByTCP" (KUSBusByTCP) - "Windows (R) Codename Longhorn DDK provider" - C:\Windows\System32\Drivers\KUSBusByTCP.sys
"Master Bus of Kernel USB Software Bus by TCP" (KUSBusByTCPMasterBus) - "Windows (R) Codename Longhorn DDK provider" - C:\Windows\System32\Drivers\KUSBusByTCPMasterBus.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys
"Padus ASPI Shell" (pfc) - "Padus, Inc." - C:\Windows\System32\drivers\pfc.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"sptd" (sptd) - ? - C:\Windows\System32\Drivers\sptd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Trust Webcam 14823" (snpstd) - ? - C:\Windows\System32\DRIVERS\snpstd.sys  (File not found)
"Virtual Machine Monitor" (vmm) - "Microsoft Corporation" - C:\Windows\system32\Drivers\vmm.sys
"VMware hcmon" (hcmon) - "VMware, Inc." - C:\Windows\system32\drivers\hcmon.sys
"VMware kbd" (vmkbd) - "VMware, Inc." - C:\Windows\system32\drivers\VMkbd.sys
"VMware Network Application Interface" (VMnetuserif) - "VMware, Inc." - C:\Windows\system32\drivers\vmnetuserif.sys
"VMware vmci" (vmci) - "VMware, Inc." - C:\Windows\system32\Drivers\vmci.sys
"VMware VMparport" (VMparport) - "VMware, Inc." - C:\Windows\system32\Drivers\VMparport.sys
"VMware vmx86" (vmx86) - "VMware, Inc." - C:\Windows\system32\Drivers\vmx86.sys
"Vstor2 WS60 Virtual Storage Driver" (vstor2-ws60) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vstor2-ws60.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{2C7339CF-2B09-4501-B3F3-F3508C9228ED} "Themes Setup" - "Microsoft Corporation" - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - "The Document Foundation" - E:\Programme\LibreOffice 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll  (File not found)
{41E300E0-78B6-11ce-849B-444553540000} "Display Effects CPL Extension" - "Microsoft Corporation" - C:\Windows\system32\themeui.dll
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\Programme\iTunes\iTunesMiniPlayer.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "LibreOffice Property Handler" - "The Document Foundation" - E:\Programme\LibreOffice 3\Basis\program\shlxthdl\propertyhdl.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{4A34B3E3-F50E-4FF6-8979-7E4176466FF2} "SageThumbs Shell Extension" - "CherubicSoft" - E:\Programme\SageThumbs\32\SageThumbs.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - e:\Programme\Unlocker\UnlockerCOM.dll  (File found, but it contains no detailed information)
{8932AEFE-9DB6-4f43-AFB2-5682F55E773A} "VPCHostCopyHook" - "Microsoft Corporation" - J:\VirtualPC\VPCShExH.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10t.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} "ClsidExtension" - ? -  (File not found | COM-object registry key not found)
"Exec" - "Microsoft Corporation" - C:\Windows\Network Diagnostic\xpnetdiag.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"BackgroundSwitcher" - "johnsadventures.com" - "E:\Programme\John's Background Switcher\BackgroundSwitcher.exe"
"MonitorSwitch" - "www.goldgingko.com" - E:\Programme\MonitorSwitch\MonitorSwitch.exe /m
"RocketDock" - ? - "E:\Programme\RocketDock\RocketDock.exe"  (File found, but it contains no detailed information)
"Skype" - "Skype Technologies S.A." - "C:\Programme\Skype\Phone\Skype.exe" /minimized
"ViGlance" - "Lee-Soft.com, Lee Matthew Chantrey" - C:\Program Files\ViGlance\ViGlance.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
"iTunesHelper" - "Apple Inc." - "E:\Programme\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"StartCCC" - "Advanced Micro Devices, Inc." - "E:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"TrayServer" - "MAGIX AG" - E:\Programme\MAGIX\Video_deluxe_MX_Premium_Download-Version\TrayServer_de.exe

