Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Gema Trojaner Win XP - Desktop leer, Taskleiste weg (https://www.trojaner-board.de/107940-gema-trojaner-win-xp-desktop-leer-taskleiste-weg.html)

tax 11.01.2012 13:45

Gema Trojaner Win XP - Desktop leer, Taskleiste weg
 
Hallo,

ich benötige Hilfe. Ich habe/hatte den Gema Virus. Mein System Win XP Prof SP 3.

Den Virus habe lt. einer Anleitung aus dem Netz entfernt.
Habe mein System mit Bart PE gestartet. Die .exe Datei aus dem Anwendungsdaten von meinem User und vom Admin gelöscht. Die Registry bereinigt, NoDesktop gelöscht, Disable Taskmanager gelöscht, den Shell Eintrag bei Winlogon auf explorer.exe umgestellt usw.
Danach noch Malwarebytes drüber laufen lassen.

Wenn ich jetzt den PC neustarte fehlt die Taskleiste, der Desktop ist leer und der Explorer ist geöffnet.

Wenn ich die explorer.exe über den Taskmanager schließe und neu Starte öffnet sich nur der Explorer. Desktop bleibt leer und auch die Taskleiste fehlt.

Habe gelesen rechte Maustaste auf den Desktop würde was bringen, da öffnet sich aber kein Menü.

Habe schon die explorer.exe vom meinem Laptop mit gleichen System überschrieben, ohne Erfolg.

Kann mir jemand weiterhelfen? Was benötigt ihr noch für Angaben?


tax

cosinus 11.01.2012 19:37

Zitat:

Danach noch Malwarebytes drüber laufen lassen.
Log dazu fehlt. Alle von MBAM posten

tax 11.01.2012 21:02

Hallo cosinus,

danke das du dir mein Problem anschaust.
Hier das Log File:

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.05.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Weisi :: SHOOT [Administrator]

10.01.2012 21:24:38
mbam-log-2012-01-10 (21-24-38).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 216045
Laufzeit: 5 Minute(n), 50 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|olmwKSKlNdgCU6b (Trojan.Agent) -> Daten: C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ActiveX32_64lo.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ActiveX32_64lo.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\RECYCLER\S-1-5-18\Dc2.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\0.3120163846121671.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 11.01.2012 21:13

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

tax 11.01.2012 21:40

Ja das gibts ein paar

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.05.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Weisi :: SHOOT [Administrator]

05.01.2012 21:22:48
mbam-log-2012-01-05 (21-22-48).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 216756
Laufzeit: 9 Minute(n), 58 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8399

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

23.12.2011 20:58:53
mbam-log-2011-12-23 (20-58-53).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 212137
Laufzeit: 5 Minute(n), 51 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8399

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20.12.2011 17:41:24
mbam-log-2011-12-20 (17-41-24).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 212182
Laufzeit: 6 Minute(n), 15 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8399

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20.12.2011 17:23:27
mbam-log-2011-12-20 (17-23-27).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 212014
Laufzeit: 7 Minute(n), 40 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 2
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\prh (Trojan.Banker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\tst (Trojan.Banker) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
c:\WINDOWS\system32\xmldm (Stolen.Data) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\WINDOWS\system32\srvblck2.tmp (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xmldm\iexplore.exe_uas001.dat (Stolen.Data) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xmldm\outlook.exe_uas001.dat (Stolen.Data) -> Quarantined and deleted successfully.

Code:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Datenbank Version: 7400

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

07.08.2011 14:36:07
mbam-log-2011-08-07 (14-36-07).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|F:\|)
Durchsuchte Objekte: 356025
Laufzeit: 1 Stunde(n), 19 Minute(n), 34 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Datenbank Version: 7400

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

07.08.2011 13:16:06
mbam-log-2011-08-07 (13-16-06).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 197382
Laufzeit: 5 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

24.02.2011 21:25:03
mbam-log-2011-02-24 (21-25-03).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 140597
Laufzeit: 9 Minute(n), 16 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

24.02.2011 21:25:03
mbam-log-2011-02-24 (21-25-03).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 140597
Laufzeit: 9 Minute(n), 16 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

Code:

alwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20.02.2011 12:40:40
mbam-log-2011-02-20 (12-40-40).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|F:\|)
Durchsuchte Objekte: 286037
Laufzeit: 1 Stunde(n), 11 Minute(n), 5 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 5
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 2
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\seneka (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Userinit.exe (Security.Hijack) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mssysfs (Trojan.Downloader) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\WINDOWS\Temp\tmp2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\f.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

Code:

Malwarebytes' Anti-Malware 1.33
Datenbank Version: 1736
Windows 5.1.2600 Service Pack 3

07.02.2009 15:42:47
mbam-log-2009-02-07 (15-42-47).txt

Scan-Methode: Quick-Scan
Durchsuchte Objekte: 58892
Laufzeit: 1 minute(s), 57 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Code:

Scan-Methode: Vollständiger Scan (C:\|)
Durchsuchte Objekte: 146377
Laufzeit: 28 minute(s), 54 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 14
Infizierte Registrierungswerte: 4
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 1
Infizierte Dateien: 10

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyatrri (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prunnet (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cogad (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\cogad (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateien:
C:\WINDOWS\system32\xxyAtrRi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\wsmaxceonr.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HDGTLD7Q\winsinstall[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekakvmydonv.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekamkjrhldo.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\senekaskmtlmog.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\senekaymvfaxpy.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\senekayueobilw.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\senekamjotuppx.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Code:

Malwarebytes' Anti-Malware 1.33
Datenbank Version: 1696
Windows 5.1.2600 Service Pack 3

26.01.2009 20:42:58
mbam-log-2009-01-26 (20-42-58).txt

Scan-Methode: Quick-Scan
Durchsuchte Objekte: 58892
Laufzeit: 1 minute(s), 5 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysLibrary (Rootkit.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Firewall auto setup (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\WINDOWS\msacm32.drv (Trojan.Agent) -> Quarantined and deleted successfully.


cosinus 11.01.2012 21:47

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


tax 11.01.2012 22:10

Bevor ich eset ausführe noch einige Fragen dazu:

Wie sehe ich das alle Hintergrundprogramme geschlossen sind? Die Taskleiste fehlt ja.

Die Tastenkombi Win-Taste und R geht nicht, bzw. da öffnet sich nichts. Habe WinXP SP3.
Geht das auch über den Task-Manager "Datei|Neuer Task(Ausführen...)"?

cosinus 12.01.2012 15:38

Dann führ ESET einfach so aus...

tax 13.01.2012 09:15

So war etwas schwierig den IE zu starten. Über die iexplorer.exe startete er nicht. Ich bin dann in denn Ordner Favoriten und darüber hat er sich dann geöffnet.

Eset ist fündig geworden.

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=0b05a8f2ed47e7408040dec21f673cff
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-13 02:39:48
# local_time=2012-01-13 03:39:48 (+0100, Westeuropäische Normalzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1797 16775141 100 94 4440 91884242 0 0
# compatibility_mode=8192 67108863 100 0 3933 3933 0 0
# scanned=200868
# found=3
# cleaned=0
# scan_time=19941
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\52\71dba774-35ff92d3        Java/Exploit.CVE-2011-3544.S trojan (unable to clean)        00000000000000000000000000000000        I
C:\WINDOWS\system32\hNWEKRqr.ini        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I
C:\WINDOWS\system32\hNWEKRqr.ini2        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I


cosinus 13.01.2012 14:45

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


tax 13.01.2012 21:54

Hier das Log File von OTL


Code:

OTL logfile created on: 13.01.2012 21:32:04 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,75 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 83,07% Memory free
4,59 Gb Paging File | 4,29 Gb Available in Paging File | 93,34% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 100,00 Gb Total Space | 17,05 Gb Free Space | 17,05% Space Free | Partition Type: NTFS
Drive D: | 153,78 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 48,83 Gb Total Space | 8,76 Gb Free Space | 17,95% Space Free | Partition Type: NTFS
Drive F: | 37,48 Gb Total Space | 2,48 Gb Free Space | 6,61% Space Free | Partition Type: NTFS
 
Computer Name: SHOOT | User Name: Weisi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.13 21:28:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
PRC - [2011.07.01 13:34:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.27 18:19:17 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Programme\Canon\CAL\CALMAIN.exe
PRC - [2008.04.14 04:22:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.06 11:55:32 | 000,301,056 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU
MOD - [2010.01.28 13:57:53 | 000,355,688 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2006.02.25 18:50:46 | 000,061,440 | ---- | M] () -- C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll
MOD - [2006.02.25 18:50:16 | 000,023,552 | ---- | M] () -- C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mkunicode.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] --  -- (HidServ)
SRV - [2011.07.01 13:34:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.27 18:19:17 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.05.10 15:50:40 | 002,452,232 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Programme\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009.08.28 19:42:54 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009.02.10 17:01:49 | 000,116,104 | ---- | M] () [Auto | Stopped] -- C:\Programme\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2008.11.11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2004.10.22 02:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004.08.27 23:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Stopped] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
SRV - [2003.07.28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003.06.10 14:52:12 | 000,196,668 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\AVM\De_serv.exe -- (de_serv)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Running] --  -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] --  -- (xcpip)
DRV - [2011.07.01 13:34:03 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.01 13:34:03 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.07.14 12:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010.02.11 08:38:10 | 003,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009.10.25 09:14:34 | 000,057,600 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3XX2K)
DRV - [2009.10.25 09:14:34 | 000,057,600 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3xx USB Smart Card Reader)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.11.13 14:10:06 | 000,007,680 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\STCFUx32.sys -- (STCFUx32)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.14 00:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006.11.23 17:55:20 | 000,012,928 | ---- | M] (Freecom) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Bonifay.sys -- (Bonifay)
DRV - [2006.03.29 12:44:18 | 000,007,040 | ---- | M] (Freecom) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Gonzales.sys -- (Gonzales)
DRV - [2005.12.02 17:09:12 | 000,105,872 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2005.04.06 02:22:30 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.06 02:22:28 | 000,033,536 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.03 18:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.02.23 16:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.01.17 06:43:26 | 000,088,576 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys -- (nvatabus)
DRV - [2004.11.17 12:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.11.08 10:22:58 | 000,024,152 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2004.11.05 11:39:08 | 000,082,148 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2004.10.19 13:40:56 | 000,028,207 | ---- | M] (IVT Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2004.10.19 13:37:38 | 000,061,312 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2004.10.19 11:39:26 | 000,020,096 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2004.10.14 10:52:27 | 000,004,962 | R--- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2004.09.21 18:18:02 | 000,011,604 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2004.09.21 18:15:34 | 000,010,804 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BtNetDrv.sys -- (BT)
DRV - [2004.08.13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.08.09 12:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 12:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.07.19 15:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1)
DRV - [2004.06.26 12:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004.06.26 12:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004.05.04 12:46:18 | 000,346,656 | R--- | M] (Siemens AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE4501D.sys -- (SE4501D)
DRV - [2004.04.14 10:08:00 | 000,044,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2004.04.14 10:08:00 | 000,021,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2004.04.14 10:08:00 | 000,014,432 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2004.04.14 10:08:00 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2004.04.14 10:08:00 | 000,005,600 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2004.03.10 13:31:18 | 000,003,328 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AsInsHelp32.sys -- (ASInsHelp)
DRV - [2003.12.01 16:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.10.15 16:52:50 | 000,174,530 | ---- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ov519vid.sys -- (ovt519)
DRV - [2003.10.06 10:29:08 | 000,007,424 | R--- | M] (Prolific Technology Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PLFF.sys -- (PLFF)
DRV - [2003.09.29 21:32:59 | 000,022,912 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2003.06.27 01:00:00 | 000,665,600 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fdssbase.sys -- (FDSSBASE) AVM FRITZ!Card DSL SL (WinXP/2000)
DRV - [2003.06.27 01:00:00 | 000,039,552 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avmdsloe.sys -- (AVMDSLPPPOE)
DRV - [2003.06.27 01:00:00 | 000,038,992 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avmndsl.sys -- (AVMNDSL)
DRV - [2003.06.10 14:52:12 | 000,336,384 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETFWDSL.SYS -- (NETFWDSL)
DRV - [2003.06.10 14:52:12 | 000,027,648 | ---- | M] (AVM Berlin) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Aadev.sys -- (aadev)
DRV - [2003.04.10 10:42:56 | 000,048,384 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SaiNtHid.sys -- (SaiNtHid)
DRV - [2002.10.01 08:22:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2001.08.17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001.01.19 23:32:34 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\dbustrcm.sys -- (dbustrcm)
DRV - [1997.04.22 09:16:00 | 000,006,272 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ASLM75.SYS -- (aslm75)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = MSN Suche
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://search.msn.de/spresults.aspx?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Programme\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2240: C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2298: C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1348: C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Programme\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.02.18 18:19:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.12.23 20:46:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.12.23 20:46:43 | 000,000,000 | ---D | M]
 
[2010.07.21 13:36:37 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Extensions
[2012.01.08 13:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\extensions
[2011.04.16 20:41:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.01.08 13:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.09.06 19:34:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.27 21:11:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.03.08 08:23:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.08.09 20:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009.03.09 20:29:32 | 000,000,000 | ---D | M] (Long Titles) -- C:\PROGRAMME\HAUFE\IDESK\IDESKBROWSER\EXTENSIONS\{C24AECC7-7C95-507F-D71F-155CB86656DF}
[2010.10.12 16:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\CCMSDK.dll
[2010.10.12 16:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\CgpCore.dll
[2010.10.12 16:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\confmgr.dll
[2010.10.12 16:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\ctxlogging.dll
[2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2010.10.12 18:16:54 | 000,484,768 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\npicaN.dll
[2010.10.12 16:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\TcpPServ.dll
[2011.10.23 09:07:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.23 09:07:08 | 000,002,344 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.23 09:07:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.23 09:07:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.23 09:07:08 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.01.26 21:38:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Reg Error: Value error.) - {7836159E-1915-4FDF-BCEB-F541C4517016} - C:\WINDOWS\system32\rqRKEWNh.dll File not found
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUS Probe] C:\Programme\ASUS\Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Programme\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Programme\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [CORSAIR_PLUtil] C:\Programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [ElbyCheckAnyDVD] C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [LexwareInfoService] C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OpwareSE2] C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PLFFAP] C:\WINDOWS\system32\HotFixQ0306270.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" File not found
O4 - HKCU..\Run: [NBJ] C:\Programme\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Alles mit BitComet herunterladen - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Alle &Videos mit BitComet herunterladen - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm File not found
O8 - Extra context menu item: Easy-WebPrint Drucken - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Schnelldruck - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Vorschau - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Zu Druckliste hinzufügen - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Mit BitComet herunter&laden - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe File not found
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ltow.de ([ag] https in Vertrauenswürdige Sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124540955031 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} hxxp://www.o2c.de/download/o2cplayer.cab (O2C-Player (ELECO Software GmbH))
O16 - DPF: {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20D67A27-0516-4A6D-B1B4-A2FA3F12F385}: NameServer = 192.168.122.252,192.168.122.253
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{921F56A6-854D-4E0E-9062-946D70AB95B7}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\haufereader - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ActiveX32_64lo.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\WINDOWS\System32\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\rqRKEWNh) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.06.22 17:01:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.11.02 15:04:58 | 000,000,046 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.13 21:28:46 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\OTL.exe
[2012.01.12 22:01:54 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.01.10 01:20:36 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.01.08 21:53:52 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Weisi\Recent
[2012.01.03 19:47:42 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
[2012.01.03 19:47:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJPLM
[2012.01.03 19:31:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon iP4700 series Benutzerregistrierung
[2012.01.03 19:31:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\CD-LabelPrint
[2012.01.03 19:30:21 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2012.01.03 19:30:07 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2012.01.03 19:30:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon iP4700 series
[2012.01.03 19:29:48 | 000,000,000 | -H-D | C] -- C:\Programme\CanonBJ
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2011.12.15 23:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\UAs
[2011.12.15 23:01:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\kock
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.13 21:28:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
[2012.01.13 21:28:47 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2012.01.13 21:24:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.01.12 21:48:15 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.01.08 17:12:15 | 000,138,520 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2012.01.08 17:12:06 | 000,234,536 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2012.01.05 21:20:27 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.03 19:30:39 | 000,001,622 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Canon My Printer.lnk
[2012.01.01 20:58:10 | 000,006,656 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.30 22:29:30 | 000,506,566 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2011.12.30 22:29:30 | 000,484,682 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.12.30 22:29:30 | 000,096,406 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2011.12.30 22:29:30 | 000,080,696 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.12.23 20:46:22 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011.12.19 21:05:13 | 000,306,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.12.19 21:03:27 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.12.16 23:41:02 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.05 21:20:27 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.03 19:30:39 | 000,001,622 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Canon My Printer.lnk
[2011.12.24 10:31:42 | 000,000,418 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2011.10.17 19:47:42 | 000,000,880 | ---- | C] () -- C:\WINDOWS\HBCIKRNL.INI
[2011.07.28 16:03:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011.07.28 16:00:45 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011.06.15 20:51:53 | 000,000,161 | ---- | C] () -- C:\WINDOWS\BHPrintHelper.INI
[2010.11.27 02:54:40 | 000,579,122 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-515967899-1229272821-839522115-1003-0.dat
[2010.11.27 02:54:39 | 000,288,538 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2010.10.14 13:19:32 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\LXPrnUtil10.dll
[2010.10.14 13:18:40 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC8.dll
[2010.10.14 13:17:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC8.dll
[2010.10.14 13:16:40 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC8.dll
[2010.09.05 18:12:51 | 000,200,704 | ---- | C] () -- C:\WINDOWS\sel3110.exe
[2010.09.05 18:12:51 | 000,040,960 | ---- | C] () -- C:\WINDOWS\CleanDev.exe
[2010.09.05 18:12:51 | 000,032,528 | ---- | C] () -- C:\WINDOWS\amcap.exe
[2010.08.19 22:14:25 | 000,441,200 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.07.21 13:36:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010.02.11 05:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010.02.11 05:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009.10.19 18:38:08 | 000,554,496 | ---- | C] () -- C:\WINDOWS\System32\dvmsg.dll
[2009.10.15 19:05:53 | 000,007,439 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\abspann_teletax_idea.gif
[2009.10.15 19:05:53 | 000,000,293 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\lastscreen.html
[2009.10.15 19:05:53 | 000,000,107 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\lastscreen.ikf
[2009.07.15 17:54:27 | 000,111,928 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PnkBstrB.exe
[2009.07.15 17:54:18 | 000,794,408 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009.06.21 11:44:55 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009.04.23 23:29:16 | 000,189,051 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009.02.07 11:40:00 | 000,383,492 | -HS- | C] () -- C:\WINDOWS\System32\hNWEKRqr.ini2
[2009.02.07 11:40:00 | 000,383,492 | -HS- | C] () -- C:\WINDOWS\System32\hNWEKRqr.ini
[2009.01.26 21:33:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009.01.26 21:33:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009.01.26 21:33:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009.01.26 21:33:20 | 000,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009.01.06 13:26:53 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2008.04.03 17:09:28 | 000,001,755 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2007.11.13 22:39:34 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA110VC8.dll
[2007.11.11 14:34:52 | 000,138,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007.11.11 14:34:46 | 000,234,536 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2007.11.11 14:34:34 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2007.10.01 20:17:08 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA100VC7.dll
[2007.10.01 20:17:07 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\LxImport50VC7.dll
[2007.10.01 20:17:07 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\LxImport40VC7.dll
[2007.10.01 20:17:07 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PXTToolVC7.dll
[2007.03.29 22:00:40 | 000,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2007.01.26 20:24:14 | 000,001,984 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2006.12.19 20:22:04 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html
[2006.11.04 22:16:26 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA100VC8.dll
[2006.10.22 18:00:14 | 000,000,800 | ---- | C] () -- C:\WINDOWS\Rtcw.INI
[2006.09.21 12:53:28 | 000,282,679 | ---- | C] () -- C:\WINDOWS\System32\dnt27.dll
[2006.09.21 12:52:24 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27.dll
[2006.09.21 12:52:14 | 000,077,881 | ---- | C] () -- C:\WINDOWS\System32\dntvm27.dll
[2006.08.06 15:30:21 | 000,000,118 | ---- | C] () -- C:\WINDOWS\Formular.INI
[2006.07.13 20:42:31 | 000,000,144 | ---- | C] () -- C:\WINDOWS\mandant.ini
[2006.05.11 20:07:39 | 000,081,984 | ---- | C] () -- C:\WINDOWS\System32\bdod.bin
[2006.03.26 00:28:24 | 000,053,248 | ---- | C] () -- C:\WINDOWS\W_ZIPPER.EXE
[2006.03.26 00:28:24 | 000,000,154 | ---- | C] () -- C:\WINDOWS\WCOSOBA.INI
[2006.03.26 00:24:06 | 000,008,192 | -HS- | C] () -- C:\WINDOWS\o2cLicStore.bin
[2006.03.26 00:14:36 | 000,000,503 | ---- | C] () -- C:\WINDOWS\System32\FeMakro.ini
[2006.03.26 00:14:36 | 000,000,497 | ---- | C] () -- C:\WINDOWS\System32\FeAnim.ini
[2006.03.26 00:14:31 | 000,073,216 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll
[2006.03.26 00:14:31 | 000,000,132 | ---- | C] () -- C:\WINDOWS\System32\synsopos.ini
[2006.01.27 14:23:27 | 000,013,299 | ---- | C] () -- C:\WINDOWS\System32\drivers\packet.sys
[2006.01.27 14:23:27 | 000,011,604 | ---- | C] () -- C:\WINDOWS\System32\drivers\vbtenum.sys
[2006.01.07 15:12:31 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\bs.bin
[2006.01.07 15:12:29 | 000,000,138 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006.01.05 17:07:04 | 000,000,846 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\FASTApp.html
[2006.01.04 19:01:09 | 000,000,210 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005.12.17 18:28:40 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\getfile.dat
[2005.11.09 11:13:48 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC7.dll
[2005.11.09 11:11:46 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC7.dll
[2005.11.09 11:11:30 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC7.dll
[2005.11.08 19:18:27 | 000,036,363 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2005.11.08 18:36:50 | 000,000,516 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2005.11.04 18:03:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005.11.04 18:03:00 | 001,622,016 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2005.11.04 18:03:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005.11.04 18:03:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2005.11.04 18:03:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005.11.04 18:03:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005.11.04 18:03:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005.11.04 18:03:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2005.11.04 18:03:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2005.11.04 18:03:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005.11.04 18:03:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.10.21 13:31:27 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2005.08.06 07:49:31 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2005.07.27 18:41:22 | 000,000,017 | ---- | C] () -- C:\WINDOWS\SHISETUP.SYS
[2005.07.18 20:31:03 | 000,320,512 | ---- | C] () -- C:\WINDOWS\System32\W32MKDE.EXE
[2005.07.18 20:31:03 | 000,110,080 | ---- | C] () -- C:\WINDOWS\System32\W32MKRC.DLL
[2005.07.18 20:31:03 | 000,041,472 | ---- | C] () -- C:\WINDOWS\System32\W32btstp.dll
[2005.07.18 20:31:03 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\W32btxlt.dll
[2005.07.18 20:31:03 | 000,015,627 | ---- | C] () -- C:\WINDOWS\System32\WBROLLRS.DLL
[2005.07.18 20:31:02 | 000,237,623 | ---- | C] () -- C:\WINDOWS\System32\dnt26.dll
[2005.07.18 20:31:02 | 000,233,527 | ---- | C] () -- C:\WINDOWS\System32\dnt25.dll
[2005.07.18 20:31:02 | 000,221,239 | ---- | C] () -- C:\WINDOWS\System32\dnt24.dll
[2005.07.18 20:31:02 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\LxUtl10.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc26.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc25.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc24.dll
[2005.07.18 20:31:02 | 000,073,786 | ---- | C] () -- C:\WINDOWS\System32\dntvmc23.dll
[2005.07.18 20:31:02 | 000,073,785 | ---- | C] () -- C:\WINDOWS\System32\dntvm26.dll
[2005.07.18 20:31:02 | 000,069,689 | ---- | C] () -- C:\WINDOWS\System32\dntvm25.dll
[2005.07.18 20:31:02 | 000,069,689 | ---- | C] () -- C:\WINDOWS\System32\dntvm24.dll
[2005.07.18 20:31:02 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PXTTool.dll
[2005.07.18 20:31:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FKStampPainter.dll
[2005.07.18 20:31:02 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\SBSPAINT.DLL
[2005.07.18 20:31:01 | 000,196,688 | ---- | C] () -- C:\WINDOWS\System32\LxImport40.dll
[2005.07.18 20:31:01 | 000,102,458 | ---- | C] () -- C:\WINDOWS\System32\LXDasi20.dll
[2005.07.18 20:23:55 | 000,003,121 | ---- | C] () -- C:\WINDOWS\tm.ini
[2005.07.18 20:05:35 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\TxActiveXCombo.dll
[2005.07.18 20:05:25 | 000,229,431 | ---- | C] () -- C:\WINDOWS\System32\dnt23.dll
[2005.07.18 20:05:25 | 000,061,497 | ---- | C] () -- C:\WINDOWS\System32\dntvm23.dll
[2005.07.04 12:15:22 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005.07.04 12:15:22 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005.07.04 12:15:22 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005.07.04 12:15:22 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005.07.04 12:15:22 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005.07.04 12:15:22 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005.07.03 12:07:07 | 000,001,479 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2005.07.03 08:15:06 | 000,006,656 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.06.24 15:47:15 | 000,000,518 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005.06.24 15:47:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2005.06.23 17:59:27 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\SaiCfg.dll
[2005.06.23 17:59:27 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\NX.exe
[2005.06.23 17:59:27 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\E2.exe
[2005.06.22 20:56:33 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2005.06.22 20:56:33 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2005.06.22 20:56:32 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2005.06.22 20:56:32 | 000,003,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2005.06.22 20:55:14 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsProbe.sys
[2005.06.22 20:54:54 | 000,006,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005.06.22 20:49:58 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2005.06.22 17:54:02 | 000,004,533 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005.06.22 17:53:15 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2005.06.22 17:53:12 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005.06.22 17:53:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2005.06.22 17:53:07 | 000,306,008 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005.06.22 17:42:21 | 000,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2005.06.22 17:42:16 | 000,005,351 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2005.06.22 17:42:14 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2005.06.22 17:42:12 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2005.06.22 17:02:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005.06.22 16:58:32 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005.05.24 22:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005.04.28 05:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.04.28 05:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005.04.28 05:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2004.10.26 23:39:05 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004.08.02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.05.06 13:07:32 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\dnt26VC7.dll
[2004.05.06 13:05:04 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvmc26VC7.dll
[2004.05.06 13:04:42 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dntvm26VC7.dll
[2003.06.27 01:00:00 | 000,305,880 | ---- | C] () -- C:\WINDOWS\System32\fdssbase.bin
[2003.02.20 17:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003.02.12 19:21:20 | 000,007,698 | ---- | C] () -- C:\WINDOWS\cadx2.ini
[2001.08.23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.08.23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.08.23 12:00:00 | 000,506,566 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2001.08.23 12:00:00 | 000,484,682 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.08.23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.08.23 12:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2001.08.23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.08.23 12:00:00 | 000,096,406 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2001.08.23 12:00:00 | 000,080,696 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.08.23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.08.23 12:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2001.08.23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.08.23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.08.23 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001.08.23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1999.01.22 19:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
 
========== LOP Check ==========
 
[2006.12.27 21:03:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve
[2012.01.03 19:30:21 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2012.01.03 19:47:42 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
[2012.01.03 19:49:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJPLM
[2011.02.15 20:27:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Citrix
[2007.10.11 18:32:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\fotobuch.de AG
[2006.12.27 21:00:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Haufe
[2009.02.18 18:17:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2011.06.18 20:22:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware
[2009.10.13 20:35:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSScanAppDataDir
[2011.04.19 05:53:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2005.11.08 19:03:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2005.11.08 18:58:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SSScanAppDataDir
[2005.11.08 18:59:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SSScanWizard
[2010.03.27 15:33:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2005.11.08 18:49:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Canon
[2006.01.27 18:49:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\DataLayer
[2012.01.05 21:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2007.10.11 18:32:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\fotobuch.de AG
[2005.06.22 21:35:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\FRITZ!
[2007.12.14 20:46:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\gslist
[2006.12.27 21:06:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Haufe
[2011.02.15 20:31:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICAClient
[2009.06.22 20:10:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICQ
[2005.07.04 12:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\InterVideo
[2007.10.03 11:05:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Lexware
[2009.10.15 18:59:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\linkundlink
[2009.02.18 18:21:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia
[2006.01.27 15:27:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia Multimedia Player
[2008.03.06 16:37:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\NWB
[2009.02.21 16:27:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PC Suite
[2005.11.08 18:36:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ScanSoft
[2012.01.05 19:17:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2007.04.09 11:26:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\TaxNMore
[2009.12.13 09:39:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Tobit
[2012.01.13 21:28:47 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2009.02.07 16:47:37 | 000,000,316 | ---- | M] () -- C:\WINDOWS\Tasks\utslqiiv.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< eventlog.dll >
 
