Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   mor.exe von Norton isoliert/entfernt - weitere Aktion erforderlich? (https://www.trojaner-board.de/118319-mor-exe-norton-isoliert-entfernt-aktion-erforderlich.html)

gr.nagus 02.07.2012 11:18

mor.exe von Norton isoliert/entfernt - weitere Aktion erforderlich?
 
Hallo,

heute bekam ich beim Surfen eine Meldung von der Norton Internetsecurity:

____________________________
____________________________
Auf Computern ab 02.07.2012 um 10:27:04
Zuletzt verwendet 02.07.2012 um 10:27:04
Start-Element Nein
Gestarted Ja
____________________________
____________________________
Sehr wenige Benutzer
Weniger als 5 Benutzer in der Norton Community haben diese Datei verwendet.
____________________________
Sehr neu
Diese Datei wurde vor weniger als 1 Woche veröffentlicht.
____________________________
Hoch
Das Risiko dieser Datei ist hoch.
____________________________
Bedrohungsdetails
SONAR-Schutz überwacht Ihren Computer auf verdächtige Programmaktivitäten.
____________________________


Quelldatei:
zipper.exe

Datei erstellt:
java.exe

Datei erstellt:
mor.exe
____________________________
Dateiaktionen
Infizierte Datei: j:\dokumente und einstellungen\kuschelbär\lokale einstellungen\temp\mor.exe
entfernt
____________________________
Netzwerkaktionen
Ereignis: Netzwerkaktivität (Ausgeführt von j:\dokumente und einstellungen\kuschelbär\lokale einstellungen\temp\mor.exe, PID:2832)
Keine Aktion unternommen
____________________________
Systemeinstellungsaktionen
Ereignis: Prozessstart (Ausgeführt von j:\dokumente und einstellungen\kuschelbär\lokale einstellungen\temp\mor.exe, PID:2832)
Keine Aktion unternommen
____________________________
Dateiabdruck - SHA:
7ff9ba4fc299cbc6fb4e9a986b1f26b45997d4620684e10d929bbef4db6aff90
____________________________
Dateiabdruck - MD5:
099fa8fd3b40b78a954287ed2f692ad5
____________________________



Norton sagt das keine weitere Aktion erforderlich ist. Ich traue der Sache aber nicht wirklich. Die Angaben zum Status ist in der Übersicht "isoliert" und in den Details steht "entfernt". Was trift jetzt zu? Ist der Bösewicht noch auf der Festplatte und kann er vielleicht wieder ausbrechen?

Anschließend habe ich mit Norton einen vollständigen Systemscan ausgeführt, bei dem aber keinen Bedrohungen gefunden wurden.

Danach habe ich Malwarebytes installiert, aktualisiert und einen vollständigen Systemscan ausgeführt, bei dem ein paar Sachen gefunden wurden, die ich dann gelöscht habe:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.02.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Kuschelbär :: KUSCHELBAER [Administrator]

Schutz: Aktiviert

02.07.2012 10:57:48
mbam-log-2012-07-02 (10-57-48).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 404958
Laufzeit: 27 Minute(n), 18 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\SYSTEM\CurrentControlSet\Services\SeekService Service (Adware.SeekService) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
J:\Programme\SeekService (Adware.SeekService) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 2
J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\SoftonicDownloader_fuer_pdf-xchange-viewer-portable.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt.
J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\ADLSoft_UnCompressor_v2.exe (PUP.Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


Anschließend habe ich wie verlangt den Rechner neu gestartet und noch mal einen ergebnislosen Quickscan mit Malwarebytes durchgeführt.

Muss ich jetzt noch etwas tun wegen der mor.exe? Was ist mit dieser java.exe die laut Norton auch erstellt wurde?

Vielen Dank für eure Hilfe!

Gruß
gr.nagus

So hier sind noch die Logfiles:

OTL:OTL Logfile:
Code:

OTL logfile created on: 02.07.2012 13:13:36 - Run 1
OTL by OldTimer - Version 3.2.53.1    Folder = J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,27 Gb Available Physical Memory | 70,02% Memory free
8,34 Gb Paging File | 7,25 Gb Available in Paging File | 87,02% Paging File free
Paging file location(s): J:\pagefile.sys 2046 4092K:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Programme
Drive C: | 5,90 Gb Total Space | 4,76 Gb Free Space | 80,71% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,06 Gb Free Space | 45,30% Space Free | Partition Type: NTFS
Drive E: | 39,01 Gb Total Space | 2,91 Gb Free Space | 7,45% Space Free | Partition Type: NTFS
Drive F: | 27,46 Gb Total Space | 24,29 Gb Free Space | 88,44% Space Free | Partition Type: NTFS
Drive G: | 35,64 Gb Total Space | 24,75 Gb Free Space | 69,44% Space Free | Partition Type: NTFS
Drive I: | 3,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive J: | 29,79 Gb Total Space | 4,17 Gb Free Space | 13,99% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 11,53 Gb Free Space | 77,41% Space Free | Partition Type: NTFS
Drive L: | 21,05 Gb Total Space | 8,79 Gb Free Space | 41,75% Space Free | Partition Type: NTFS
 
Computer Name: KUSCHELBAER | User Name: Kuschelbär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.02 13:12:31 | 000,595,968 | ---- | M] (OldTimer Tools) -- J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\OTL.exe
PRC - [2012.06.26 22:08:10 | 000,400,352 | ---- | M] (Mozilla Messaging) -- J:\Programme\Mozilla Thunderbird\thunderbird.exe
PRC - [2012.06.25 00:07:32 | 000,913,888 | ---- | M] (Mozilla Corporation) -- J:\Programme\Mozilla Firefox\firefox.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- J:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) -- J:\Programme\Norton 360\Engine\6.2.1.5\ccsvchst.exe
PRC - [2012.01.18 14:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) -- J:\WINDOWS\system32\HPSIsvc.exe
PRC - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
PRC - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) -- J:\WINDOWS\system32\LGScsiCommandService.exe
PRC - [2008.06.24 17:06:06 | 001,840,424 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
PRC - [2008.06.18 12:01:56 | 000,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- J:\WINDOWS\SoundMan.exe
PRC - [2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\explorer.exe
PRC - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
PRC - [2007.10.11 16:19:44 | 000,308,224 | ---- | M] (Portrait Displays, Inc) -- J:\Programme\Portrait Displays\forteManager\dthtml.exe
PRC - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
PRC - [2007.10.11 16:17:02 | 000,110,592 | ---- | M] (Portrait Displays Inc.) -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\HookManager.exe
PRC - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2006.12.28 15:05:14 | 000,196,608 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoumain.exe
PRC - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) -- J:\WINDOWS\system32\spool\drivers\w32x86\3\fpdisp5a.exe
PRC - [2005.11.03 12:09:50 | 000,126,976 | ---- | M] (Saitek) -- J:\Programme\Saitek\Software\SaiMfd.exe
PRC - [2005.10.18 15:34:08 | 000,163,840 | ---- | M] (Saitek) -- J:\Programme\Saitek\Software\ProfilerU.exe
PRC - [2004.12.14 03:12:46 | 000,196,608 | ---- | M] (Adobe Systems Incorporated.) -- J:\Programme\Adobe\Acrobat 7.0\Distillr\acrodist.exe
PRC - [2004.12.14 03:12:02 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- J:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.26 22:08:14 | 001,977,312 | ---- | M] () -- J:\Programme\Mozilla Thunderbird\mozjs.dll
MOD - [2012.06.26 22:08:13 | 000,162,784 | ---- | M] () -- J:\Programme\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2012.06.26 22:08:13 | 000,021,984 | ---- | M] () -- J:\Programme\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2012.06.25 00:07:31 | 002,042,848 | ---- | M] () -- J:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2012.06.23 11:54:28 | 009,459,912 | ---- | M] () -- J:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll
MOD - [2011.01.11 01:25:48 | 000,096,112 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
MOD - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
MOD - [2009.11.20 15:48:58 | 000,176,128 | R--- | M] () -- J:\WINDOWS\system32\m1210nwia.dll
MOD - [2009.11.20 14:42:08 | 000,163,840 | ---- | M] () -- J:\WINDOWS\system32\HPM1210LM.DLL
MOD - [2009.11.20 14:42:08 | 000,069,632 | ---- | M] () -- J:\WINDOWS\system32\spool\prtprocs\w32x86\HPM1210PP.dll
MOD - [2009.05.07 03:38:14 | 000,020,480 | R--- | M] () -- J:\WINDOWS\system32\SendScsiCmd.dll
MOD - [2009.03.13 11:30:44 | 000,109,096 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\ycc.dll
MOD - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
MOD - [2007.10.11 16:17:54 | 000,167,936 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DThook.dll
MOD - [2007.10.11 16:17:48 | 000,077,824 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\CC\gui.dll
MOD - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
MOD - [2007.10.11 16:16:58 | 000,102,400 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\PresetsCOM.dll
MOD - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
MOD - [2007.02.09 03:22:52 | 000,022,723 | ---- | M] () -- J:\WINDOWS\system32\ml163sl3.dll
MOD - [2006.12.28 15:05:14 | 000,196,608 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoumain.exe
MOD - [2006.12.28 06:00:10 | 000,098,304 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoures.dll
MOD - [2006.12.28 05:59:48 | 000,032,768 | ---- | M] () -- J:\WINDOWS\system32\Amhooker.dll
MOD - [2006.11.27 06:13:32 | 000,028,672 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Setuphk.dll
MOD - [2005.10.18 15:30:14 | 000,077,824 | ---- | M] () -- J:\Programme\Saitek\Software\SAILNKU.dll
MOD - [2005.10.18 15:24:32 | 000,147,456 | ---- | M] () -- J:\Programme\Saitek\Software\SAICFG.dll
MOD - [2004.12.14 04:28:26 | 001,212,416 | ---- | M] () -- J:\Programme\Adobe\Acrobat 7.0\Distillr\AdistRes.DEU
MOD - [2004.11.17 16:49:06 | 004,603,904 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\qt-mt332.dll
MOD - [2004.05.11 15:51:56 | 000,798,720 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\libeay32.dll
MOD - [2004.05.11 15:51:56 | 000,155,648 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\ssleay32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- J:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2012.06.25 00:07:32 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- J:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.23 11:54:34 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- J:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) [Auto | Running] -- J:\Programme\Norton 360\Engine\6.2.1.5\ccSvcHst.exe -- (N360)
SRV - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) [Auto | Running] -- J:\WINDOWS\system32\HPSIsvc.exe -- (HPSIService)
SRV - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () [Auto | Running] -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) [Auto | Running] -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe -- (HPM1210RcvFaxSrvc)
SRV - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Running] -- J:\WINDOWS\system32\LGScsiCommandService.exe -- (LGScsiCommandService)
SRV - [2009.05.13 00:35:56 | 000,095,896 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009.03.05 20:24:32 | 000,069,632 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- J:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) [On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe -- (Asset Management Daemon)
SRV - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
SRV - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) [Auto | Running] -- J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe -- (FinePrint Dispatcher v5)
SRV - [2005.08.24 03:29:52 | 000,118,272 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- J:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | Auto | Stopped] -- J:\WINDOWS\system32\Drivers\SSPORT.sys -- (SSPORT)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012.07.02 13:11:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- J:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2012.06.19 02:01:14 | 000,821,920 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120619.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012.06.18 20:26:27 | 000,369,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120629.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012.05.31 16:45:18 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012.05.31 16:45:18 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012.05.16 19:25:35 | 001,589,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120701.008\NAVEX15.SYS -- (NAVEX15)
DRV - [2012.05.16 19:25:35 | 000,087,928 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120701.008\NAVENG.SYS -- (NAVENG)
DRV - [2012.05.06 19:34:37 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.29 08:03:27 | 000,574,072 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtsp.sys -- (SRTSP)
DRV - [2012.03.29 08:03:27 | 000,032,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2012.03.29 00:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symtdi.sys -- (SYMTDI)
DRV - [2012.03.29 00:28:30 | 000,905,336 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symefa.sys -- (SymEFA)
DRV - [2012.03.29 00:28:26 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symds.sys -- (SymDS)
DRV - [2012.03.29 00:06:26 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ironx86.sys -- (SymIRON)
DRV - [2011.11.29 16:44:14 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ccsetx86.sys -- (ccSet_N360)
DRV - [2011.03.18 18:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- J:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2008.11.19 17:09:10 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008.11.19 17:09:08 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008.11.19 17:09:08 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008.06.27 05:24:56 | 004,742,656 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.06.16 09:08:42 | 000,109,184 | R--- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.03.05 10:11:00 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- J:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2006.12.28 16:07:34 | 000,013,824 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Amusbprt.sys -- (Amusbprt)
DRV - [2006.12.28 16:02:22 | 000,008,704 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\Amfilter.sys -- (Amfilter)
DRV - [2006.11.16 17:20:48 | 000,015,920 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\PdiPorts.sys -- (PdiPorts)
DRV - [2006.07.27 13:49:34 | 000,035,200 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2006.07.27 13:49:34 | 000,013,824 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2006.07.27 13:49:27 | 000,176,640 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiH075C.sys -- (SaiH075C)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- J:\WINDOWS\system32\giveio.sys -- (giveio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\..\SearchScopes,DefaultScope = {0D7562AE-8EF6-416d-A838-AB665251703A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=6
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.1.3
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: J:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: J:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: J:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: J:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: J:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: J:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: J:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: J:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012.05.06 19:38:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012.07.02 13:11:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: J:\Programme\Mozilla Firefox\components [2012.06.25 00:07:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Firefox\plugins [2012.06.05 22:24:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: J:\Programme\Mozilla Thunderbird\components [2012.06.26 22:08:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Thunderbird\plugins
 