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"HP Fax Port" - "Hewlett-Packard Company" - C:\Windows\system32\hppfaxprintermon5.dll
"HP Standard TCP/IP Port" - "Hewlett Packard" - C:\Windows\system32\HpTcpMon.dll
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%SystemRoot%\System32\shsvcs.dll,-12288" (ShellHWDetection) - "Microsoft Corporation" - C:\Windows\System32\shsvcs.dll
"@%SystemRoot%\System32\shsvcs.dll,-8192" (Themes) - "Microsoft Corporation" - C:\Windows\system32\shsvcs.dll
"@C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"AMD FUEL Service" (AMD FUEL Service) - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\sched.exe
"Defragmentation-Service" (DfSdkS) - "mst software GmbH, Germany" - E:\Programme\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"DokanMounter" (DokanMounter) - ? - C:\Program Files\Dokan\DokanLibrary\mounter.exe  (File found, but it contains no detailed information)
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP LaserJet Service" (HP LaserJet Service) - "HP" - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LogMeIn Hamachi Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - E:\Programme\LogMeIn Hamachi\hamachi-2.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"MySQL51" (MySQL51) - ? - C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - E:\Programme\TeamViewer\Version6\TeamViewer_Service.exe
"VMware Agent Service" (ufad-ws60) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vmware-ufad.exe
"VMware Authorization Service" (VMAuthdService) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vmware-authd.exe
"VMware DHCP Service" (VMnetDHCP) - "VMware, Inc." - C:\Windows\system32\vmnetdhcp.exe
"VMware NAT Service" (VMware NAT Service) - "VMware, Inc." - C:\Windows\system32\vmnat.exe
"VMware USB Arbitration Service" (VMUSBArbService) - "VMware, Inc." - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"VMCI sockets DGRAM" - "VMware, Inc." - E:\Programme\VMware\VMware Player\vsocklib.dll
"VMCI sockets STREAM" - "VMware, Inc." - E:\Programme\VMware\VMware Player\vsocklib.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 05.01.2012 10:26

Zitat:

"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"EagleXNt" (EagleXNt) - ? - C:\Windows\system32\drivers\EagleXNt.sys (File not found)
Bitte mit OSAM deaktivieren und löschen.
Kommt aswMBR auch noch?`

TitanNano 05.01.2012 21:30

aswMBR:
Code:

aswMBR version 0.9.9.1156 Copyright(c) 2011 AVAST Software
Run date: 2012-01-04 23:46:30
-----------------------------
23:46:30.539    OS Version: Windows 6.0.6002 Service Pack 2
23:46:30.539    Number of processors: 2 586 0x6B02
23:46:30.540    ComputerName: TITAN21  UserName: Jovan
23:47:13.191    Initialize success
23:51:07.106    AVAST engine defs: 12010401
23:51:15.772    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:51:15.784    Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ10001 Size: 953869MB BusType: 3
23:51:15.788    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2
23:51:15.792    Disk 1 Vendor: ST380215A 3.AAD Size: 76319MB BusType: 3
23:51:15.796    Disk 2  \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-1
23:51:15.800    Disk 2 Vendor: WDC_WD1200JD-00HBC0 08.02D08 Size: 114473MB BusType: 3
23:51:15.830    Disk 1 MBR read successfully
23:51:15.845    Disk 1 MBR scan
23:51:15.884    Disk 1 Windows VISTA default MBR code
23:51:15.902    Disk 1 Partition 1 80 (A) 07    HPFS/NTFS NTFS        76317 MB offset 63
23:51:15.912    Disk 1 scanning sectors +156298752
23:51:16.063    Disk 1 scanning C:\Windows\system32\drivers
23:51:35.895    Service scanning
23:51:37.333    Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
23:51:38.082    Modules scanning
23:52:22.748    Disk 1 trace - called modules:
23:52:22.765    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84c531e8]<<
23:52:22.779    1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x86166410]
23:52:22.787    3 CLASSPNP.SYS[88da88b3] -> nt!IofCallDriver -> [0x8562ded8]
23:52:22.794    5 acpi.sys[807266bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85645030]
23:52:22.817    \Driver\atapi[0x8560f960] -> IRP_MJ_CREATE -> 0x84c531e8
23:52:23.808    AVAST engine scan C:\Windows
23:52:31.260    AVAST engine scan C:\Windows\system32
23:57:01.439    AVAST engine scan C:\Windows\system32\drivers
23:57:24.751    AVAST engine scan C:\Users\Jovan
00:08:38.876    AVAST engine scan C:\ProgramData
00:17:19.751    Scan finished successfully
00:17:43.617    Disk 1 MBR has been saved successfully to "D:\Benutzer\Jovan\Desktop\MBR.dat"
00:17:43.624    The log file has been saved successfully to "D:\Benutzer\Jovan\Desktop\aswMBR.txt"