< scecli.dll >
 
< netlogon.dll >
 
< cngaudit.dll >
 
< ws2ifsl.sys >
 
< sceclt.dll >
 
< ntelogon.dll >
 
< winlogon.exe >
 
< logevent.dll >
 
< user32.DLL >
 
< iaStor.sys >
 
< nvstor.sys >
 
< atapi.sys >
 
< IdeChnDr.sys >
 
< viasraid.sys >
 
< AGP440.sys >
 
< vaxscsi.sys >
 
< nvatabus.sys >
 
< viamraid.sys >
 
< nvata.sys >
 
< nvgts.sys >
 
< iastorv.sys >
 
< ViPrt.sys >
 
< eNetHook.dll >
 
< ahcix86.sys >
 
< KR10N.sys >
 
< nvstor32.sys >
 
< ahcix86s.sys >
 
< /md5stop >
Invalid Switch: md5stop

 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2005.06.22 18:52:10 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005.06.22 18:52:10 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005.06.22 18:52:10 | 000,405,504 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
<          >

< End of report >


cosinus 14.01.2012 00:06

Wiederhol den Scan bitte, sieht aus als wäre da ein Kopierfehler unterlaufen

tax 14.01.2012 08:37

Versuch zwei


Code:

OTL logfile created on: 14.01.2012 08:13:44 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,75 Gb Total Physical Memory | 2,31 Gb Available Physical Memory | 84,19% Memory free
4,59 Gb Paging File | 4,31 Gb Available in Paging File | 93,90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 100,00 Gb Total Space | 17,02 Gb Free Space | 17,02% Space Free | Partition Type: NTFS
Drive D: | 153,78 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 48,83 Gb Total Space | 8,76 Gb Free Space | 17,95% Space Free | Partition Type: NTFS
Drive F: | 37,48 Gb Total Space | 2,48 Gb Free Space | 6,61% Space Free | Partition Type: NTFS
 
Computer Name: SHOOT | User Name: Weisi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.13 21:28:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
PRC - [2011.07.01 13:34:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.27 18:19:17 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.01.28 13:57:53 | 000,355,688 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Disabled | Stopped] --  -- (HidServ)
SRV - [2011.07.01 13:34:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.27 18:19:17 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.05.10 15:50:40 | 002,452,232 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Stopped] -- C:\Programme\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009.08.28 19:42:54 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009.02.10 17:01:49 | 000,116,104 | ---- | M] () [Auto | Stopped] -- C:\Programme\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2008.11.11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2004.10.22 02:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004.08.27 23:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Stopped] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
SRV - [2003.07.28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003.06.10 14:52:12 | 000,196,668 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\AVM\De_serv.exe -- (de_serv)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Running] --  -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] --  -- (xcpip)
DRV - [2011.07.01 13:34:03 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.01 13:34:03 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.07.14 12:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010.02.11 08:38:10 | 003,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009.10.25 09:14:34 | 000,057,600 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3XX2K)
DRV - [2009.10.25 09:14:34 | 000,057,600 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3xx USB Smart Card Reader)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.11.13 14:10:06 | 000,007,680 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\STCFUx32.sys -- (STCFUx32)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.14 00:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006.11.23 17:55:20 | 000,012,928 | ---- | M] (Freecom) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Bonifay.sys -- (Bonifay)
DRV - [2006.03.29 12:44:18 | 000,007,040 | ---- | M] (Freecom) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Gonzales.sys -- (Gonzales)
DRV - [2005.12.02 17:09:12 | 000,105,872 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2005.04.06 02:22:30 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005.04.06 02:22:28 | 000,033,536 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.03 18:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.02.23 16:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.01.17 06:43:26 | 000,088,576 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys -- (nvatabus)
DRV - [2004.11.17 12:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.11.08 10:22:58 | 000,024,152 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2004.11.05 11:39:08 | 000,082,148 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2004.10.19 13:40:56 | 000,028,207 | ---- | M] (IVT Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2004.10.19 13:37:38 | 000,061,312 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2004.10.19 11:39:26 | 000,020,096 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2004.10.14 10:52:27 | 000,004,962 | R--- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2004.09.21 18:18:02 | 000,011,604 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2004.09.21 18:15:34 | 000,010,804 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BtNetDrv.sys -- (BT)
DRV - [2004.08.13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.08.09 12:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 12:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.07.19 15:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1)
DRV - [2004.06.26 12:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004.06.26 12:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004.05.04 12:46:18 | 000,346,656 | R--- | M] (Siemens AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE4501D.sys -- (SE4501D)
DRV - [2004.04.14 10:08:00 | 000,044,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2004.04.14 10:08:00 | 000,021,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2004.04.14 10:08:00 | 000,014,432 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2004.04.14 10:08:00 | 000,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2004.04.14 10:08:00 | 000,005,600 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2004.03.10 13:31:18 | 000,003,328 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AsInsHelp32.sys -- (ASInsHelp)
DRV - [2003.12.01 16:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.10.15 16:52:50 | 000,174,530 | ---- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ov519vid.sys -- (ovt519)
DRV - [2003.10.06 10:29:08 | 000,007,424 | R--- | M] (Prolific Technology Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PLFF.sys -- (PLFF)
DRV - [2003.09.29 21:32:59 | 000,022,912 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2003.06.27 01:00:00 | 000,665,600 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fdssbase.sys -- (FDSSBASE) AVM FRITZ!Card DSL SL (WinXP/2000)
DRV - [2003.06.27 01:00:00 | 000,039,552 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avmdsloe.sys -- (AVMDSLPPPOE)
DRV - [2003.06.27 01:00:00 | 000,038,992 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avmndsl.sys -- (AVMNDSL)
DRV - [2003.06.10 14:52:12 | 000,336,384 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETFWDSL.SYS -- (NETFWDSL)
DRV - [2003.06.10 14:52:12 | 000,027,648 | ---- | M] (AVM Berlin) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Aadev.sys -- (aadev)
DRV - [2003.04.10 10:42:56 | 000,048,384 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SaiNtHid.sys -- (SaiNtHid)
DRV - [2002.10.01 08:22:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2001.08.17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001.01.19 23:32:34 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\temp\dbustrcm.sys -- (dbustrcm)
DRV - [1997.04.22 09:16:00 | 000,006,272 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ASLM75.SYS -- (aslm75)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = MSN Suche
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://search.msn.de/spresults.aspx?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Programme\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2240: C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2298: C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1348: C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Programme\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.02.18 18:19:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.12.23 20:46:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.12.23 20:46:43 | 000,000,000 | ---D | M]
 
[2010.07.21 13:36:37 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Extensions
[2012.01.08 13:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\extensions
[2011.04.16 20:41:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.01.08 13:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.09.06 19:34:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.01.27 21:11:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.03.08 08:23:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.08.09 20:21:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009.03.09 20:29:32 | 000,000,000 | ---D | M] (Long Titles) -- C:\PROGRAMME\HAUFE\IDESK\IDESKBROWSER\EXTENSIONS\{C24AECC7-7C95-507F-D71F-155CB86656DF}
[2010.10.12 16:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\CCMSDK.dll
[2010.10.12 16:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\CgpCore.dll
[2010.10.12 16:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\confmgr.dll
[2010.10.12 16:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\ctxlogging.dll
[2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2010.10.12 18:16:54 | 000,484,768 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\npicaN.dll
[2010.10.12 16:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\TcpPServ.dll
[2011.10.23 09:07:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.23 09:07:08 | 000,002,344 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.23 09:07:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.23 09:07:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.23 09:07:08 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.01.26 21:38:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Reg Error: Value error.) - {7836159E-1915-4FDF-BCEB-F541C4517016} - C:\WINDOWS\system32\rqRKEWNh.dll File not found
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUS Probe] C:\Programme\ASUS\Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Programme\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Programme\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [CORSAIR_PLUtil] C:\Programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [ElbyCheckAnyDVD] C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [LexwareInfoService] C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OpwareSE2] C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PLFFAP] C:\WINDOWS\system32\HotFixQ0306270.exe (Prolific Technology Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" File not found
O4 - HKCU..\Run: [NBJ] C:\Programme\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Alles mit BitComet herunterladen - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Alle &Videos mit BitComet herunterladen - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm File not found
O8 - Extra context menu item: Easy-WebPrint Drucken - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Schnelldruck - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Vorschau - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Zu Druckliste hinzufügen - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Mit BitComet herunter&laden - C:\Programme\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe File not found
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ltow.de ([ag] https in Vertrauenswürdige Sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124540955031 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} hxxp://www.o2c.de/download/o2cplayer.cab (O2C-Player (ELECO Software GmbH))
O16 - DPF: {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20D67A27-0516-4A6D-B1B4-A2FA3F12F385}: NameServer = 192.168.122.252,192.168.122.253
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{921F56A6-854D-4E0E-9062-946D70AB95B7}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\haufereader - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ActiveX32_64lo.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\WINDOWS\System32\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\rqRKEWNh) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.06.22 17:01:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.11.02 15:04:58 | 000,000,046 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: 6to4 -  File not found
NetSvcs: HidServ -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
MsConfig - StartUpReg: AWatch - hkey= - key= - C:\Programme\FRITZ!DSL\AWatch.exe (AVM Berlin)
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Programme\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: PC Suite Tray - hkey= - key= - C:\Programme\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
MsConfig - StartUpReg: rfxsrvtray - hkey= - key= - C:\Programme\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
MsConfig - StartUpReg: Start WingMan Profiler - hkey= - key= - C:\Programme\Logitech\Profiler\lwemon.exe (Logitech Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.1.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.1.4
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {JJhOKXSl-ZUWD-ubpK-1idX-wzG4eyU41q1K} -
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: aux1 - c_030600.nls File not found
Drivers32: aux2 - c_030600.nls File not found
Drivers32: midi1 - c_030600.nls File not found
Drivers32: midi2 - c_030600.nls File not found
Drivers32: mixer1 - c_030600.nls File not found
Drivers32: mixer2 - c_030600.nls File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\WINDOWS\system32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: wave1 - c_030600.nls File not found
Drivers32: wave2 - c_030600.nls File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.13 21:28:46 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\OTL.exe
[2012.01.12 22:01:54 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.01.10 01:20:36 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.01.08 21:53:52 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Weisi\Recent
[2012.01.03 19:47:42 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
[2012.01.03 19:47:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJPLM
[2012.01.03 19:31:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon iP4700 series Benutzerregistrierung
[2012.01.03 19:31:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\CD-LabelPrint
[2012.01.03 19:30:21 | 000,000,000 | -H-D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2012.01.03 19:30:07 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2012.01.03 19:30:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon iP4700 series
[2012.01.03 19:29:48 | 000,000,000 | -H-D | C] -- C:\Programme\CanonBJ
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2011.12.15 23:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\UAs
[2011.12.15 23:01:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\kock
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.14 08:10:21 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2012.01.14 08:06:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.01.13 21:28:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
[2012.01.12 21:48:15 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.01.08 17:12:15 | 000,138,520 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2012.01.08 17:12:06 | 000,234,536 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2012.01.05 21:20:27 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.03 19:30:39 | 000,001,622 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Canon My Printer.lnk
[2012.01.01 20:58:10 | 000,006,656 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.30 22:29:30 | 000,506,566 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2011.12.30 22:29:30 | 000,484,682 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.12.30 22:29:30 | 000,096,406 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2011.12.30 22:29:30 | 000,080,696 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.12.23 20:46:22 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011.12.19 21:05:13 | 000,306,008 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.12.19 21:03:27 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.12.16 23:41:02 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.05 21:20:27 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.03 19:30:39 | 000,001,622 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Canon My Printer.lnk
[2011.12.24 10:31:42 | 000,000,418 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2011.10.17 19:47:42 | 000,000,880 | ---- | C] () -- C:\WINDOWS\HBCIKRNL.INI
[2011.07.28 16:03:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011.07.28 16:00:45 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011.06.15 20:51:53 | 000,000,161 | ---- | C] () -- C:\WINDOWS\BHPrintHelper.INI
[2010.11.27 02:54:40 | 000,579,122 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-515967899-1229272821-839522115-1003-0.dat
[2010.11.27 02:54:39 | 000,288,538 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2010.10.14 13:19:32 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\LXPrnUtil10.dll
[2010.10.14 13:18:40 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC8.dll
[2010.10.14 13:17:00 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC8.dll
[2010.10.14 13:16:40 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC8.dll
[2010.09.05 18:12:51 | 000,200,704 | ---- | C] () -- C:\WINDOWS\sel3110.exe
[2010.09.05 18:12:51 | 000,040,960 | ---- | C] () -- C:\WINDOWS\CleanDev.exe
[2010.09.05 18:12:51 | 000,032,528 | ---- | C] () -- C:\WINDOWS\amcap.exe
[2010.08.19 22:14:25 | 000,441,200 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.07.21 13:36:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010.02.11 05:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010.02.11 05:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009.10.19 18:38:08 | 000,554,496 | ---- | C] () -- C:\WINDOWS\System32\dvmsg.dll
[2009.10.15 19:05:53 | 000,007,439 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\abspann_teletax_idea.gif
[2009.10.15 19:05:53 | 000,000,293 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\lastscreen.html
[2009.10.15 19:05:53 | 000,000,107 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\lastscreen.ikf
[2009.07.15 17:54:27 | 000,111,928 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PnkBstrB.exe
[2009.07.15 17:54:18 | 000,794,408 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009.06.21 11:44:55 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009.04.23 23:29:16 | 000,189,051 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009.02.07 11:40:00 | 000,383,492 | -HS- | C] () -- C:\WINDOWS\System32\hNWEKRqr.ini2
[2009.02.07 11:40:00 | 000,383,492 | -HS- | C] () -- C:\WINDOWS\System32\hNWEKRqr.ini
[2009.01.26 21:33:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009.01.26 21:33:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009.01.26 21:33:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009.01.26 21:33:20 | 000,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009.01.06 13:26:53 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2008.04.03 17:09:28 | 000,001,755 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2007.11.13 22:39:34 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA110VC8.dll
[2007.11.11 14:34:52 | 000,138,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007.11.11 14:34:46 | 000,234,536 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2007.11.11 14:34:34 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2007.10.01 20:17:08 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA100VC7.dll
[2007.10.01 20:17:07 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\LxImport50VC7.dll
[2007.10.01 20:17:07 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\LxImport40VC7.dll
[2007.10.01 20:17:07 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PXTToolVC7.dll
[2007.03.29 22:00:40 | 000,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2007.01.26 20:24:14 | 000,001,984 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2006.12.19 20:22:04 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html
[2006.11.04 22:16:26 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\BH_DATA100VC8.dll
[2006.10.22 18:00:14 | 000,000,800 | ---- | C] () -- C:\WINDOWS\Rtcw.INI
[2006.09.21 12:53:28 | 000,282,679 | ---- | C] () -- C:\WINDOWS\System32\dnt27.dll
[2006.09.21 12:52:24 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27.dll
[2006.09.21 12:52:14 | 000,077,881 | ---- | C] () -- C:\WINDOWS\System32\dntvm27.dll
[2006.08.06 15:30:21 | 000,000,118 | ---- | C] () -- C:\WINDOWS\Formular.INI
[2006.07.13 20:42:31 | 000,000,144 | ---- | C] () -- C:\WINDOWS\mandant.ini
[2006.05.11 20:07:39 | 000,081,984 | ---- | C] () -- C:\WINDOWS\System32\bdod.bin
[2006.03.26 00:28:24 | 000,053,248 | ---- | C] () -- C:\WINDOWS\W_ZIPPER.EXE
[2006.03.26 00:28:24 | 000,000,154 | ---- | C] () -- C:\WINDOWS\WCOSOBA.INI
[2006.03.26 00:24:06 | 000,008,192 | -HS- | C] () -- C:\WINDOWS\o2cLicStore.bin
[2006.03.26 00:14:36 | 000,000,503 | ---- | C] () -- C:\WINDOWS\System32\FeMakro.ini
[2006.03.26 00:14:36 | 000,000,497 | ---- | C] () -- C:\WINDOWS\System32\FeAnim.ini
[2006.03.26 00:14:31 | 000,073,216 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll
[2006.03.26 00:14:31 | 000,000,132 | ---- | C] () -- C:\WINDOWS\System32\synsopos.ini
[2006.01.27 14:23:27 | 000,013,299 | ---- | C] () -- C:\WINDOWS\System32\drivers\packet.sys
[2006.01.27 14:23:27 | 000,011,604 | ---- | C] () -- C:\WINDOWS\System32\drivers\vbtenum.sys
[2006.01.07 15:12:31 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\bs.bin
[2006.01.07 15:12:29 | 000,000,138 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006.01.05 17:07:04 | 000,000,846 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\FASTApp.html
[2006.01.04 19:01:09 | 000,000,210 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005.12.17 18:28:40 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\getfile.dat
[2005.11.09 11:13:48 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\dnt27VC7.dll
[2005.11.09 11:11:46 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvmc27VC7.dll
[2005.11.09 11:11:30 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\dntvm27VC7.dll
[2005.11.08 19:18:27 | 000,036,363 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2005.11.08 18:36:50 | 000,000,516 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2005.11.04 18:03:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005.11.04 18:03:00 | 001,622,016 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2005.11.04 18:03:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005.11.04 18:03:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2005.11.04 18:03:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005.11.04 18:03:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005.11.04 18:03:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005.11.04 18:03:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2005.11.04 18:03:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2005.11.04 18:03:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005.11.04 18:03:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.10.21 13:31:27 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2005.08.06 07:49:31 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2005.07.27 18:41:22 | 000,000,017 | ---- | C] () -- C:\WINDOWS\SHISETUP.SYS
[2005.07.18 20:31:03 | 000,320,512 | ---- | C] () -- C:\WINDOWS\System32\W32MKDE.EXE
[2005.07.18 20:31:03 | 000,110,080 | ---- | C] () -- C:\WINDOWS\System32\W32MKRC.DLL
[2005.07.18 20:31:03 | 000,041,472 | ---- | C] () -- C:\WINDOWS\System32\W32btstp.dll
[2005.07.18 20:31:03 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\W32btxlt.dll
[2005.07.18 20:31:03 | 000,015,627 | ---- | C] () -- C:\WINDOWS\System32\WBROLLRS.DLL
[2005.07.18 20:31:02 | 000,237,623 | ---- | C] () -- C:\WINDOWS\System32\dnt26.dll
[2005.07.18 20:31:02 | 000,233,527 | ---- | C] () -- C:\WINDOWS\System32\dnt25.dll
[2005.07.18 20:31:02 | 000,221,239 | ---- | C] () -- C:\WINDOWS\System32\dnt24.dll
[2005.07.18 20:31:02 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\LxUtl10.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc26.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc25.dll
[2005.07.18 20:31:02 | 000,077,882 | ---- | C] () -- C:\WINDOWS\System32\dntvmc24.dll
[2005.07.18 20:31:02 | 000,073,786 | ---- | C] () -- C:\WINDOWS\System32\dntvmc23.dll
[2005.07.18 20:31:02 | 000,073,785 | ---- | C] () -- C:\WINDOWS\System32\dntvm26.dll
[2005.07.18 20:31:02 | 000,069,689 | ---- | C] () -- C:\WINDOWS\System32\dntvm25.dll
[2005.07.18 20:31:02 | 000,069,689 | ---- | C] () -- C:\WINDOWS\System32\dntvm24.dll
[2005.07.18 20:31:02 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PXTTool.dll
[2005.07.18 20:31:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FKStampPainter.dll
[2005.07.18 20:31:02 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\SBSPAINT.DLL
[2005.07.18 20:31:01 | 000,196,688 | ---- | C] () -- C:\WINDOWS\System32\LxImport40.dll
[2005.07.18 20:31:01 | 000,102,458 | ---- | C] () -- C:\WINDOWS\System32\LXDasi20.dll
[2005.07.18 20:23:55 | 000,003,121 | ---- | C] () -- C:\WINDOWS\tm.ini
[2005.07.18 20:05:35 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\TxActiveXCombo.dll
[2005.07.18 20:05:25 | 000,229,431 | ---- | C] () -- C:\WINDOWS\System32\dnt23.dll
[2005.07.18 20:05:25 | 000,061,497 | ---- | C] () -- C:\WINDOWS\System32\dntvm23.dll
[2005.07.04 12:15:22 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005.07.04 12:15:22 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005.07.04 12:15:22 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005.07.04 12:15:22 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005.07.04 12:15:22 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005.07.04 12:15:22 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005.07.03 12:07:07 | 000,001,479 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2005.07.03 08:15:06 | 000,006,656 | ---- | C] () -- C:\Dokumente und Einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.06.24 15:47:15 | 000,000,518 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005.06.24 15:47:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2005.06.23 17:59:27 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\SaiCfg.dll
[2005.06.23 17:59:27 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\NX.exe
[2005.06.23 17:59:27 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\E2.exe
[2005.06.22 20:56:33 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2005.06.22 20:56:33 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2005.06.22 20:56:32 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2005.06.22 20:56:32 | 000,003,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2005.06.22 20:55:14 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsProbe.sys
[2005.06.22 20:54:54 | 000,006,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005.06.22 20:49:58 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2005.06.22 17:54:02 | 000,004,533 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005.06.22 17:53:15 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2005.06.22 17:53:12 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005.06.22 17:53:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2005.06.22 17:53:07 | 000,306,008 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005.06.22 17:42:21 | 000,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2005.06.22 17:42:16 | 000,005,351 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2005.06.22 17:42:14 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2005.06.22 17:42:12 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2005.06.22 17:02:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005.06.22 16:58:32 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005.05.24 22:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005.04.28 05:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.04.28 05:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005.04.28 05:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2004.10.26 23:39:05 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004.08.02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.05.06 13:07:32 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\dnt26VC7.dll
[2004.05.06 13:05:04 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dntvmc26VC7.dll
[2004.05.06 13:04:42 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dntvm26VC7.dll
[2003.06.27 01:00:00 | 000,305,880 | ---- | C] () -- C:\WINDOWS\System32\fdssbase.bin
[2003.02.20 17:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003.02.12 19:21:20 | 000,007,698 | ---- | C] () -- C:\WINDOWS\cadx2.ini
[2001.08.23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.08.23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.08.23 12:00:00 | 000,506,566 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2001.08.23 12:00:00 | 000,484,682 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.08.23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.08.23 12:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2001.08.23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.08.23 12:00:00 | 000,096,406 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2001.08.23 12:00:00 | 000,080,696 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.08.23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.08.23 12:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2001.08.23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.08.23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.08.23 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001.08.23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1999.01.22 19:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
 
========== LOP Check ==========
 
[2006.12.27 21:03:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve
[2012.01.03 19:30:21 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2012.01.03 19:47:42 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
[2012.01.03 19:49:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJPLM
[2011.02.15 20:27:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Citrix
[2007.10.11 18:32:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\fotobuch.de AG
[2006.12.27 21:00:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Haufe
[2009.02.18 18:17:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2011.06.18 20:22:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware
[2009.10.13 20:35:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSScanAppDataDir
[2011.04.19 05:53:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2005.11.08 19:03:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2005.11.08 18:58:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SSScanAppDataDir
[2005.11.08 18:59:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SSScanWizard
[2010.03.27 15:33:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2005.11.08 18:49:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Canon
[2006.01.27 18:49:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\DataLayer
[2012.01.05 21:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2007.10.11 18:32:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\fotobuch.de AG
[2005.06.22 21:35:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\FRITZ!
[2007.12.14 20:46:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\gslist
[2006.12.27 21:06:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Haufe
[2011.02.15 20:31:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICAClient
[2009.06.22 20:10:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICQ
[2005.07.04 12:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\InterVideo
[2007.10.03 11:05:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Lexware
[2009.10.15 18:59:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\linkundlink
[2009.02.18 18:21:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia
[2006.01.27 15:27:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia Multimedia Player
[2008.03.06 16:37:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\NWB
[2009.02.21 16:27:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PC Suite
[2005.11.08 18:36:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ScanSoft
[2012.01.05 19:17:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2007.04.09 11:26:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\TaxNMore
[2009.12.13 09:39:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Tobit
[2012.01.14 08:10:21 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
[2009.02.07 16:47:37 | 000,000,316 | ---- | M] () -- C:\WINDOWS\Tasks\utslqiiv.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.08.10 06:21:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Adobe
[2005.07.12 16:56:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\AdobeUM
[2005.07.20 20:13:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Ahead
[2010.03.27 15:33:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Apple Computer
[2006.05.01 15:41:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ArcSoft
[2011.07.28 16:04:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ATI
[2010.12.30 15:26:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Avira
[2005.11.08 18:49:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Canon
[2010.12.31 16:17:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\CANON INC
[2006.01.27 18:49:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\DataLayer
[2011.02.15 20:28:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Download Manager
[2012.01.05 21:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2007.10.11 18:32:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\fotobuch.de AG
[2005.06.22 21:35:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\FRITZ!
[2007.02.04 12:31:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Google
[2007.12.14 20:46:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\gslist
[2006.12.27 21:06:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Haufe
[2005.09.04 15:06:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Help
[2011.02.15 20:31:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICAClient
[2009.06.22 20:10:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ICQ
[2005.06.22 17:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Identities
[2006.12.27 21:01:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\InstallShield
[2005.07.04 12:16:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\InterVideo
[2011.02.20 10:31:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Lavasoft
[2007.10.03 11:05:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Lexware
[2009.10.15 18:59:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\linkundlink
[2006.10.03 15:14:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Macromedia
[2009.01.26 20:34:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Malwarebytes
[2010.12.10 17:00:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Media Player Classic
[2011.08.10 06:21:55 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft
[2005.06.24 15:43:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft Web Folders
[2010.07.21 13:36:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Mozilla
[2009.02.18 18:21:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia
[2006.01.27 15:27:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Nokia Multimedia Player
[2008.03.06 16:37:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\NWB
[2009.02.21 16:27:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PC Suite
[2008.08.16 19:24:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real
[2005.11.08 18:36:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ScanSoft
[2012.01.05 19:17:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2011.07.07 19:21:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Skype
[2011.07.07 19:20:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\skypePM
[2005.07.27 17:11:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sun
[2007.04.09 11:26:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\TaxNMore
[2009.09.18 18:44:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\teamspeak2
[2009.12.13 09:39:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Tobit
[2010.12.31 14:28:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\ZoomBrowser EX
 
< %APPDATA%\*.exe /s >
[2009.07.15 17:54:27 | 000,111,928 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\PnkBstrB.exe
[2011.11.22 22:36:13 | 003,763,360 | ---- | M] (Adobe Systems, Inc.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2011.07.28 15:55:07 | 000,009,158 | R--- | M] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
[2008.01.02 10:19:01 | 000,086,016 | R--- | M] (InstallShield Software Corp.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft\Installer\{A4E86B6A-6EEC-41FD-8960-26947F0E3353}\ARPPRODUCTICON.exe
[2009.03.09 20:29:17 | 000,086,016 | R--- | M] (InstallShield Software Corp.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft\Installer\{D5C8E140-6E6F-11DD-9AA9-0050560400B1}\ARPPRODUCTICON.exe
[2009.03.09 20:29:34 | 000,086,016 | R--- | M] (InstallShield Software Corp.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Microsoft\Installer\{F48AAE0F-52F4-11DD-B1F7-0050560400B1}\ARPPRODUCTICON.exe
[2008.08.16 19:24:24 | 000,054,816 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\schedule.exe
[2008.08.16 19:24:24 | 000,312,864 | ---- | M] (RealNetworks, Inc.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\setup.exe
[2008.08.16 19:25:24 | 006,287,800 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\data\ff\firefoxgoogletoolbarsetup.exe
[2008.08.16 19:25:38 | 000,755,816 | ---- | M] () -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\data\gds\GOOGLE_DESKTOP\gdssetup.exe
[2008.08.16 19:25:53 | 001,240,104 | ---- | M] (Google) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\data\gtb\GOOGLE_TOOLBAR\googletoolbarinstaller.exe
[2008.08.16 19:26:02 | 001,240,104 | ---- | M] (Google) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\data\gtb_gds\GOOGLE_TOOLBAR\googletoolbarinstaller.exe
[2008.10.03 20:50:04 | 013,743,600 | ---- | M] (RealNetworks, Inc.) -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Real\Update\setup\data\rp\RealPlayer11GOLD_de.exe
 
< %SYSTEMDRIVE%\*.exe >
[2012.01.13 21:28:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
 
 
< MD5 for: AGP440.SYS  >
[2004.08.04 00:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.04 00:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WXPVOL_DE\I386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2004.08.04 00:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.04 00:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 08:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WXPVOL_DE\I386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 07:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 07:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2004.08.03 23:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 07:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 07:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.03 23:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
 
< MD5 for: NVATA.SYS  >
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\Win2K\sata_ide\nvata.sys
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\WinXP\sata_ide\nvata.sys
 
< MD5 for: NVATABUS.SYS  >
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\Win2K\legacy\nvatabus.sys
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\Win2K\sataraid\nvatabus.sys
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\WinXP\legacy\nvatabus.sys
[2005.08.18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\NVIDIA\nForceWin2KXP\8.22\IDE\WinXP\sataraid\nvatabus.sys
[2005.01.17 06:43:26 | 000,088,576 | R--- | M] (NVIDIA Corporation) MD5=3BFC1DEA3076D9EAA282E9CC1E4D7A23 -- C:\WINDOWS\system32\drivers\nvatabus.sys
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 07:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 07:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.03 23:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2005.03.02 19:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 19:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004.08.03 23:57:38 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2008.04.14 07:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 07:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 07:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 07:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 07:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.03 23:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2004.08.03 23:58:20 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 07:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 07:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2001.08.23 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2001.08.23 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2005.06.22 18:52:10 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005.06.22 18:52:10 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005.06.22 18:52:10 | 000,405,504 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< End of report >


cosinus 14.01.2012 15:33

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
DRV - File not found [Kernel | On_Demand | Running] --  -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] --  -- (xcpip)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\rqRKEWNh) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.06.22 17:01:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.11.02 15:04:58 | 000,000,046 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\Shell\AutoRun\command - "" = D:\ASUSACPI.exe
Drivers32: aux1 - c_030600.nls File not found
Drivers32: aux2 - c_030600.nls File not found
Drivers32: midi1 - c_030600.nls File not found
Drivers32: midi2 - c_030600.nls File not found
Drivers32: mixer1 - c_030600.nls File not found
Drivers32: mixer2 - c_030600.nls File not found
Drivers32: wave1 - c_030600.nls File not found
Drivers32: wave2 - c_030600.nls File not found
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa
[2011.12.24 10:24:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby
[2011.12.15 23:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\UAs
[2011.12.15 23:01:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\kock
[2009.02.07 16:47:37 | 000,000,316 | ---- | M] () -- C:\WINDOWS\Tasks\utslqiiv.job
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

tax 14.01.2012 15:54

Habe den Avira drauf.
Da die Taskleiste fehlt, kann ich Avira nicht beenden.
Über den Taskmanager lässt sich Avira auch nicht beendet. Kommt die Meldung Zugriff verweigert.