[2009.11.21 10:49:28 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Extensions
[2012.05.02 19:14:27 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions
[2010.05.18 12:43:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.06.22 21:29:50 | 000,002,448 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\searchplugins\safesearch.xml
[2012.06.25 00:07:41 | 000,000,000 | ---D | M] (No name found) -- J:\Programme\Mozilla Firefox\extensions
[2012.07.02 13:11:57 | 000,000,000 | ---D | M] (Norton Toolbar) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\COFFPLGN
[2012.05.06 19:38:22 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPLGN
[2012.05.13 13:36:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- J:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.06.25 00:07:33 | 000,085,472 | ---- | M] (Mozilla Foundation) -- J:\Programme\mozilla firefox\components\browsercomps.dll
[2012.06.25 00:07:28 | 000,001,392 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.25 00:07:28 | 000,002,252 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.06.25 00:07:28 | 000,001,153 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.30 17:35:34 | 000,002,048 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\fcmdSrch.xml
[2012.06.25 00:07:28 | 000,006,805 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2009.10.01 16:35:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice124.xml
[2009.10.21 18:31:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice133.xml
[2012.06.25 00:07:28 | 000,001,178 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.25 00:07:28 | 000,001,105 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2008.04.14 14:00:00 | 000,000,820 | ---- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - J:\Programme\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - J:\Programme\Norton 360\Engine\6.2.1.5\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - J:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] J:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] J:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] J:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] J:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXUpdate] J:\Programme\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DT LGE] J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [facemoods] J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [FinePrint Dispatcher v5] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] J:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] J:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] J:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] J:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Profiler] J:\Programme\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [SaiMfd] J:\Programme\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [Samsung PanelMgr] J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SoundMan] J:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WheelMouse] J:\Programme\OCZ Technology\Mouse\Amoumain.exe ()
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - Startup: J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\Autostart\SpeedFan.lnk = J:\Programme\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1236273297031 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF80DD1E-FD72-4F1B-AB97-85A9EBB1B389}: NameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (J:\WINDOWS\system32\userinit.exe) - J:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.05 18:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.09.24 23:37:50 | 000,000,041 | R--- | M] () - I:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.02 10:56:27 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Malwarebytes
[2012.07.02 10:56:17 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- J:\WINDOWS\System32\drivers\mbam.sys
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.06.13 19:39:10 | 000,521,728 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012.06.05 22:24:46 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\QuickTime
[2012.06.05 22:24:14 | 000,000,000 | ---D | C] -- J:\Programme\QuickTime
[2012.06.05 22:24:12 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Apple Computer
[2012.06.04 20:50:52 | 000,000,000 | ---D | C] -- J:\Programme\Microsoft.NET
[2012.06.04 20:32:26 | 000,527,192 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_7.dll
[2012.06.04 20:32:26 | 000,074,072 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_5.dll
[2012.06.04 20:32:25 | 000,239,960 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_7.dll
[2012.06.04 20:32:24 | 002,106,216 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_43.dll
[2012.06.04 20:32:24 | 001,868,128 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dcsx_43.dll
[2012.06.04 20:32:23 | 000,470,880 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_43.dll
[2012.06.04 20:32:23 | 000,248,672 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx11_43.dll
[2012.06.04 20:32:22 | 001,998,168 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_43.dll
[2012.06.04 20:32:21 | 000,528,216 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_6.dll
[2012.06.04 20:32:21 | 000,238,936 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_6.dll
[2012.06.04 20:32:21 | 000,074,072 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_4.dll
[2012.06.04 20:32:20 | 000,022,360 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_7.dll
[2012.06.04 20:32:19 | 000,515,416 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_5.dll
[2012.06.04 20:32:18 | 000,238,936 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_5.dll
[2012.06.04 20:32:17 | 001,974,616 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_42.dll
[2012.06.04 20:32:16 | 005,501,792 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dcsx_42.dll
[2012.06.04 20:32:15 | 000,235,344 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx11_42.dll
[2012.06.04 20:32:14 | 001,892,184 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_42.dll
[2012.06.04 20:32:14 | 000,453,456 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_42.dll
[2012.06.04 20:32:13 | 001,846,632 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_41.dll
[2012.06.04 20:32:13 | 000,453,456 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_41.dll
[2012.06.04 20:32:12 | 004,178,264 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_41.dll
[2012.06.04 20:32:11 | 000,517,448 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_4.dll
[2012.06.04 20:32:11 | 000,069,464 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_3.dll
[2012.06.04 20:32:10 | 000,235,352 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_4.dll
[2012.06.04 20:32:09 | 000,022,360 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_6.dll
[2012.06.04 20:32:08 | 004,379,984 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_40.dll
[2012.06.04 20:32:08 | 002,036,576 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_40.dll
[2012.06.04 20:32:08 | 000,452,440 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_40.dll
[2012.06.04 20:32:07 | 000,514,384 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_3.dll
[2012.06.04 20:32:07 | 000,070,992 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_2.dll
[2012.06.04 20:32:06 | 000,235,856 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_3.dll
[2012.06.04 20:32:06 | 000,023,376 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_5.dll
[2012.06.04 20:32:05 | 000,509,448 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_2.dll
[2012.06.04 20:32:05 | 000,238,088 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_2.dll
[2012.06.04 20:32:05 | 000,068,616 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_1.dll
[2012.06.04 20:32:04 | 001,493,528 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_39.dll
[2012.06.04 20:32:04 | 000,467,984 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_39.dll
[2012.06.04 20:32:03 | 003,851,784 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_39.dll
[2012.06.04 20:32:02 | 000,507,400 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_1.dll
[2012.06.04 20:32:02 | 000,238,088 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_1.dll
[2012.06.04 20:32:02 | 000,065,032 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAPOFX1_0.dll
[2012.06.04 20:32:01 | 000,025,608 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_4.dll
[2012.06.04 20:32:00 | 001,491,992 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_38.dll
[2012.06.04 20:32:00 | 000,467,984 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_38.dll
[2012.06.04 20:31:59 | 003,850,760 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_38.dll
[2012.06.04 20:31:59 | 000,479,752 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\XAudio2_0.dll
[2012.06.04 20:31:58 | 000,238,088 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine3_0.dll
[2012.06.04 20:31:57 | 000,025,608 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_3.dll
[2012.06.04 20:31:56 | 001,420,824 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_37.dll
[2012.06.04 20:31:56 | 000,462,864 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_37.dll
[2012.06.04 20:31:55 | 003,786,760 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DX9_37.dll
[2012.06.04 20:31:51 | 000,267,272 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_10.dll
[2012.06.04 20:31:48 | 001,374,232 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_36.dll
[2012.06.04 20:31:48 | 000,444,776 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_36.dll
[2012.06.04 20:31:47 | 003,734,536 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_36.dll
[2012.06.04 20:31:46 | 000,267,112 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_9.dll
[2012.06.04 20:31:45 | 003,727,720 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_35.dll
[2012.06.04 20:31:45 | 001,358,192 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_35.dll
[2012.06.04 20:31:45 | 000,444,776 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_35.dll
[2012.06.04 20:31:43 | 000,266,088 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_8.dll
[2012.06.04 20:31:43 | 000,017,928 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\X3DAudio1_2.dll
[2012.06.04 20:31:42 | 003,497,832 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_34.dll
[2012.06.04 20:31:42 | 001,124,720 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_34.dll
[2012.06.04 20:31:42 | 000,443,752 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_34.dll
[2012.06.04 20:31:41 | 000,261,480 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_7.dll
[2012.06.04 20:31:41 | 000,081,768 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xinput1_3.dll
[2012.06.04 20:31:40 | 001,123,696 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\D3DCompiler_33.dll
[2012.06.04 20:31:40 | 000,443,752 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx10_33.dll
[2012.06.04 20:31:39 | 003,495,784 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_33.dll
[2012.06.04 20:31:38 | 000,255,848 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_6.dll
[2012.06.04 20:31:37 | 003,426,072 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_32.dll
[2012.06.04 20:31:37 | 000,251,672 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_5.dll
[2012.06.04 20:31:36 | 002,414,360 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_31.dll
[2012.06.04 20:31:36 | 000,237,848 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_4.dll
[2012.06.04 20:31:36 | 000,015,128 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\x3daudio1_1.dll
[2012.06.04 20:31:35 | 000,236,824 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_3.dll
[2012.06.04 20:31:35 | 000,062,744 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xinput1_2.dll
[2012.06.04 20:31:34 | 000,230,168 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_2.dll
[2012.06.04 20:31:33 | 000,062,672 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xinput1_1.dll
[2012.06.04 20:31:32 | 000,229,584 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_1.dll
[2012.06.04 20:31:27 | 002,332,368 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_29.dll
[2012.06.04 20:31:27 | 000,230,096 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xactengine2_0.dll
[2012.06.04 20:31:27 | 000,014,032 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\x3daudio1_0.dll
[2012.06.04 20:31:26 | 002,319,568 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_27.dll
[2012.06.04 20:31:26 | 000,061,136 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\xinput9_1_0.dll
[2012.06.04 20:31:25 | 002,337,488 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_25.dll
[2012.06.04 20:31:25 | 002,297,552 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_26.dll
[2012.06.04 20:31:24 | 002,222,800 | ---- | C] (Microsoft Corporation) -- J:\WINDOWS\System32\d3dx9_24.dll
[2012.06.04 20:29:03 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\VideoLAN
[2012.06.04 20:28:07 | 000,000,000 | ---D | C] -- J:\Programme\VideoLAN
[2012.06.04 20:26:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\SiSoftware
[2012.06.04 20:26:08 | 000,000,000 | ---D | C] -- J:\Programme\SiSoftware
[2012.06.04 20:12:38 | 000,000,000 | ---D | C] -- J:\Programme\SpeedFan
[2012.06.04 20:12:38 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\SpeedFan
[2010.08.12 23:24:06 | 000,047,360 | ---- | C] (VSO Software) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.sys
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.02 13:11:18 | 000,212,641 | ---- | M] () -- J:\WINDOWS\System32\nvapps.xml
[2012.07.02 13:11:16 | 000,002,422 | ---- | M] () -- J:\WINDOWS\System32\wpa.dbl
[2012.07.02 13:11:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- J:\WINDOWS\gdrv.sys
[2012.07.02 13:10:51 | 000,002,048 | --S- | M] () -- J:\WINDOWS\bootstat.dat
[2012.07.02 12:10:00 | 000,001,090 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.02 11:54:15 | 000,000,884 | ---- | M] () -- J:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.07.02 11:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2012.07.02 10:56:21 | 000,000,762 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 09:10:00 | 000,001,086 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.28 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2012.06.27 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012.06.26 22:19:00 | 000,000,276 | ---- | M] () -- J:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.06.26 19:13:29 | 000,000,069 | ---- | M] () -- J:\WINDOWS\NeroDigital.ini
[2012.06.26 15:28:27 | 000,122,368 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.23 11:54:28 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- J:\WINDOWS\System32\FlashPlayerApp.exe
[2012.06.23 11:54:28 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- J:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.06.14 18:52:34 | 000,152,384 | ---- | M] () -- J:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.13 23:31:36 | 000,517,474 | ---- | M] () -- J:\WINDOWS\System32\perfh007.dat
[2012.06.13 23:31:36 | 000,494,148 | ---- | M] () -- J:\WINDOWS\System32\perfh009.dat
[2012.06.13 23:31:36 | 000,101,628 | ---- | M] () -- J:\WINDOWS\System32\perfc007.dat
[2012.06.13 23:31:36 | 000,084,692 | ---- | M] () -- J:\WINDOWS\System32\perfc009.dat
[2012.06.13 23:20:30 | 000,001,374 | ---- | M] () -- J:\WINDOWS\imsins.BAK
[2012.06.05 22:24:46 | 000,001,590 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.06.05 22:08:27 | 000,157,037 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\bezahlen Google.jpg
[2012.06.04 20:26:32 | 000,001,009 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\SiSoftware Sandra Lite 2012.SP4a.lnk
[2012.06.04 20:12:40 | 000,000,660 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\SpeedFan.lnk
[2012.06.04 20:12:39 | 000,000,672 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\Autostart\SpeedFan.lnk
[2012.06.04 20:12:38 | 000,000,045 | ---- | M] () -- J:\WINDOWS\System32\initdebug.nfo
[2012.06.04 19:50:49 | 000,000,064 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sandra.ldb
[2012.06.02 15:19:38 | 000,329,240 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wucltui.dll
[2012.06.02 15:19:38 | 000,329,240 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wucltui.dll
[2012.06.02 15:19:38 | 000,219,160 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2012.06.02 15:19:38 | 000,210,968 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wuweb.dll
[2012.06.02 15:19:38 | 000,015,896 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wuapi.dll.mui
[2012.06.02 15:19:34 | 000,097,304 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\cdm.dll
[2012.06.02 15:19:34 | 000,097,304 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\cdm.dll
[2012.06.02 15:19:34 | 000,053,784 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wuauclt.exe
[2012.06.02 15:19:34 | 000,045,080 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wups2.dll
[2012.06.02 15:19:34 | 000,035,864 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wups.dll
[2012.06.02 15:19:34 | 000,035,864 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wups.dll
[2012.06.02 15:19:28 | 000,023,576 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wucltui.dll.mui
[2012.06.02 15:19:24 | 000,577,048 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\wuapi.dll
[2012.06.02 15:19:24 | 000,577,048 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wuapi.dll
[2012.06.02 15:19:18 | 001,933,848 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\System32\dllcache\wuaueng.dll
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.02 10:56:21 | 000,000,762 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.05 22:24:46 | 000,001,590 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.06.05 22:08:27 | 000,157,037 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\bezahlen Google.jpg
[2012.06.04 20:59:16 | 011,567,104 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Sandra.mdb
[2012.06.04 20:26:32 | 000,001,009 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\SiSoftware Sandra Lite 2012.SP4a.lnk
[2012.06.04 20:12:39 | 000,000,660 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\SpeedFan.lnk
[2012.06.04 20:12:38 | 000,000,672 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\Autostart\SpeedFan.lnk
[2012.06.04 20:12:34 | 000,000,045 | ---- | C] () -- J:\WINDOWS\System32\initdebug.nfo
[2012.06.04 19:50:49 | 000,000,064 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sandra.ldb
[2012.05.26 11:23:30 | 000,109,001 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2011_Sieg_Andreas_und_Sieg_Gitta.elfo
[2012.02.15 08:58:58 | 000,003,072 | ---- | C] () -- J:\WINDOWS\System32\iacenc.dll
[2011.12.13 10:07:09 | 000,053,760 | R--- | C] () -- J:\WINDOWS\System32\HPM1210SMs.dll
[2011.12.13 10:07:08 | 001,265,664 | ---- | C] () -- J:\WINDOWS\System32\HPM1210SM.exe
[2011.12.13 10:07:08 | 000,163,840 | ---- | C] () -- J:\WINDOWS\System32\HPM1210LM.DLL
[2011.12.13 10:07:04 | 000,176,128 | R--- | C] () -- J:\WINDOWS\System32\m1210nwia.dll
[2011.12.13 09:41:17 | 000,284,160 | ---- | C] () -- J:\WINDOWS\System32\mvhlewsi.DLL
[2011.09.20 15:44:19 | 000,101,876 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2010_Sieg_Andreas_und_Sieg_Gitta.elfo
[2011.06.15 23:23:19 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011.06.15 23:18:18 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010.08.12 23:24:06 | 000,087,608 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\inst.exe
[2010.08.12 23:24:06 | 000,007,887 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.cat
[2010.08.12 23:24:06 | 000,001,144 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.inf
[2010.03.18 21:22:30 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\$_hpcst$.hpc
[2010.02.07 16:30:27 | 000,131,919 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\2009.elfo
[2009.12.01 23:04:06 | 000,122,368 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.11.21 10:39:43 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\$_hpcst$.hpc
[2009.03.06 23:50:53 | 000,000,040 | -HS- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2009.03.05 21:03:58 | 000,001,024 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\.rnd
[2009.03.05 18:48:16 | 000,049,152 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\index.dat
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 24 bytes -> J:\WINDOWS:AA0B7C486F752FC7