TitanNano 05.01.2012 21:34

Hier noch mal der neue OSAM Log:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:34:18 on 05.01.2012

OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Aurora 11.0a2

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Personal" - ? - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl  (File not found)
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
"SageThumbs Shell Extension" - "CherubicSoft" - E:\Programme\SageThumbs\32\SageThumbs.dll

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"%Jumi%" (jumi) - "Windows (R) Win 7 DDK provider" - C:\Windows\System32\DRIVERS\jumi.sys
"AsIO" (AsIO) - ? - C:\Windows\System32\drivers\AsIO.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Dokan" (Dokan) - "Windows (R) Win 7 DDK provider" - C:\Windows\system32\drivers\dokan.sys
"GEAR ASPI Filter Driver" (GEARAspiWDM) - "GEAR Software Inc." - C:\Windows\System32\DRIVERS\GEARAspiWDM.sys
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"KUSBusByTCP" (KUSBusByTCP) - "Windows (R) Codename Longhorn DDK provider" - C:\Windows\System32\Drivers\KUSBusByTCP.sys
"Master Bus of Kernel USB Software Bus by TCP" (KUSBusByTCPMasterBus) - "Windows (R) Codename Longhorn DDK provider" - C:\Windows\System32\Drivers\KUSBusByTCPMasterBus.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys
"Padus ASPI Shell" (pfc) - "Padus, Inc." - C:\Windows\System32\drivers\pfc.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"sptd" (sptd) - ? - C:\Windows\System32\Drivers\sptd.sys  (File not found)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Trust Webcam 14823" (snpstd) - ? - C:\Windows\System32\DRIVERS\snpstd.sys  (File not found)
"Virtual Machine Monitor" (vmm) - "Microsoft Corporation" - C:\Windows\system32\Drivers\vmm.sys
"VMware hcmon" (hcmon) - "VMware, Inc." - C:\Windows\system32\drivers\hcmon.sys
"VMware kbd" (vmkbd) - "VMware, Inc." - C:\Windows\system32\drivers\VMkbd.sys
"VMware Network Application Interface" (VMnetuserif) - "VMware, Inc." - C:\Windows\system32\drivers\vmnetuserif.sys
"VMware vmci" (vmci) - "VMware, Inc." - C:\Windows\system32\Drivers\vmci.sys
"VMware VMparport" (VMparport) - "VMware, Inc." - C:\Windows\system32\Drivers\VMparport.sys
"VMware vmx86" (vmx86) - "VMware, Inc." - C:\Windows\system32\Drivers\vmx86.sys
"Vstor2 WS60 Virtual Storage Driver" (vstor2-ws60) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vstor2-ws60.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{2C7339CF-2B09-4501-B3F3-F3508C9228ED} "Themes Setup" - "Microsoft Corporation" - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - "The Document Foundation" - E:\Programme\LibreOffice 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll  (File not found)
{41E300E0-78B6-11ce-849B-444553540000} "Display Effects CPL Extension" - "Microsoft Corporation" - C:\Windows\system32\themeui.dll
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\Programme\iTunes\iTunesMiniPlayer.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "LibreOffice Property Handler" - "The Document Foundation" - E:\Programme\LibreOffice 3\Basis\program\shlxthdl\propertyhdl.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{4A34B3E3-F50E-4FF6-8979-7E4176466FF2} "SageThumbs Shell Extension" - "CherubicSoft" - E:\Programme\SageThumbs\32\SageThumbs.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - e:\Programme\Unlocker\UnlockerCOM.dll  (File found, but it contains no detailed information)
{8932AEFE-9DB6-4f43-AFB2-5682F55E773A} "VPCHostCopyHook" - "Microsoft Corporation" - J:\VirtualPC\VPCShExH.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10t.ocx / hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} "ClsidExtension" - ? -  (File not found | COM-object registry key not found)
"Exec" - "Microsoft Corporation" - C:\Windows\Network Diagnostic\xpnetdiag.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll

[Logon]
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"BackgroundSwitcher" - "johnsadventures.com" - "E:\Programme\John's Background Switcher\BackgroundSwitcher.exe"
"MonitorSwitch" - "www.goldgingko.com" - E:\Programme\MonitorSwitch\MonitorSwitch.exe /m
"RocketDock" - ? - "E:\Programme\RocketDock\RocketDock.exe"  (File found, but it contains no detailed information)
"Skype" - "Skype Technologies S.A." - "C:\Programme\Skype\Phone\Skype.exe" /minimized
"ViGlance" - "Lee-Soft.com, Lee Matthew Chantrey" - C:\Program Files\ViGlance\ViGlance.exe
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
"iTunesHelper" - "Apple Inc." - "E:\Programme\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"StartCCC" - "Advanced Micro Devices, Inc." - "E:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"TrayServer" - "MAGIX AG" - E:\Programme\MAGIX\Video_deluxe_MX_Premium_Download-Version\TrayServer_de.exe

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"HP Fax Port" - "Hewlett-Packard Company" - C:\Windows\system32\hppfaxprintermon5.dll
"HP Standard TCP/IP Port" - "Hewlett Packard" - C:\Windows\system32\HpTcpMon.dll
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%SystemRoot%\System32\shsvcs.dll,-12288" (ShellHWDetection) - "Microsoft Corporation" - C:\Windows\System32\shsvcs.dll
"@%SystemRoot%\System32\shsvcs.dll,-8192" (Themes) - "Microsoft Corporation" - C:\Windows\system32\shsvcs.dll
"@C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"AMD FUEL Service" (AMD FUEL Service) - "Advanced Micro Devices, Inc." - E:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Programme\Avira\AntiVir Desktop\sched.exe
"Defragmentation-Service" (DfSdkS) - "mst software GmbH, Germany" - E:\Programme\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"DokanMounter" (DokanMounter) - ? - C:\Program Files\Dokan\DokanLibrary\mounter.exe  (File found, but it contains no detailed information)
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP LaserJet Service" (HP LaserJet Service) - "HP" - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LogMeIn Hamachi Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - E:\Programme\LogMeIn Hamachi\hamachi-2.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"MySQL51" (MySQL51) - ? - C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - E:\Programme\TeamViewer\Version6\TeamViewer_Service.exe
"VMware Agent Service" (ufad-ws60) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vmware-ufad.exe
"VMware Authorization Service" (VMAuthdService) - "VMware, Inc." - E:\Programme\VMware\VMware Player\vmware-authd.exe
"VMware DHCP Service" (VMnetDHCP) - "VMware, Inc." - C:\Windows\system32\vmnetdhcp.exe
"VMware NAT Service" (VMware NAT Service) - "VMware, Inc." - C:\Windows\system32\vmnat.exe
"VMware USB Arbitration Service" (VMUSBArbService) - "VMware, Inc." - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"VMCI sockets DGRAM" - "VMware, Inc." - E:\Programme\VMware\VMware Player\vsocklib.dll
"VMCI sockets STREAM" - "VMware, Inc." - E:\Programme\VMware\VMware Player\vsocklib.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 05.01.2012 22:14

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


TitanNano 06.01.2012 21:49

Malwarebytes:
Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.06.03

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Jovan :: TITAN21 [Administrator]

Schutz: Deaktiviert

06.01.2012 18:10:54
mbam-log-2012-01-06 (18-10-54).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 589253
Laufzeit: 3 Stunde(n), 35 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


TitanNano 08.01.2012 15:16

SUPERAntiSpyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/07/2012 at 02:48 AM