Kann ich den Fix trotzdem ausführen?

cosinus 14.01.2012 16:12

Zugriffscanner deaktivieren reicht.
Notfalls den Fix im abgesicherten Modus machen

tax 14.01.2012 16:17

Zitat:

Zitat von cosinus (Beitrag 754505)
Zugriffscanner deaktivieren reicht.

Was meinst du damit?

cosinus 14.01.2012 16:19

Zugrifsscanner=Hintergrundwächter

tax 14.01.2012 16:37

So ist durchgelaufen.


Code:

All processes killed
========== OTL ==========
Error: Unable to stop service xpsec!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xpsec deleted successfully.
Error: Unable to stop service xcpip!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xcpip deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\rqRKEWNh deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\AUTOEXEC.BAT moved successfully.
File move failed. D:\autorun.inf scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a97259c-e345-11d9-98ef-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a97259c-e345-11d9-98ef-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a97259c-e345-11d9-98ef-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a97259c-e345-11d9-98ef-806d6172696f}\ not found.
File D:\ASUSACPI.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5bb0f5f0-b9fd-11db-9b2d-806d6172696f}\ not found.
File D:\ASUSACPI.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\aux1 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\aux2 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\midi1 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\midi2 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\mixer1 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\mixer2 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\wave1 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\\wave2 deleted successfully.
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sewa folder moved successfully.
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Exby folder moved successfully.
C:\WINDOWS\System32\UAs folder moved successfully.
C:\WINDOWS\System32\kock folder moved successfully.
C:\WINDOWS\Tasks\utslqiiv.job moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 69783 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 21480583 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 2976009 bytes
 
User: Vanessa
->Temp folder emptied: 4078373 bytes
->Temporary Internet Files folder emptied: 21158986 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 6022 bytes
 
User: Weisi
->Temp folder emptied: 1547669120 bytes
->Temporary Internet Files folder emptied: 103140289 bytes
->Java cache emptied: 72886057 bytes
->FireFox cache emptied: 106049291 bytes
->Flash cache emptied: 3791905 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1138908 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32935003 bytes
RecycleBin emptied: 1670 bytes
 
Total Files Cleaned = 1.829,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 01142012_162424

Files\Folders moved on Reboot...
File move failed. D:\autorun.inf scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 14.01.2012 17:18

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

tax 14.01.2012 18:18

Unhide habe ich ausgeführt. Ohne Erfolg.

Hier das Log File vom TDSSKiller. Hat was gefunden.

Code:

17:43:03.0031 2144        TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05
17:43:03.0156 2144        ============================================================
17:43:03.0156 2144        Current date / time: 2012/01/14 17:43:03.0156
17:43:03.0156 2144        SystemInfo:
17:43:03.0156 2144       
17:43:03.0156 2144        OS Version: 5.1.2600 ServicePack: 3.0
17:43:03.0156 2144        Product type: Workstation
17:43:03.0156 2144        ComputerName: SHOOT
17:43:03.0156 2144        UserName: Weisi
17:43:03.0156 2144        Windows directory: C:\WINDOWS
17:43:03.0156 2144        System windows directory: C:\WINDOWS
17:43:03.0156 2144        Processor architecture: Intel x86
17:43:03.0156 2144        Number of processors: 1
17:43:03.0156 2144        Page size: 0x1000
17:43:03.0156 2144        Boot type: Normal boot
17:43:03.0156 2144        ============================================================
17:43:04.0468 2144        Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000, SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054
17:43:04.0562 2144        Initialize success
17:43:25.0343 2036        ============================================================
17:43:25.0343 2036        Scan started
17:43:25.0343 2036        Mode: Manual; SigCheck; TDLFS;
17:43:25.0343 2036        ============================================================
17:43:26.0125 2036        aadev          (6bfb6def4eb16b74c0179de110077920) C:\WINDOWS\system32\DRIVERS\aadev.sys
17:43:26.0250 2036        aadev ( UnsignedFile.Multi.Generic ) - warning
17:43:26.0250 2036        aadev - detected UnsignedFile.Multi.Generic (1)
17:43:26.0265 2036        Abiosdsk - ok
17:43:26.0281 2036        abp480n5 - ok
17:43:26.0328 2036        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:43:27.0609 2036        ACPI - ok
17:43:27.0718 2036        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:43:27.0875 2036        ACPIEC - ok
17:43:27.0890 2036        adpu160m - ok
17:43:27.0953 2036        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:43:28.0140 2036        aec - ok
17:43:28.0187 2036        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:43:28.0328 2036        AFD - ok
17:43:28.0359 2036        Aha154x - ok
17:43:28.0375 2036        aic78u2 - ok
17:43:28.0390 2036        aic78xx - ok
17:43:28.0500 2036        ALCXWDM        (933933288df5ed26d1928215c97d05c7) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
17:43:28.0718 2036        ALCXWDM - ok
17:43:28.0750 2036        AliIde - ok
17:43:28.0796 2036        AmdK8          (b9dbaae3219661f4d0c5e8dc0c2f987d) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
17:43:28.0828 2036        AmdK8 - ok
17:43:28.0843 2036        amsint - ok
17:43:28.0906 2036        AnyDVD          (44c905e4dfd93a8c49f97c14d9c399f3) C:\WINDOWS\system32\Drivers\AnyDVD.sys
17:43:28.0921 2036        AnyDVD ( UnsignedFile.Multi.Generic ) - warning
17:43:28.0921 2036        AnyDVD - detected UnsignedFile.Multi.Generic (1)
17:43:28.0937 2036        asc - ok
17:43:28.0968 2036        asc3350p - ok
17:43:28.0984 2036        asc3550 - ok
17:43:29.0000 2036        ASInsHelp      (33c171de483ee145f31234d93b078919) C:\WINDOWS\system32\drivers\AsInsHelp32.sys
17:43:29.0015 2036        ASInsHelp ( UnsignedFile.Multi.Generic ) - warning
17:43:29.0015 2036        ASInsHelp - detected UnsignedFile.Multi.Generic (1)
17:43:29.0046 2036        AsIO            (c959989e2ce8da9bde8cafddba84badf) C:\WINDOWS\system32\drivers\AsIO.sys
17:43:29.0078 2036        AsIO ( UnsignedFile.Multi.Generic ) - warning
17:43:29.0078 2036        AsIO - detected UnsignedFile.Multi.Generic (1)
17:43:29.0093 2036        aslm75          (71356a1370739e25375a1d17b6ae318f) C:\WINDOWS\system32\drivers\aslm75.sys
17:43:29.0109 2036        aslm75 ( UnsignedFile.Multi.Generic ) - warning
17:43:29.0109 2036        aslm75 - detected UnsignedFile.Multi.Generic (1)
17:43:29.0171 2036        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:43:29.0312 2036        AsyncMac - ok
17:43:29.0375 2036        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:43:29.0531 2036        atapi - ok
17:43:29.0546 2036        Atdisk - ok
17:43:29.0687 2036        ati2mtag        (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
17:43:29.0859 2036        ati2mtag ( UnsignedFile.Multi.Generic ) - warning
17:43:29.0859 2036        ati2mtag - detected UnsignedFile.Multi.Generic (1)
17:43:29.0921 2036        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:43:30.0093 2036        Atmarpc - ok
17:43:30.0125 2036        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:43:30.0265 2036        audstub - ok
17:43:30.0390 2036        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
17:43:30.0421 2036        avgio - ok
17:43:30.0484 2036        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
17:43:30.0593 2036        avgntflt - ok
17:43:30.0640 2036        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
17:43:30.0656 2036        avipbb - ok
17:43:30.0703 2036        AVMDSLPPPOE    (aa5874f64d6f2ffafa8c5fbc202ce6ef) C:\WINDOWS\system32\DRIVERS\avmdsloe.sys
17:43:30.0750 2036        AVMDSLPPPOE - ok
17:43:30.0765 2036        AVMNDSL        (140ba5bf4666c27c15368cce9df54a93) C:\WINDOWS\system32\DRIVERS\avmndsl.sys
17:43:30.0781 2036        AVMNDSL - ok
17:43:30.0812 2036        bdfdll - ok
17:43:30.0859 2036        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:43:31.0000 2036        Beep - ok
17:43:31.0046 2036        BlueletAudio    (31ff5b87c1dd907613cc613224b8e303) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
17:43:31.0078 2036        BlueletAudio ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0078 2036        BlueletAudio - detected UnsignedFile.Multi.Generic (1)
17:43:31.0109 2036        Bonifay        (b63f6bc2f76db693e4ed51ebe7f34828) C:\WINDOWS\system32\DRIVERS\Bonifay.sys
17:43:31.0109 2036        Bonifay ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0109 2036        Bonifay - detected UnsignedFile.Multi.Generic (1)
17:43:31.0156 2036        BT              (9da8abc4885aff4793d4aa420e40bb12) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
17:43:31.0171 2036        BT ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0171 2036        BT - detected UnsignedFile.Multi.Generic (1)
17:43:31.0203 2036        Btcsrusb        (95a061d5217cbb6642e73a8fd9aa9734) C:\WINDOWS\system32\Drivers\btcusb.sys
17:43:31.0234 2036        Btcsrusb ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0234 2036        Btcsrusb - detected UnsignedFile.Multi.Generic (1)
17:43:31.0281 2036        BthEnum        (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
17:43:31.0453 2036        BthEnum - ok
17:43:31.0500 2036        BTHidEnum      (083ad7f6ff500d0a93c0bea2cf298c93) C:\WINDOWS\system32\DRIVERS\vbtenum.sys
17:43:31.0531 2036        BTHidEnum ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0531 2036        BTHidEnum - detected UnsignedFile.Multi.Generic (1)
17:43:31.0546 2036        BTHidMgr        (f408264f6ad1dc7e7bdd4837440f115d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
17:43:31.0562 2036        BTHidMgr ( UnsignedFile.Multi.Generic ) - warning
17:43:31.0562 2036        BTHidMgr - detected UnsignedFile.Multi.Generic (1)
17:43:31.0593 2036        BTHMODEM        (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
17:43:31.0750 2036        BTHMODEM - ok
17:43:31.0781 2036        BthPan          (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
17:43:31.0953 2036        BthPan - ok
17:43:32.0000 2036        BTHPORT        (592e1cedbe314d0ef184dc6f46141e76) C:\WINDOWS\system32\Drivers\BTHport.sys
17:43:32.0046 2036        BTHPORT - ok
17:43:32.0078 2036        BTHUSB          (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
17:43:32.0250 2036        BTHUSB - ok
17:43:32.0296 2036        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:43:32.0437 2036        cbidf2k - ok
17:43:32.0515 2036        CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:43:32.0718 2036        CCDECODE - ok
17:43:32.0734 2036        cd20xrnt - ok
17:43:32.0750 2036        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:43:32.0921 2036        Cdaudio - ok
17:43:32.0937 2036        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:43:33.0109 2036        Cdfs - ok
17:43:33.0140 2036        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:43:33.0406 2036        Cdrom - ok
17:43:33.0421 2036        Changer - ok
17:43:33.0484 2036        CmdIde - ok
17:43:33.0500 2036        Cpqarray - ok
17:43:33.0562 2036        ctxusbm        (cb6ff7012bb5d59d7c12350db795ce1f) C:\WINDOWS\system32\DRIVERS\ctxusbm.sys
17:43:33.0578 2036        ctxusbm - ok
17:43:33.0593 2036        dac2w2k - ok
17:43:33.0609 2036        dac960nt - ok
17:43:33.0687 2036        dbustrcm - ok
17:43:33.0718 2036        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:43:33.0875 2036        Disk - ok
17:43:33.0937 2036        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
17:43:34.0140 2036        dmboot - ok
17:43:34.0156 2036        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
17:43:34.0328 2036        dmio - ok
17:43:34.0359 2036        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:43:34.0531 2036        dmload - ok
17:43:34.0609 2036        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:43:34.0765 2036        DMusic - ok
17:43:34.0812 2036        dpti2o - ok
17:43:34.0828 2036        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:43:34.0984 2036        drmkaud - ok
17:43:35.0031 2036        ElbyCDIO        (37c3a9fef349d13685ec9c2acaaeafce) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
17:43:35.0046 2036        ElbyCDIO ( UnsignedFile.Multi.Generic ) - warning
17:43:35.0046 2036        ElbyCDIO - detected UnsignedFile.Multi.Generic (1)
17:43:35.0078 2036        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:43:35.0218 2036        Fastfat - ok
17:43:35.0250 2036        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:43:35.0406 2036        Fdc - ok
17:43:35.0468 2036        FDSSBASE        (551a237a1ce44261dc0783661bcfb9a5) C:\WINDOWS\system32\DRIVERS\fdssbase.sys
17:43:35.0515 2036        FDSSBASE - ok
17:43:35.0546 2036        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
17:43:35.0703 2036        Fips - ok
17:43:35.0718 2036        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:43:35.0875 2036        Flpydisk - ok
17:43:35.0921 2036        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:43:36.0078 2036        FltMgr - ok
17:43:36.0109 2036        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:43:36.0265 2036        Fs_Rec - ok
17:43:36.0296 2036        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:43:36.0453 2036        Ftdisk - ok
17:43:36.0484 2036        gameenum        (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
17:43:36.0625 2036        gameenum - ok
17:43:36.0671 2036        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
17:43:36.0687 2036        GEARAspiWDM - ok
17:43:36.0718 2036        Gonzales        (829870058335703af4b95cbc1f83affc) C:\WINDOWS\system32\DRIVERS\Gonzales.sys
17:43:36.0734 2036        Gonzales ( UnsignedFile.Multi.Generic ) - warning
17:43:36.0734 2036        Gonzales - detected UnsignedFile.Multi.Generic (1)
17:43:36.0750 2036        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:43:36.0890 2036        Gpc - ok
17:43:36.0921 2036        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:43:37.0093 2036        HidUsb - ok
17:43:37.0109 2036        hpn - ok
17:43:37.0125 2036        hpt3xx - ok
17:43:37.0171 2036        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:43:37.0250 2036        HTTP - ok
17:43:37.0265 2036        i2omgmt - ok
17:43:37.0281 2036        i2omp - ok
17:43:37.0312 2036        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:43:37.0484 2036        i8042prt - ok
17:43:37.0531 2036        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:43:37.0687 2036        Imapi - ok
17:43:37.0703 2036        ini910u - ok
17:43:37.0734 2036        IntelIde - ok
17:43:37.0781 2036        ip6fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:43:37.0937 2036        ip6fw - ok
17:43:37.0984 2036        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:43:38.0140 2036        IpFilterDriver - ok
17:43:38.0171 2036        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:43:38.0343 2036        IpInIp - ok
17:43:38.0359 2036        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:43:38.0515 2036        IpNat - ok
17:43:38.0546 2036        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:43:38.0687 2036        IPSec - ok
17:43:38.0781 2036        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:43:38.0859 2036        IRENUM - ok
17:43:38.0875 2036        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:43:39.0015 2036        isapnp - ok
17:43:39.0046 2036        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:43:39.0187 2036        Kbdclass - ok
17:43:39.0218 2036        kbdhid          (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
17:43:39.0359 2036        kbdhid - ok
17:43:39.0390 2036        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:43:39.0562 2036        kmixer - ok
17:43:39.0578 2036        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:43:39.0671 2036        KSecDD - ok
17:43:39.0687 2036        lbrtfdc - ok
17:43:39.0734 2036        meiudf          (a4798cd432781bc382603499d301e176) C:\WINDOWS\system32\Drivers\meiudf.sys
17:43:39.0765 2036        meiudf ( UnsignedFile.Multi.Generic ) - warning
17:43:39.0765 2036        meiudf - detected UnsignedFile.Multi.Generic (1)
17:43:39.0828 2036        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:43:39.0968 2036        mnmdd - ok
17:43:40.0000 2036        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
17:43:40.0156 2036        Modem - ok
17:43:40.0187 2036        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:43:40.0343 2036        Mouclass - ok
17:43:40.0390 2036        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:43:40.0531 2036        mouhid - ok
17:43:40.0546 2036        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:43:40.0687 2036        MountMgr - ok
17:43:40.0703 2036        mraid35x - ok
17:43:40.0734 2036        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:43:40.0906 2036        MRxDAV - ok
17:43:40.0968 2036        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:43:41.0000 2036        MRxSmb - ok
17:43:41.0046 2036        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:43:41.0156 2036        Msfs - ok
17:43:41.0187 2036        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:43:41.0359 2036        MSKSSRV - ok
17:43:41.0375 2036        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:43:41.0515 2036        MSPCLOCK - ok
17:43:41.0546 2036        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:43:41.0703 2036        MSPQM - ok
17:43:41.0750 2036        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:43:41.0906 2036        mssmbios - ok
17:43:41.0953 2036        MSTEE          (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:43:42.0109 2036        MSTEE - ok
17:43:42.0156 2036        ms_mpu401      (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
17:43:42.0281 2036        ms_mpu401 - ok
17:43:42.0343 2036        MTsensor        (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
17:43:42.0359 2036        MTsensor ( UnsignedFile.Multi.Generic ) - warning
17:43:42.0359 2036        MTsensor - detected UnsignedFile.Multi.Generic (1)
17:43:42.0562 2036        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:43:42.0593 2036        Mup - ok
17:43:42.0625 2036        NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:43:42.0781 2036        NABTSFEC - ok
17:43:42.0812 2036        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:43:42.0968 2036        NDIS - ok
17:43:43.0000 2036        NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:43:43.0156 2036        NdisIP - ok
17:43:43.0187 2036        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:43:43.0218 2036        NdisTapi - ok
17:43:43.0234 2036        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:43:43.0375 2036        Ndisuio - ok
17:43:43.0406 2036        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:43:43.0546 2036        NdisWan - ok
17:43:43.0578 2036        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:43:43.0609 2036        NDProxy - ok
17:43:43.0640 2036        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:43:43.0781 2036        NetBIOS - ok
17:43:43.0828 2036        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:43:43.0984 2036        NetBT - ok
17:43:44.0062 2036        NETFWDSL        (a001e7d84da39a5e7aff3cb05e77e033) C:\WINDOWS\system32\DRIVERS\NETFWDSL.SYS
17:43:44.0093 2036        NETFWDSL ( UnsignedFile.Multi.Generic ) - warning
17:43:44.0093 2036        NETFWDSL - detected UnsignedFile.Multi.Generic (1)
17:43:44.0125 2036        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:43:44.0250 2036        Npfs - ok
17:43:44.0281 2036        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:43:44.0453 2036        Ntfs - ok
17:43:44.0484 2036        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:43:44.0609 2036        Null - ok
17:43:44.0765 2036        nv              (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
17:43:45.0062 2036        nv - ok
17:43:45.0171 2036        nvatabus        (3bfc1dea3076d9eaa282e9cc1e4d7a23) C:\WINDOWS\system32\DRIVERS\nvatabus.sys
17:43:45.0187 2036        nvatabus ( UnsignedFile.Multi.Generic ) - warning
17:43:45.0187 2036        nvatabus - detected UnsignedFile.Multi.Generic (1)
17:43:45.0234 2036        NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
17:43:45.0296 2036        NVENETFD - ok
17:43:45.0328 2036        nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
17:43:45.0375 2036        nvnetbus - ok
17:43:45.0421 2036        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:43:45.0578 2036        NwlnkFlt - ok
17:43:45.0593 2036        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:43:45.0734 2036        NwlnkFwd - ok
17:43:45.0781 2036        ovt519          (4cdadec3dc1300ee1d313ea5494e6472) C:\WINDOWS\system32\Drivers\ov519vid.sys
17:43:45.0812 2036        ovt519 ( UnsignedFile.Multi.Generic ) - warning
17:43:45.0812 2036        ovt519 - detected UnsignedFile.Multi.Generic (1)
17:43:45.0859 2036        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
17:43:45.0984 2036        Parport - ok
17:43:46.0062 2036        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:43:46.0171 2036        PartMgr - ok
17:43:46.0218 2036        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
17:43:46.0359 2036        ParVdm - ok
17:43:46.0390 2036        pccsmcfd        (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
17:43:46.0437 2036        pccsmcfd - ok
17:43:46.0453 2036        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
17:43:46.0609 2036        PCI - ok
17:43:46.0625 2036        PCIDump - ok
17:43:46.0656 2036        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:43:46.0781 2036        PCIIde - ok
17:43:46.0812 2036        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:43:46.0968 2036        Pcmcia - ok
17:43:46.0984 2036        PDCOMP - ok
17:43:47.0000 2036        PDFRAME - ok
17:43:47.0015 2036        PDRELI - ok
17:43:47.0046 2036        PDRFRAME - ok
17:43:47.0062 2036        perc2 - ok
17:43:47.0078 2036        perc2hib - ok
17:43:47.0140 2036        pfc            (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
17:43:47.0171 2036        pfc ( UnsignedFile.Multi.Generic ) - warning
17:43:47.0171 2036        pfc - detected UnsignedFile.Multi.Generic (1)
17:43:47.0203 2036        PLFF            (a20ac92609f3b246be3b761bb72fc6a5) C:\WINDOWS\system32\Drivers\PLFF.sys
17:43:47.0218 2036        PLFF ( UnsignedFile.Multi.Generic ) - warning
17:43:47.0218 2036        PLFF - detected UnsignedFile.Multi.Generic (1)
17:43:47.0265 2036        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:43:47.0390 2036        PptpMiniport - ok
17:43:47.0421 2036        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
17:43:47.0578 2036        Processor - ok
17:43:47.0609 2036        prodrv06        (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
17:43:47.0671 2036        prodrv06 ( UnsignedFile.Multi.Generic ) - warning
17:43:47.0671 2036        prodrv06 - detected UnsignedFile.Multi.Generic (1)
17:43:47.0687 2036        prohlp02        (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
17:43:47.0718 2036        prohlp02 ( UnsignedFile.Multi.Generic ) - warning
17:43:47.0718 2036        prohlp02 - detected UnsignedFile.Multi.Generic (1)
17:43:47.0734 2036        prosync1        (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
17:43:47.0750 2036        prosync1 ( UnsignedFile.Multi.Generic ) - warning
17:43:47.0750 2036        prosync1 - detected UnsignedFile.Multi.Generic (1)
17:43:47.0765 2036        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:43:47.0906 2036        PSched - ok
17:43:47.0953 2036        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:43:48.0078 2036        Ptilink - ok
17:43:48.0125 2036        ql1080 - ok
17:43:48.0140 2036        Ql10wnt - ok
17:43:48.0156 2036        ql12160 - ok
17:43:48.0171 2036        ql1240 - ok
17:43:48.0187 2036        ql1280 - ok
17:43:48.0218 2036        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:43:48.0343 2036        RasAcd - ok
17:43:48.0375 2036        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:43:48.0515 2036        Rasl2tp - ok
17:43:48.0531 2036        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:43:48.0671 2036        RasPppoe - ok
17:43:48.0687 2036        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:43:48.0812 2036        Raspti - ok
17:43:48.0843 2036        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:43:48.0984 2036        Rdbss - ok
17:43:49.0000 2036        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:43:49.0140 2036        RDPCDD - ok
17:43:49.0171 2036        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:43:49.0328 2036        rdpdr - ok
17:43:49.0375 2036        RDPWD          (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
17:43:49.0421 2036        RDPWD - ok
17:43:49.0453 2036        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:43:49.0593 2036        redbook - ok
17:43:49.0640 2036        RFCOMM          (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
17:43:49.0781 2036        RFCOMM - ok
17:43:49.0812 2036        ROOTMODEM      (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
17:43:49.0953 2036        ROOTMODEM - ok
17:43:50.0015 2036        SaiNtHid        (a007103ef0e50fb0e0ed08b511d721d7) C:\WINDOWS\system32\DRIVERS\SaiNtHid.sys
17:43:50.0046 2036        SaiNtHid ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0046 2036        SaiNtHid - detected UnsignedFile.Multi.Generic (1)
17:43:50.0078 2036        SCR3xx USB Smart Card Reader (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
17:43:50.0187 2036        SCR3xx USB Smart Card Reader - ok
17:43:50.0218 2036        SCR3XX2K        (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
17:43:50.0234 2036        SCR3XX2K - ok
17:43:50.0312 2036        SE4501D        (b84c83e5355c2aa96bb5c5fab9f5d3e4) C:\WINDOWS\system32\DRIVERS\SE4501D.sys
17:43:50.0343 2036        SE4501D ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0343 2036        SE4501D - detected UnsignedFile.Multi.Generic (1)
17:43:50.0375 2036        Secdrv          (ba0d892d2f786bcebdf03b0a252b47f3) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:43:50.0390 2036        Secdrv ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0390 2036        Secdrv - detected UnsignedFile.Multi.Generic (1)
17:43:50.0437 2036        Serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:43:50.0562 2036        Serenum - ok
17:43:50.0593 2036        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
17:43:50.0734 2036        Serial - ok
17:43:50.0828 2036        sfdrv01        (00de597b81b381053cb5b21a7f20e365) C:\WINDOWS\system32\drivers\sfdrv01.sys
17:43:50.0843 2036        sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0843 2036        sfdrv01 - detected UnsignedFile.Multi.Generic (1)
17:43:50.0875 2036        sfhlp01        (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
17:43:50.0875 2036        sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0875 2036        sfhlp01 - detected UnsignedFile.Multi.Generic (1)
17:43:50.0906 2036        sfhlp02        (64b9ab76f1b16eb059cb6cdd906c067a) C:\WINDOWS\system32\drivers\sfhlp02.sys
17:43:50.0921 2036        sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
17:43:50.0921 2036        sfhlp02 - detected UnsignedFile.Multi.Generic (1)
17:43:50.0937 2036        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:43:51.0062 2036        Sfloppy - ok
17:43:51.0093 2036        Simbad - ok
17:43:51.0125 2036        SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:43:51.0281 2036        SLIP - ok
17:43:51.0296 2036        Sparrow - ok
17:43:51.0343 2036        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:43:51.0453 2036        splitter - ok
17:43:51.0468 2036        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
17:43:51.0546 2036        sr - ok
17:43:51.0609 2036        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:43:51.0671 2036        Srv - ok
17:43:51.0718 2036        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
17:43:51.0734 2036        ssmdrv - ok
17:43:51.0750 2036        STC2DFU - ok
17:43:51.0796 2036        STCFUx32        (68c00ee8c35e4ea63dca5ca7d572e25e) C:\WINDOWS\system32\DRIVERS\STCFUx32.SYS
17:43:51.0859 2036        STCFUx32 - ok
17:43:51.0875 2036        streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:43:52.0031 2036        streamip - ok
17:43:52.0062 2036        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:43:52.0187 2036        swenum - ok
17:43:52.0218 2036        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:43:52.0375 2036        swmidi - ok
17:43:52.0406 2036        symc810 - ok
17:43:52.0421 2036        symc8xx - ok
17:43:52.0437 2036        sym_hi - ok
17:43:52.0453 2036        sym_u3 - ok
17:43:52.0484 2036        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:43:52.0640 2036        sysaudio - ok
17:43:52.0703 2036        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:43:52.0765 2036        Tcpip - ok
17:43:52.0796 2036        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:43:52.0921 2036        TDPIPE - ok
17:43:52.0953 2036        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:43:53.0093 2036        TDTCP - ok
17:43:53.0125 2036        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:43:53.0250 2036        TermDD - ok
17:43:53.0281 2036        TosIde - ok
17:43:53.0312 2036        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:43:53.0468 2036        Udfs - ok
17:43:53.0484 2036        ultra - ok
17:43:53.0546 2036        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:43:53.0703 2036        Update - ok
17:43:53.0750 2036        USBAAPL        (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
17:43:53.0812 2036        USBAAPL - ok
17:43:53.0843 2036        usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
17:43:53.0984 2036        usbaudio - ok
17:43:54.0031 2036        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:43:54.0171 2036        usbccgp - ok
17:43:54.0203 2036        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:43:54.0359 2036        usbehci - ok
17:43:54.0437 2036        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:43:54.0562 2036        usbhub - ok
17:43:54.0578 2036        usbohci        (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
17:43:54.0703 2036        usbohci - ok
17:43:54.0734 2036        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:43:54.0875 2036        usbprint - ok
17:43:54.0890 2036        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:43:55.0015 2036        usbscan - ok
17:43:55.0031 2036        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:43:55.0171 2036        USBSTOR - ok
17:43:55.0203 2036        uxy9b.sys - ok
17:43:55.0234 2036        VComm          (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys
17:43:55.0265 2036        VComm ( UnsignedFile.Multi.Generic ) - warning
17:43:55.0265 2036        VComm - detected UnsignedFile.Multi.Generic (1)
17:43:55.0296 2036        VcommMgr        (ef0d45ed806b0c9ae9756bfeecb077ed) C:\WINDOWS\system32\Drivers\VcommMgr.sys
17:43:55.0312 2036        VcommMgr ( UnsignedFile.Multi.Generic ) - warning
17:43:55.0312 2036        VcommMgr - detected UnsignedFile.Multi.Generic (1)
17:43:55.0343 2036        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:43:55.0453 2036        VgaSave - ok
17:43:55.0468 2036        ViaIde - ok
17:43:55.0531 2036        vnccom          (b67632451f760797bb183e1fb99f4b39) C:\WINDOWS\system32\Drivers\vnccom.SYS
17:43:55.0546 2036        vnccom ( UnsignedFile.Multi.Generic ) - warning
17:43:55.0546 2036        vnccom - detected UnsignedFile.Multi.Generic (1)
17:43:55.0578 2036        vncdrv          (4ec979b157d1aa075330362acb5424e5) C:\WINDOWS\system32\DRIVERS\vncdrv.sys
17:43:55.0593 2036        vncdrv ( UnsignedFile.Multi.Generic ) - warning
17:43:55.0593 2036        vncdrv - detected UnsignedFile.Multi.Generic (1)
17:43:55.0609 2036        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
17:43:55.0750 2036        VolSnap - ok
17:43:55.0781 2036        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:43:55.0921 2036        Wanarp - ok
17:43:55.0953 2036        WDICA - ok
17:43:55.0968 2036        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:43:56.0109 2036        wdmaud - ok
17:43:56.0187 2036        WmBEnum        (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys
17:43:56.0234 2036        WmBEnum - ok
17:43:56.0265 2036        WmFilter        (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys
17:43:56.0328 2036        WmFilter - ok
17:43:56.0359 2036        WmHidLo        (bb49902577091f634e752537181d2c19) C:\WINDOWS\system32\drivers\WmHidLo.sys
17:43:56.0375 2036        WmHidLo - ok
17:43:56.0421 2036        WmVirHid        (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys
17:43:56.0453 2036        WmVirHid - ok
17:43:56.0531 2036        WmXlCore        (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys
17:43:56.0546 2036        WmXlCore - ok
17:43:56.0578 2036        WpdUsb          (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
17:43:56.0656 2036        WpdUsb - ok
17:43:56.0703 2036        WS2IFSL        (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:43:56.0828 2036        WS2IFSL - ok
17:43:56.0875 2036        WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:43:57.0015 2036        WSTCODEC - ok
17:43:57.0078 2036        WudfPf          (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:43:57.0140 2036        WudfPf - ok
17:43:57.0187 2036        WudfRd          (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:43:57.0218 2036        WudfRd - ok
17:43:57.0234 2036        xcpip - ok
17:43:57.0265 2036        xpsec - ok
17:43:57.0343 2036        zlportio - ok
17:43:57.0406 2036        MBR (0x1B8)    (eeadaf356113e54427e990a5bcad82b5) \Device\Harddisk0\DR0
17:43:57.0406 2036        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected
17:43:57.0406 2036        \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0)
17:43:57.0484 2036        Boot (0x1200)  (76ae28f380934ee0dad55c95a523df03) \Device\Harddisk0\DR0\Partition0
17:43:57.0484 2036        \Device\Harddisk0\DR0\Partition0 - ok
17:43:57.0515 2036        Boot (0x1200)  (852b9f665a1f7c90b5737e2b210f086d) \Device\Harddisk0\DR0\Partition1
17:43:57.0515 2036        \Device\Harddisk0\DR0\Partition1 - ok
17:43:57.0546 2036        Boot (0x1200)  (0403679a73ca5dd9e147c2a422f00c8f) \Device\Harddisk0\DR0\Partition2
17:43:57.0562 2036        \Device\Harddisk0\DR0\Partition2 - ok
17:43:57.0562 2036        ============================================================
17:43:57.0562 2036        Scan finished
17:43:57.0562 2036        ============================================================
17:43:57.0687 2852        Detected object count: 35
17:43:57.0687 2852        Actual detected object count: 35
17:44:56.0281 2852        aadev ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        aadev ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0281 2852        AnyDVD ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        AnyDVD ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0281 2852        ASInsHelp ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        ASInsHelp ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0281 2852        AsIO ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        AsIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0281 2852        aslm75 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        aslm75 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0281 2852        ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0281 2852        ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        BlueletAudio ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        BlueletAudio ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        Bonifay ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        Bonifay ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        BT ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        BT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        Btcsrusb ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        Btcsrusb ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        BTHidEnum ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        BTHidEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        BTHidMgr ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        BTHidMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        ElbyCDIO ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        ElbyCDIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0296 2852        Gonzales ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0296 2852        Gonzales ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        meiudf ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        meiudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        MTsensor ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        MTsensor ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        NETFWDSL ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        NETFWDSL ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        nvatabus ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        nvatabus ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        ovt519 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        ovt519 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        pfc ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        PLFF ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        PLFF ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0312 2852        prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0312 2852        prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        SaiNtHid ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        SaiNtHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        SE4501D ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        SE4501D ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        Secdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        VComm ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        VComm ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0328 2852        VcommMgr ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0328 2852        VcommMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0343 2852        vnccom ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0343 2852        vnccom ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0343 2852        vncdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:44:56.0343 2852        vncdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:44:56.0343 2852        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - skipped by user
17:44:56.0343 2852        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Skip