< End of report >

--- --- ---


Extras:OTL Logfile:
Code:

OTL Extras logfile created on: 02.07.2012 13:13:36 - Run 1
OTL by OldTimer - Version 3.2.53.1    Folder = J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,27 Gb Available Physical Memory | 70,02% Memory free
8,34 Gb Paging File | 7,25 Gb Available in Paging File | 87,02% Paging File free
Paging file location(s): J:\pagefile.sys 2046 4092K:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Programme
Drive C: | 5,90 Gb Total Space | 4,76 Gb Free Space | 80,71% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,06 Gb Free Space | 45,30% Space Free | Partition Type: NTFS
Drive E: | 39,01 Gb Total Space | 2,91 Gb Free Space | 7,45% Space Free | Partition Type: NTFS
Drive F: | 27,46 Gb Total Space | 24,29 Gb Free Space | 88,44% Space Free | Partition Type: NTFS
Drive G: | 35,64 Gb Total Space | 24,75 Gb Free Space | 69,44% Space Free | Partition Type: NTFS
Drive I: | 3,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive J: | 29,79 Gb Total Space | 4,17 Gb Free Space | 13,99% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 11,53 Gb Free Space | 77,41% Space Free | Partition Type: NTFS
Drive L: | 21,05 Gb Total Space | 8,79 Gb Free Space | 41,75% Space Free | Partition Type: NTFS
 