Application Version : 5.0.1142

Core Rules Database Version : 8109
Trace Rules Database Version: 5921

Scan type      : Complete Scan
Total Scan Time : 04:48:49

Operating System Information
Windows Vista Business 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned      : 916
Memory threats detected  : 0
Registry items scanned    : 39125
Registry threats detected : 0
File items scanned        : 624437
File threats detected    : 543

Adware.Tracking Cookie
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@apmebf[1].txt [ /apmebf ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[1].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[2].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[3].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[4].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[5].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@doubleclick[6].txt [ /doubleclick ]
        C:\Users\Jovan\AppData\Roaming\Microsoft\Windows\Cookies\jovan@mediaplex[1].txt [ /mediaplex ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\cyrill@eaeacom.112.2o7[1].txt [ Cookie:cyrill@eaeacom.112.2o7.net/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\2QELTBZM.txt [ Cookie:cyrill@c.atdmt.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\XBR7UWKL.txt [ Cookie:cyrill@ad2.adfarm1.adition.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\cyrill@smartadserver[1].txt [ Cookie:cyrill@smartadserver.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\0OQOMSS7.txt [ Cookie:cyrill@atdmt.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\2MFA0L79.txt [ Cookie:cyrill@doubleclick.net/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\6CVPQ6ZL.txt [ Cookie:cyrill@ad3.adfarm1.adition.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\K8WT7JBP.txt [ Cookie:cyrill@adfarm1.adition.com/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\Low\cyrill@eaeacom.112.2o7[1].txt [ Cookie:cyrill@eaeacom.112.2o7.net/ ]
        C:\USERS\CYRILL\AppData\Roaming\Microsoft\Windows\Cookies\Low\cyrill@doubleclick[1].txt [ Cookie:cyrill@doubleclick.net/ ]
        C:\USERS\CYRILL\Cookies\cyrill@eaeacom.112.2o7[1].txt [ Cookie:cyrill@eaeacom.112.2o7.net/ ]
        C:\USERS\CYRILL\Cookies\2QELTBZM.txt [ Cookie:cyrill@c.atdmt.com/ ]
        C:\USERS\CYRILL\Cookies\XBR7UWKL.txt [ Cookie:cyrill@ad2.adfarm1.adition.com/ ]
        C:\USERS\CYRILL\Cookies\cyrill@smartadserver[1].txt [ Cookie:cyrill@smartadserver.com/ ]
        C:\USERS\CYRILL\Cookies\0OQOMSS7.txt [ Cookie:cyrill@atdmt.com/ ]
        C:\USERS\CYRILL\Cookies\2MFA0L79.txt [ Cookie:cyrill@doubleclick.net/ ]
        C:\USERS\CYRILL\Cookies\6CVPQ6ZL.txt [ Cookie:cyrill@ad3.adfarm1.adition.com/ ]
        C:\USERS\CYRILL\Cookies\K8WT7JBP.txt [ Cookie:cyrill@adfarm1.adition.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\UQ0H4F1O.txt [ Cookie:jovan@adfarm1.adition.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\CDHUDE50.txt [ Cookie:jovan@atdmt.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PONQEVV7.txt [ Cookie:jovan@c.atdmt.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\8GS1RTAX.txt [ Cookie:jovan@serving-sys.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\A2WH7XU9.txt [ Cookie:jovan@mediaplex.com/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\NP0TEOMN.txt [ Cookie:jovan@specificclick.net/ ]
        C:\USERS\JOVAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\FZJFQJOJ.txt [ Cookie:jovan@apmebf.com/ ]
        C:\USERS\USER\AppData\Roaming\Microsoft\Windows\Cookies\ABFPIIDI.txt [ Cookie:user@tracking.gameforge.de/track/ ]
        C:\USERS\USER\Cookies\ABFPIIDI.txt [ Cookie:user@tracking.gameforge.de/track/ ]
        .tns-counter.ru [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rambler.ru [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .foxfilmedentertainment.122.2o7.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads2.net2day.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads3.net2day.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tribalfusion.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.dc-storm.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.dc-storm.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .microsoftwindows.112.2o7.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .c1.atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .c.atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .c.atdmt.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kontera.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .nextag.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .nextag.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        imagesrv.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stats.computecmedia.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver.ps3m.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.gameforge.de [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .warnerbros.112.2o7.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .rambler.ru [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.netxmedia.net [ C:\USERS\CYRILL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tns-counter.ru [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        rts.pgmediaserve.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .de.partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .rambler.ru [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .animetoplist.org [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .www.animetoplist.org [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .superrtl.122.2o7.net [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\CYRILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H482KBY7.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .imrworldwide.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adserver.ip-phone-forum.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .specificclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unitymedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unitymedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .eaeacom.112.2o7.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .a.revenuemax.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .toplist.cz [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking-technology.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.pointroll.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .sexysims2.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yadro.ru [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tns-counter.ru [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        s07.flagcounter.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.freebloghitcounter.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        fl01.ct2.comclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        banner.electronic-arts.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .server.cpmstar.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .amazon-adsystem.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.youtube.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        auslieferung.commindo-media-ressourcen.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        auslieferung.commindo-media-ressourcen.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        auslieferung.commindo-media-ressourcen.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        teufel-media.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adserver.adtechus.