cosinus 14.01.2012 20:07

Zitat:

\Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf )
Den Sinowal (und NICHTS anderes!!) bitte mit dem TDSS-Killer löschen lassen, starte Windows danach neu und mach ein neues Log mit diesem Tool. Poste es wieder mit CODE-Tags umschlossen.

tax 14.01.2012 21:55

Code:

21:46:56.0953 2572        TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05
21:46:57.0187 2572        ============================================================
21:46:57.0187 2572        Current date / time: 2012/01/14 21:46:57.0187
21:46:57.0187 2572        SystemInfo:
21:46:57.0187 2572       
21:46:57.0187 2572        OS Version: 5.1.2600 ServicePack: 3.0
21:46:57.0187 2572        Product type: Workstation
21:46:57.0187 2572        ComputerName: SHOOT
21:46:57.0187 2572        UserName: Weisi
21:46:57.0187 2572        Windows directory: C:\WINDOWS
21:46:57.0187 2572        System windows directory: C:\WINDOWS
21:46:57.0187 2572        Processor architecture: Intel x86
21:46:57.0187 2572        Number of processors: 1
21:46:57.0187 2572        Page size: 0x1000
21:46:57.0187 2572        Boot type: Normal boot
21:46:57.0187 2572        ============================================================
21:46:58.0375 2572        Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000, SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054
21:46:58.0453 2572        Initialize success
21:47:04.0109 3432        ============================================================
21:47:04.0109 3432        Scan started
21:47:04.0109 3432        Mode: Manual; SigCheck; TDLFS;
21:47:04.0109 3432        ============================================================
21:47:05.0078 3432        aadev          (6bfb6def4eb16b74c0179de110077920) C:\WINDOWS\system32\DRIVERS\aadev.sys
21:47:05.0218 3432        aadev ( UnsignedFile.Multi.Generic ) - warning
21:47:05.0218 3432        aadev - detected UnsignedFile.Multi.Generic (1)
21:47:05.0234 3432        Abiosdsk - ok
21:47:05.0250 3432        abp480n5 - ok
21:47:05.0296 3432        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:47:05.0484 3432        ACPI - ok
21:47:05.0515 3432        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:47:05.0656 3432        ACPIEC - ok
21:47:05.0671 3432        adpu160m - ok
21:47:05.0718 3432        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:47:05.0875 3432        aec - ok
21:47:05.0953 3432        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
21:47:06.0015 3432        AFD - ok
21:47:06.0031 3432        Aha154x - ok
21:47:06.0062 3432        aic78u2 - ok
21:47:06.0078 3432        aic78xx - ok
21:47:06.0187 3432        ALCXWDM        (933933288df5ed26d1928215c97d05c7) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
21:47:06.0328 3432        ALCXWDM - ok
21:47:06.0359 3432        AliIde - ok
21:47:06.0406 3432        AmdK8          (b9dbaae3219661f4d0c5e8dc0c2f987d) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
21:47:06.0437 3432        AmdK8 - ok
21:47:06.0453 3432        amsint - ok
21:47:06.0515 3432        AnyDVD          (44c905e4dfd93a8c49f97c14d9c399f3) C:\WINDOWS\system32\Drivers\AnyDVD.sys
21:47:06.0531 3432        AnyDVD ( UnsignedFile.Multi.Generic ) - warning
21:47:06.0531 3432        AnyDVD - detected UnsignedFile.Multi.Generic (1)
21:47:06.0546 3432        asc - ok
21:47:06.0562 3432        asc3350p - ok
21:47:06.0578 3432        asc3550 - ok
21:47:06.0609 3432        ASInsHelp      (33c171de483ee145f31234d93b078919) C:\WINDOWS\system32\drivers\AsInsHelp32.sys
21:47:06.0625 3432        ASInsHelp ( UnsignedFile.Multi.Generic ) - warning
21:47:06.0625 3432        ASInsHelp - detected UnsignedFile.Multi.Generic (1)
21:47:06.0656 3432        AsIO            (c959989e2ce8da9bde8cafddba84badf) C:\WINDOWS\system32\drivers\AsIO.sys
21:47:06.0656 3432        AsIO ( UnsignedFile.Multi.Generic ) - warning
21:47:06.0656 3432        AsIO - detected UnsignedFile.Multi.Generic (1)
21:47:06.0687 3432        aslm75          (71356a1370739e25375a1d17b6ae318f) C:\WINDOWS\system32\drivers\aslm75.sys
21:47:06.0703 3432        aslm75 ( UnsignedFile.Multi.Generic ) - warning
21:47:06.0703 3432        aslm75 - detected UnsignedFile.Multi.Generic (1)
21:47:06.0765 3432        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:47:06.0906 3432        AsyncMac - ok
21:47:06.0921 3432        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:47:07.0062 3432        atapi - ok
21:47:07.0093 3432        Atdisk - ok
21:47:07.0250 3432        ati2mtag        (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
21:47:07.0406 3432        ati2mtag ( UnsignedFile.Multi.Generic ) - warning
21:47:07.0406 3432        ati2mtag - detected UnsignedFile.Multi.Generic (1)
21:47:07.0531 3432        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:47:07.0687 3432        Atmarpc - ok
21:47:07.0734 3432        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:47:07.0875 3432        audstub - ok
21:47:07.0968 3432        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
21:47:07.0984 3432        avgio - ok
21:47:08.0031 3432        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
21:47:08.0078 3432        avgntflt - ok
21:47:08.0171 3432        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
21:47:08.0203 3432        avipbb - ok
21:47:08.0234 3432        AVMDSLPPPOE    (aa5874f64d6f2ffafa8c5fbc202ce6ef) C:\WINDOWS\system32\DRIVERS\avmdsloe.sys
21:47:08.0250 3432        AVMDSLPPPOE - ok
21:47:08.0281 3432        AVMNDSL        (140ba5bf4666c27c15368cce9df54a93) C:\WINDOWS\system32\DRIVERS\avmndsl.sys
21:47:08.0296 3432        AVMNDSL - ok
21:47:08.0343 3432        bdfdll - ok
21:47:08.0375 3432        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:47:08.0562 3432        Beep - ok
21:47:08.0609 3432        BlueletAudio    (31ff5b87c1dd907613cc613224b8e303) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
21:47:08.0640 3432        BlueletAudio ( UnsignedFile.Multi.Generic ) - warning
21:47:08.0640 3432        BlueletAudio - detected UnsignedFile.Multi.Generic (1)
21:47:08.0656 3432        Bonifay        (b63f6bc2f76db693e4ed51ebe7f34828) C:\WINDOWS\system32\DRIVERS\Bonifay.sys
21:47:08.0671 3432        Bonifay ( UnsignedFile.Multi.Generic ) - warning
21:47:08.0671 3432        Bonifay - detected UnsignedFile.Multi.Generic (1)
21:47:08.0718 3432        BT              (9da8abc4885aff4793d4aa420e40bb12) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
21:47:08.0750 3432        BT ( UnsignedFile.Multi.Generic ) - warning
21:47:08.0750 3432        BT - detected UnsignedFile.Multi.Generic (1)
21:47:08.0781 3432        Btcsrusb        (95a061d5217cbb6642e73a8fd9aa9734) C:\WINDOWS\system32\Drivers\btcusb.sys
21:47:08.0796 3432        Btcsrusb ( UnsignedFile.Multi.Generic ) - warning
21:47:08.0796 3432        Btcsrusb - detected UnsignedFile.Multi.Generic (1)
21:47:08.0843 3432        BthEnum        (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
21:47:09.0000 3432        BthEnum - ok
21:47:09.0031 3432        BTHidEnum      (083ad7f6ff500d0a93c0bea2cf298c93) C:\WINDOWS\system32\DRIVERS\vbtenum.sys
21:47:09.0046 3432        BTHidEnum ( UnsignedFile.Multi.Generic ) - warning
21:47:09.0046 3432        BTHidEnum - detected UnsignedFile.Multi.Generic (1)
21:47:09.0078 3432        BTHidMgr        (f408264f6ad1dc7e7bdd4837440f115d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
21:47:09.0078 3432        BTHidMgr ( UnsignedFile.Multi.Generic ) - warning
21:47:09.0078 3432        BTHidMgr - detected UnsignedFile.Multi.Generic (1)
21:47:09.0109 3432        BTHMODEM        (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
21:47:09.0281 3432        BTHMODEM - ok
21:47:09.0328 3432        BthPan          (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
21:47:09.0500 3432        BthPan - ok
21:47:09.0562 3432        BTHPORT        (592e1cedbe314d0ef184dc6f46141e76) C:\WINDOWS\system32\Drivers\BTHport.sys
21:47:09.0593 3432        BTHPORT - ok
21:47:09.0625 3432        BTHUSB          (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
21:47:09.0781 3432        BTHUSB - ok
21:47:09.0812 3432        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:47:09.0953 3432        cbidf2k - ok
21:47:10.0015 3432        CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:47:10.0171 3432        CCDECODE - ok
21:47:10.0234 3432        cd20xrnt - ok
21:47:10.0265 3432        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:47:10.0421 3432        Cdaudio - ok
21:47:10.0453 3432        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:47:10.0609 3432        Cdfs - ok
21:47:10.0640 3432        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:47:10.0796 3432        Cdrom - ok
21:47:10.0812 3432        Changer - ok
21:47:10.0843 3432        CmdIde - ok
21:47:10.0875 3432        Cpqarray - ok
21:47:10.0937 3432        ctxusbm        (cb6ff7012bb5d59d7c12350db795ce1f) C:\WINDOWS\system32\DRIVERS\ctxusbm.sys
21:47:10.0937 3432        ctxusbm - ok
21:47:10.0968 3432        dac2w2k - ok
21:47:10.0984 3432        dac960nt - ok
21:47:11.0062 3432        dbustrcm - ok
21:47:11.0093 3432        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:47:11.0250 3432        Disk - ok
21:47:11.0312 3432        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
21:47:11.0546 3432        dmboot - ok
21:47:11.0562 3432        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
21:47:11.0734 3432        dmio - ok
21:47:11.0750 3432        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:47:11.0921 3432        dmload - ok
21:47:11.0953 3432        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:47:12.0093 3432        DMusic - ok
21:47:12.0109 3432        dpti2o - ok
21:47:12.0140 3432        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:47:12.0296 3432        drmkaud - ok
21:47:12.0343 3432        ElbyCDIO        (37c3a9fef349d13685ec9c2acaaeafce) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
21:47:12.0375 3432        ElbyCDIO ( UnsignedFile.Multi.Generic ) - warning
21:47:12.0375 3432        ElbyCDIO - detected UnsignedFile.Multi.Generic (1)
21:47:12.0406 3432        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:47:12.0546 3432        Fastfat - ok
21:47:12.0578 3432        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
21:47:12.0750 3432        Fdc - ok
21:47:12.0796 3432        FDSSBASE        (551a237a1ce44261dc0783661bcfb9a5) C:\WINDOWS\system32\DRIVERS\fdssbase.sys
21:47:12.0859 3432        FDSSBASE - ok
21:47:12.0875 3432        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
21:47:13.0031 3432        Fips - ok
21:47:13.0046 3432        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
21:47:13.0203 3432        Flpydisk - ok
21:47:13.0250 3432        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:47:13.0437 3432        FltMgr - ok
21:47:13.0515 3432        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:47:13.0656 3432        Fs_Rec - ok
21:47:13.0687 3432        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:47:13.0843 3432        Ftdisk - ok
21:47:13.0875 3432        gameenum        (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
21:47:14.0031 3432        gameenum - ok
21:47:14.0078 3432        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
21:47:14.0078 3432        GEARAspiWDM - ok
21:47:14.0125 3432        Gonzales        (829870058335703af4b95cbc1f83affc) C:\WINDOWS\system32\DRIVERS\Gonzales.sys
21:47:14.0125 3432        Gonzales ( UnsignedFile.Multi.Generic ) - warning
21:47:14.0125 3432        Gonzales - detected UnsignedFile.Multi.Generic (1)
21:47:14.0171 3432        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:47:14.0296 3432        Gpc - ok
21:47:14.0328 3432        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:47:14.0484 3432        HidUsb - ok
21:47:14.0500 3432        hpn - ok
21:47:14.0531 3432        hpt3xx - ok
21:47:14.0578 3432        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:47:14.0625 3432        HTTP - ok
21:47:14.0640 3432        i2omgmt - ok
21:47:14.0656 3432        i2omp - ok
21:47:14.0703 3432        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:47:14.0859 3432        i8042prt - ok
21:47:14.0890 3432        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:47:15.0046 3432        Imapi - ok
21:47:15.0078 3432        ini910u - ok
21:47:15.0093 3432        IntelIde - ok
21:47:15.0140 3432        ip6fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:47:15.0296 3432        ip6fw - ok
21:47:15.0328 3432        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:47:15.0500 3432        IpFilterDriver - ok
21:47:15.0531 3432        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:47:15.0687 3432        IpInIp - ok
21:47:15.0734 3432        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:47:15.0890 3432        IpNat - ok
21:47:15.0937 3432        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:47:16.0109 3432        IPSec - ok
21:47:16.0140 3432        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:47:16.0218 3432        IRENUM - ok
21:47:16.0250 3432        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:47:16.0390 3432        isapnp - ok
21:47:16.0406 3432        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:47:16.0562 3432        Kbdclass - ok
21:47:16.0593 3432        kbdhid          (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
21:47:16.0734 3432        kbdhid - ok
21:47:16.0765 3432        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:47:16.0906 3432        kmixer - ok
21:47:16.0937 3432        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:47:16.0984 3432        KSecDD - ok
21:47:17.0000 3432        lbrtfdc - ok
21:47:17.0062 3432        meiudf          (a4798cd432781bc382603499d301e176) C:\WINDOWS\system32\Drivers\meiudf.sys
21:47:17.0078 3432        meiudf ( UnsignedFile.Multi.Generic ) - warning
21:47:17.0078 3432        meiudf - detected UnsignedFile.Multi.Generic (1)
21:47:17.0125 3432        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:47:17.0265 3432        mnmdd - ok
21:47:17.0296 3432        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
21:47:17.0437 3432        Modem - ok
21:47:17.0468 3432        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:47:17.0609 3432        Mouclass - ok
21:47:17.0656 3432        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:47:17.0796 3432        mouhid - ok
21:47:17.0812 3432        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:47:17.0968 3432        MountMgr - ok
21:47:17.0984 3432        mraid35x - ok
21:47:18.0015 3432        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:47:18.0171 3432        MRxDAV - ok
21:47:18.0218 3432        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:47:18.0281 3432        MRxSmb - ok
21:47:18.0312 3432        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:47:18.0453 3432        Msfs - ok
21:47:18.0484 3432        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:47:18.0640 3432        MSKSSRV - ok
21:47:18.0671 3432        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:47:18.0796 3432        MSPCLOCK - ok
21:47:18.0828 3432        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:47:18.0984 3432        MSPQM - ok
21:47:19.0031 3432        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:47:19.0171 3432        mssmbios - ok
21:47:19.0187 3432        MSTEE          (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:47:19.0328 3432        MSTEE - ok
21:47:19.0375 3432        ms_mpu401      (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
21:47:19.0562 3432        ms_mpu401 - ok
21:47:19.0609 3432        MTsensor        (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
21:47:19.0625 3432        MTsensor ( UnsignedFile.Multi.Generic ) - warning
21:47:19.0625 3432        MTsensor - detected UnsignedFile.Multi.Generic (1)
21:47:19.0671 3432        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:47:19.0875 3432        Mup - ok
21:47:19.0890 3432        NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:47:20.0046 3432        NABTSFEC - ok
21:47:20.0078 3432        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:47:20.0250 3432        NDIS - ok
21:47:20.0281 3432        NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:47:20.0437 3432        NdisIP - ok
21:47:20.0484 3432        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:47:20.0515 3432        NdisTapi - ok
21:47:20.0546 3432        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:47:20.0687 3432        Ndisuio - ok
21:47:20.0734 3432        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:47:20.0875 3432        NdisWan - ok
21:47:20.0890 3432        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:47:20.0906 3432        NDProxy - ok
21:47:20.0937 3432        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:47:21.0078 3432        NetBIOS - ok
21:47:21.0109 3432        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:47:21.0250 3432        NetBT - ok
21:47:21.0296 3432        NETFWDSL        (a001e7d84da39a5e7aff3cb05e77e033) C:\WINDOWS\system32\DRIVERS\NETFWDSL.SYS
21:47:21.0312 3432        NETFWDSL ( UnsignedFile.Multi.Generic ) - warning
21:47:21.0312 3432        NETFWDSL - detected UnsignedFile.Multi.Generic (1)
21:47:21.0359 3432        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:47:21.0531 3432        Npfs - ok
21:47:21.0578 3432        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:47:21.0718 3432        Ntfs - ok
21:47:21.0750 3432        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:47:21.0875 3432        Null - ok
21:47:22.0031 3432        nv              (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:47:22.0187 3432        nv - ok
21:47:22.0281 3432        nvatabus        (3bfc1dea3076d9eaa282e9cc1e4d7a23) C:\WINDOWS\system32\DRIVERS\nvatabus.sys
21:47:22.0312 3432        nvatabus ( UnsignedFile.Multi.Generic ) - warning
21:47:22.0312 3432        nvatabus - detected UnsignedFile.Multi.Generic (1)
21:47:22.0359 3432        NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
21:47:22.0375 3432        NVENETFD - ok
21:47:22.0406 3432        nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
21:47:22.0437 3432        nvnetbus - ok
21:47:22.0484 3432        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:47:22.0625 3432        NwlnkFlt - ok
21:47:22.0656 3432        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:47:22.0796 3432        NwlnkFwd - ok
21:47:22.0828 3432        ovt519          (4cdadec3dc1300ee1d313ea5494e6472) C:\WINDOWS\system32\Drivers\ov519vid.sys
21:47:22.0859 3432        ovt519 ( UnsignedFile.Multi.Generic ) - warning
21:47:22.0859 3432        ovt519 - detected UnsignedFile.Multi.Generic (1)
21:47:22.0906 3432        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
21:47:23.0062 3432        Parport - ok
21:47:23.0093 3432        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:47:23.0234 3432        PartMgr - ok
21:47:23.0265 3432        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
21:47:23.0390 3432        ParVdm - ok
21:47:23.0437 3432        pccsmcfd        (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
21:47:23.0468 3432        pccsmcfd - ok
21:47:23.0500 3432        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
21:47:23.0640 3432        PCI - ok
21:47:23.0656 3432        PCIDump - ok
21:47:23.0687 3432        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:47:23.0812 3432        PCIIde - ok
21:47:23.0843 3432        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
21:47:24.0000 3432        Pcmcia - ok
21:47:24.0015 3432        PDCOMP - ok
21:47:24.0031 3432        PDFRAME - ok
21:47:24.0062 3432        PDRELI - ok
21:47:24.0078 3432        PDRFRAME - ok
21:47:24.0093 3432        perc2 - ok
21:47:24.0109 3432        perc2hib - ok
21:47:24.0156 3432        pfc            (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
21:47:24.0171 3432        pfc ( UnsignedFile.Multi.Generic ) - warning
21:47:24.0171 3432        pfc - detected UnsignedFile.Multi.Generic (1)
21:47:24.0218 3432        PLFF            (a20ac92609f3b246be3b761bb72fc6a5) C:\WINDOWS\system32\Drivers\PLFF.sys
21:47:24.0234 3432        PLFF ( UnsignedFile.Multi.Generic ) - warning
21:47:24.0234 3432        PLFF - detected UnsignedFile.Multi.Generic (1)
21:47:24.0265 3432        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:47:24.0406 3432        PptpMiniport - ok
21:47:24.0437 3432        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
21:47:24.0578 3432        Processor - ok
21:47:24.0640 3432        prodrv06        (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
21:47:24.0687 3432        prodrv06 ( UnsignedFile.Multi.Generic ) - warning
21:47:24.0687 3432        prodrv06 - detected UnsignedFile.Multi.Generic (1)
21:47:24.0718 3432        prohlp02        (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
21:47:24.0750 3432        prohlp02 ( UnsignedFile.Multi.Generic ) - warning
21:47:24.0750 3432        prohlp02 - detected UnsignedFile.Multi.Generic (1)
21:47:24.0781 3432        prosync1        (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
21:47:24.0781 3432        prosync1 ( UnsignedFile.Multi.Generic ) - warning
21:47:24.0781 3432        prosync1 - detected UnsignedFile.Multi.Generic (1)
21:47:24.0812 3432        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:47:24.0953 3432        PSched - ok
21:47:25.0000 3432        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:47:25.0125 3432        Ptilink - ok
21:47:25.0156 3432        ql1080 - ok
21:47:25.0171 3432        Ql10wnt - ok
21:47:25.0187 3432        ql12160 - ok
21:47:25.0203 3432        ql1240 - ok
21:47:25.0218 3432        ql1280 - ok
21:47:25.0250 3432        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:47:25.0375 3432        RasAcd - ok
21:47:25.0390 3432        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:47:25.0578 3432        Rasl2tp - ok
21:47:25.0625 3432        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:47:25.0765 3432        RasPppoe - ok
21:47:25.0781 3432        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:47:25.0906 3432        Raspti - ok
21:47:25.0937 3432        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:47:26.0093 3432        Rdbss - ok
21:47:26.0125 3432        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:47:26.0234 3432        RDPCDD - ok
21:47:26.0265 3432        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:47:26.0406 3432        rdpdr - ok
21:47:26.0453 3432        RDPWD          (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:47:26.0468 3432        RDPWD - ok
21:47:26.0500 3432        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:47:26.0640 3432        redbook - ok
21:47:26.0687 3432        RFCOMM          (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
21:47:26.0843 3432        RFCOMM - ok
21:47:26.0906 3432        ROOTMODEM      (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
21:47:27.0031 3432        ROOTMODEM - ok
21:47:27.0093 3432        SaiNtHid        (a007103ef0e50fb0e0ed08b511d721d7) C:\WINDOWS\system32\DRIVERS\SaiNtHid.sys
21:47:27.0109 3432        SaiNtHid ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0109 3432        SaiNtHid - detected UnsignedFile.Multi.Generic (1)
21:47:27.0156 3432        SCR3xx USB Smart Card Reader (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
21:47:27.0187 3432        SCR3xx USB Smart Card Reader - ok
21:47:27.0203 3432        SCR3XX2K        (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
21:47:27.0218 3432        SCR3XX2K - ok
21:47:27.0265 3432        SE4501D        (b84c83e5355c2aa96bb5c5fab9f5d3e4) C:\WINDOWS\system32\DRIVERS\SE4501D.sys
21:47:27.0296 3432        SE4501D ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0296 3432        SE4501D - detected UnsignedFile.Multi.Generic (1)
21:47:27.0343 3432        Secdrv          (ba0d892d2f786bcebdf03b0a252b47f3) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:47:27.0359 3432        Secdrv ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0359 3432        Secdrv - detected UnsignedFile.Multi.Generic (1)
21:47:27.0421 3432        Serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:47:27.0578 3432        Serenum - ok
21:47:27.0609 3432        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
21:47:27.0734 3432        Serial - ok
21:47:27.0812 3432        sfdrv01        (00de597b81b381053cb5b21a7f20e365) C:\WINDOWS\system32\drivers\sfdrv01.sys
21:47:27.0812 3432        sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0812 3432        sfdrv01 - detected UnsignedFile.Multi.Generic (1)
21:47:27.0843 3432        sfhlp01        (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
21:47:27.0859 3432        sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0859 3432        sfhlp01 - detected UnsignedFile.Multi.Generic (1)
21:47:27.0906 3432        sfhlp02        (64b9ab76f1b16eb059cb6cdd906c067a) C:\WINDOWS\system32\drivers\sfhlp02.sys
21:47:27.0906 3432        sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
21:47:27.0906 3432        sfhlp02 - detected UnsignedFile.Multi.Generic (1)
21:47:27.0921 3432        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:47:28.0078 3432        Sfloppy - ok
21:47:28.0093 3432        Simbad - ok
21:47:28.0125 3432        SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:47:28.0281 3432        SLIP - ok
21:47:28.0296 3432        Sparrow - ok
21:47:28.0328 3432        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:47:28.0437 3432        splitter - ok
21:47:28.0453 3432        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
21:47:28.0531 3432        sr - ok
21:47:28.0593 3432        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:47:28.0625 3432        Srv - ok
21:47:28.0687 3432        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
21:47:28.0703 3432        ssmdrv - ok
21:47:28.0765 3432        STC2DFU - ok
21:47:28.0812 3432        STCFUx32        (68c00ee8c35e4ea63dca5ca7d572e25e) C:\WINDOWS\system32\DRIVERS\STCFUx32.SYS
21:47:28.0843 3432        STCFUx32 - ok
21:47:28.0875 3432        streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:47:29.0015 3432        streamip - ok
21:47:29.0031 3432        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:47:29.0171 3432        swenum - ok
21:47:29.0203 3432        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:47:29.0343 3432        swmidi - ok
21:47:29.0359 3432        symc810 - ok
21:47:29.0375 3432        symc8xx - ok
21:47:29.0406 3432        sym_hi - ok
21:47:29.0421 3432        sym_u3 - ok
21:47:29.0437 3432        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:47:29.0593 3432        sysaudio - ok
21:47:29.0656 3432        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:47:29.0687 3432        Tcpip - ok
21:47:29.0703 3432        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:47:29.0859 3432        TDPIPE - ok
21:47:29.0906 3432        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:47:30.0046 3432        TDTCP - ok
21:47:30.0078 3432        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:47:30.0203 3432        TermDD - ok
21:47:30.0234 3432        TosIde - ok
21:47:30.0265 3432        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:47:30.0390 3432        Udfs - ok
21:47:30.0406 3432        ultra - ok
21:47:30.0484 3432        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:47:30.0640 3432        Update - ok
21:47:30.0687 3432        USBAAPL        (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
21:47:30.0718 3432        USBAAPL - ok
21:47:30.0765 3432        usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:47:30.0906 3432        usbaudio - ok
21:47:30.0953 3432        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:47:31.0093 3432        usbccgp - ok
21:47:31.0109 3432        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:47:31.0250 3432        usbehci - ok
21:47:31.0296 3432        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:47:31.0421 3432        usbhub - ok
21:47:31.0437 3432        usbohci        (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
21:47:31.0562 3432        usbohci - ok
21:47:31.0593 3432        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:47:31.0703 3432        usbprint - ok
21:47:31.0750 3432        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:47:31.0875 3432        usbscan - ok
21:47:31.0906 3432        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:47:32.0046 3432        USBSTOR - ok
21:47:32.0062 3432        uxy9b.sys - ok
21:47:32.0109 3432        VComm          (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys
21:47:32.0125 3432        VComm ( UnsignedFile.Multi.Generic ) - warning
21:47:32.0125 3432        VComm - detected UnsignedFile.Multi.Generic (1)
21:47:32.0156 3432        VcommMgr        (ef0d45ed806b0c9ae9756bfeecb077ed) C:\WINDOWS\system32\Drivers\VcommMgr.sys
21:47:32.0187 3432        VcommMgr ( UnsignedFile.Multi.Generic ) - warning
21:47:32.0187 3432        VcommMgr - detected UnsignedFile.Multi.Generic (1)
21:47:32.0203 3432        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:47:32.0328 3432        VgaSave - ok
21:47:32.0328 3432        ViaIde - ok
21:47:32.0375 3432        vnccom          (b67632451f760797bb183e1fb99f4b39) C:\WINDOWS\system32\Drivers\vnccom.SYS
21:47:32.0390 3432        vnccom ( UnsignedFile.Multi.Generic ) - warning
21:47:32.0390 3432        vnccom - detected UnsignedFile.Multi.Generic (1)
21:47:32.0421 3432        vncdrv          (4ec979b157d1aa075330362acb5424e5) C:\WINDOWS\system32\DRIVERS\vncdrv.sys
21:47:32.0453 3432        vncdrv ( UnsignedFile.Multi.Generic ) - warning
21:47:32.0453 3432        vncdrv - detected UnsignedFile.Multi.Generic (1)
21:47:32.0484 3432        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
21:47:32.0609 3432        VolSnap - ok
21:47:32.0671 3432        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:47:32.0796 3432        Wanarp - ok
21:47:32.0812 3432        WDICA - ok
21:47:32.0890 3432        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:47:33.0031 3432        wdmaud - ok
21:47:33.0093 3432        WmBEnum        (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys
21:47:33.0109 3432        WmBEnum - ok
21:47:33.0156 3432        WmFilter        (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys
21:47:33.0171 3432        WmFilter - ok
21:47:33.0203 3432        WmHidLo        (bb49902577091f634e752537181d2c19) C:\WINDOWS\system32\drivers\WmHidLo.sys
21:47:33.0218 3432        WmHidLo - ok
21:47:33.0265 3432        WmVirHid        (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys
21:47:33.0281 3432        WmVirHid - ok
21:47:33.0312 3432        WmXlCore        (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys
21:47:33.0328 3432        WmXlCore - ok
21:47:33.0359 3432        WpdUsb          (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
21:47:33.0390 3432        WpdUsb - ok
21:47:33.0437 3432        WS2IFSL        (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
21:47:33.0609 3432        WS2IFSL - ok
21:47:33.0656 3432        WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:47:33.0796 3432        WSTCODEC - ok
21:47:33.0843 3432        WudfPf          (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:47:33.0875 3432        WudfPf - ok
21:47:33.0937 3432        WudfRd          (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:47:33.0953 3432        WudfRd - ok
21:47:33.0968 3432        xcpip - ok
21:47:34.0000 3432        xpsec - ok
21:47:34.0062 3432        zlportio - ok
21:47:34.0093 3432        MBR (0x1B8)    (eeadaf356113e54427e990a5bcad82b5) \Device\Harddisk0\DR0
21:47:34.0093 3432        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected
21:47:34.0093 3432        \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0)
21:47:34.0171 3432        Boot (0x1200)  (76ae28f380934ee0dad55c95a523df03) \Device\Harddisk0\DR0\Partition0
21:47:34.0171 3432        \Device\Harddisk0\DR0\Partition0 - ok
21:47:34.0203 3432        Boot (0x1200)  (852b9f665a1f7c90b5737e2b210f086d) \Device\Harddisk0\DR0\Partition1
21:47:34.0203 3432        \Device\Harddisk0\DR0\Partition1 - ok
21:47:34.0218 3432        Boot (0x1200)  (0403679a73ca5dd9e147c2a422f00c8f) \Device\Harddisk0\DR0\Partition2
21:47:34.0218 3432        \Device\Harddisk0\DR0\Partition2 - ok
21:47:34.0234 3432        ============================================================
21:47:34.0234 3432        Scan finished
21:47:34.0234 3432        ============================================================
21:47:34.0359 3920        Detected object count: 35
21:47:34.0359 3920        Actual detected object count: 35
21:50:17.0203 3920        aadev ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0203 3920        aadev ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0203 3920        AnyDVD ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0203 3920        AnyDVD ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        ASInsHelp ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        ASInsHelp ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        AsIO ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        AsIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        aslm75 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        aslm75 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        BlueletAudio ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        BlueletAudio ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        Bonifay ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        Bonifay ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        BT ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        BT ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0218 3920        Btcsrusb ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0218 3920        Btcsrusb ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        BTHidEnum ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        BTHidEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        BTHidMgr ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        BTHidMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        ElbyCDIO ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        ElbyCDIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        Gonzales ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        Gonzales ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        meiudf ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        meiudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        MTsensor ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        MTsensor ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        NETFWDSL ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        NETFWDSL ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0234 3920        nvatabus ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0234 3920        nvatabus ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        ovt519 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        ovt519 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        pfc ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        PLFF ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        PLFF ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        SaiNtHid ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        SaiNtHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        SE4501D ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0250 3920        SE4501D ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0250 3920        Secdrv ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        VComm ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        VComm ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        VcommMgr ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        VcommMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        vnccom ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        vnccom ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0265 3920        vncdrv ( UnsignedFile.Multi.Generic ) - skipped by user
21:50:17.0265 3920        vncdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:50:17.0296 3920        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - will be cured on reboot
21:50:17.0296 3920        \Device\Harddisk0\DR0 - ok
21:50:17.0296 3920        \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Cure
21:50:21.0515 2720        Deinitialize success