Computer Name: KUSCHELBAER | User Name: Kuschelbär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- J:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "J:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "J:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"J:\Programme\GIGABYTE\EnergySaver\run.exe" = J:\Programme\GIGABYTE\EnergySaver\run.exe:*:Enabled:update
"J:\Programme\eMule\emule.exe" = J:\Programme\eMule\emule.exe:*:Disabled:eMule
"J:\Programme\TeamViewer\Version6\TeamViewer.exe" = J:\Programme\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
"J:\Programme\TeamViewer\Version6\TeamViewer_Service.exe" = J:\Programme\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH)
"J:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe" = J:\Programme\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service
"J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe" = J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\RpcSandraSrv.exe" = J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"J:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe" = J:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{04830D0F-F980-4EC0-89F1-594F2FD2A1B5}" = ElsterFormular 2008/2009
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{1883A84D-94AA-432C-9519-FA31B6B118B9}" = forteManager
"{1FA6376A-3120-45DA-8686-96DEFC8A0513}" = HP LaserJet Toolbox
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32
"{33FA361C-6545-4490-945C-1B869370489D}" = HP LaserJet Professional M1210 MFP Series Toolbox
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{688116E1-3223-11D4-B0F4-004005A44561}" = Flamco Berechnungsprogramm
"{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77077FFF-8831-470F-9627-E86F06A50CCD}" = Avery Wizard 3.1
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79438F1E-DEC3-443D-9DCD-FECE2D68C605}" = IL-2 Sturmovik 1946
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B10.0309.1
"{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{967FB80D-56BD-42EF-A942-9E8C78F984A4}" = Saitek SST Programming Software
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000002}" = Adobe Acrobat 7.0 Professional - English, Français, Deutsch
"{BFFE230A-8520-423D-8A22-DB82C9922925}" = Das Interaktive Kartenwerk. Deutschland
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1" = SiSoftware Sandra Lite 2012.SP4a
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C9AF27-9414-46C8-B9D8-D878BA041031}" = Nero 8
"{D9FBE6FB-63A5-477E-B671-26FC8B7FE100}" = Desastersoft - Operation Overlord XXL Addon
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers
"{E8A34AC8-0137-4515-A94B-0A0946DDC251}" = Scan To
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FA3AFC80-05A5-45A6-BD6E-92641BF93129}" = HP LaserJet Professional M1210 MFP Series Fax Installer
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Acrobat 7.0 Professional - EFG" = Adobe Acrobat 7.0 Professional - English, Français, Deutsch
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Audio Recorder for FREE_is1" = Audio Recorder for FREE 2009 v12.5.3
"Birth of the Federation" = Birth of the Federation
"CD Bremse_is1" = CD Bremse 1.48
"DivX Setup.divx.com" = DivX-Setup
"ElsterFormular für Privatanwender 12.2.0.6412p" = ElsterFormular für Privatanwender
"facemoods" = Facemoods Toolbar
"FinePrint" = FinePrint
"FreeUndelete" = FreeUndelete
"HP LaserJet Professional M1130-M1210 MFP Series" = HP LaserJet Professional M1130-M1210 MFP Series
"ie8" = Windows Internet Explorer 8
"Image Analyzer" = Image Analyzer
"InstallShield_{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"InstallShield_{79438F1E-DEC3-443D-9DCD-FECE2D68C605}" = IL-2 Sturmovik 1946
"Kalender-Excel_is1" = Kalender-Excel 8.6.1
"KOMPASS Digital Map Madeira_is1" = KOMPASS Digital Map Madeira
"KOMPASS Digital Map_is1" = KOMPASS Digital Map
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"Mozilla Thunderbird 13.0.1 (x86 de)" = Mozilla Thunderbird 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"My Program_is1" = VA Tutorial 2.01
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"Paint Shop Pro 5.01" = Paint Shop Pro 5.01 CD
"Pixum ePrint" = Pixum ePrint 1.2
"RedEye" = RedEye (remove only)
"Samsung ML-1630 Series" = Samsung ML-1630 Series
"SpeedFan" = SpeedFan (remove only)
"TAPPS DE_is1" = TAPPS 1.26 DE
"TeamViewer 6" = TeamViewer 6
"VAHausDesignerPremium.Exe" = VA HausDesigner Premium
"VLC media player" = VLC media player 2.0.1
"WheelMouse" = OCZ Technology Laser Gaming Mouse
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR Archivierer
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 18.04.2012 17:29:47 | Computer Name = KUSCHELBAER | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
 von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 ist fehlgeschlagen mit dem Fehler: Dieser Vorgang wurde wegen Zeitüberschreitung
 zurückgegeben.  .
 
Error - 18.04.2012 17:29:47 | Computer Name = KUSCHELBAER | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
 von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 ist fehlgeschlagen mit dem Fehler: Der angegebene Server kann den angeforderten
 Vorgang nicht ausführen.  .
 
Error - 07.05.2012 05:26:36 | Computer Name = KUSCHELBAER | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Acrobat.exe, Version 7.0.0.1333, Stillstandmodul
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
 
Error - 07.05.2012 05:26:37 | Computer Name = KUSCHELBAER | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Acrobat.exe, Version 7.0.0.1333, Stillstandmodul
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
 
Error - 14.06.2012 12:53:01 | Computer Name = KUSCHELBAER | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
 - Tried to start a service that wasn't the latest version of CLR Optimization service.
 Will shutdown
 
Error - 23.06.2012 07:54:27 | Computer Name = KUSCHELBAER | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung FlashPlayerUpdateService.exe, Version 11.3.300.262,
 fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.6055, Fehleradresse 0x000113c0.
 
Error - 26.06.2012 12:54:28 | Computer Name = KUSCHELBAER | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung FlashPlayerUpdateService.exe, Version 11.3.300.262,
 fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.6055, Fehleradresse 0x000113c0.
 
Error - 26.06.2012 12:54:39 | Computer Name = KUSCHELBAER | Source = Application Error | ID = 1001
Description = Fehlerhafter Speicherbereich -1264370443.
 
Error - 26.06.2012 13:54:43 | Computer Name = KUSCHELBAER | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung FlashPlayerUpdateService.exe, Version 11.3.300.262,
 fehlgeschlagenes Modul ntdll.dll, Version 5.1.2600.6055, Fehleradresse 0x000113c0.
 
Error - 01.07.2012 03:25:07 | Computer Name = KUSCHELBAER | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung nmindexstoresvr.exe, Version 3.3.8.0, fehlgeschlagenes
 Modul unknown, Version 0.0.0.0, Fehleradresse 0x01eaed9f.
 
[ System Events ]
Error - 01.07.2012 13:47:30 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 01.07.2012 15:51:39 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden
Fehlers nicht gestartet:  %%2
 
Error - 01.07.2012 15:51:39 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 02.07.2012 04:05:33 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden
Fehlers nicht gestartet:  %%2
 
Error - 02.07.2012 04:05:33 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 02.07.2012 05:31:20 | Computer Name = KUSCHELBAER | Source = sr | ID = 1
Description = Beim Verarbeiten der Datei "" auf Volume "HarddiskVolume8" ist im
Wiederherstellungsfilter der unerwartete Fehler "0xC0000001" aufgetreten. Die Volumeüberwachung
 wurde angehalten.
 
Error - 02.07.2012 05:31:21 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden
Fehlers nicht gestartet:  %%2
 
Error - 02.07.2012 05:31:21 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 02.07.2012 07:11:09 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden
Fehlers nicht gestartet:  %%2
 
Error - 02.07.2012 07:11:09 | Computer Name = KUSCHELBAER | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSPORT" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
 
< End of report >

--- --- ---


Gmer:

GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-02 15:00:37
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-29 WDC_WD1600AAJS-08PSA0 rev.05.06H05
Running: gcgukm0o.exe; Driver: J:\DOKUME~1\KUSCHE~1\LOKALE~1\Temp\fxdiqaob.sys


---- System - GMER 1.0.15 ----

SSDT            89AC3898                                                                                    ZwAlertResumeThread
SSDT            89AC3978                                                                                    ZwAlertThread
SSDT            89A4BCD0                                                                                    ZwAllocateVirtualMemory
SSDT            89AB53F8                                                                                    ZwAssignProcessToJobObject
SSDT            89B346B8                                                                                    ZwConnectPort
SSDT            \??\J:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)  ZwCreateKey [0xB6C41D40]
SSDT            89A489A8                                                                                    ZwCreateMutant
SSDT            89A865E8                                                                                    ZwCreateSymbolicLinkObject
SSDT            89A4CFB0                                                                                    ZwCreateThread
SSDT            89AB54D8                                                                                    ZwDebugActiveProcess
SSDT            \??\J:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)  ZwDeleteKey [0xB6C41FC0]
SSDT            \??\J:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)  ZwDeleteValueKey [0xB6C42680]
SSDT            89A86E70                                                                                    ZwDuplicateObject
SSDT            89AA0AE8                                                                                    ZwFreeVirtualMemory
SSDT            89AA28D8                                                                                    ZwImpersonateAnonymousToken
SSDT            89AA29B8                                                                                    ZwImpersonateThread
SSDT            8A207690                                                                                    ZwLoadDriver
SSDT            89A6ADA8                                                                                    ZwMapViewOfSection
SSDT            89A488E8                                                                                    ZwOpenEvent
SSDT            89A4CE58                                                                                    ZwOpenProcess
SSDT            89A72248                                                                                    ZwOpenProcessToken
SSDT            89A89930                                                                                    ZwOpenSection
SSDT            89A86F60                                                                                    ZwOpenThread
SSDT            89A866D8                                                                                    ZwProtectVirtualMemory
SSDT            89AB4A78                                                                                    ZwResumeThread
SSDT            89A723D0                                                                                    ZwSetContextThread
SSDT            89A6AC18                                                                                    ZwSetInformationProcess
SSDT            89AB5598                                                                                    ZwSetSystemInformation
SSDT            \??\J:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)  ZwSetValueKey [0xB6C42910]
SSDT            89A48828                                                                                    ZwSuspendProcess
SSDT            89AB4B38                                                                                    ZwSuspendThread
SSDT            89AC8A08                                                                                    ZwTerminateProcess
SSDT            89A722F0                                                                                    ZwTerminateThread
SSDT            89A6ACE8                                                                                    ZwUnmapViewOfSection
SSDT            89AA0BB8                                                                                    ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!ZwCallbackReturn + 2CAC                                                        80504564 8 Bytes  [E8, 65, A8, 89, B0, CF, A4, ...]
.text          ntkrnlpa.exe!ZwCallbackReturn + 2D28                                                        805045E0 4 Bytes  [E8, 0A, AA, 89]
.text          ntkrnlpa.exe!ZwCallbackReturn + 2DA4                                                        8050465C 4 Bytes  CALL EED9EAE9
.text          ntkrnlpa.exe!ZwCallbackReturn + 3008                                                        805048C0 4 Bytes  CALL BED9EF71
?              SYMDS.SYS                                                                                  Das System kann die angegebene Datei nicht finden. !
?              SYMEFA.SYS                                                                                  Das System kann die angegebene Datei nicht finden. !
.text          J:\WINDOWS\system32\DRIVERS\nv4_mini.sys                                                    section is writeable [0xB9652360, 0x35483F, 0xE8000020]

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\Tcpip \Device\Ip                                                                    SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                  SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                  SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                    fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

--- --- ---


Ich hoffe das hilft etwas.

Danke nochmal.

Gruß
gr.nagus

cosinus 02.07.2012 16:12

Code:

J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\SoftonicDownloader_fuer_pdf-xchange-viewer-portable.exe
Vermüllte Software von Softonic scheint gerade stark in Mode zu sein! http://cosgan.de/images/midi/boese/a040.gif

Finger weg von Softonic!! :pfui:

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

gr.nagus 02.07.2012 18:03

Hallo Cosinus,

Malwarebytes habe ich heute zum ersten mal benutzt, daher gibts kein älteren Log-Files.

Mit der Software die man sucht, ist das so, dass man manchmal den Hersteller garnicht kennt und dann nicht so richtig weiß bei wem man da eigentlich läd.
Ich gelobe in Zukunft besser aufzupassen. :pfeiff:

Danke für den Hinweis.

Droht jetzt noch Gefahr von mor.exe?