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tacoda.at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .at.atwola.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediacollege.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediacollege.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediacollege.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        de.sitestat.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ru4.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.active-tracking.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.active-tracking.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.active-tracking.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ads.adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.mindshare.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.effiliation.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad1.adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .2o7.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        stats.computecmedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.blogcounter.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        gr.burstnet.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .burstnet.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .collective-media.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .gametracker.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .casalemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .yieldmanager.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        count.asnetworks.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .insightexpressai.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad-emea.doubleclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad-emea.doubleclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .medialoot.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .xiti.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        eas.apm.emediate.eu [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .im.banner.t-online.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adtech.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .verticaltechmedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .verticaltechmedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.quartermedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ads.quartermedia.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ww251.smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .swsoft.122.2o7.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .advertising.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .www.burstnet.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .burstnet.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .overture.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lucidmedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .invitemedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .lfstmedia.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .microsoftwindows.112.2o7.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        count.primawebtools.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.gameforge.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .questionmarket.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adxvalue.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.etracker.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adviva.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tribalfusion.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .kontera.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .trafficmp.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .trafficmp.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tradedoubler.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .traffictrack.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .smartadserver.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.effiliation.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.effiliation.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.effiliation.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.effiliation.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .statcounter.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .getclicky.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .static.getclicky.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        in.getclicky.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .tracking.quisma.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .dyntracker.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .ad.adnet.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .c.atdmt.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .c.atdmt.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .myroitracking.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .clicksor.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .interclick.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        statse.webtrendslive.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        track.adform.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adform.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad4.adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adbrite.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zedo.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad2.adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .media6degrees.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .fastclick.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        www.usenext.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .webmasterplan.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.zanox.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .zanox-affiliate.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad.yieldmanager.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        adx.chip.de [ C:\USERS\JOVAN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[4].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@SERVING-SYS[1].TXT [ /SERVING-SYS ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@MEDIAPLEX[1].TXT [ /MEDIAPLEX ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[5].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[2].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[6].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@DOUBLECLICK[3].TXT [ /DOUBLECLICK ]
        C:\USERS\JOVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\JOVAN@APMEBF[1].TXT [ /APMEBF ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        www.elitepvpers.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .elitepvpers.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediafire.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediavrog.net [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediavrog.net [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        www.blogcounter.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        count.primawebtools.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediaevent.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediaevent.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .mediaevent.de [ C:\USERS\JOVAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B2UKVCBI.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .himedia.individuad.net [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YYWFP8QF.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-SoftonicDownloader
        D:\BENUTZER\JOVAN\DOWNLOADS\SOFTONICDOWNLOADER_FUER_LESEFIXPRO.EXE