cosinus 16.01.2012 15:55

Sry aber du solltest neu starten und dann ein neues erstelltes Log posten...

tax 16.01.2012 16:29

Du meinst den TDSSKiller noch mal ausführen? Falls ja mit welchen Einstellungen?

cosinus 16.01.2012 16:35

ja wie in #20 genannt

tax 16.01.2012 17:30

Aber jetzt

Code:

17:24:06.0093 3524        TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05
17:24:07.0546 3524        ============================================================
17:24:07.0546 3524        Current date / time: 2012/01/16 17:24:07.0546
17:24:07.0546 3524        SystemInfo:
17:24:07.0546 3524       
17:24:07.0546 3524        OS Version: 5.1.2600 ServicePack: 3.0
17:24:07.0546 3524        Product type: Workstation
17:24:07.0546 3524        ComputerName: SHOOT
17:24:07.0546 3524        UserName: Weisi
17:24:07.0546 3524        Windows directory: C:\WINDOWS
17:24:07.0546 3524        System windows directory: C:\WINDOWS
17:24:07.0546 3524        Processor architecture: Intel x86
17:24:07.0546 3524        Number of processors: 1
17:24:07.0546 3524        Page size: 0x1000
17:24:07.0546 3524        Boot type: Normal boot
17:24:07.0546 3524        ============================================================
17:24:08.0828 3524        Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000, SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054
17:24:08.0937 3524        Initialize success
17:24:15.0703 3576        ============================================================
17:24:15.0703 3576        Scan started
17:24:15.0703 3576        Mode: Manual; SigCheck; TDLFS;
17:24:15.0703 3576        ============================================================
17:24:16.0296 3576        aadev          (6bfb6def4eb16b74c0179de110077920) C:\WINDOWS\system32\DRIVERS\aadev.sys
17:24:16.0421 3576        aadev ( UnsignedFile.Multi.Generic ) - warning
17:24:16.0421 3576        aadev - detected UnsignedFile.Multi.Generic (1)
17:24:16.0453 3576        Abiosdsk - ok
17:24:16.0468 3576        abp480n5 - ok
17:24:16.0515 3576        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:24:17.0531 3576        ACPI - ok
17:24:17.0640 3576        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:24:17.0828 3576        ACPIEC - ok
17:24:17.0875 3576        adpu160m - ok
17:24:17.0921 3576        aec            (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:24:18.0078 3576        aec - ok
17:24:18.0125 3576        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:24:18.0187 3576        AFD - ok
17:24:18.0218 3576        Aha154x - ok
17:24:18.0234 3576        aic78u2 - ok
17:24:18.0250 3576        aic78xx - ok
17:24:18.0359 3576        ALCXWDM        (933933288df5ed26d1928215c97d05c7) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
17:24:18.0531 3576        ALCXWDM - ok
17:24:18.0562 3576        AliIde - ok
17:24:18.0593 3576        AmdK8          (b9dbaae3219661f4d0c5e8dc0c2f987d) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
17:24:18.0640 3576        AmdK8 - ok
17:24:18.0656 3576        amsint - ok
17:24:18.0734 3576        AnyDVD          (44c905e4dfd93a8c49f97c14d9c399f3) C:\WINDOWS\system32\Drivers\AnyDVD.sys
17:24:18.0765 3576        AnyDVD ( UnsignedFile.Multi.Generic ) - warning
17:24:18.0765 3576        AnyDVD - detected UnsignedFile.Multi.Generic (1)
17:24:18.0796 3576        asc - ok
17:24:18.0812 3576        asc3350p - ok
17:24:18.0828 3576        asc3550 - ok
17:24:18.0875 3576        ASInsHelp      (33c171de483ee145f31234d93b078919) C:\WINDOWS\system32\drivers\AsInsHelp32.sys
17:24:18.0890 3576        ASInsHelp ( UnsignedFile.Multi.Generic ) - warning
17:24:18.0890 3576        ASInsHelp - detected UnsignedFile.Multi.Generic (1)
17:24:18.0921 3576        AsIO            (c959989e2ce8da9bde8cafddba84badf) C:\WINDOWS\system32\drivers\AsIO.sys
17:24:18.0953 3576        AsIO ( UnsignedFile.Multi.Generic ) - warning
17:24:18.0953 3576        AsIO - detected UnsignedFile.Multi.Generic (1)
17:24:18.0984 3576        aslm75          (71356a1370739e25375a1d17b6ae318f) C:\WINDOWS\system32\drivers\aslm75.sys
17:24:19.0000 3576        aslm75 ( UnsignedFile.Multi.Generic ) - warning
17:24:19.0000 3576        aslm75 - detected UnsignedFile.Multi.Generic (1)
17:24:19.0062 3576        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:24:19.0203 3576        AsyncMac - ok
17:24:19.0234 3576        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:24:19.0390 3576        atapi - ok
17:24:19.0406 3576        Atdisk - ok
17:24:19.0546 3576        ati2mtag        (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
17:24:19.0734 3576        ati2mtag ( UnsignedFile.Multi.Generic ) - warning
17:24:19.0734 3576        ati2mtag - detected UnsignedFile.Multi.Generic (1)
17:24:19.0843 3576        Atmarpc        (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:24:20.0015 3576        Atmarpc - ok
17:24:20.0046 3576        audstub        (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:24:20.0203 3576        audstub - ok
17:24:20.0312 3576        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys
17:24:20.0328 3576        avgio - ok
17:24:20.0375 3576        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
17:24:20.0421 3576        avgntflt - ok
17:24:20.0468 3576        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
17:24:20.0484 3576        avipbb - ok
17:24:20.0531 3576        AVMDSLPPPOE    (aa5874f64d6f2ffafa8c5fbc202ce6ef) C:\WINDOWS\system32\DRIVERS\avmdsloe.sys
17:24:20.0578 3576        AVMDSLPPPOE - ok
17:24:20.0593 3576        AVMNDSL        (140ba5bf4666c27c15368cce9df54a93) C:\WINDOWS\system32\DRIVERS\avmndsl.sys
17:24:20.0609 3576        AVMNDSL - ok
17:24:20.0640 3576        bdfdll - ok
17:24:20.0687 3576        Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:24:20.0828 3576        Beep - ok
17:24:20.0875 3576        BlueletAudio    (31ff5b87c1dd907613cc613224b8e303) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
17:24:20.0906 3576        BlueletAudio ( UnsignedFile.Multi.Generic ) - warning
17:24:20.0906 3576        BlueletAudio - detected UnsignedFile.Multi.Generic (1)
17:24:20.0921 3576        Bonifay        (b63f6bc2f76db693e4ed51ebe7f34828) C:\WINDOWS\system32\DRIVERS\Bonifay.sys
17:24:20.0937 3576        Bonifay ( UnsignedFile.Multi.Generic ) - warning
17:24:20.0937 3576        Bonifay - detected UnsignedFile.Multi.Generic (1)
17:24:20.0984 3576        BT              (9da8abc4885aff4793d4aa420e40bb12) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
17:24:21.0015 3576        BT ( UnsignedFile.Multi.Generic ) - warning
17:24:21.0015 3576        BT - detected UnsignedFile.Multi.Generic (1)
17:24:21.0046 3576        Btcsrusb        (95a061d5217cbb6642e73a8fd9aa9734) C:\WINDOWS\system32\Drivers\btcusb.sys
17:24:21.0062 3576        Btcsrusb ( UnsignedFile.Multi.Generic ) - warning
17:24:21.0062 3576        Btcsrusb - detected UnsignedFile.Multi.Generic (1)
17:24:21.0109 3576        BthEnum        (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
17:24:21.0250 3576        BthEnum - ok
17:24:21.0281 3576        BTHidEnum      (083ad7f6ff500d0a93c0bea2cf298c93) C:\WINDOWS\system32\DRIVERS\vbtenum.sys
17:24:21.0296 3576        BTHidEnum ( UnsignedFile.Multi.Generic ) - warning
17:24:21.0296 3576        BTHidEnum - detected UnsignedFile.Multi.Generic (1)
17:24:21.0328 3576        BTHidMgr        (f408264f6ad1dc7e7bdd4837440f115d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
17:24:21.0328 3576        BTHidMgr ( UnsignedFile.Multi.Generic ) - warning
17:24:21.0328 3576        BTHidMgr - detected UnsignedFile.Multi.Generic (1)
17:24:21.0375 3576        BTHMODEM        (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
17:24:21.0515 3576        BTHMODEM - ok
17:24:21.0546 3576        BthPan          (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
17:24:21.0703 3576        BthPan - ok
17:24:21.0750 3576        BTHPORT        (592e1cedbe314d0ef184dc6f46141e76) C:\WINDOWS\system32\Drivers\BTHport.sys
17:24:21.0812 3576        BTHPORT - ok
17:24:21.0843 3576        BTHUSB          (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
17:24:22.0000 3576        BTHUSB - ok
17:24:22.0031 3576        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:24:22.0171 3576        cbidf2k - ok
17:24:22.0218 3576        CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:24:22.0359 3576        CCDECODE - ok
17:24:22.0375 3576        cd20xrnt - ok
17:24:22.0406 3576        Cdaudio        (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:24:22.0562 3576        Cdaudio - ok
17:24:22.0593 3576        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:24:22.0734 3576        Cdfs - ok
17:24:22.0765 3576        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:24:22.0921 3576        Cdrom - ok
17:24:22.0953 3576        Changer - ok
17:24:23.0000 3576        CmdIde - ok
17:24:23.0031 3576        Cpqarray - ok
17:24:23.0078 3576        ctxusbm        (cb6ff7012bb5d59d7c12350db795ce1f) C:\WINDOWS\system32\DRIVERS\ctxusbm.sys
17:24:23.0093 3576        ctxusbm - ok
17:24:23.0109 3576        dac2w2k - ok
17:24:23.0125 3576        dac960nt - ok
17:24:23.0203 3576        dbustrcm - ok
17:24:23.0234 3576        Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:24:23.0390 3576        Disk - ok
17:24:23.0437 3576        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
17:24:23.0625 3576        dmboot - ok
17:24:23.0656 3576        dmio            (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
17:24:23.0812 3576        dmio - ok
17:24:23.0843 3576        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:24:24.0000 3576        dmload - ok
17:24:24.0031 3576        DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:24:24.0171 3576        DMusic - ok
17:24:24.0203 3576        dpti2o - ok
17:24:24.0234 3576        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:24:24.0375 3576        drmkaud - ok
17:24:24.0421 3576        ElbyCDIO        (37c3a9fef349d13685ec9c2acaaeafce) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
17:24:24.0421 3576        ElbyCDIO ( UnsignedFile.Multi.Generic ) - warning
17:24:24.0421 3576        ElbyCDIO - detected UnsignedFile.Multi.Generic (1)
17:24:24.0468 3576        Fastfat        (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:24:24.0609 3576        Fastfat - ok
17:24:24.0640 3576        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:24:24.0796 3576        Fdc - ok
17:24:24.0859 3576        FDSSBASE        (551a237a1ce44261dc0783661bcfb9a5) C:\WINDOWS\system32\DRIVERS\fdssbase.sys
17:24:24.0921 3576        FDSSBASE - ok
17:24:24.0953 3576        Fips            (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
17:24:25.0093 3576        Fips - ok
17:24:25.0109 3576        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:24:25.0250 3576        Flpydisk - ok
17:24:25.0296 3576        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:24:25.0453 3576        FltMgr - ok
17:24:25.0500 3576        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:24:25.0656 3576        Fs_Rec - ok
17:24:25.0703 3576        Ftdisk          (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:24:25.0859 3576        Ftdisk - ok
17:24:25.0875 3576        gameenum        (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
17:24:26.0343 3576        gameenum - ok
17:24:26.0359 3576        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
17:24:26.0375 3576        GEARAspiWDM - ok
17:24:26.0406 3576        Gonzales        (829870058335703af4b95cbc1f83affc) C:\WINDOWS\system32\DRIVERS\Gonzales.sys
17:24:26.0406 3576        Gonzales ( UnsignedFile.Multi.Generic ) - warning
17:24:26.0406 3576        Gonzales - detected UnsignedFile.Multi.Generic (1)
17:24:26.0437 3576        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:24:26.0593 3576        Gpc - ok
17:24:26.0625 3576        HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:24:26.0781 3576        HidUsb - ok
17:24:26.0796 3576        hpn - ok
17:24:26.0828 3576        hpt3xx - ok
17:24:26.0859 3576        HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:24:26.0937 3576        HTTP - ok
17:24:26.0953 3576        i2omgmt - ok
17:24:26.0984 3576        i2omp - ok
17:24:27.0015 3576        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:24:27.0156 3576        i8042prt - ok
17:24:27.0187 3576        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:24:27.0343 3576        Imapi - ok
17:24:27.0375 3576        ini910u - ok
17:24:27.0390 3576        IntelIde - ok
17:24:27.0437 3576        ip6fw          (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:24:27.0609 3576        ip6fw - ok
17:24:27.0640 3576        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:24:27.0796 3576        IpFilterDriver - ok
17:24:27.0828 3576        IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:24:27.0984 3576        IpInIp - ok
17:24:28.0015 3576        IpNat          (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:24:28.0156 3576        IpNat - ok
17:24:28.0187 3576        IPSec          (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:24:28.0328 3576        IPSec - ok
17:24:28.0375 3576        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:24:28.0437 3576        IRENUM - ok
17:24:28.0468 3576        isapnp          (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:24:28.0593 3576        isapnp - ok
17:24:28.0640 3576        Kbdclass        (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:24:28.0781 3576        Kbdclass - ok
17:24:28.0812 3576        kbdhid          (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
17:24:28.0953 3576        kbdhid - ok
17:24:28.0984 3576        kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:24:29.0140 3576        kmixer - ok
17:24:29.0171 3576        KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:24:29.0265 3576        KSecDD - ok
17:24:29.0296 3576        lbrtfdc - ok
17:24:29.0328 3576        meiudf          (a4798cd432781bc382603499d301e176) C:\WINDOWS\system32\Drivers\meiudf.sys
17:24:29.0359 3576        meiudf ( UnsignedFile.Multi.Generic ) - warning
17:24:29.0359 3576        meiudf - detected UnsignedFile.Multi.Generic (1)
17:24:29.0390 3576        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:24:29.0531 3576        mnmdd - ok
17:24:29.0562 3576        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
17:24:29.0703 3576        Modem - ok
17:24:29.0750 3576        Mouclass        (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:24:29.0890 3576        Mouclass - ok
17:24:29.0937 3576        mouhid          (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:24:30.0078 3576        mouhid - ok
17:24:30.0093 3576        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:24:30.0234 3576        MountMgr - ok
17:24:30.0250 3576        mraid35x - ok
17:24:30.0281 3576        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:24:30.0437 3576        MRxDAV - ok
17:24:30.0484 3576        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:24:30.0562 3576        MRxSmb - ok
17:24:30.0593 3576        Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:24:30.0734 3576        Msfs - ok
17:24:30.0765 3576        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:24:30.0906 3576        MSKSSRV - ok
17:24:30.0937 3576        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:24:31.0078 3576        MSPCLOCK - ok
17:24:31.0093 3576        MSPQM          (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:24:31.0234 3576        MSPQM - ok
17:24:31.0281 3576        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:24:31.0406 3576        mssmbios - ok
17:24:31.0453 3576        MSTEE          (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:24:31.0609 3576        MSTEE - ok
17:24:31.0656 3576        ms_mpu401      (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
17:24:31.0796 3576        ms_mpu401 - ok
17:24:31.0843 3576        MTsensor        (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
17:24:31.0859 3576        MTsensor ( UnsignedFile.Multi.Generic ) - warning
17:24:31.0859 3576        MTsensor - detected UnsignedFile.Multi.Generic (1)
17:24:31.0906 3576        Mup            (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:24:31.0937 3576        Mup - ok
17:24:31.0953 3576        NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:24:32.0109 3576        NABTSFEC - ok
17:24:32.0140 3576        NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:24:32.0296 3576        NDIS - ok
17:24:32.0328 3576        NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:24:32.0453 3576        NdisIP - ok
17:24:32.0500 3576        NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:24:32.0546 3576        NdisTapi - ok
17:24:32.0578 3576        Ndisuio        (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:24:32.0718 3576        Ndisuio - ok
17:24:32.0750 3576        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:24:32.0875 3576        NdisWan - ok
17:24:32.0906 3576        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:24:32.0953 3576        NDProxy - ok
17:24:32.0984 3576        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:24:33.0125 3576        NetBIOS - ok
17:24:33.0171 3576        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:24:33.0312 3576        NetBT - ok
17:24:33.0359 3576        NETFWDSL        (a001e7d84da39a5e7aff3cb05e77e033) C:\WINDOWS\system32\DRIVERS\NETFWDSL.SYS
17:24:33.0390 3576        NETFWDSL ( UnsignedFile.Multi.Generic ) - warning
17:24:33.0390 3576        NETFWDSL - detected UnsignedFile.Multi.Generic (1)
17:24:33.0421 3576        Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:24:33.0562 3576        Npfs - ok
17:24:33.0609 3576        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:24:33.0750 3576        Ntfs - ok
17:24:33.0781 3576        Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:24:33.0921 3576        Null - ok
17:24:34.0078 3576        nv              (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
17:24:34.0312 3576        nv - ok
17:24:34.0421 3576        nvatabus        (3bfc1dea3076d9eaa282e9cc1e4d7a23) C:\WINDOWS\system32\DRIVERS\nvatabus.sys
17:24:34.0437 3576        nvatabus ( UnsignedFile.Multi.Generic ) - warning
17:24:34.0437 3576        nvatabus - detected UnsignedFile.Multi.Generic (1)
17:24:34.0468 3576        NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
17:24:34.0531 3576        NVENETFD - ok
17:24:34.0578 3576        nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
17:24:34.0625 3576        nvnetbus - ok
17:24:34.0703 3576        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:24:34.0859 3576        NwlnkFlt - ok
17:24:34.0890 3576        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:24:35.0031 3576        NwlnkFwd - ok
17:24:35.0078 3576        ovt519          (4cdadec3dc1300ee1d313ea5494e6472) C:\WINDOWS\system32\Drivers\ov519vid.sys
17:24:35.0109 3576        ovt519 ( UnsignedFile.Multi.Generic ) - warning
17:24:35.0109 3576        ovt519 - detected UnsignedFile.Multi.Generic (1)
17:24:35.0156 3576        Parport        (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\DRIVERS\parport.sys
17:24:35.0296 3576        Parport - ok
17:24:35.0312 3576        PartMgr        (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:24:35.0453 3576        PartMgr - ok
17:24:35.0484 3576        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
17:24:35.0625 3576        ParVdm - ok
17:24:35.0656 3576        pccsmcfd        (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
17:24:35.0718 3576        pccsmcfd - ok
17:24:35.0750 3576        PCI            (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
17:24:35.0890 3576        PCI - ok
17:24:35.0906 3576        PCIDump - ok
17:24:35.0937 3576        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:24:36.0062 3576        PCIIde - ok
17:24:36.0093 3576        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:24:36.0234 3576        Pcmcia - ok
17:24:36.0250 3576        PDCOMP - ok
17:24:36.0265 3576        PDFRAME - ok
17:24:36.0281 3576        PDRELI - ok
17:24:36.0296 3576        PDRFRAME - ok
17:24:36.0312 3576        perc2 - ok
17:24:36.0343 3576        perc2hib - ok
17:24:36.0406 3576        pfc            (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
17:24:36.0421 3576        pfc ( UnsignedFile.Multi.Generic ) - warning
17:24:36.0421 3576        pfc - detected UnsignedFile.Multi.Generic (1)
17:24:36.0468 3576        PLFF            (a20ac92609f3b246be3b761bb72fc6a5) C:\WINDOWS\system32\Drivers\PLFF.sys
17:24:36.0484 3576        PLFF ( UnsignedFile.Multi.Generic ) - warning
17:24:36.0484 3576        PLFF - detected UnsignedFile.Multi.Generic (1)
17:24:36.0531 3576        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:24:36.0656 3576        PptpMiniport - ok
17:24:36.0703 3576        Processor      (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys
17:24:36.0828 3576        Processor - ok
17:24:36.0859 3576        prodrv06        (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
17:24:36.0906 3576        prodrv06 ( UnsignedFile.Multi.Generic ) - warning
17:24:36.0921 3576        prodrv06 - detected UnsignedFile.Multi.Generic (1)
17:24:36.0937 3576        prohlp02        (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
17:24:36.0968 3576        prohlp02 ( UnsignedFile.Multi.Generic ) - warning
17:24:36.0968 3576        prohlp02 - detected UnsignedFile.Multi.Generic (1)
17:24:36.0984 3576        prosync1        (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
17:24:37.0000 3576        prosync1 ( UnsignedFile.Multi.Generic ) - warning
17:24:37.0000 3576        prosync1 - detected UnsignedFile.Multi.Generic (1)
17:24:37.0031 3576        PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:24:37.0171 3576        PSched - ok
17:24:37.0203 3576        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:24:37.0328 3576        Ptilink - ok
17:24:37.0343 3576        ql1080 - ok
17:24:37.0375 3576        Ql10wnt - ok
17:24:37.0390 3576        ql12160 - ok
17:24:37.0406 3576        ql1240 - ok
17:24:37.0421 3576        ql1280 - ok
17:24:37.0437 3576        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:24:37.0687 3576        RasAcd - ok
17:24:37.0718 3576        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:24:37.0859 3576        Rasl2tp - ok
17:24:37.0875 3576        RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:24:38.0000 3576        RasPppoe - ok
17:24:38.0015 3576        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:24:38.0140 3576        Raspti - ok
17:24:38.0171 3576        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:24:38.0312 3576        Rdbss - ok
17:24:38.0328 3576        RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:24:38.0468 3576        RDPCDD - ok
17:24:38.0500 3576        rdpdr          (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:24:38.0656 3576        rdpdr - ok
17:24:38.0718 3576        RDPWD          (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
17:24:38.0765 3576        RDPWD - ok
17:24:38.0796 3576        redbook        (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:24:38.0921 3576        redbook - ok
17:24:38.0984 3576        RFCOMM          (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
17:24:39.0140 3576        RFCOMM - ok
17:24:39.0171 3576        ROOTMODEM      (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
17:24:39.0296 3576        ROOTMODEM - ok
17:24:39.0359 3576        SaiNtHid        (a007103ef0e50fb0e0ed08b511d721d7) C:\WINDOWS\system32\DRIVERS\SaiNtHid.sys
17:24:39.0375 3576        SaiNtHid ( UnsignedFile.Multi.Generic ) - warning
17:24:39.0375 3576        SaiNtHid - detected UnsignedFile.Multi.Generic (1)
17:24:39.0437 3576        SCR3xx USB Smart Card Reader (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
17:24:39.0484 3576        SCR3xx USB Smart Card Reader - ok
17:24:39.0500 3576        SCR3XX2K        (60ab2853a89e7db562b2a56e8de2d0e7) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
17:24:39.0500 3576        SCR3XX2K - ok
17:24:39.0562 3576        SE4501D        (b84c83e5355c2aa96bb5c5fab9f5d3e4) C:\WINDOWS\system32\DRIVERS\SE4501D.sys
17:24:39.0578 3576        SE4501D ( UnsignedFile.Multi.Generic ) - warning
17:24:39.0578 3576        SE4501D - detected UnsignedFile.Multi.Generic (1)
17:24:39.0625 3576        Secdrv          (ba0d892d2f786bcebdf03b0a252b47f3) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:24:39.0640 3576        Secdrv ( UnsignedFile.Multi.Generic ) - warning
17:24:39.0640 3576        Secdrv - detected UnsignedFile.Multi.Generic (1)
17:24:39.0703 3576        Serenum        (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:24:39.0828 3576        Serenum - ok
17:24:39.0843 3576        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\DRIVERS\serial.sys
17:24:39.0984 3576        Serial - ok
17:24:40.0062 3576        sfdrv01        (00de597b81b381053cb5b21a7f20e365) C:\WINDOWS\system32\drivers\sfdrv01.sys
17:24:40.0078 3576        sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
17:24:40.0078 3576        sfdrv01 - detected UnsignedFile.Multi.Generic (1)
17:24:40.0109 3576        sfhlp01        (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
17:24:40.0125 3576        sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
17:24:40.0125 3576        sfhlp01 - detected UnsignedFile.Multi.Generic (1)
17:24:40.0140 3576        sfhlp02        (64b9ab76f1b16eb059cb6cdd906c067a) C:\WINDOWS\system32\drivers\sfhlp02.sys
17:24:40.0171 3576        sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
17:24:40.0171 3576        sfhlp02 - detected UnsignedFile.Multi.Generic (1)
17:24:40.0187 3576        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:24:40.0312 3576        Sfloppy - ok
17:24:40.0343 3576        Simbad - ok
17:24:40.0375 3576        SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:24:40.0515 3576        SLIP - ok
17:24:40.0531 3576        Sparrow - ok
17:24:40.0562 3576        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:24:40.0687 3576        splitter - ok
17:24:40.0703 3576        sr              (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
17:24:40.0781 3576        sr - ok
17:24:40.0828 3576        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:24:40.0921 3576        Srv - ok
17:24:40.0984 3576        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
17:24:41.0000 3576        ssmdrv - ok
17:24:41.0015 3576        STC2DFU - ok
17:24:41.0062 3576        STCFUx32        (68c00ee8c35e4ea63dca5ca7d572e25e) C:\WINDOWS\system32\DRIVERS\STCFUx32.SYS
17:24:41.0109 3576        STCFUx32 - ok
17:24:41.0140 3576        streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:24:41.0265 3576        streamip - ok
17:24:41.0281 3576        swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:24:41.0421 3576        swenum - ok
17:24:41.0453 3576        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:24:41.0593 3576        swmidi - ok
17:24:41.0609 3576        symc810 - ok
17:24:41.0625 3576        symc8xx - ok
17:24:41.0656 3576        sym_hi - ok
17:24:41.0671 3576        sym_u3 - ok
17:24:41.0703 3576        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:24:41.0843 3576        sysaudio - ok
17:24:41.0906 3576        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:24:41.0968 3576        Tcpip - ok
17:24:42.0000 3576        TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:24:42.0125 3576        TDPIPE - ok
17:24:42.0140 3576        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:24:42.0281 3576        TDTCP - ok
17:24:42.0312 3576        TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:24:42.0437 3576        TermDD - ok
17:24:42.0468 3576        TosIde - ok
17:24:42.0515 3576        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:24:42.0656 3576        Udfs - ok
17:24:42.0671 3576        ultra - ok
17:24:42.0734 3576        Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:24:42.0890 3576        Update - ok
17:24:42.0937 3576        USBAAPL        (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
17:24:42.0984 3576        USBAAPL - ok
17:24:43.0031 3576        usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
17:24:43.0187 3576        usbaudio - ok
17:24:43.0218 3576        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:24:43.0359 3576        usbccgp - ok
17:24:43.0375 3576        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:24:43.0515 3576        usbehci - ok
17:24:43.0562 3576        usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:24:43.0687 3576        usbhub - ok
17:24:43.0703 3576        usbohci        (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
17:24:43.0828 3576        usbohci - ok
17:24:43.0875 3576        usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:24:44.0000 3576        usbprint - ok
17:24:44.0015 3576        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:24:44.0140 3576        usbscan - ok
17:24:44.0171 3576        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:24:44.0296 3576        USBSTOR - ok
17:24:44.0312 3576        uxy9b.sys - ok
17:24:44.0343 3576        VComm          (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys
17:24:44.0375 3576        VComm ( UnsignedFile.Multi.Generic ) - warning
17:24:44.0375 3576        VComm - detected UnsignedFile.Multi.Generic (1)
17:24:44.0421 3576        VcommMgr        (ef0d45ed806b0c9ae9756bfeecb077ed) C:\WINDOWS\system32\Drivers\VcommMgr.sys
17:24:44.0437 3576        VcommMgr ( UnsignedFile.Multi.Generic ) - warning
17:24:44.0437 3576        VcommMgr - detected UnsignedFile.Multi.Generic (1)
17:24:44.0468 3576        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:24:44.0593 3576        VgaSave - ok
17:24:44.0609 3576        ViaIde - ok
17:24:44.0656 3576        vnccom          (b67632451f760797bb183e1fb99f4b39) C:\WINDOWS\system32\Drivers\vnccom.SYS
17:24:44.0687 3576        vnccom ( UnsignedFile.Multi.Generic ) - warning
17:24:44.0687 3576        vnccom - detected UnsignedFile.Multi.Generic (1)
17:24:44.0718 3576        vncdrv          (4ec979b157d1aa075330362acb5424e5) C:\WINDOWS\system32\DRIVERS\vncdrv.sys
17:24:44.0734 3576        vncdrv ( UnsignedFile.Multi.Generic ) - warning
17:24:44.0734 3576        vncdrv - detected UnsignedFile.Multi.Generic (1)
17:24:44.0765 3576        VolSnap        (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
17:24:44.0890 3576        VolSnap - ok
17:24:44.0921 3576        Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:24:45.0046 3576        Wanarp - ok
17:24:45.0062 3576        WDICA - ok
17:24:45.0093 3576        wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:24:45.0218 3576        wdmaud - ok
17:24:45.0296 3576        WmBEnum        (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys
17:24:45.0328 3576        WmBEnum - ok
17:24:45.0359 3576        WmFilter        (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys
17:24:45.0421 3576        WmFilter - ok
17:24:45.0437 3576        WmHidLo        (bb49902577091f634e752537181d2c19) C:\WINDOWS\system32\drivers\WmHidLo.sys
17:24:45.0453 3576        WmHidLo - ok
17:24:45.0515 3576        WmVirHid        (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys
17:24:45.0546 3576        WmVirHid - ok
17:24:45.0578 3576        WmXlCore        (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys
17:24:45.0593 3576        WmXlCore - ok
17:24:45.0640 3576        WpdUsb          (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
17:24:45.0718 3576        WpdUsb - ok
17:24:45.0750 3576        WS2IFSL        (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:24:45.0906 3576        WS2IFSL - ok
17:24:45.0937 3576        WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:24:46.0078 3576        WSTCODEC - ok
17:24:46.0125 3576        WudfPf          (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:24:46.0171 3576        WudfPf - ok
17:24:46.0203 3576        WudfRd          (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:24:46.0218 3576        WudfRd - ok
17:24:46.0250 3576        xcpip - ok
17:24:46.0281 3576        xpsec - ok
17:24:46.0343 3576        zlportio - ok
17:24:46.0406 3576        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
17:24:46.0687 3576        \Device\Harddisk0\DR0 - ok
17:24:46.0718 3576        Boot (0x1200)  (76ae28f380934ee0dad55c95a523df03) \Device\Harddisk0\DR0\Partition0
17:24:46.0718 3576        \Device\Harddisk0\DR0\Partition0 - ok
17:24:46.0750 3576        Boot (0x1200)  (852b9f665a1f7c90b5737e2b210f086d) \Device\Harddisk0\DR0\Partition1
17:24:46.0750 3576        \Device\Harddisk0\DR0\Partition1 - ok
17:24:46.0781 3576        Boot (0x1200)  (0403679a73ca5dd9e147c2a422f00c8f) \Device\Harddisk0\DR0\Partition2
17:24:46.0781 3576        \Device\Harddisk0\DR0\Partition2 - ok
17:24:46.0781 3576        ============================================================
17:24:46.0781 3576        Scan finished
17:24:46.0781 3576        ============================================================
17:24:46.0906 3568        Detected object count: 34
17:24:46.0906 3568        Actual detected object count: 34
17:27:17.0359 3568        aadev ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0359 3568        aadev ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0359 3568        AnyDVD ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0359 3568        AnyDVD ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0359 3568        ASInsHelp ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0359 3568        ASInsHelp ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0359 3568        AsIO ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0359 3568        AsIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        aslm75 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        aslm75 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        BlueletAudio ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        BlueletAudio ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        Bonifay ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        Bonifay ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        BT ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        BT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        Btcsrusb ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        Btcsrusb ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        BTHidEnum ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        BTHidEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0375 3568        BTHidMgr ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0375 3568        BTHidMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        ElbyCDIO ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        ElbyCDIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        Gonzales ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        Gonzales ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        meiudf ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        meiudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        MTsensor ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        MTsensor ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        NETFWDSL ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        NETFWDSL ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        nvatabus ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        nvatabus ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        ovt519 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        ovt519 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0390 3568        pfc ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0390 3568        pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        PLFF ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        PLFF ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        SaiNtHid ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        SaiNtHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        SE4501D ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        SE4501D ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        Secdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0406 3568        sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0406 3568        sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        VComm ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        VComm ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        VcommMgr ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        VcommMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        vnccom ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        vnccom ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:17.0421 3568        vncdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:27:17.0421 3568        vncdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:27:25.0421 3520        Deinitialize success