Gruß
gr.nagus

cosinus 03.07.2012 11:32

Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://img695.imageshack.us/img695/1599/eset1l.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.

gr.nagus 03.07.2012 22:04

Hallo Cosinus,

hier ist das Ergebnis des ESET Scans:
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=b8ca76f2733c9842a2a6acf0e7c5d1a1
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-03 08:57:09
# local_time=2012-07-03 10:57:09 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=3589 16777173 100 74 2420656 92008968 0 0
# compatibility_mode=8192 67108863 100 0 131 131 0 0
# scanned=138537
# found=3
# cleaned=0
# scan_time=2557
F:\Andreas_9\Nero-8.3.6.0_deu_trial.exe Win32/Toolbar.AskSBar application (unable to clean) 00000000000000000000000000000000 I
F:\Andreas_9\Audigrabber\agsetup183se.exe a variant of Win32/Adware.ADON application (unable to clean) 00000000000000000000000000000000 I
J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\vlc-1.1.11-win32.exe Win32/StartPage.OIE trojan (unable to clean) 00000000000000000000000000000000 I


....mit jedem neuen Scanner wird neues Zeugs gefunden :crazy:

Gruß
gr.nagus

cosinus 04.07.2012 17:01

Zitat:

J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\vlc-1.1.11-win32.exe
Wenn man sich Software von shice Seiten runterlädt ist das auch kein Wunder, dass ständig was gefunden wird! :pfui:
Den VLC-Player lädt man von videolan.org und nicht vlc.de ! :balla:

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

gr.nagus 04.07.2012 21:24

Zitat:

Zitat von cosinus (Beitrag 857526)
Den VLC-Player lädt man von videolan.org und nicht vlc.de ! :balla:

OK, jetzt weiß ich das. :stirn:


Zitat:

Zitat von cosinus (Beitrag 857526)
Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

Der normale Windows-Modus ging immer. Ich hatte damit keinem Zeitpunkt Probleme. Ich war nur verunsichert weil Norton sich nicht klar ausdrückt was mit dem Schädling geschehen ist. (isoliert oder gelöscht?)
Leere Programmordner gibts nicht. Alles sieht aus wie immer, ich habe auch keine Fehlfunktionen festgestellt.

Gruß
gr.nagus

cosinus 05.07.2012 10:17

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


gr.nagus 05.07.2012 20:30

Hallo Cosinus,

so, hier ist ein neuer Scan:

OTL Logfile:
Code:

OTL logfile created on: 05.07.2012 21:21:18 - Run 2
OTL by OldTimer - Version 3.2.53.1    Folder = J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 76,54% Memory free
8,34 Gb Paging File | 7,49 Gb Available in Paging File | 89,84% Paging File free
Paging file location(s): J:\pagefile.sys 2046 4092K:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Programme
Drive C: | 5,90 Gb Total Space | 4,76 Gb Free Space | 80,71% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,06 Gb Free Space | 45,30% Space Free | Partition Type: NTFS
Drive E: | 39,01 Gb Total Space | 5,71 Gb Free Space | 14,64% Space Free | Partition Type: NTFS
Drive F: | 27,46 Gb Total Space | 24,29 Gb Free Space | 88,44% Space Free | Partition Type: NTFS
Drive G: | 35,64 Gb Total Space | 17,03 Gb Free Space | 47,80% Space Free | Partition Type: NTFS
Drive I: | 3,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive J: | 29,79 Gb Total Space | 3,06 Gb Free Space | 10,26% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 11,53 Gb Free Space | 77,41% Space Free | Partition Type: NTFS
Drive L: | 21,05 Gb Total Space | 8,79 Gb Free Space | 41,75% Space Free | Partition Type: NTFS
 
Computer Name: KUSCHELBAER | User Name: Kuschelbär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.02 13:12:31 | 000,595,968 | ---- | M] (OldTimer Tools) -- J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) -- J:\Programme\Norton 360\Engine\6.2.1.5\ccsvchst.exe
PRC - [2012.03.26 19:05:04 | 004,656,632 | ---- | M] (Almico Software (www.almico.com)) -- J:\Programme\SpeedFan\speedfan.exe
PRC - [2012.01.18 14:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) -- J:\WINDOWS\system32\HPSIsvc.exe
PRC - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
PRC - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) -- J:\WINDOWS\system32\LGScsiCommandService.exe
PRC - [2008.06.24 17:06:06 | 001,840,424 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
PRC - [2008.06.18 12:01:56 | 000,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- J:\WINDOWS\SoundMan.exe
PRC - [2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\explorer.exe
PRC - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
PRC - [2007.10.11 16:19:44 | 000,308,224 | ---- | M] (Portrait Displays, Inc) -- J:\Programme\Portrait Displays\forteManager\dthtml.exe
PRC - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
PRC - [2007.10.11 16:17:02 | 000,110,592 | ---- | M] (Portrait Displays Inc.) -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\HookManager.exe
PRC - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2006.12.28 15:05:14 | 000,196,608 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoumain.exe
PRC - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) -- J:\WINDOWS\system32\spool\drivers\w32x86\3\fpdisp5a.exe
PRC - [2005.11.03 12:09:50 | 000,126,976 | ---- | M] (Saitek) -- J:\Programme\Saitek\Software\SaiMfd.exe
PRC - [2005.10.18 15:34:08 | 000,163,840 | ---- | M] (Saitek) -- J:\Programme\Saitek\Software\ProfilerU.exe
PRC - [2004.12.14 03:12:02 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- J:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.07.05 20:50:19 | 000,192,512 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Temp\sfamcc00001.dll
MOD - [2012.07.05 20:50:19 | 000,158,720 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Temp\sfareca00001.dll
MOD - [2011.01.11 01:25:48 | 000,096,112 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
MOD - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
MOD - [2009.11.20 15:48:58 | 000,176,128 | R--- | M] () -- J:\WINDOWS\system32\m1210nwia.dll
MOD - [2009.11.20 14:42:08 | 000,163,840 | ---- | M] () -- J:\WINDOWS\system32\HPM1210LM.DLL
MOD - [2009.11.20 14:42:08 | 000,069,632 | ---- | M] () -- J:\WINDOWS\system32\spool\prtprocs\w32x86\HPM1210PP.dll
MOD - [2009.05.07 03:38:14 | 000,020,480 | R--- | M] () -- J:\WINDOWS\system32\SendScsiCmd.dll
MOD - [2009.03.13 11:30:44 | 000,109,096 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\ycc.dll
MOD - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
MOD - [2007.10.11 16:17:54 | 000,167,936 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DThook.dll
MOD - [2007.10.11 16:17:48 | 000,077,824 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\CC\gui.dll
MOD - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
MOD - [2007.10.11 16:16:58 | 000,102,400 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\PresetsCOM.dll
MOD - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
MOD - [2007.02.09 03:22:52 | 000,022,723 | ---- | M] () -- J:\WINDOWS\system32\ml163sl3.dll
MOD - [2006.12.28 15:05:14 | 000,196,608 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoumain.exe
MOD - [2006.12.28 06:00:10 | 000,098,304 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Amoures.dll
MOD - [2006.12.28 05:59:48 | 000,032,768 | ---- | M] () -- J:\WINDOWS\system32\Amhooker.dll
MOD - [2005.10.18 15:30:14 | 000,077,824 | ---- | M] () -- J:\Programme\Saitek\Software\SAILNKU.dll
MOD - [2005.10.18 15:24:32 | 000,147,456 | ---- | M] () -- J:\Programme\Saitek\Software\SAICFG.dll
MOD - [2004.12.14 04:28:26 | 001,212,416 | ---- | M] () -- J:\Programme\Adobe\Acrobat 7.0\Distillr\AdistRes.DEU
MOD - [2004.11.17 16:49:06 | 004,603,904 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\qt-mt332.dll
MOD - [2004.05.11 15:51:56 | 000,798,720 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\libeay32.dll
MOD - [2004.05.11 15:51:56 | 000,155,648 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\ssleay32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- J:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2012.06.25 00:07:32 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- J:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.23 11:54:34 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- J:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) [Auto | Running] -- J:\Programme\Norton 360\Engine\6.2.1.5\ccSvcHst.exe -- (N360)
SRV - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) [Auto | Running] -- J:\WINDOWS\system32\HPSIsvc.exe -- (HPSIService)
SRV - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () [Auto | Running] -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) [Auto | Running] -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe -- (HPM1210RcvFaxSrvc)
SRV - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Running] -- J:\WINDOWS\system32\LGScsiCommandService.exe -- (LGScsiCommandService)
SRV - [2009.05.13 00:35:56 | 000,095,896 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009.03.05 20:24:32 | 000,069,632 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- J:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) [On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe -- (Asset Management Daemon)
SRV - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
SRV - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) [Auto | Running] -- J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe -- (FinePrint Dispatcher v5)
SRV - [2005.08.24 03:29:52 | 000,118,272 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- J:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | Auto | Stopped] -- J:\WINDOWS\system32\Drivers\SSPORT.sys -- (SSPORT)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012.07.05 20:49:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- J:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2012.06.19 02:01:14 | 000,821,920 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120619.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012.06.18 20:26:27 | 000,369,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120704.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012.05.31 16:45:18 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012.05.31 16:45:18 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012.05.16 19:25:35 | 001,589,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120704.017\NAVEX15.SYS -- (NAVEX15)
DRV - [2012.05.16 19:25:35 | 000,087,928 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120704.017\NAVENG.SYS -- (NAVENG)
DRV - [2012.05.06 19:34:37 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.29 08:03:27 | 000,574,072 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtsp.sys -- (SRTSP)
DRV - [2012.03.29 08:03:27 | 000,032,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2012.03.29 00:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symtdi.sys -- (SYMTDI)
DRV - [2012.03.29 00:28:30 | 000,905,336 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symefa.sys -- (SymEFA)
DRV - [2012.03.29 00:28:26 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symds.sys -- (SymDS)
DRV - [2012.03.29 00:06:26 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ironx86.sys -- (SymIRON)
DRV - [2011.11.29 16:44:14 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ccsetx86.sys -- (ccSet_N360)
DRV - [2011.03.18 18:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- J:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2008.11.19 17:09:10 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008.11.19 17:09:08 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008.11.19 17:09:08 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008.06.27 05:24:56 | 004,742,656 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.06.16 09:08:42 | 000,109,184 | R--- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.03.05 10:11:00 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- J:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2006.12.28 16:07:34 | 000,013,824 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Amusbprt.sys -- (Amusbprt)
DRV - [2006.12.28 16:02:22 | 000,008,704 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\Amfilter.sys -- (Amfilter)
DRV - [2006.11.16 17:20:48 | 000,015,920 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\PdiPorts.sys -- (PdiPorts)
DRV - [2006.07.27 13:49:34 | 000,035,200 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2006.07.27 13:49:34 | 000,013,824 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2006.07.27 13:49:27 | 000,176,640 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiH075C.sys -- (SaiH075C)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- J:\WINDOWS\system32\giveio.sys -- (giveio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\..\SearchScopes,DefaultScope = {0D7562AE-8EF6-416d-A838-AB665251703A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=6
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.1.3
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: J:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: J:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: J:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: J:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: J:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: J:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: J:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: J:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012.05.06 19:38:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012.07.05 20:49:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: J:\Programme\Mozilla Firefox\components [2012.06.25 00:07:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Firefox\plugins [2012.06.05 22:24:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: J:\Programme\Mozilla Thunderbird\components [2012.06.26 22:08:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Thunderbird\plugins
 