Trojan.Agent/Gen-FakeAV
        E:\GAMES\FRAGORIA ONLINE DE\FILES\PATCH2_21_05_2010.EXE
        E:\GAMES\FRAGORIA ONLINE DE\FILES\PATCH_08_06_2010.EXE
        E:\GAMES\FRAGORIA ONLINE DE\UPDATES\PATCH1_04_04_2011.EXE
        E:\GAMES\FRAGORIA ONLINE DE\UPDATES\PATCH2_04_04_2011.EXE
        E:\GAMES\FRAGORIA ONLINE DE\UPDATES\PATCH_08_06_2010.EXE
        E:\GAMES\FRAGORIA ONLINE DE\UPDATES\PATCH_11_08_2010.EXE


TitanNano 08.01.2012 20:39

ESET:
Code:

C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll        a variant of Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll        Win32/Toolbar.Babylon application
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe        probably a variant of Win32/Toolbar.Babylon application
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe        Win32/Adware.Toolbar.Dealio application
C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5        a variant of Win32/Adware.Toolbar.Dealio application
D:\Benutzer\Jovan\Desktop\Programme\Sacred 2 Tools\Sacred Tool.exe        Win32/Packed.Autoit.C.Gen application
D:\Benutzer\Jovan\Downloads\gb3-setup.exe        a variant of Win32/Toolbar.Widgi application
D:\Benutzer\Jovan\Downloads\Unlocker1.9.1.exe        Win32/Adware.ADON application
D:\_OTL\MovedFiles\12302011_230706\C_Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll        Win32/Toolbar.Babylon application
D:\_OTL\MovedFiles\12302011_230706\C_Programme\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll        Win32/Toolbar.Babylon application


cosinus 08.01.2012 21:44

Zitat:

Trojan.Agent/Gen-FakeAV
E:\GAMES\FRAGORIA ONLINE DE\FILES\PATCH2_21_05_2010.EXE
E:\GAMES\FRAGORIA ONLINE DE\FILES\PATCH_08_06_2010.EXE
Diese Patches kennst du? :pfeiff:

TitanNano 08.01.2012 21:55

Also das is ein Spiel was ich früher mal gespielt hab...

cosinus 08.01.2012 22:13

Das beantwortet nicht meine Frage zu den Patches. Was das ist und wo die herkommen

TitanNano 08.01.2012 22:22

Also ich kenn sie nicht, hab sie nicht selbst runtergeladen. Aber warscheinlich wahren die bei der Installation dabei.

cosinus 08.01.2012 22:30

Ok...löschen wir den Rest der Toolbar-Plage

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":Files" muss mitkopiert werden!!!)

Code:

:Files
C:\Program Files\BabylonToolbar
C:\Program Files\Common Files\Spigot
D:\Benutzer\Jovan\Desktop\Programme\Sacred 2 Tools\Sacred Tool.exe
D:\Benutzer\Jovan\Downloads\gb3-setup.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

TitanNano 09.01.2012 17:24

Code:

All processes killed
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Cyrill
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
 
User: Jovan
->Temp folder emptied: 126175656 bytes
->Temporary Internet Files folder emptied: 53762147 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 32071025 bytes
->Google Chrome cache emptied: 40153961 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 2435 bytes
 
User: LocalService.NT-AUTORITÄT
->Temp folder emptied: 0 bytes
 
User: NetworkService.NT-AUTORITÄT
->Temp folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6882815 bytes
RecycleBin emptied: 3189534741 bytes
 
Total Files Cleaned = 3.289,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 01092012_171220

Files\Folders moved on Reboot...
C:\Windows\temp\vmware-SYSTEM\vmauthd.log scheduled to be moved on reboot.
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2116.log moved successfully.
File\Folder C:\Program Files\BabylonToolbar moved successfully.
File\Folder C:\Program Files\Common Files\Spigot moved successfully.
D:\Benutzer\Jovan\Desktop\Programme\Sacred 2 Tools\Sacred Tool.exe moved successfully.
File\Folder D:\Benutzer\Jovan\Downloads\gb3-setup.exe moved successfully.

Registry entries deleted on Reboot...


cosinus 09.01.2012 19:11

Ok. Rechner soweit wieder im Lot?

TitanNano 09.01.2012 19:13

ich hoffe es, werde jetzt dann mal Skype neu installieren und Opera durchtesten und hoffe mal das alles läuft...


Alle Zeitangaben in WEZ +1. Es ist jetzt 19:14 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27