cosinus 16.01.2012 20:41

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

tax 16.01.2012 21:30

Habe ComboFix ausgeführt.

Während des Scans kam die Meldung "PEV.exe hat ein Problem festgestellt und muss beendet werden".
Das Fenster im Hintergrund von ComboFix stand bei Stufe50.
Nachdem ich die Meldung geschlossen habe, lief ComboFix weiter durch.

Und welch Wunder, die Taskleiste und die Desktop Symbole sind wieder da!
Ich sag :dankeschoen: ! :dankeschoen: ! :dankeschoen: !
Das hast du spitzemäßig hinbekommen! :knuddel:

Wars das gewesen, oder müssen wir noch was machen?

Hier das Logfile:

Code:

ComboFix 12-01-16.02 - Weisi 16.01.2012  21:13:18.2.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2815.2398 [GMT 1:00]
ausgeführt von:: C:\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Weisi\Anwendungsdaten\PnkBstrB.exe
c:\dokumente und einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\.#
c:\dokumente und einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\.#\MBX@F84@8834D8.###
c:\dokumente und einstellungen\Weisi\Lokale Einstellungen\Anwendungsdaten\assembly\tmp
c:\dokumente und einstellungen\Weisi\WINDOWS
c:\programme\xp-AntiSpy
c:\programme\xp-AntiSpy\sponsoring\ebay.ico
c:\programme\xp-AntiSpy\sponsoring\ebay_hover.ico
c:\programme\xp-AntiSpy\uninst.exe
c:\programme\xp-AntiSpy\xp-AntiSpy.chm
c:\programme\xp-AntiSpy\xp-AntiSpy.exe
c:\programme\xp-AntiSpy\xp-AntiSpy.url
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\alcrmv.exe
c:\windows\IsUn0407.exe
c:\windows\run.log
c:\windows\system\BCBSMP35.BPL
c:\windows\system\VCL35.BPL
c:\windows\system32\CddbCdda.dll
c:\windows\system32\CoolXPProgress.ocx
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\explorer.exe
c:\windows\system32\hNWEKRqr.ini
c:\windows\system32\hNWEKRqr.ini2
c:\windows\system32\HotFixQ0306270.exe
c:\windows\system32\WindowsXP-KB829558-x86-DEU.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-16 bis 2012-01-16  ))))))))))))))))))))))))))))))
.
.
2012-01-14 16:46 . 2012-01-14 16:46        684297        ----a-w-        C:\unhide.exe
2012-01-14 16:42 . 2012-01-14 16:42        1972528        ----a-w-        C:\tdsskiller.exe
2012-01-14 15:24 . 2012-01-14 15:24        --------        d-----w-        C:\_OTL
2012-01-13 20:28 . 2012-01-13 20:28        584192        ----a-w-        C:\OTL.exe
2012-01-12 21:01 . 2012-01-12 21:01        --------        d-----w-        c:\programme\ESET
2012-01-10 22:41 . 2008-04-14 03:22        1036800        ----a-w-        c:\windows\explorer.exe
2012-01-10 00:20 . 2012-01-10 06:43        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
2012-01-03 18:47 . 2012-01-03 18:47        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
2012-01-03 18:47 . 2012-01-03 18:49        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonIJPLM
2012-01-03 18:30 . 2012-01-03 18:30        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonBJ
2012-01-03 18:30 . 2009-03-24 04:00        70656        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\CNMPPA1.DLL
2012-01-03 18:30 . 2009-03-24 04:00        27648        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\CNMPDA1.DLL
2012-01-03 18:30 . 2009-03-24 04:00        272384        ----a-w-        c:\windows\system32\CNMLMA1.DLL
2012-01-03 18:30 . 2012-01-03 18:30        --------        d-----w-        c:\windows\system32\CanonIJ Uninstaller Information
2012-01-03 18:30 . 2009-03-18 09:09        178176        ----a-w-        c:\windows\system32\CNMIUA1.DLL
2012-01-03 18:29 . 2012-01-03 18:29        --------        d-----w-        c:\programme\CanonBJ
2012-01-03 18:25 . 2008-04-13 23:17        25856        -c--a-w-        c:\windows\system32\dllcache\usbprint.sys
2012-01-03 18:25 . 2008-04-13 23:17        25856        ----a-w-        c:\windows\system32\drivers\usbprint.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-08 16:12 . 2007-11-11 13:34        138520        ----a-w-        c:\windows\system32\drivers\PnkBstrK.sys
2012-01-08 16:12 . 2009-07-16 17:43        234536        ----a-w-        c:\windows\system32\PnkBstrB.xtr
2012-01-08 16:12 . 2007-11-11 13:34        234536        ----a-w-        c:\windows\system32\PnkBstrB.exe
2012-01-06 14:45 . 2001-08-23 11:00        12400        ----a-w-        c:\windows\system32\drivers\secdrv.sys
2012-01-05 18:30 . 2005-06-22 21:45        60416        ----a-w-        c:\windows\ALCFDRTM.VER
2011-12-10 14:24 . 2009-02-07 14:01        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-11-23 14:40 . 2001-08-23 11:00        1859712        ----a-w-        c:\windows\system32\win32k.sys
2011-11-22 21:36 . 2011-08-14 20:24        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-20 12:40 . 2005-10-21 12:31        43520        ----a-w-        c:\windows\system32\CmdLineExt03.dll
2011-11-04 19:13 . 2001-08-23 11:00        916992        ----a-w-        c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2001-08-23 11:00        43520        ----a-w-        c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2001-08-23 11:00        1469440        ------w-        c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2005-06-22 16:15        385024        ----a-w-        c:\windows\system32\html.iec
2011-11-01 16:07 . 2001-08-23 11:00        1288704        ----a-w-        c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2001-08-23 11:00        33280        ----a-w-        c:\windows\system32\csrsrv.dll
2011-10-26 10:49 . 2001-08-23 11:00        2195072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2011-10-26 10:49 . 2001-08-18 04:28        2071680        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2010-10-12 15:33 . 2010-10-12 15:33        124344        ----a-w-        c:\programme\mozilla firefox\plugins\CCMSDK.dll
2010-10-12 17:15 . 2010-10-12 17:15        13240        ----a-w-        c:\programme\mozilla firefox\plugins\cgpcfg.dll
2010-10-12 15:37 . 2010-10-12 15:37        70592        ----a-w-        c:\programme\mozilla firefox\plugins\CgpCore.dll
2010-10-12 15:35 . 2010-10-12 15:35        91576        ----a-w-        c:\programme\mozilla firefox\plugins\confmgr.dll
2010-10-12 15:34 . 2010-10-12 15:34        22464        ----a-w-        c:\programme\mozilla firefox\plugins\ctxlogging.dll
2010-10-12 15:32 . 2010-10-12 15:32        255416        ----a-w-        c:\programme\mozilla firefox\plugins\ctxmui.dll
2010-10-12 15:35 . 2010-10-12 15:35        31672        ----a-w-        c:\programme\mozilla firefox\plugins\icafile.dll
2010-10-12 15:34 . 2010-10-12 15:34        40384        ----a-w-        c:\programme\mozilla firefox\plugins\icalogon.dll
2010-07-14 11:42 . 2010-07-14 11:42        898480        ----a-w-        c:\programme\mozilla firefox\plugins\sslsdk_b.dll
2010-10-12 15:37 . 2010-10-12 15:37        24000        ----a-w-        c:\programme\mozilla firefox\plugins\TcpPServ.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\programme\Ahead\Nero BackItUp\NBJ.exe" [2003-11-04 1720320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ElbyCheckAnyDVD"="c:\programme\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"ASUS Probe"="c:\programme\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"CORSAIR_PLUtil"="c:\programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe" [2004-11-11 90112]
"OpwareSE2"="c:\programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"LexwareInfoService"="c:\programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe" [2010-09-15 339312]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2009-11-10 417792]
"ConnectionCenter"="c:\programme\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"CanonMyPrinter"="c:\programme\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (cleanup)"="c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2011-12-24 1080904]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
Microsoft Office.lnk - c:\programme\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-1-5 155648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2010-12-30 14:37        281768        ----a-w-        c:\programme\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWatch]
2003-06-10 13:52        507904        ----a-w-        c:\programme\FRITZ!DSL\AWatch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 17:07        141608        ----a-w-        c:\programme\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2008-12-03 11:47        1205760        ----a-w-        c:\programme\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfxsrvtray]
2010-01-13 11:24        686344        ----a-w-        c:\programme\Tobit Radio.fx\Client\rfx-tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
2004-04-23 12:28        77824        ----a-w-        c:\programme\Logitech\Profiler\LWEMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Spiele\\Battlefield 2\\BF2.exe"=
"c:\\Programme\\GameSpy Arcade\\Aphex.exe"=
"e:\\Spiele\\Battlefield 1942\\BF1942.exe"=
"e:\\Spiele\\Return to Castle Wolfenstein\\WolfMP.exe"=
"e:\\Spiele\\Wolfenstein - Enemy Territory\\ET.exe"=
"e:\\Spiele\\Sudden Strike II\\game\\code\\Release\\game_exe.exe"=
"c:\\Programme\\THQ\\Company of Heroes\\BugReport\\BugReport.exe"=
"e:\\Spiele\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Programme\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Programme\\UltraVNC\\vncviewer.exe"=
"c:\\Programme\\Real\\RealPlayer\\realplay.exe"=
"c:\\Programme\\fotobuch.de AG\\Designer 2.0\\Designer.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\ICQ6.5\\ICQ.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programme\\Tobit Radio.fx\\Server\\rfx-server.exe"=
"c:\\Programme\\Tobit Radio.fx\\Client\\rfx-client.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"e:\\Spiele\\Steam\\Steam.exe"=
"c:\\Programme\\THQ\\Relic Entertainment\\Company of Heroes Online\\Game\\RelicCoHOWW.exe"=
"c:\\Dokumente und Einstellungen\\Weisi\\Lokale Einstellungen\\Apps\\2.0\\BM2ZNJ6X.QHP\\PHOMJ3MO.R9H\\coho..tion_4fdd38d166a17713_0001.0001_2ea3ae6aea32b9ef\\CoHOLauncher.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Spiele\\Battlefield Vietnam\\bfvietnam.exe"=
"e:\\Spiele\\Landwirtschafts Simulator 2011\\FarmingSimulator2011.exe"=
"e:\\Spiele\\Landwirtschafts Simulator 2011\\game.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"e:\\Spiele\\Battlefield 2\\forgottenhope2.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"17496:TCP"= 17496:TCP:BitComet 17496 TCP
"17496:UDP"= 17496:UDP:BitComet 17496 UDP
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [14.07.2010 12:51 65584]
R2 aadev;AVM ADSL Adapter Device;c:\windows\system32\drivers\Aadev.sys [22.06.2005 18:34 27648]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [27.11.2009 22:05 136360]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [26.03.2007 20:03 6016]
R3 AVMDSLPPPOE;AVM DSL PPPoE CAPI Treiber;c:\windows\system32\drivers\avmdsloe.sys [27.06.2003 01:00 39552]
R3 AVMNDSL;AVM DSL NDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmndsl.sys [27.06.2003 01:00 38992]
R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifay.sys [23.10.2007 16:32 12928]
R3 FDSSBASE;AVM FRITZ!Card DSL SL (WinXP/2000);c:\windows\system32\drivers\fdssbase.sys [27.06.2003 01:00 665600]
S0 PLFF;USB Flash Disk Driver;c:\windows\system32\drivers\plff.sys [30.08.2005 18:41 7424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.03.2010 13:16 130384]
S3 Gonzales;Gonzales;c:\windows\system32\drivers\Gonzales.sys [23.10.2007 16:32 7040]
S3 NETFWDSL;AVM FRITZ!web DSL PPP;c:\windows\system32\drivers\NETFWDSL.SYS [22.06.2005 18:34 336384]
S3 Radio.fx;Radio.fx Server;c:\programme\Tobit Radio.fx\Server\rfx-server.exe [13.12.2009 09:34 2452232]
S3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\drivers\SCR3XX2K.sys [25.10.2009 09:14 57600]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [25.10.2009 09:14 57600]
S3 SE4501D;Gigaset USB Adapter 54 Driver;c:\windows\system32\drivers\SE4501D.sys [26.03.2006 17:10 346656]
S3 STC2DFU;STCII DFU Adapter;c:\windows\system32\DRIVERS\Stc2Dfu.SYS --> c:\windows\system32\DRIVERS\Stc2Dfu.SYS [?]
S3 STCFUx32;STC DFU Driver;c:\windows\system32\drivers\STCFUx32.sys [13.11.2008 14:10 7680]
S3 uxy9b.sys;uxy9b.sys;\??\c:\windows\system32\drivers\uxy9b.sys --> c:\windows\system32\drivers\uxy9b.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.03.2010 13:16 753504]
S3 xcpip;TCP/IP-Protokolltreiber;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
S3 xpsec;IPSEC-Treiber;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S3 zlportio;zlportio;\??\c:\programme\UltraStar Deluxe\zlportio.sys --> c:\programme\UltraStar Deluxe\zlportio.sys [?]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 33242191
*Deregistered* - 33242191
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2012-01-16 c:\windows\Tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uSearchMigratedDefaultURL = hxxp://search.msn.de/spresults.aspx?q={searchTerms}
uInternet Settings,ProxyOverride = *.local
IE: &Alles mit BitComet herunterladen - c:\programme\BitComet\BitComet.exe/AddAllLink.htm
IE: Alle &Videos mit BitComet herunterladen - c:\programme\BitComet\BitComet.exe/AddVideo.htm
IE: Alles mit FlashGet laden - c:\programme\FlashGet\jc_all.htm
IE: Easy-WebPrint Drucken - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Schnelldruck - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Vorschau - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Zu Druckliste hinzufügen - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Mit BitComet herunter&laden - c:\programme\BitComet\BitComet.exe/AddLink.htm
IE: Mit FlashGet laden - c:\programme\FlashGet\jc_link.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: ltow.de\ag
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{20D67A27-0516-4A6D-B1B4-A2FA3F12F385}: NameServer = 192.168.122.252,192.168.122.253
DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} - hxxp://www.o2c.de/download/o2cplayer.cab
FF - ProfilePath - c:\dokumente und einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programme\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{7836159E-1915-4FDF-BCEB-F541C4517016} - c:\windows\system32\rqRKEWNh.dll
HKLM-Run-PLFFAP - c:\windows\system32\HotfixQ0306270.exe
HKLM-Run-SunJavaUpdateSched - c:\programme\Java\jre6\bin\jusched.exe
AddRemove-AnyDVD - c:\programme\SlySoft\AnyDVD\AnyDVD-uninst.exe
AddRemove-Easy-PhotoPrint - c:\windows\ISUN0407.EXE
AddRemove-Easy-PhotoPrint Plus - c:\windows\ISUN0407.EXE
AddRemove-Easy-WebPrint - c:\windows\IsUn0407.exe
AddRemove-Formular-Manager - c:\windows\IsUn0407.exe
AddRemove-FRITZ!DSL - c:\windows\IsUn0407.exe
AddRemove-HaufeReader - c:\windows\IsUn0407.exe
AddRemove-Runtime - c:\windows\IsUn0407.exe
AddRemove-xp-AntiSpy - c:\programme\xp-AntiSpy\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-16 21:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-515967899-1229272821-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|ù•Ñw*]
"7040210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"7040210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2012-01-16  21:19:54
ComboFix-quarantined-files.txt  2012-01-16 20:19
ComboFix2.txt  2009-01-26 20:40
.
Vor Suchlauf: 17 Verzeichnis(se), 20.627.304.448 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 20.710.989.824 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 97C148514A49E68B76965E2D80F69871


cosinus 16.01.2012 21:36

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

File::
c:\windows\system32\drivers\uxy9b.sys
c:\windows\system32\drivers\xcpip.sys
c:\windows\system32\drivers\xpsec.sys

Driver::
uxy9b.sys
xcpip
xpsec

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

tax 16.01.2012 21:44

Beim ausführen kommt die Meldung
_______________
CFScript Namensfehler

Hast Du versucht, CFScript auszuführen?
Der Name, CFScript scheint nicht korrekt buchstabiert zu sein.