[2009.11.21 10:49:28 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Extensions
[2012.05.02 19:14:27 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions
[2010.05.18 12:43:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.06.22 21:29:50 | 000,002,448 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\searchplugins\safesearch.xml
[2012.07.02 15:05:23 | 000,000,000 | ---D | M] (No name found) -- J:\Programme\Mozilla Firefox\extensions
[2012.07.02 15:05:27 | 000,000,000 | ---D | M] (Java Console) -- J:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.07.05 20:49:40 | 000,000,000 | ---D | M] (Norton Toolbar) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\COFFPLGN
[2012.05.06 19:38:22 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPLGN
[2012.05.13 13:36:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- J:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.06.25 00:07:33 | 000,085,472 | ---- | M] (Mozilla Foundation) -- J:\Programme\mozilla firefox\components\browsercomps.dll
[2012.06.25 00:07:28 | 000,001,392 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.25 00:07:28 | 000,002,252 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.06.25 00:07:28 | 000,001,153 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.30 17:35:34 | 000,002,048 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\fcmdSrch.xml
[2012.06.25 00:07:28 | 000,006,805 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2009.10.01 16:35:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice124.xml
[2009.10.21 18:31:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice133.xml
[2012.06.25 00:07:28 | 000,001,178 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.25 00:07:28 | 000,001,105 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2008.04.14 14:00:00 | 000,000,820 | ---- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - J:\Programme\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - J:\Programme\Norton 360\Engine\6.2.1.5\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - J:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] J:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] J:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] J:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] J:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXUpdate] J:\Programme\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DT LGE] J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [facemoods] J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [FinePrint Dispatcher v5] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] J:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] J:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] J:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] J:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Profiler] J:\Programme\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [SaiMfd] J:\Programme\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [Samsung PanelMgr] J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SoundMan] J:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WheelMouse] J:\Programme\OCZ Technology\Mouse\Amoumain.exe ()
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - Startup: J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\Autostart\SpeedFan.lnk = J:\Programme\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1236273297031 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF80DD1E-FD72-4F1B-AB97-85A9EBB1B389}: NameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (J:\WINDOWS\system32\userinit.exe) - J:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.05 18:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.09.24 23:37:50 | 000,000,041 | R--- | M] () - I:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.03 22:12:21 | 000,000,000 | ---D | C] -- J:\Programme\ESET
[2012.07.02 10:56:27 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Malwarebytes
[2012.07.02 10:56:17 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- J:\WINDOWS\System32\drivers\mbam.sys
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.06.05 22:24:46 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\QuickTime
[2012.06.05 22:24:14 | 000,000,000 | ---D | C] -- J:\Programme\QuickTime
[2012.06.05 22:24:12 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Apple Computer
[2010.08.12 23:24:06 | 000,047,360 | ---- | C] (VSO Software) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.sys
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.05 21:10:00 | 000,001,090 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.05 20:54:15 | 000,000,884 | ---- | M] () -- J:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.07.05 20:50:05 | 000,212,641 | ---- | M] () -- J:\WINDOWS\System32\nvapps.xml
[2012.07.05 20:50:02 | 000,002,422 | ---- | M] () -- J:\WINDOWS\System32\wpa.dbl
[2012.07.05 20:48:56 | 000,002,048 | --S- | M] () -- J:\WINDOWS\bootstat.dat
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2012.07.03 22:19:01 | 000,000,276 | ---- | M] () -- J:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.07.02 13:15:03 | 000,302,592 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\gcgukm0o.exe
[2012.07.02 11:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2012.07.02 10:56:21 | 000,000,762 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 09:10:00 | 000,001,086 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.26 19:13:29 | 000,000,069 | ---- | M] () -- J:\WINDOWS\NeroDigital.ini
[2012.06.26 15:28:27 | 000,122,368 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.14 18:52:34 | 000,152,384 | ---- | M] () -- J:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.13 23:31:36 | 000,517,474 | ---- | M] () -- J:\WINDOWS\System32\perfh007.dat
[2012.06.13 23:31:36 | 000,494,148 | ---- | M] () -- J:\WINDOWS\System32\perfh009.dat
[2012.06.13 23:31:36 | 000,101,628 | ---- | M] () -- J:\WINDOWS\System32\perfc007.dat
[2012.06.13 23:31:36 | 000,084,692 | ---- | M] () -- J:\WINDOWS\System32\perfc009.dat
[2012.06.13 23:20:30 | 000,001,374 | ---- | M] () -- J:\WINDOWS\imsins.BAK
[2012.06.05 22:24:46 | 000,001,590 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.06.05 22:08:27 | 000,157,037 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\bezahlen Google.jpg
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.02 13:15:01 | 000,302,592 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\gcgukm0o.exe
[2012.07.02 10:56:21 | 000,000,762 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.05 22:24:46 | 000,001,590 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.06.05 22:08:27 | 000,157,037 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\bezahlen Google.jpg
[2012.06.04 20:59:16 | 011,567,104 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Sandra.mdb
[2012.06.04 19:50:49 | 000,000,064 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sandra.ldb
[2012.05.26 11:23:30 | 000,109,001 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2011_Sieg_Andreas_und_Sieg_Gitta.elfo
[2012.02.15 08:58:58 | 000,003,072 | ---- | C] () -- J:\WINDOWS\System32\iacenc.dll
[2011.12.13 10:07:09 | 000,053,760 | R--- | C] () -- J:\WINDOWS\System32\HPM1210SMs.dll
[2011.12.13 10:07:08 | 001,265,664 | ---- | C] () -- J:\WINDOWS\System32\HPM1210SM.exe
[2011.12.13 10:07:08 | 000,163,840 | ---- | C] () -- J:\WINDOWS\System32\HPM1210LM.DLL
[2011.12.13 10:07:04 | 000,176,128 | R--- | C] () -- J:\WINDOWS\System32\m1210nwia.dll
[2011.12.13 09:41:17 | 000,284,160 | ---- | C] () -- J:\WINDOWS\System32\mvhlewsi.DLL
[2011.09.20 15:44:19 | 000,101,876 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2010_Sieg_Andreas_und_Sieg_Gitta.elfo
[2011.06.15 23:23:19 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011.06.15 23:18:18 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010.08.12 23:24:06 | 000,087,608 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\inst.exe
[2010.08.12 23:24:06 | 000,007,887 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.cat
[2010.08.12 23:24:06 | 000,001,144 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.inf
[2010.03.18 21:22:30 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\$_hpcst$.hpc
[2010.02.07 16:30:27 | 000,131,919 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\2009.elfo
[2009.12.01 23:04:06 | 000,122,368 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.11.21 10:39:43 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\$_hpcst$.hpc
[2009.03.06 23:50:53 | 000,000,040 | -HS- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2009.03.05 21:03:58 | 000,001,024 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\.rnd
[2009.03.05 18:48:16 | 000,049,152 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\index.dat
 
========== LOP Check ==========
 
[2011.09.20 11:40:18 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\elsterformular
[2010.09.12 09:40:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Fighters
[2009.12.11 18:30:16 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SlySoft
[2009.06.26 17:48:39 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2009.03.05 21:06:25 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.09.12 09:40:29 | 000,000,000 | -H-D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{41E385AC-E411-4D65-9CAE-35076FE3CCA3}
[2010.02.16 20:15:04 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2010.10.15 21:18:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Amazon
[2010.01.04 19:21:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\diginet
[2009.11.21 10:37:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\DisplayTune
[2012.05.26 10:14:56 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\elsterformular
[2011.10.31 09:00:14 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
[2010.09.12 09:40:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Fighters
[2011.01.30 20:54:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TeamViewer
[2012.05.14 10:03:25 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Thunderbird
[2009.12.11 18:31:09 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TuneUp Software
[2010.08.12 23:24:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Vso
[2012.03.30 17:15:00 | 000,000,412 | ---- | M] () -- J:\WINDOWS\Tasks\1-Klick-Wartung.job
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2012.05.06 12:43:21 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2012.07.02 11:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2011.10.01 23:30:33 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 24 bytes -> J:\WINDOWS:AA0B7C486F752FC7

< End of report >

--- --- ---


Und, was sagt der Meister?

Gruß
gr.nagus

cosinus 05.07.2012 20:58

Code:

Scan Mode: Current user
Du hast den Haken bei alle Benutzer vergessen :(
Und ein CustomScan war das auch nicht! http://cosgan.de/images/midi/boese/a040.gif

gr.nagus 06.07.2012 12:51

Hallo Meister der Winkelfunktion,

ja mit mir hat man´s nicht leicht. :balla:
Ich war wohl schon zumüde um die Aufgabenstellung zu verstehen.

Ein neuer Versuch:

OTL Logfile:
Code:

OTL logfile created on: 06.07.2012 13:38:06 - Run 3
OTL by OldTimer - Version 3.2.53.1    Folder = J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,46 Gb Available Physical Memory | 75,73% Memory free
8,34 Gb Paging File | 7,50 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): J:\pagefile.sys 2046 4092K:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Programme
Drive C: | 5,90 Gb Total Space | 4,76 Gb Free Space | 80,71% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,06 Gb Free Space | 45,30% Space Free | Partition Type: NTFS
Drive E: | 39,01 Gb Total Space | 5,71 Gb Free Space | 14,64% Space Free | Partition Type: NTFS
Drive F: | 27,46 Gb Total Space | 24,29 Gb Free Space | 88,44% Space Free | Partition Type: NTFS
Drive G: | 35,64 Gb Total Space | 17,03 Gb Free Space | 47,80% Space Free | Partition Type: NTFS
Drive I: | 3,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive J: | 29,79 Gb Total Space | 3,87 Gb Free Space | 12,99% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 11,53 Gb Free Space | 77,41% Space Free | Partition Type: NTFS
Drive L: | 21,05 Gb Total Space | 8,79 Gb Free Space | 41,75% Space Free | Partition Type: NTFS
 
Computer Name: KUSCHELBAER | User Name: Kuschelbär | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.02 13:12:31 | 000,595,968 | ---- | M] (OldTimer Tools) -- J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) -- J:\Programme\Norton 360\Engine\6.2.1.5\ccsvchst.exe
PRC - [2012.01.18 14:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) -- J:\WINDOWS\system32\HPSIsvc.exe
PRC - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
PRC - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) -- J:\WINDOWS\system32\LGScsiCommandService.exe
PRC - [2008.06.24 17:06:06 | 001,840,424 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
PRC - [2008.06.18 12:01:56 | 000,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- J:\WINDOWS\SoundMan.exe
PRC - [2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- J:\WINDOWS\explorer.exe
PRC - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
PRC - [2007.10.11 16:19:44 | 000,308,224 | ---- | M] (Portrait Displays, Inc) -- J:\Programme\Portrait Displays\forteManager\dthtml.exe
PRC - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
PRC - [2007.10.11 16:17:02 | 000,110,592 | ---- | M] (Portrait Displays Inc.) -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\HookManager.exe
PRC - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) -- J:\WINDOWS\system32\spool\drivers\w32x86\3\fpdisp5a.exe
PRC - [2005.11.03 12:09:50 | 000,126,976 | ---- | M] (Saitek) -- J:\Programme\Saitek\Software\SaiMfd.exe
PRC - [2004.12.14 03:12:02 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- J:\Programme\Adobe\Acrobat 7.0\Distillr\acrotray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.01.11 01:25:48 | 000,096,112 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.01.11 01:25:06 | 001,230,704 | ---- | M] () -- J:\Programme\DivX\DivX Update\DivXUpdate.exe
MOD - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
MOD - [2009.11.20 15:48:58 | 000,176,128 | R--- | M] () -- J:\WINDOWS\system32\m1210nwia.dll
MOD - [2009.11.20 14:42:08 | 000,163,840 | ---- | M] () -- J:\WINDOWS\system32\HPM1210LM.DLL
MOD - [2009.11.20 14:42:08 | 000,069,632 | ---- | M] () -- J:\WINDOWS\system32\spool\prtprocs\w32x86\HPM1210PP.dll
MOD - [2009.05.07 03:38:14 | 000,020,480 | R--- | M] () -- J:\WINDOWS\system32\SendScsiCmd.dll
MOD - [2009.03.13 11:30:44 | 000,109,096 | ---- | M] () -- J:\Programme\GIGABYTE\EnergySaver\ycc.dll
MOD - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
MOD - [2007.10.11 16:17:54 | 000,167,936 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DThook.dll
MOD - [2007.10.11 16:17:48 | 000,077,824 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\CC\gui.dll
MOD - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
MOD - [2007.10.11 16:16:58 | 000,102,400 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\PresetsCOM.dll
MOD - [2007.06.29 06:17:56 | 000,520,192 | ---- | M] () -- J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
MOD - [2007.02.09 03:22:52 | 000,022,723 | ---- | M] () -- J:\WINDOWS\system32\ml163sl3.dll
MOD - [2006.11.27 06:13:32 | 000,028,672 | ---- | M] () -- J:\Programme\OCZ Technology\Mouse\Setuphk.dll
MOD - [2004.12.14 04:28:26 | 001,212,416 | ---- | M] () -- J:\Programme\Adobe\Acrobat 7.0\Distillr\AdistRes.DEU
MOD - [2004.11.17 16:49:06 | 004,603,904 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\qt-mt332.dll
MOD - [2004.05.11 15:51:56 | 000,798,720 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\libeay32.dll
MOD - [2004.05.11 15:51:56 | 000,155,648 | ---- | M] () -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\ssleay32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- J:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2012.06.25 00:07:32 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- J:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.23 11:54:34 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- J:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.28 01:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) [Auto | Running] -- J:\Programme\Norton 360\Engine\6.2.1.5\ccSvcHst.exe -- (N360)
SRV - [2009.12.04 08:49:40 | 000,099,896 | R--- | M] (HP) [Auto | Running] -- J:\WINDOWS\system32\HPSIsvc.exe -- (HPSIService)
SRV - [2009.12.02 19:40:40 | 000,068,136 | ---- | M] () [Auto | Running] -- J:\Programme\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2009.11.20 15:14:02 | 000,245,760 | ---- | M] (Marvell) [Auto | Running] -- J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe -- (HPM1210RcvFaxSrvc)
SRV - [2009.08.02 06:43:30 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Running] -- J:\WINDOWS\system32\LGScsiCommandService.exe -- (LGScsiCommandService)
SRV - [2009.05.13 00:35:56 | 000,095,896 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009.03.05 20:24:32 | 000,069,632 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- J:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) [On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007.10.11 16:20:14 | 000,114,688 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe -- (Asset Management Daemon)
SRV - [2007.10.11 16:17:48 | 000,065,536 | ---- | M] () [Auto | Running] -- J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
SRV - [2006.12.08 22:10:58 | 000,507,904 | ---- | M] (FinePrint Software, LLC) [Auto | Running] -- J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe -- (FinePrint Dispatcher v5)
SRV - [2005.08.24 03:29:52 | 000,118,272 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- J:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | Auto | Stopped] -- J:\WINDOWS\system32\Drivers\SSPORT.sys -- (SSPORT)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012.07.06 13:21:24 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- J:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2012.06.19 02:01:14 | 000,821,920 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120619.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012.06.18 20:26:27 | 000,369,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120705.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012.05.31 16:45:18 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012.05.31 16:45:18 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012.05.16 19:25:35 | 001,589,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120705.036\NAVEX15.SYS -- (NAVEX15)
DRV - [2012.05.16 19:25:35 | 000,087,928 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120705.036\NAVENG.SYS -- (NAVENG)
DRV - [2012.05.06 19:34:37 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.29 08:03:27 | 000,574,072 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtsp.sys -- (SRTSP)
DRV - [2012.03.29 08:03:27 | 000,032,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2012.03.29 00:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symtdi.sys -- (SYMTDI)
DRV - [2012.03.29 00:28:30 | 000,905,336 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symefa.sys -- (SymEFA)
DRV - [2012.03.29 00:28:26 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\symds.sys -- (SymDS)
DRV - [2012.03.29 00:06:26 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ironx86.sys -- (SymIRON)
DRV - [2011.11.29 16:44:14 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\N360\0602010.005\ccsetx86.sys -- (ccSet_N360)
DRV - [2011.03.18 18:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- J:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2008.11.19 17:09:10 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008.11.19 17:09:08 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008.11.19 17:09:08 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- J:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008.06.27 05:24:56 | 004,742,656 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.06.16 09:08:42 | 000,109,184 | R--- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.03.05 10:11:00 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- J:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2006.12.28 16:07:34 | 000,013,824 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\Amusbprt.sys -- (Amusbprt)
DRV - [2006.12.28 16:02:22 | 000,008,704 | R--- | M] (OCZ Technology Co.,Ltd.) [Kernel | System | Running] -- J:\WINDOWS\system32\drivers\Amfilter.sys -- (Amfilter)
DRV - [2006.11.16 17:20:48 | 000,015,920 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\PdiPorts.sys -- (PdiPorts)
DRV - [2006.07.27 13:49:34 | 000,035,200 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2006.07.27 13:49:34 | 000,013,824 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2006.07.27 13:49:27 | 000,176,640 | R--- | M] (Saitek) [Kernel | On_Demand | Running] -- J:\WINDOWS\system32\drivers\SaiH075C.sys -- (SaiH075C)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- J:\WINDOWS\system32\giveio.sys -- (giveio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes,DefaultScope = {0D7562AE-8EF6-416d-A838-AB665251703A}
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=6
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.1.3
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: J:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: J:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: J:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: J:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: J:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: J:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: J:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: J:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: J:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012.05.06 19:38:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012.07.06 13:22:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: J:\Programme\Mozilla Firefox\components [2012.06.25 00:07:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Firefox\plugins [2012.06.05 22:24:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: J:\Programme\Mozilla Thunderbird\components [2012.06.26 22:08:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: J:\Programme\Mozilla Thunderbird\plugins
 
[2009.11.21 10:49:28 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Extensions
[2012.05.02 19:14:27 | 000,000,000 | ---D | M] (No name found) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions
[2010.05.18 12:43:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.06.22 21:29:50 | 000,002,448 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\searchplugins\safesearch.xml
[2012.07.02 15:05:23 | 000,000,000 | ---D | M] (No name found) -- J:\Programme\Mozilla Firefox\extensions
[2012.07.02 15:05:27 | 000,000,000 | ---D | M] (Java Console) -- J:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.07.06 13:22:09 | 000,000,000 | ---D | M] (Norton Toolbar) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\COFFPLGN
[2012.05.06 19:38:22 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- J:\DOKUMENTE UND EINSTELLUNGEN\ALL USERS\ANWENDUNGSDATEN\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPLGN
[2012.05.13 13:36:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- J:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012.06.25 00:07:33 | 000,085,472 | ---- | M] (Mozilla Foundation) -- J:\Programme\mozilla firefox\components\browsercomps.dll
[2012.06.25 00:07:28 | 000,001,392 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.25 00:07:28 | 000,002,252 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.06.25 00:07:28 | 000,001,153 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.30 17:35:34 | 000,002,048 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\fcmdSrch.xml
[2012.06.25 00:07:28 | 000,006,805 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2009.10.01 16:35:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice124.xml
[2009.10.21 18:31:38 | 000,002,400 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\seekservice133.xml
[2012.06.25 00:07:28 | 000,001,178 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.25 00:07:28 | 000,001,105 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2008.04.14 14:00:00 | 000,000,820 | ---- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - J:\Programme\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - J:\Programme\Norton 360\Engine\6.2.1.5\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - J:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
O3 - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - J:\Programme\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] J:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] J:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] J:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] J:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXUpdate] J:\Programme\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DT LGE] J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [facemoods] J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com)
O4 - HKLM..\Run: [FinePrint Dispatcher v5] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] J:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] J:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] J:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] J:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Profiler] J:\Programme\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [SaiMfd] J:\Programme\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [Samsung PanelMgr] J:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SoundMan] J:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] J:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WheelMouse] J:\Programme\OCZ Technology\Mouse\Amoumain.exe ()
O4 - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - Startup: J:\Dokumente und Einstellungen\Kuschelbär\Startmenü\Programme\Autostart\SpeedFan.lnk = J:\Programme\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - J:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1236273297031 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF80DD1E-FD72-4F1B-AB97-85A9EBB1B389}: NameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - J:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (J:\WINDOWS\system32\userinit.exe) - J:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: J:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.05 18:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.09.24 23:37:50 | 000,000,041 | R--- | M] () - I:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
 