OK
___________________________

cosinus 16.01.2012 21:50

Zitat:

ausgeführt von:: C:\ComboFix.exe
Kann es vllt hier dran liegen! Wo soll die combofix.exe liegen und warum liegt sie bei dir nicht dort?

Zitat:

Der Name, CFScript scheint nicht korrekt buchstabiert zu sein.
Das Script heißt CFScript.txt

tax 16.01.2012 21:52

Hätte wohl vorher fragen sollen.
Da du geschrieben hast das Script auf dem Desktop speichern, und es müssen alle Programme geschlossen sein, habe ich die ComboFix.exe von C: auf den Desktop verschoben.
Hatte vorher auf C: gespeichert da der Desktop ja weg war.

cosinus 16.01.2012 21:59

Starte neu und probier es einfach nochmal. ggf auch mal combofix.exe neu runterladen auf den DESKTOP

tax 16.01.2012 22:13

War wieder zu schnell, habe das Script auf C: kopiert und nicht die exe auf den Desktop. Hat aber trotzdem geklappt.

System neu gestartet...

Beim starten kommt die Meldung

_________________

AsusProb.exe - Komponente nicht gefunden

Die Anwendung konnte nicht gestartet werden, weil VCL35.bpl nicht gefunden wurde. Neuinstallation der Anwendung könnte das Problem beheben.

OK
_________________


Code:

ComboFix 12-01-16.02 - Weisi 16.01.2012  21:55:11.3.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2815.2355 [GMT 1:00]
ausgeführt von:: C:\ComboFix.exe
Benutzte Befehlsschalter :: c:\dokumente und einstellungen\Weisi\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\windows\system32\drivers\uxy9b.sys"
"c:\windows\system32\drivers\xcpip.sys"
"c:\windows\system32\drivers\xpsec.sys"
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Thumbs.db
.
.
(((((((((((((((((((((((((((((((((((((((  Treiber/Dienste  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_UXY9B.SYS
-------\Service_uxy9b.sys
-------\Service_xcpip
-------\Service_xpsec
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-16 bis 2012-01-16  ))))))))))))))))))))))))))))))
.
.
2012-01-14 16:46 . 2012-01-14 16:46        684297        ----a-w-        C:\unhide.exe
2012-01-14 16:42 . 2012-01-14 16:42        1972528        ----a-w-        C:\tdsskiller.exe
2012-01-14 15:24 . 2012-01-14 15:24        --------        d-----w-        C:\_OTL
2012-01-13 20:28 . 2012-01-13 20:28        584192        ----a-w-        C:\OTL.exe
2012-01-12 21:01 . 2012-01-12 21:01        --------        d-----w-        c:\programme\ESET
2012-01-10 22:41 . 2008-04-14 03:22        1036800        ----a-w-        c:\windows\explorer.exe
2012-01-10 00:20 . 2012-01-10 06:43        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
2012-01-03 18:47 . 2012-01-03 18:47        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonIJMyPrinter
2012-01-03 18:47 . 2012-01-03 18:49        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonIJPLM
2012-01-03 18:30 . 2012-01-03 18:30        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\CanonBJ
2012-01-03 18:30 . 2009-03-24 04:00        70656        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\CNMPPA1.DLL
2012-01-03 18:30 . 2009-03-24 04:00        27648        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\CNMPDA1.DLL
2012-01-03 18:30 . 2009-03-24 04:00        272384        ----a-w-        c:\windows\system32\CNMLMA1.DLL
2012-01-03 18:30 . 2012-01-03 18:30        --------        d-----w-        c:\windows\system32\CanonIJ Uninstaller Information
2012-01-03 18:30 . 2009-03-18 09:09        178176        ----a-w-        c:\windows\system32\CNMIUA1.DLL
2012-01-03 18:29 . 2012-01-03 18:29        --------        d-----w-        c:\programme\CanonBJ
2012-01-03 18:25 . 2008-04-13 23:17        25856        -c--a-w-        c:\windows\system32\dllcache\usbprint.sys
2012-01-03 18:25 . 2008-04-13 23:17        25856        ----a-w-        c:\windows\system32\drivers\usbprint.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-08 16:12 . 2007-11-11 13:34        138520        ----a-w-        c:\windows\system32\drivers\PnkBstrK.sys
2012-01-08 16:12 . 2009-07-16 17:43        234536        ----a-w-        c:\windows\system32\PnkBstrB.xtr
2012-01-08 16:12 . 2007-11-11 13:34        234536        ----a-w-        c:\windows\system32\PnkBstrB.exe
2012-01-06 14:45 . 2001-08-23 11:00        12400        ----a-w-        c:\windows\system32\drivers\secdrv.sys
2012-01-05 18:30 . 2005-06-22 21:45        60416        ----a-w-        c:\windows\ALCFDRTM.VER
2011-12-10 14:24 . 2009-02-07 14:01        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-11-23 14:40 . 2001-08-23 11:00        1859712        ----a-w-        c:\windows\system32\win32k.sys
2011-11-22 21:36 . 2011-08-14 20:24        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-20 12:40 . 2005-10-21 12:31        43520        ----a-w-        c:\windows\system32\CmdLineExt03.dll
2011-11-04 19:13 . 2001-08-23 11:00        916992        ----a-w-        c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2001-08-23 11:00        43520        ----a-w-        c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2001-08-23 11:00        1469440        ------w-        c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2005-06-22 16:15        385024        ----a-w-        c:\windows\system32\html.iec
2011-11-01 16:07 . 2001-08-23 11:00        1288704        ----a-w-        c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2001-08-23 11:00        33280        ----a-w-        c:\windows\system32\csrsrv.dll
2011-10-26 10:49 . 2001-08-23 11:00        2195072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2011-10-26 10:49 . 2001-08-18 04:28        2071680        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2010-10-12 15:33 . 2010-10-12 15:33        124344        ----a-w-        c:\programme\mozilla firefox\plugins\CCMSDK.dll
2010-10-12 17:15 . 2010-10-12 17:15        13240        ----a-w-        c:\programme\mozilla firefox\plugins\cgpcfg.dll
2010-10-12 15:37 . 2010-10-12 15:37        70592        ----a-w-        c:\programme\mozilla firefox\plugins\CgpCore.dll
2010-10-12 15:35 . 2010-10-12 15:35        91576        ----a-w-        c:\programme\mozilla firefox\plugins\confmgr.dll
2010-10-12 15:34 . 2010-10-12 15:34        22464        ----a-w-        c:\programme\mozilla firefox\plugins\ctxlogging.dll
2010-10-12 15:32 . 2010-10-12 15:32        255416        ----a-w-        c:\programme\mozilla firefox\plugins\ctxmui.dll
2010-10-12 15:35 . 2010-10-12 15:35        31672        ----a-w-        c:\programme\mozilla firefox\plugins\icafile.dll
2010-10-12 15:34 . 2010-10-12 15:34        40384        ----a-w-        c:\programme\mozilla firefox\plugins\icalogon.dll
2010-07-14 11:42 . 2010-07-14 11:42        898480        ----a-w-        c:\programme\mozilla firefox\plugins\sslsdk_b.dll
2010-10-12 15:37 . 2010-10-12 15:37        24000        ----a-w-        c:\programme\mozilla firefox\plugins\TcpPServ.dll
.
.
(((((((((((((((((((((((((((((  SnapShot@2012-01-16_20.18.11  )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-16 21:04 . 2012-01-16 21:04        16384              c:\windows\temp\Perflib_Perfdata_57c.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\programme\Ahead\Nero BackItUp\NBJ.exe" [2003-11-04 1720320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ElbyCheckAnyDVD"="c:\programme\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"ASUS Probe"="c:\programme\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"CORSAIR_PLUtil"="c:\programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe" [2004-11-11 90112]
"OpwareSE2"="c:\programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"LexwareInfoService"="c:\programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe" [2010-09-15 339312]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2009-11-10 417792]
"ConnectionCenter"="c:\programme\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"CanonMyPrinter"="c:\programme\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
Microsoft Office.lnk - c:\programme\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-1-5 155648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2010-12-30 14:37        281768        ----a-w-        c:\programme\Avira\AntiVir Desktop\avgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWatch]
2003-06-10 13:52        507904        ----a-w-        c:\programme\FRITZ!DSL\AWatch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 17:07        141608        ----a-w-        c:\programme\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2008-12-03 11:47        1205760        ----a-w-        c:\programme\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfxsrvtray]
2010-01-13 11:24        686344        ----a-w-        c:\programme\Tobit Radio.fx\Client\rfx-tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
2004-04-23 12:28        77824        ----a-w-        c:\programme\Logitech\Profiler\LWEMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Spiele\\Battlefield 2\\BF2.exe"=
"c:\\Programme\\GameSpy Arcade\\Aphex.exe"=
"e:\\Spiele\\Battlefield 1942\\BF1942.exe"=
"e:\\Spiele\\Return to Castle Wolfenstein\\WolfMP.exe"=
"e:\\Spiele\\Wolfenstein - Enemy Territory\\ET.exe"=
"e:\\Spiele\\Sudden Strike II\\game\\code\\Release\\game_exe.exe"=
"c:\\Programme\\THQ\\Company of Heroes\\BugReport\\BugReport.exe"=
"e:\\Spiele\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Programme\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Programme\\UltraVNC\\vncviewer.exe"=
"c:\\Programme\\Real\\RealPlayer\\realplay.exe"=
"c:\\Programme\\fotobuch.de AG\\Designer 2.0\\Designer.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\ICQ6.5\\ICQ.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programme\\Tobit Radio.fx\\Server\\rfx-server.exe"=
"c:\\Programme\\Tobit Radio.fx\\Client\\rfx-client.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"e:\\Spiele\\Steam\\Steam.exe"=
"c:\\Programme\\THQ\\Relic Entertainment\\Company of Heroes Online\\Game\\RelicCoHOWW.exe"=
"c:\\Dokumente und Einstellungen\\Weisi\\Lokale Einstellungen\\Apps\\2.0\\BM2ZNJ6X.QHP\\PHOMJ3MO.R9H\\coho..tion_4fdd38d166a17713_0001.0001_2ea3ae6aea32b9ef\\CoHOLauncher.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Spiele\\Battlefield Vietnam\\bfvietnam.exe"=
"e:\\Spiele\\Landwirtschafts Simulator 2011\\FarmingSimulator2011.exe"=
"e:\\Spiele\\Landwirtschafts Simulator 2011\\game.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"e:\\Spiele\\Battlefield 2\\forgottenhope2.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"17496:TCP"= 17496:TCP:BitComet 17496 TCP
"17496:UDP"= 17496:UDP:BitComet 17496 UDP
.
R0 PLFF;USB Flash Disk Driver;c:\windows\system32\drivers\plff.sys [30.08.2005 18:41 7424]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [14.07.2010 12:51 65584]
R2 aadev;AVM ADSL Adapter Device;c:\windows\system32\drivers\Aadev.sys [22.06.2005 18:34 27648]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [27.11.2009 22:05 136360]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [26.03.2007 20:03 6016]
R3 AVMDSLPPPOE;AVM DSL PPPoE CAPI Treiber;c:\windows\system32\drivers\avmdsloe.sys [27.06.2003 01:00 39552]
R3 AVMNDSL;AVM DSL NDIS WAN CAPI Treiber;c:\windows\system32\drivers\avmndsl.sys [27.06.2003 01:00 38992]
R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifay.sys [23.10.2007 16:32 12928]
R3 FDSSBASE;AVM FRITZ!Card DSL SL (WinXP/2000);c:\windows\system32\drivers\fdssbase.sys [27.06.2003 01:00 665600]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.03.2010 13:16 130384]
S3 Gonzales;Gonzales;c:\windows\system32\drivers\Gonzales.sys [23.10.2007 16:32 7040]
S3 NETFWDSL;AVM FRITZ!web DSL PPP;c:\windows\system32\drivers\NETFWDSL.SYS [22.06.2005 18:34 336384]
S3 Radio.fx;Radio.fx Server;c:\programme\Tobit Radio.fx\Server\rfx-server.exe [13.12.2009 09:34 2452232]
S3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\drivers\SCR3XX2K.sys [25.10.2009 09:14 57600]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [25.10.2009 09:14 57600]
S3 SE4501D;Gigaset USB Adapter 54 Driver;c:\windows\system32\drivers\SE4501D.sys [26.03.2006 17:10 346656]
S3 STC2DFU;STCII DFU Adapter;c:\windows\system32\DRIVERS\Stc2Dfu.SYS --> c:\windows\system32\DRIVERS\Stc2Dfu.SYS [?]
S3 STCFUx32;STC DFU Driver;c:\windows\system32\drivers\STCFUx32.sys [13.11.2008 14:10 7680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.03.2010 13:16 753504]
S3 zlportio;zlportio;\??\c:\programme\UltraStar Deluxe\zlportio.sys --> c:\programme\UltraStar Deluxe\zlportio.sys [?]
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2012-01-16 c:\windows\Tasks\User_Feed_Synchronization-{5B2A5CDB-E6AE-431D-9038-90B3EEABA11D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uSearchMigratedDefaultURL = hxxp://search.msn.de/spresults.aspx?q={searchTerms}
uInternet Settings,ProxyOverride = *.local
IE: &Alles mit BitComet herunterladen - c:\programme\BitComet\BitComet.exe/AddAllLink.htm
IE: Alle &Videos mit BitComet herunterladen - c:\programme\BitComet\BitComet.exe/AddVideo.htm
IE: Alles mit FlashGet laden - c:\programme\FlashGet\jc_all.htm
IE: Easy-WebPrint Drucken - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Schnelldruck - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Vorschau - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Zu Druckliste hinzufügen - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Mit BitComet herunter&laden - c:\programme\BitComet\BitComet.exe/AddLink.htm
IE: Mit FlashGet laden - c:\programme\FlashGet\jc_link.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: ltow.de\ag
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{20D67A27-0516-4A6D-B1B4-A2FA3F12F385}: NameServer = 192.168.122.252,192.168.122.253
DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} - hxxp://www.o2c.de/download/o2cplayer.cab
FF - ProfilePath - c:\dokumente und einstellungen\Weisi\Anwendungsdaten\Mozilla\Firefox\Profiles\3hez5sd9.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programme\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-16 22:05
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-515967899-1229272821-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|ù•Ñw*]
"7040210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"7040210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2736)
c:\programme\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programme\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programme\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programme\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ger.nlr
c:\programme\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\DVDRAMSV.exe
c:\programme\Canon\IJPLM\IJPLMSVC.EXE
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\programme\Canon\CAL\CALMAIN.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\rundll32.exe
c:\programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\programme\Citrix\ICA Client\wfcrun32.exe
c:\programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-01-16  22:10:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-01-16 21:10
ComboFix2.txt  2012-01-16 20:19
ComboFix3.txt  2009-01-26 20:40
.
Vor Suchlauf: 18 Verzeichnis(se), 20.714.639.360 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 20.660.105.216 Bytes frei
.
- - End Of File - - 123EA74B81B58D16992398F84D31FF57


cosinus 16.01.2012 22:19

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


tax 17.01.2012 16:39

GMER

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-01-17 06:35:56
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-9 SAMSUNG_SP2004C rev.VM100-33
Running: o6u1gzl5.exe; Driver: C:\DOKUME~1\Weisi\LOKALE~1\Temp\fgtdypog.sys


---- System - GMER 1.0.15 ----

SSDT            BA74208E                                                                                        ZwCreateKey
SSDT            BA742084                                                                                        ZwCreateThread
SSDT            BA742093                                                                                        ZwDeleteKey
SSDT            BA74209D                                                                                        ZwDeleteValueKey
SSDT            BA7420A2                                                                                        ZwLoadKey
SSDT            BA742070                                                                                        ZwOpenProcess
SSDT            BA742075                                                                                        ZwOpenThread
SSDT            BA7420AC                                                                                        ZwReplaceKey
SSDT            BA7420A7                                                                                        ZwRestoreKey
SSDT            BA742098                                                                                        ZwSetValueKey

---- Kernel code sections - GMER 1.0.15 ----

?              Combo-Fix.sys                                                                                    Das System kann die angegebene Datei nicht finden. !
.text          C:\WINDOWS\system32\DRIVERS\ati2mtag.sys                                                        section is writeable [0xB95D0000, 0x1C5D38, 0xE8000020]
?              C:\ComboFix\catchme.sys                                                                          Das System kann den angegebenen Pfad nicht finden. !
?              C:\WINDOWS\system32\Drivers\PROCEXP113.SYS                                                      Das System kann die angegebene Datei nicht finden. !

---- Devices - GMER 1.0.15 ----

Device          \Driver\prodrv06 \Device\ProDrv06                                                                E1BBDC30
Device          \Driver\atapi \Device\Ide\IdePort0                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort1                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort2                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort3                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort4                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort5                                                              prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-16                                                    prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-9                                                      prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\prohlp02 \Device\ProHlp02                                                                E17293F0

AttachedDevice  \FileSystem\Fastfat \Fat                                                                        fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011f605286e                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011f605286e@00126213232f        0xCD 0xCE 0x15 0xE5 ...
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011f605286e@0013fd7f3568        0x70 0x0F 0x3B 0x27 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0011f605286e (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0011f605286e@00126213232f            0xCD 0xCE 0x15 0xE5 ...
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0011f605286e@0013fd7f3568            0x70 0x0F 0x3B 0x27 ...

---- Disk sectors - GMER 1.0.15 ----

Disk            \Device\Harddisk0\DR0                                                                            malicious Win32:MBRoot code @ sector 390716868

---- EOF - GMER 1.0.15 ----


OSAM

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 06:46:31 on 17.01.2012

OS: Windows XP Professional Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 8.00.6001.18702

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"ImageDrive.cpl" - "Ahead Software AG" - C:\WINDOWS\system32\ImageDrive.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Personal - Free Antivirus " - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl
"Avira AntiVir PersonalEdition Classic" - ? - C:\PROGRA~1\ANTIVI~1\avconfig.cpl  (File not found)
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~1\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"%SAINTHID_NAME%" (SaiNtHid) - "Saitek" - C:\WINDOWS\System32\DRIVERS\SaiNtHid.sys
"%USB\vid_054c&pid_0155.DeviceDesc%" (ovt519) - "OmniVision Technologies, Inc." - C:\WINDOWS\System32\Drivers\ov519vid.sys
"AnyDVD" (AnyDVD) - "SlySoft, Inc." - C:\WINDOWS\System32\Drivers\AnyDVD.sys
"ASInsHelp" (ASInsHelp) - ? - C:\WINDOWS\system32\drivers\AsInsHelp32.sys  (File found, but it contains no detailed information)
"AsIO" (AsIO) - ? - C:\WINDOWS\system32\drivers\AsIO.sys  (File found, but it contains no detailed information)
"aslm75" (aslm75) - ? - C:\WINDOWS\system32\drivers\aslm75.sys  (File found, but it contains no detailed information)
"ati2mtag" (ati2mtag) - "ATI Technologies Inc." - C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
"ATK0110 ACPI UTILITY" (MTsensor) - ? - C:\WINDOWS\System32\DRIVERS\ASACPI.sys
"avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"AVM ADSL Adapter Device" (aadev) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\aadev.sys
"AVM FRITZ!web DSL PPP" (NETFWDSL) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\NETFWDSL.SYS
"bdfdll" (bdfdll) - ? - C:\Programme\Softwin\BitDefender9\bdfdll.sys  (File not found)
"Bluetooth Audio Service" (BlueletAudio) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\blueletaudio.sys
"Bluetooth HID Enumerator" (BTHidEnum) - ? - C:\WINDOWS\System32\DRIVERS\vbtenum.sys  (File found, but it contains no detailed information)
"Bluetooth HID Manager Service" (BTHidMgr) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\BTHidMgr.sys
"Bluetooth PAN Network Adapter" (BT) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\btnetdrv.sys
"Bluetooth USB For Bluetooth Service" (Btcsrusb) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\btcusb.sys
"Bluetooth VComm Manager Service" (VcommMgr) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\VcommMgr.sys
"Bonifay" (Bonifay) - "Freecom" - C:\WINDOWS\System32\DRIVERS\Bonifay.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
"dbustrcm" (dbustrcm) - ? - C:\DOKUME~1\Weisi\LOKALE~1\Temp\dbustrcm.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
"Gigaset USB Adapter 54 Driver" (SE4501D) - "Siemens AG" - C:\WINDOWS\System32\DRIVERS\SE4501D.sys
"Gonzales" (Gonzales) - "Freecom" - C:\WINDOWS\System32\DRIVERS\Gonzales.sys
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"meiudf" (meiudf) - "Matsushita Electric Industrial Co.,Ltd." - C:\WINDOWS\System32\Drivers\meiudf.sys
"nvatabus" (nvatabus) - "NVIDIA Corporation" - C:\WINDOWS\System32\DRIVERS\nvatabus.sys
"Padus ASPI Shell" (pfc) - "Padus, Inc." - C:\WINDOWS\System32\drivers\pfc.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"Secdrv" (Secdrv) - "Macrovision Europe Ltd" - C:\WINDOWS\System32\DRIVERS\secdrv.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"StarForce Protection Environment Driver (version 1.x)" (sfdrv01) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfdrv01.sys
"StarForce Protection Environment Driver v6" (prodrv06) - "Protection Technology" - C:\WINDOWS\System32\drivers\prodrv06.sys
"StarForce Protection Helper Driver" (sfhlp01) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfhlp01.sys
"StarForce Protection Helper Driver (version 2.x)" (sfhlp02) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfhlp02.sys
"StarForce Protection Helper Driver v2" (prohlp02) - "Protection Technology" - C:\WINDOWS\System32\drivers\prohlp02.sys
"StarForce Protection Synchronization Driver v1" (prosync1) - "Protection Technology" - C:\WINDOWS\System32\drivers\prosync1.sys
"STCII DFU Adapter" (STC2DFU) - ? - C:\WINDOWS\System32\DRIVERS\Stc2Dfu.SYS  (File not found)
"USB Flash Disk Driver" (PLFF) - "Prolific Technology Inc." - C:\WINDOWS\System32\Drivers\PLFF.sys
"Virtual Serial port driver" (VComm) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\VComm.sys
"vnccom" (vnccom) - "RDV Soft" - C:\WINDOWS\System32\Drivers\vnccom.SYS
"vncdrv" (vncdrv) - "RDV Soft" - C:\WINDOWS\System32\DRIVERS\vncdrv.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
"zlportio" (zlportio) - ? - C:\Programme\UltraStar Deluxe\zlportio.sys  (File not found)

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll  (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{D653647D-D607-4DF6-A5B8-48D2BA195F7B} "BitDefender Antivirus v8" - ? -  (File not found | COM-object registry key not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? -  (File not found | COM-object registry key not found)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll  (File found, but it contains no detailed information)
{E4D8441D-F89C-4b5c-90AC-A857E1768F1F} "Haali Matroska Thumbnail Exctractor" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Programme\iTunes\iTunesMiniPlayer.dll
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -  (File not found | COM-object registry key not found)
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Programme\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Programme\Real\RealPlayer\rpshell.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -  (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\WinRAR\rarext.dll  (File found, but it contains no detailed information)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{03C1C47F-0538-4645-8372-D3109B9FC636} "Easy-WebPrint" - ? - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{784797A8-342D-4072-9486-03C8D0F2F0A1} "Battlefield Heroes Updater" - "EA Digital Illusions CE AB" - C:\WINDOWS\Downloaded Program Files\BFHUpdater.dll / https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} "DLM Control" - "Akamai Technologies, Inc." - C:\WINDOWS\DOWNLO~1\DOWNLO~1.OCX / hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{B1953AD6-C50E-11D3-B020-00A0C9251384} "O2C-Player (ELECO Software GmbH)" - "Eleco plc" - C:\WINDOWS\system32\O2CPLA~1.OCX / hxxp://www.o2c.de/download/o2cplayer.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} "QuickTime Object" - "Apple Inc." - C:\Programme\QuickTime\QTPlugin.ocx / hxxp://www.apple.com/qtactivex/qtplugin.cab
{166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\WINDOWS\system32\macromed\Director\SwDir.dll / hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} "{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}" - ? -  (File not found | COM-object registry key not found) / hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} "{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}" - ? -  (File not found | COM-object registry key not found) / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"BitComet" - ? - res://C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll/206  (File not found)
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC} "ClsidExtension" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll
"FlashGet" - ? - C:\PROGRA~1\FlashGet\flashget.exe  (File not found)
"ICQ6" - "ICQ, LLC." - C:\Programme\ICQ6.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
{77BF5300-1474-4EC7-9980-D32B190E9B07} "Skype" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} "Easy-WebPrint" - ? - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
{E0E899AB-F487-11D5-8D29-0050BA6940E3} "FlashGet Bar" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} "BitComet Helper" - "BitComet" - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} "Skype add-on (mastermind)" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\ssv.dll

[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office\OSA9.EXE  (Shortcut exists | File exists)
"RAMASST.lnk" - "Matsushita Electric Industrial Co., Ltd." - C:\WINDOWS\system32\RAMASST.exe  (Shortcut exists | File exists)
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\Weisi\Startmenü\Programme\Autostart\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"NBJ" - "Ahead Software AG" - "C:\Programme\Ahead\Nero BackItUp\NBJ.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"ASUS Probe" - ? - C:\Programme\ASUS\Probe\AsusProb.exe  (File found, but it contains no detailed information)
"CanonMyPrinter" - "CANON INC." - C:\Programme\Canon\MyPrinter\BJMyPrt.exe /logon
"ConnectionCenter" - "Citrix Systems, Inc." - "C:\Programme\Citrix\ICA Client\concentr.exe" /startup
"CORSAIR_PLUtil" - "Prolific Technology Inc." - C:\Programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe
"ElbyCheckAnyDVD" - "Elaborate Bytes AG" - "C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
"LexwareInfoService" - "Haufe-Lexware GmbH & Co. KG" - C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe /autostart
"NeroFilterCheck" - "Ahead Software Gmbh" - C:\WINDOWS\system32\NeroCheck.exe
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"OpwareSE2" - "ScanSoft, Inc." - "C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\qttask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Ati HotKey Poller" (Ati HotKey Poller) - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.exe
"ATI Smart" (ATI Smart) - ? - C:\WINDOWS\system32\ati2sgag.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe
"AVM FRITZ!web Routing Service" (de_serv) - "AVM Berlin" - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe
"Canon Camera Access Library 8" (CCALib8) - "Canon Inc." - C:\Programme\Canon\CAL\CALMAIN.exe
"Canon Inkjet Printer/Scanner/Fax Extended Survey Program" (IJPLMSVC) - ? - C:\Programme\Canon\IJPLM\IJPLMSVC.EXE
"DVD-RAM_Service" (DVD-RAM_Service) - "Matsushita Electric Industrial Co., Ltd." - C:\WINDOWS\system32\DVDRAMSV.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
"PLFlash DeviceIoControl Service" (PLFlash DeviceIoControl Service) - "Prolific Technology Inc." - C:\WINDOWS\system32\IoctlSvc.exe
"PnkBstrA" (PnkBstrA) - ? - C:\WINDOWS\system32\PnkBstrA.exe  (File found, but it contains no detailed information)
"Radio.fx Server" (Radio.fx) - ? - C:\Programme\Tobit Radio.fx\Server\rfx-server.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"Windows Presentation Foundation Font Cache 4.0.0.0" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"AtiExtEvent" - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.dll

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Programme\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


aswMBR

Code:

aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-17 06:47:29
-----------------------------
06:47:29.062    OS Version: Windows 5.1.2600 Service Pack 3
06:47:29.062    Number of processors: 1 586 0x2F00
06:47:29.062    ComputerName: SHOOT  UserName: Weisi
06:47:29.484    Initialize success
06:52:22.171    AVAST engine defs: 12011601
07:01:15.875    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-9
07:01:15.875    Disk 0 Vendor: SAMSUNG_SP2004C VM100-33 Size: 190782MB BusType: 3
07:01:15.875    Disk 0 MBR read successfully
07:01:15.890    Disk 0 MBR scan
07:01:15.906    Disk 0 Windows XP default MBR code
07:01:15.921    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      102398 MB offset 63
07:01:15.921    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        49999 MB offset 209712510
07:01:15.953    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        38381 MB offset 312110820
07:01:15.953    Disk 0 scanning sectors +390716865
07:01:15.968    Disk 0 malicious Win32:MBRoot code @ sector 390716868 !
07:01:16.000    Disk 0 scanning C:\WINDOWS\system32\drivers
07:01:26.453    Service scanning
07:01:27.343    Modules scanning
07:01:31.921    Disk 0 trace - called modules:
07:01:31.921    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys atapi.sys pciide.sys PCIIDEX.SYS
07:01:31.921    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ab4cab8]
07:01:31.921    3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000081[0x8ac0af18]
07:01:31.921    5 ACPI.sys[b9f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-9[0x8aae0d98]
07:01:31.921    \Driver\atapi[0x8aadc788] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> prosync1.sys[0xba5b06c1]
07:01:32.312    AVAST engine scan C:\WINDOWS
07:01:46.484    AVAST engine scan C:\WINDOWS\system32
07:04:01.750    AVAST engine scan C:\WINDOWS\system32\drivers
07:04:17.906    AVAST engine scan C:\Dokumente und Einstellungen\Weisi
07:18:41.500    AVAST engine scan C:\Dokumente und Einstellungen\All Users
07:26:48.937    Scan finished successfully
16:29:57.343    Disk 0 MBR has been saved successfully to "H:\MBR.dat"
16:29:57.468    The log file has been saved successfully to "H:\aswMBR.txt"


cosinus 17.01.2012 20:31

Zitat:

Disk 0 malicious Win32:MBRoot code @ sector 390716868 !
Das an sich ist nicht weiter schlimm, müssen wir aber weiter analysieren. Mach aber erstmal das hier mit OSAM weg:

Zitat:

"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found)
"dbustrcm" (dbustrcm) - ? - C:\DOKUME~1\Weisi\LOKALE~1\Temp\dbustrcm.sys (File not found)
mit OSAM deaktivieren und löschen ("delete from storage" - siehe Anleitung zu OSAM)
danach wieder ein neues Log mit osam machen und hier posten

tax 17.01.2012 20:52

Hat alles geklappt.

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:51:47 on 17.01.2012

OS: Windows XP Professional Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 8.00.6001.18702

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"ImageDrive.cpl" - "Ahead Software AG" - C:\WINDOWS\system32\ImageDrive.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Personal - Free Antivirus " - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl
"Avira AntiVir PersonalEdition Classic" - ? - C:\PROGRA~1\ANTIVI~1\avconfig.cpl  (File not found)
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~1\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"%SAINTHID_NAME%" (SaiNtHid) - "Saitek" - C:\WINDOWS\System32\DRIVERS\SaiNtHid.sys
"%USB\vid_054c&pid_0155.DeviceDesc%" (ovt519) - "OmniVision Technologies, Inc." - C:\WINDOWS\System32\Drivers\ov519vid.sys
"AnyDVD" (AnyDVD) - "SlySoft, Inc." - C:\WINDOWS\System32\Drivers\AnyDVD.sys
"ASInsHelp" (ASInsHelp) - ? - C:\WINDOWS\system32\drivers\AsInsHelp32.sys  (File found, but it contains no detailed information)
"AsIO" (AsIO) - ? - C:\WINDOWS\system32\drivers\AsIO.sys  (File found, but it contains no detailed information)
"aslm75" (aslm75) - ? - C:\WINDOWS\system32\drivers\aslm75.sys  (File found, but it contains no detailed information)
"ati2mtag" (ati2mtag) - "ATI Technologies Inc." - C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
"ATK0110 ACPI UTILITY" (MTsensor) - ? - C:\WINDOWS\System32\DRIVERS\ASACPI.sys
"avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"AVM ADSL Adapter Device" (aadev) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\aadev.sys
"AVM FRITZ!web DSL PPP" (NETFWDSL) - "AVM Berlin" - C:\WINDOWS\System32\DRIVERS\NETFWDSL.SYS
"bdfdll" (bdfdll) - ? - C:\Programme\Softwin\BitDefender9\bdfdll.sys  (File not found)
"Bluetooth Audio Service" (BlueletAudio) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\blueletaudio.sys
"Bluetooth HID Enumerator" (BTHidEnum) - ? - C:\WINDOWS\System32\DRIVERS\vbtenum.sys  (File found, but it contains no detailed information)
"Bluetooth HID Manager Service" (BTHidMgr) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\BTHidMgr.sys
"Bluetooth PAN Network Adapter" (BT) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\btnetdrv.sys
"Bluetooth USB For Bluetooth Service" (Btcsrusb) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\btcusb.sys
"Bluetooth VComm Manager Service" (VcommMgr) - "IVT Corporation" - C:\WINDOWS\System32\Drivers\VcommMgr.sys
"Bonifay" (Bonifay) - "Freecom" - C:\WINDOWS\System32\DRIVERS\Bonifay.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\WINDOWS\System32\Drivers\ElbyCDIO.sys
"Gigaset USB Adapter 54 Driver" (SE4501D) - "Siemens AG" - C:\WINDOWS\System32\DRIVERS\SE4501D.sys
"Gonzales" (Gonzales) - "Freecom" - C:\WINDOWS\System32\DRIVERS\Gonzales.sys
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
"meiudf" (meiudf) - "Matsushita Electric Industrial Co.,Ltd." - C:\WINDOWS\System32\Drivers\meiudf.sys
"nvatabus" (nvatabus) - "NVIDIA Corporation" - C:\WINDOWS\System32\DRIVERS\nvatabus.sys
"Padus ASPI Shell" (pfc) - "Padus, Inc." - C:\WINDOWS\System32\drivers\pfc.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
"Secdrv" (Secdrv) - "Macrovision Europe Ltd" - C:\WINDOWS\System32\DRIVERS\secdrv.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"StarForce Protection Environment Driver (version 1.x)" (sfdrv01) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfdrv01.sys
"StarForce Protection Environment Driver v6" (prodrv06) - "Protection Technology" - C:\WINDOWS\System32\drivers\prodrv06.sys
"StarForce Protection Helper Driver" (sfhlp01) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfhlp01.sys
"StarForce Protection Helper Driver (version 2.x)" (sfhlp02) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfhlp02.sys
"StarForce Protection Helper Driver v2" (prohlp02) - "Protection Technology" - C:\WINDOWS\System32\drivers\prohlp02.sys
"StarForce Protection Synchronization Driver v1" (prosync1) - "Protection Technology" - C:\WINDOWS\System32\drivers\prosync1.sys
"STCII DFU Adapter" (STC2DFU) - ? - C:\WINDOWS\System32\DRIVERS\Stc2Dfu.SYS  (File not found)
"USB Flash Disk Driver" (PLFF) - "Prolific Technology Inc." - C:\WINDOWS\System32\Drivers\PLFF.sys
"Virtual Serial port driver" (VComm) - "IVT Corporation" - C:\WINDOWS\System32\DRIVERS\VComm.sys
"vnccom" (vnccom) - "RDV Soft" - C:\WINDOWS\System32\Drivers\vnccom.SYS
"vncdrv" (vncdrv) - "RDV Soft" - C:\WINDOWS\System32\DRIVERS\vncdrv.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
"zlportio" (zlportio) - ? - C:\Programme\UltraStar Deluxe\zlportio.sys  (File not found)

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll  (File found, but it contains no detailed information)
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{CFB6322E-CC85-4d1b-82C7-893888A236BC} "IcaMimeFilterPP Class" - "Citrix Systems, Inc." - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{D653647D-D607-4DF6-A5B8-48D2BA195F7B} "BitDefender Antivirus v8" - ? -  (File not found | COM-object registry key not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? -  (File not found | COM-object registry key not found)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{0561EC90-CE54-4f0c-9C55-E226110A740C} "Haali Column Provider" - ? - C:\Programme\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll  (File found, but it contains no detailed information)
{E4D8441D-F89C-4b5c-90AC-A857E1768F1F} "Haali Matroska Thumbnail Exctractor" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Programme\iTunes\iTunesMiniPlayer.dll
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -  (File not found | COM-object registry key not found)
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Programme\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Programme\Real\RealPlayer\rpshell.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -  (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\WinRAR\rarext.dll  (File found, but it contains no detailed information)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{03C1C47F-0538-4645-8372-D3109B9FC636} "Easy-WebPrint" - ? - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{784797A8-342D-4072-9486-03C8D0F2F0A1} "Battlefield Heroes Updater" - "EA Digital Illusions CE AB" - C:\WINDOWS\Downloaded Program Files\BFHUpdater.dll / https://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} "DLM Control" - "Akamai Technologies, Inc." - C:\WINDOWS\DOWNLO~1\DOWNLO~1.OCX / hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{B1953AD6-C50E-11D3-B020-00A0C9251384} "O2C-Player (ELECO Software GmbH)" - "Eleco plc" - C:\WINDOWS\system32\O2CPLA~1.OCX / hxxp://www.o2c.de/download/o2cplayer.cab
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} "QuickTime Object" - "Apple Inc." - C:\Programme\QuickTime\QTPlugin.ocx / hxxp://www.apple.com/qtactivex/qtplugin.cab
{166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control" - "Adobe Systems, Inc." - C:\WINDOWS\system32\macromed\Director\SwDir.dll / hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} "{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}" - ? -  (File not found | COM-object registry key not found) / hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} "{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}" - ? -  (File not found | COM-object registry key not found) / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"BitComet" - ? - res://C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll/206  (File not found)
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC} "ClsidExtension" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_26.dll
"FlashGet" - ? - C:\PROGRA~1\FlashGet\flashget.exe  (File not found)
"ICQ6" - "ICQ, LLC." - C:\Programme\ICQ6.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
{77BF5300-1474-4EC7-9980-D32B190E9B07} "Skype" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} "Easy-WebPrint" - ? - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
{E0E899AB-F487-11D5-8D29-0050BA6940E3} "FlashGet Bar" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} "BitComet Helper" - "BitComet" - C:\Programme\BitComet\tools\BitCometBHO_1.2.8.7.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} "Skype add-on (mastermind)" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\ssv.dll

[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office\OSA9.EXE  (Shortcut exists | File exists)
"RAMASST.lnk" - "Matsushita Electric Industrial Co., Ltd." - C:\WINDOWS\system32\RAMASST.exe  (Shortcut exists | File exists)
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\Weisi\Startmenü\Programme\Autostart\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"NBJ" - "Ahead Software AG" - "C:\Programme\Ahead\Nero BackItUp\NBJ.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"ASUS Probe" - ? - C:\Programme\ASUS\Probe\AsusProb.exe  (File found, but it contains no detailed information)
"CanonMyPrinter" - "CANON INC." - C:\Programme\Canon\MyPrinter\BJMyPrt.exe /logon
"ConnectionCenter" - "Citrix Systems, Inc." - "C:\Programme\Citrix\ICA Client\concentr.exe" /startup
"CORSAIR_PLUtil" - "Prolific Technology Inc." - C:\Programme\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe
"ElbyCheckAnyDVD" - "Elaborate Bytes AG" - "C:\Programme\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
"LexwareInfoService" - "Haufe-Lexware GmbH & Co. KG" - C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe /autostart
"NeroFilterCheck" - "Ahead Software Gmbh" - C:\WINDOWS\system32\NeroCheck.exe
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"OpwareSE2" - "ScanSoft, Inc." - "C:\Programme\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\qttask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Ati HotKey Poller" (Ati HotKey Poller) - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.exe
"ATI Smart" (ATI Smart) - ? - C:\WINDOWS\system32\ati2sgag.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe
"AVM FRITZ!web Routing Service" (de_serv) - "AVM Berlin" - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe
"Canon Camera Access Library 8" (CCALib8) - "Canon Inc." - C:\Programme\Canon\CAL\CALMAIN.exe
"Canon Inkjet Printer/Scanner/Fax Extended Survey Program" (IJPLMSVC) - ? - C:\Programme\Canon\IJPLM\IJPLMSVC.EXE
"DVD-RAM_Service" (DVD-RAM_Service) - "Matsushita Electric Industrial Co., Ltd." - C:\WINDOWS\system32\DVDRAMSV.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
"PLFlash DeviceIoControl Service" (PLFlash DeviceIoControl Service) - "Prolific Technology Inc." - C:\WINDOWS\system32\IoctlSvc.exe
"PnkBstrA" (PnkBstrA) - ? - C:\WINDOWS\system32\PnkBstrA.exe  (File found, but it contains no detailed information)
"Radio.fx Server" (Radio.fx) - ? - C:\Programme\Tobit Radio.fx\Server\rfx-server.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"Windows Presentation Foundation Font Cache 4.0.0.0" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll  (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"AtiExtEvent" - "ATI Technologies Inc." - C:\WINDOWS\system32\Ati2evxx.dll

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Programme\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 17.01.2012 22:10

Live-System PartedMagic / GParted

1. Lade Dir das ISO-Image von PartedMagic herunter, müssten ca. 180 MB sein
2. Brenn es per Imagebrennfunktion auf CD, geht zB mit ImgBurn unter Windows
3. Boote von der gebrannten CD, im Bootmenü von Option 1 starten und warten bis der Linux-Desktop oben ist

http://partedmagic.com/lib/exe/fetch...ia=desktop.png

4. Du müsstest ein Symbol PartitionEditor auf dem Desktop finden, das doppelklicken
5. Wenn das Tool die Partitionen aufgelistet hat, bitte einen Screenshot mit Hilfe der Taste DRUCK auf der Tastatur erstellen, diesen Screenshot hier posten (idR hast du einen Internetzugang mit PartedMagic, wenn nicht einfach den Screenshot auf einem Stick abspeichern und unter Windows hier posten)

tax 18.01.2012 18:11

Liste der Anhänge anzeigen (Anzahl: 1)
Im Anhang der Screenshot

cosinus 18.01.2012 19:11

Ist ok. Falls dich das hier stört:

Zitat:

sector 390716868 !
Können wir das auch noch wegmachen ist aber nicht unbedingt erforderlich.

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


tax 18.01.2012 20:35

Hier schon mal das Log von Malwarebytes.
Er hat schon wieder was gefunden. Kann ich das löschen?

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.18.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Weisi :: SHOOT [Administrator]

18.01.2012 19:27:15
mbam-log-2012-01-18 (20-33-56).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 395905
Laufzeit: 1 Stunde(n), 1 Minute(n), 51 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 5
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243898.exe.vir (Trojan.Zbot.CBCGen) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243907.exe.vir (Trojan.Zbot.CBCGen) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243944.exe.vir (Trojan.Ransom.BP) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP896\A0244293.exe.vir (Trojan.Ransom.BP) -> Keine Aktion durchgeführt.
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP903\A0254966.sys (Trojan.Agent.RKH) -> Keine Aktion durchgeführt.

(Ende)


cosinus 18.01.2012 20:51

In System Volume Information sind die Dateien für Wiederherstellungspunkte gespeichert.

Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des Systems durch einen Wiederherstellungspunkt wahrscheinlich wieder eine Infektion nach sich ziehen würde.

tax 19.01.2012 06:49

1. Was konntest du auf dem Screenshot von PartitionEditor erkennen?
2. Systemwiederherstellung. D. h. mit dem deaktivieren werden die Dateien gelöscht und danach kann sie wieder aktivieren?
3. Hier das Log von SASW. Die Funde hab ich noch nicht gelöscht.

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/19/2012 at 00:57 AM

Application Version : 5.0.1142

Core Rules Database Version : 8141
Trace Rules Database Version: 5953

Scan type      : Complete Scan
Total Scan Time : 01:43:19

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned      : 610
Memory threats detected  : 0
Registry items scanned    : 39057
Registry threats detected : 6
File items scanned        : 151611
File threats detected    : 139

Adware.IEPlugin
        HKCR\Remove

Rogue.Component/Trace
        HKLM\Software\Microsoft\38A940D2
        HKLM\Software\Microsoft\38A940D2#38a940d2
        HKLM\Software\Microsoft\38A940D2#Version
        HKLM\Software\Microsoft\38A940D2#38a9ed52
        HKLM\Software\Microsoft\38A940D2#38a984b7

Adware.Tracking Cookie
        C:\Dokumente und Einstellungen\Weisi\Cookies\8JLMJEJ3.txt [ /adtech.de ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\S41VKXQS.txt [ /ad.adnet.de ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\O6D2MXEK.txt [ /webmasterplan.com ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\3E5SA0XQ.txt [ /ad2.adfarm1.adition.com ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\HDJPBL1K.txt [ /ad.ad-srv.net ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\DYL30F95.txt [ /track.effiliation.com ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\Y5YAV25K.txt [ /apmebf.com ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\MWZA2SW7.txt [ /doubleclick.net ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\EHS9XEBM.txt [ /adviva.net ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\E8231PAT.txt [ /zanox.com ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\28HLAOGL.txt [ /ad.dyntracker.de ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\0GH7A79A.txt [ /zanox-affiliate.de ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\YZX05MUW.txt [ /www.zanox-affiliate.de ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\8EA0XWAD.txt [ /fastclick.net ]
        C:\Dokumente und Einstellungen\Weisi\Cookies\8SLR17IJ.txt [ /lfstmedia.com ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@de.sitestat[1].txt [ Cookie:***@de.sitestat.com/is24/is24/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@apmebf[1].txt [ Cookie:***@apmebf.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@ads.familymedia[1].txt [ Cookie:***@ads.familymedia.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@holidaycheckag.122.2o7[1].txt [ Cookie:***@holidaycheckag.122.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\19YGSKAE.txt [ Cookie:***@smartadserver.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\TIAN2UEM.txt [ Cookie:***@fastclick.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@stat.onestat[2].txt [ Cookie:***@stat.onestat.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@adserver.mediadomain-verlag[2].txt [ Cookie:***@adserver.mediadomain-verlag.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\76A5PA92.txt [ Cookie:***@webmasterplan.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\JZM53LQR.txt [ Cookie:***@ad.zanox.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@specificclick[2].txt [ Cookie:***@specificclick.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\2XFUQVF2.txt [ Cookie:***@adviva.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@fr.sitestat[1].txt [ Cookie:***@fr.sitestat.com/europcar/europcar-de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@tracking.metalyzer[1].txt [ Cookie:***@tracking.metalyzer.com/lastminute_com/lm/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\OSGY4267.txt [ Cookie:***@doubleclick.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\MBUNGN5J.txt [ Cookie:***@tracking.quisma.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\BHBJY97R.txt [ Cookie:***@e-2dj6wjkywjcjchp.stats.esomniture.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@adserver.onemediagroup[1].txt [ Cookie:***@adserver.onemediagroup.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@adsrv.admediate[2].txt [ Cookie:***@adsrv.admediate.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@fashionworld.112.2o7[1].txt [ Cookie:***@fashionworld.112.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@ads.mikinimedia[2].txt [ Cookie:***@ads.mikinimedia.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@fr.sitestat[2].txt [ Cookie:***@fr.sitestat.com/europcar/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@cdn5.specificclick[1].txt [ Cookie:***@cdn5.specificclick.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\LVNE7JAM.txt [ Cookie:***@adtech.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@ad.adition[1].txt [ Cookie:***@ad.adition.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\ZFRYXQDA.txt [ Cookie:***@serving-sys.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@tracking.mindshare[1].txt [ Cookie:***@tracking.mindshare.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\B5F2Q22R.txt [ Cookie:***@ad.yieldmanager.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@www.etracker[1].txt [ Cookie:***@www.etracker.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@a.revenuemax[1].txt [ Cookie:***@a.revenuemax.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\IWJZBE3I.txt [ Cookie:***@mediaplex.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@www.burstnet[2].txt [ Cookie:***@www.burstnet.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@track.webtrekk[1].txt [ Cookie:***@track.webtrekk.de/141455347332844/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\2NDMKWJG.txt [ Cookie:***@www.googleadservices.com/pagead/conversion/1038913304/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@statse.webtrendslive[2].txt [ Cookie:***@statse.webtrendslive.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@shop.zanox[2].txt [ Cookie:***@shop.zanox.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@atdmt[2].txt [ Cookie:***@atdmt.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@frontlinegmbh.122.2o7[1].txt [ Cookie:***@frontlinegmbh.122.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@de.sitestat[4].txt [ Cookie:***@de.sitestat.com/otto-de/otto-de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@babybel[1].txt [ Cookie:***@babybel.de/tracker/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@go.dynamic-tracking[1].txt [ Cookie:***@go.dynamic-tracking.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\99S98ECG.txt [ Cookie:***@advertising.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@www.active-tracking[1].txt [ Cookie:***@www.active-tracking.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\CHM0LV74.txt [ Cookie:***@tradedoubler.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\KLODZZM7.txt [ Cookie:***@content.yieldmanager.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\N63EMRA7.txt [ Cookie:***@track.effiliation.com/servlet/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\KQWG0R4O.txt [ Cookie:***@bs.serving-sys.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\CFWMCNB9.txt [ Cookie:***@zanox-affiliate.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@nextag[2].txt [ Cookie:***@nextag.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@userstats[2].txt [ Cookie:***@userstats.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@server.iad.liveperson[1].txt [ Cookie:***@server.iad.liveperson.net/hc/64975841 ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@de.sitestat[2].txt [ Cookie:***@de.sitestat.com/karstadt-de/karstadt/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@stat.dealtime[1].txt [ Cookie:***@stat.dealtime.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@collective-media[2].txt [ Cookie:***@collective-media.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\NHKV1C2W.txt [ Cookie:***@ad2.adfarm1.adition.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@sevenoneintermedia.112.2o7[1].txt [ Cookie:***@sevenoneintermedia.112.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\OPE790QI.txt [ Cookie:***@www.googleadservices.com/pagead/conversion/1026195524/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\N27DYFBA.txt [ Cookie:***@www.zanox-affiliate.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@clickandbuy[2].txt [ Cookie:***@clickandbuy.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@komtrack[2].txt [ Cookie:***@komtrack.com/tr/400038 ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\AWOTJS82.txt [ Cookie:***@e-2dj6wjk4qmczeho.stats.esomniture.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\F4VRHMIU.txt [ Cookie:***@party-discount.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@track.adform[1].txt [ Cookie:***@track.adform.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@secmedia[2].txt [ Cookie:***@secmedia.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@opodo.122.2o7[1].txt [ Cookie:***@opodo.122.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\YPVPZSW4.txt [ Cookie:***@ad4.adfarm1.adition.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@komtrack[1].txt [ Cookie:***@komtrack.com/tr ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\1NIY0G9I.txt [ Cookie:***@ww251.smartadserver.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\JD8K9T90.txt [ Cookie:***@www.usenext.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@tribalfusion[2].txt [ Cookie:***@tribalfusion.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\WSSIWQ1S.txt [ Cookie:***@ad3.adfarm1.adition.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@xiti[1].txt [ Cookie:***@xiti.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\CX89JR3L.txt [ Cookie:***@ad.dyntracker.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@ad.adserver01[1].txt [ Cookie:***@ad.adserver01.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@banner.adlive[2].txt [ Cookie:***@banner.adlive.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@adservercentral[1].txt [ Cookie:***@adservercentral.info/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\Q4X2IJWY.txt [ Cookie:***@www.googleadservices.com/pagead/conversion/1072259810/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@jibjab.112.2o7[1].txt [ Cookie:***@jibjab.112.2o7.net/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@ad5.adfarm1.adition[2].txt [ Cookie:***@ad5.adfarm1.adition.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@statcounter[1].txt [ Cookie:***@statcounter.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@adbrite[2].txt [ Cookie:***@adbrite.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\I28PAE83.txt [ Cookie:***@e-2dj6aelygldjido.stats.esomniture.com/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\***@tracking.mlsat02[2].txt [ Cookie:***@tracking.mlsat02.de/tmobile/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\Cookies\ZNH9Q5BI.txt [ Cookie:***@ad.dyntracker.de/ ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS.ADSHOPPING[2].TXT [ /ADS.ADSHOPPING ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@BANNER.TESTBERICHTE[2].TXT [ /BANNER.TESTBERICHTE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@BABYDISCOUNT[2].TXT [ /BABYDISCOUNT ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.ZANOX[1].TXT [ /AD.ZANOX ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@TRACK.EFFILIATION[2].TXT [ /TRACK.EFFILIATION ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@MICROSOFTMACHINETRANSLATION.112.2O7[1].TXT [ /MICROSOFTMACHINETRANSLATION.112.2O7 ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@TRACKING.TCHIBO[1].TXT [ /TRACKING.TCHIBO ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.ADC-SERV[1].TXT [ /AD.ADC-SERV ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS.QUARTERMEDIA[1].TXT [ /ADS.QUARTERMEDIA ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD1.CHEFKOCH[1].TXT [ /AD1.CHEFKOCH ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS.PUBMATIC[1].TXT [ /ADS.PUBMATIC ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@TRAFFICTRACK[2].TXT [ /TRAFFICTRACK ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@MEDIAPLEX[2].TXT [ /MEDIAPLEX ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.BOREUS[1].TXT [ /AD.BOREUS ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@IM.BANNER.T-ONLINE[3].TXT [ /IM.BANNER.T-ONLINE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@IM.BANNER.T-ONLINE[1].TXT [ /IM.BANNER.T-ONLINE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@TRACKING.HANNOVERSCHE[2].TXT [ /TRACKING.HANNOVERSCHE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AXELSPRINGER.122.2O7[1].TXT [ /AXELSPRINGER.122.2O7 ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@EAS.APM.EMEDIATE[2].TXT [ /EAS.APM.EMEDIATE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ROTATOR.ADJUGGLER[2].TXT [ /ROTATOR.ADJUGGLER ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@SERVER.IAD.LIVEPERSON[2].TXT [ /SERVER.IAD.LIVEPERSON ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@DC.TREMORMEDIA[2].TXT [ /DC.TREMORMEDIA ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@FL01.CT2.COMCLICK[1].TXT [ /FL01.CT2.COMCLICK ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@KEYWORD-ADVERTISING.WEB[1].TXT [ /KEYWORD-ADVERTISING.WEB ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ZEDO[1].TXT [ /ZEDO ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADFARM1.ADITION[2].TXT [ /ADFARM1.ADITION ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@TRACKING.KLICKTEL[1].TXT [ /TRACKING.KLICKTEL ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.ADNET[2].TXT [ /AD.ADNET ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS.123RECHT[1].TXT [ /ADS.123RECHT ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@STAT.ALDI[2].TXT [ /STAT.ALDI ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ZANOX[2].TXT [ /ZANOX ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@IMRWORLDWIDE[2].TXT [ /IMRWORLDWIDE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADS2.WWE[2].TXT [ /ADS2.WWE ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@STATS.SEARCHTRACK[1].TXT [ /STATS.SEARCHTRACK ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD.TRIPLEMIND[1].TXT [ /AD.TRIPLEMIND ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@AD1.ADFARM1.ADITION[1].TXT [ /AD1.ADFARM1.ADITION ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@ADSERVER.S-IMMOBILIEN-MAINFRANKEN[1].TXT [ /ADSERVER.S-IMMOBILIEN-MAINFRANKEN ]
        C:\DOKUMENTE UND EINSTELLUNGEN\***\COOKIES\***@2O7[2].TXT [ /2O7 ]


cosinus 19.01.2012 10:48

Zitat:

1. Was konntest du auf dem Screenshot von PartitionEditor erkennen?
Nichts ungewöhnliches

Zitat:

2. Systemwiederherstellung. D. h. mit dem deaktivieren werden die Dateien gelöscht und danach kann sie wieder aktivieren?
ja

Zitat:

3. Hier das Log von SASW. Die Funde hab ich noch nicht gelöscht.
Sind nur ein paar Überreste (wenn überhaupt) in der Registry und Cookies. Weg damit.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Was ist mit ESET?

tax 19.01.2012 17:32

Zum Schluß noch von ESET

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=0b05a8f2ed47e7408040dec21f673cff
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-13 02:39:48
# local_time=2012-01-13 03:39:48 (+0100, Westeuropäische Normalzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1797 16775141 100 94 4440 91884242 0 0
# compatibility_mode=8192 67108863 100 0 3933 3933 0 0
# scanned=200868
# found=3
# cleaned=0
# scan_time=19941
C:\Dokumente und Einstellungen\Weisi\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\52\71dba774-35ff92d3        Java/Exploit.CVE-2011-3544.S trojan (unable to clean)        00000000000000000000000000000000        I
C:\WINDOWS\system32\hNWEKRqr.ini        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I
C:\WINDOWS\system32\hNWEKRqr.ini2        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=0b05a8f2ed47e7408040dec21f673cff
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-19 09:07:32
# local_time=2012-01-19 10:07:32 (+0100, Westeuropäische Normalzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1797 16775141 100 94 469731 92434163 169807 0
# compatibility_mode=8192 67108863 100 0 553854 553854 0 0
# scanned=269758
# found=7
# cleaned=0
# scan_time=11686
C:\Qoobox\Quarantine\C\WINDOWS\system32\hNWEKRqr.ini.vir        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hNWEKRqr.ini2.vir        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243898.exe.vir        a variant of Win32/Kryptik.XZY trojan (unable to clean)        00000000000000000000000000000000        I
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243907.exe.vir        a variant of Win32/Kryptik.XZY trojan (unable to clean)        00000000000000000000000000000000        I
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP894\A0243944.exe.vir        a variant of Win32/Kryptik.ZCB trojan (unable to clean)        00000000000000000000000000000000        I
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP896\A0244293.exe.vir        a variant of Win32/Kryptik.YGQ trojan (unable to clean)        00000000000000000000000000000000        I
C:\System Volume Information\_restore{96BF581B-404B-47D5-AE35-03C725F190AB}\RP903\A0254686.ini        Win32/Adware.Virtumonde.NEO application (unable to clean)        00000000000000000000000000000000        I


cosinus 19.01.2012 21:38

Das ist ok. In C:\Qoobox bzw. C:\_OTL (Q-Ordner von CF und OTL) sind die Schädlinge isoliert und gut aufgehoben.

In System Volume Information sind die Dateien für Wiederherstellungspunkte gespeichert.

Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des Systems durch einen Wiederherstellungspunkt wahrscheinlich wieder eine Infektion nach sich ziehen würde.


Rechner soweit wieder im Lot?

tax 20.01.2012 08:06

Ja es sieht gut aus, er läuft wieder. Nochmal vielen Dank!
D. h. wird sind fertig?

cosinus 20.01.2012 11:39

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:24 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131