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {0E811BDB-CFC4-0AB4-02FF-63966E6AAE5D} - Internet Explorer
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection J:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection J:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - J:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - J:\WINDOWS\system32\Rundll32.exe J:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - J:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - J:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - J:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "J:\WINDOWS\system32\rundll32.exe" "J:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
Drivers32: msacm.iac2 - J:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - J:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - J:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - J:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - J:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - J:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - J:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - J:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - J:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - J:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - J:\WINDOWS\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.03 22:12:21 | 000,000,000 | ---D | C] -- J:\Programme\ESET
[2012.07.02 10:56:27 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Malwarebytes
[2012.07.02 10:56:17 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- J:\WINDOWS\System32\drivers\mbam.sys
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.07.02 10:56:17 | 000,000,000 | ---D | C] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.08.12 23:24:06 | 000,047,360 | ---- | C] (VSO Software) -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.sys
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.06 13:22:32 | 000,212,641 | ---- | M] () -- J:\WINDOWS\System32\nvapps.xml
[2012.07.06 13:22:29 | 000,002,422 | ---- | M] () -- J:\WINDOWS\System32\wpa.dbl
[2012.07.06 13:21:11 | 000,002,048 | --S- | M] () -- J:\WINDOWS\bootstat.dat
[2012.07.05 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2012.07.05 23:10:00 | 000,001,090 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.05 22:54:00 | 000,000,884 | ---- | M] () -- J:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012.07.03 22:19:01 | 000,000,276 | ---- | M] () -- J:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.07.02 13:15:03 | 000,302,592 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\gcgukm0o.exe
[2012.07.02 11:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2012.07.02 10:56:21 | 000,000,762 | ---- | M] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 09:10:00 | 000,001,086 | ---- | M] () -- J:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.26 19:13:29 | 000,000,069 | ---- | M] () -- J:\WINDOWS\NeroDigital.ini
[2012.06.26 15:28:27 | 000,122,368 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.14 18:52:34 | 000,152,384 | ---- | M] () -- J:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.13 23:31:36 | 000,517,474 | ---- | M] () -- J:\WINDOWS\System32\perfh007.dat
[2012.06.13 23:31:36 | 000,494,148 | ---- | M] () -- J:\WINDOWS\System32\perfh009.dat
[2012.06.13 23:31:36 | 000,101,628 | ---- | M] () -- J:\WINDOWS\System32\perfc007.dat
[2012.06.13 23:31:36 | 000,084,692 | ---- | M] () -- J:\WINDOWS\System32\perfc009.dat
[2012.06.13 23:20:30 | 000,001,374 | ---- | M] () -- J:\WINDOWS\imsins.BAK
[5 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[3 J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.02 13:15:01 | 000,302,592 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Desktop\gcgukm0o.exe
[2012.07.02 10:56:21 | 000,000,762 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.04 20:59:16 | 011,567,104 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Sandra.mdb
[2012.06.04 19:50:49 | 000,000,064 | ---- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sandra.ldb
[2012.05.26 11:23:30 | 000,109,001 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2011_Sieg_Andreas_und_Sieg_Gitta.elfo
[2012.02.15 08:58:58 | 000,003,072 | ---- | C] () -- J:\WINDOWS\System32\iacenc.dll
[2011.12.13 10:07:09 | 000,053,760 | R--- | C] () -- J:\WINDOWS\System32\HPM1210SMs.dll
[2011.12.13 10:07:08 | 001,265,664 | ---- | C] () -- J:\WINDOWS\System32\HPM1210SM.exe
[2011.12.13 10:07:08 | 000,163,840 | ---- | C] () -- J:\WINDOWS\System32\HPM1210LM.DLL
[2011.12.13 10:07:04 | 000,176,128 | R--- | C] () -- J:\WINDOWS\System32\m1210nwia.dll
[2011.12.13 09:41:17 | 000,284,160 | ---- | C] () -- J:\WINDOWS\System32\mvhlewsi.DLL
[2011.09.20 15:44:19 | 000,101,876 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\ESt2010_Sieg_Andreas_und_Sieg_Gitta.elfo
[2011.06.15 23:23:19 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011.06.15 23:18:18 | 000,001,940 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010.08.12 23:24:06 | 000,087,608 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\inst.exe
[2010.08.12 23:24:06 | 000,007,887 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.cat
[2010.08.12 23:24:06 | 000,001,144 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\pcouffin.inf
[2010.03.18 21:22:30 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\$_hpcst$.hpc
[2010.02.07 16:30:27 | 000,131,919 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\2009.elfo
[2009.12.01 23:04:06 | 000,122,368 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.11.21 10:39:43 | 000,002,528 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\$_hpcst$.hpc
[2009.03.06 23:50:53 | 000,000,040 | -HS- | C] () -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2009.03.05 21:03:58 | 000,001,024 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\.rnd
[2009.03.05 18:48:16 | 000,049,152 | ---- | C] () -- J:\Dokumente und Einstellungen\Kuschelbär\index.dat
 
========== LOP Check ==========
 
[2009.11.21 12:42:53 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\DisplayTune
[2011.09.20 11:40:18 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\elsterformular
[2010.09.12 09:40:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Fighters
[2009.12.11 18:30:16 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SlySoft
[2009.06.26 17:48:39 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2009.03.05 21:06:25 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.09.12 09:40:29 | 000,000,000 | -H-D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{41E385AC-E411-4D65-9CAE-35076FE3CCA3}
[2010.02.16 20:15:04 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2009.11.21 10:57:19 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\e\Anwendungsdaten\DisplayTune
[2010.10.15 21:18:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Amazon
[2010.01.04 19:21:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\diginet
[2009.11.21 10:37:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\DisplayTune
[2012.05.26 10:14:56 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\elsterformular
[2011.10.31 09:00:14 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
[2010.09.12 09:40:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Fighters
[2011.01.30 20:54:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TeamViewer
[2012.05.14 10:03:25 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Thunderbird
[2009.12.11 18:31:09 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TuneUp Software
[2010.08.12 23:24:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Vso
[2011.11.02 13:44:06 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Spatzl\Anwendungsdaten\facemoods.com
[2012.03.30 17:15:00 | 000,000,412 | ---- | M] () -- J:\WINDOWS\Tasks\1-Klick-Wartung.job
[2012.07.05 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2012.05.06 12:43:21 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2012.07.02 11:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2011.10.01 23:30:33 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2012.07.04 23:29:00 | 000,000,470 | ---- | M] () -- J:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.03.23 20:33:02 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Adobe
[2009.11.21 11:56:54 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\AdobeUM
[2010.10.15 21:18:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Amazon
[2012.04.09 08:32:55 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Apple Computer
[2009.12.16 18:49:03 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\CyberLink
[2010.01.04 19:21:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\diginet
[2009.11.21 10:37:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\DisplayTune
[2010.05.29 00:01:58 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\DivX
[2012.01.16 15:32:21 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\dvdcss
[2012.05.26 10:14:56 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\elsterformular
[2011.10.31 09:00:14 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
[2010.09.12 09:40:29 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Fighters
[2009.12.05 18:58:04 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Google
[2009.12.31 16:45:43 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Help
[2011.12.13 10:04:02 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\HP
[2009.11.21 10:37:32 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Identities
[2009.05.22 18:08:45 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Macromedia
[2012.07.02 10:56:27 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Malwarebytes
[2012.01.19 15:33:56 | 000,000,000 | --SD | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Microsoft
[2009.11.21 10:49:28 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla
[2009.12.11 18:17:41 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Nero
[2009.11.21 13:08:25 | 000,000,000 | RH-D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\SecuROM
[2009.11.21 10:51:16 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Sun
[2011.01.30 20:54:51 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TeamViewer
[2012.05.14 10:03:25 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Thunderbird
[2009.12.11 18:31:09 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\TuneUp Software
[2012.07.02 20:19:58 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\vlc
[2010.08.12 23:24:13 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Vso
[2011.10.31 19:45:35 | 000,000,000 | ---D | M] -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\WinRAR
 
< %APPDATA%\*.exe /s >
[2010.08.12 23:24:13 | 000,087,608 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\inst.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.04.14 14:00:00 | 020,108,202 | ---- | M] () .cab file -- J:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.04.14 14:00:00 | 020,108,202 | ---- | M] () .cab file -- J:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- J:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- J:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- J:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- J:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- J:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- J:\WINDOWS\system32\eventlog.dll
 
< MD5 for: NETLOGON.DLL  >
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- J:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- J:\WINDOWS\system32\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.14 14:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- J:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 14:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- J:\WINDOWS\system32\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.04.14 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- J:\WINDOWS\system32\dllcache\user32.dll
[2008.04.14 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- J:\WINDOWS\system32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.04.14 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- J:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- J:\WINDOWS\system32\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- J:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 14:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- J:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 14:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- J:\WINDOWS\system32\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.04.14 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- J:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2008.04.14 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- J:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2009.03.05 19:21:23 | 000,094,208 | ---- | M] () -- J:\WINDOWS\System32\config\default.sav
[2009.03.05 19:21:23 | 001,089,536 | ---- | M] () -- J:\WINDOWS\System32\config\software.sav
[2009.03.05 19:21:23 | 000,475,136 | ---- | M] () -- J:\WINDOWS\System32\config\system.sav
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[5 J:\WINDOWS\system32\*.tmp files -> J:\WINDOWS\system32\*.tmp -> ]
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 24 bytes -> J:\WINDOWS:AA0B7C486F752FC7

< End of report >

--- --- ---


Gruß
gr.nagus

cosinus 06.07.2012 14:06

Ja nun ist es richtig :)

Code:

Drive C: | 5,90 Gb Total Space | 4,76 Gb Free Space | 80,71% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,06 Gb Free Space | 45,30% Space Free | Partition Type: NTFS
Drive E: | 39,01 Gb Total Space | 5,71 Gb Free Space | 14,64% Space Free | Partition Type: NTFS
Drive F: | 27,46 Gb Total Space | 24,29 Gb Free Space | 88,44% Space Free | Partition Type: NTFS
Drive G: | 35,64 Gb Total Space | 17,03 Gb Free Space | 47,80% Space Free | Partition Type: NTFS
Drive I: | 3,36 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive J: | 29,79 Gb Total Space | 3,87 Gb Free Space | 12,99% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 11,53 Gb Free Space | 77,41% Space Free | Partition Type: NTFS
Drive L: | 21,05 Gb Total Space | 8,79 Gb Free Space | 41,75% Space Free | Partition Type: NTFS

Sage mir mal, was willst du mit so vielen kleinen Splitter-Partitionen? :wtf:
Zur logischen Ordnung gibt es doch Verzeichnisse

gr.nagus 07.07.2012 08:16

Zitat:

Zitat von cosinus (Beitrag 858998)
Sage mir mal, was willst du mit so vielen kleinen Splitter-Partitionen? :wtf:
Zur logischen Ordnung gibt es doch Verzeichnisse

Ja, einmal sind es 3 Festplatten 2 kleine SSD´s, und eine 160er Platte. Die SSD´s sind später dazugekommen. Die Festplatte zu zerhackstücken ist noch so ne Angewohnheit aus Windows 98-Zeiten, wo ich alle 6 Monate neu installiert habe. Also einmal eine Systempartition wo nix anderes drauf sollte als das System, dann eine separate Partition für die Auslagerungsdatei (wegen Fragmentierung), dann eine für eigene Dateien damit die bei der Neuinstallation nicht weg sind und der Rest sollte so eine Art Ordungssystem sein.

Zugegeben, so wie das jetzt ist macht es keinen Sinn mehr. Wen ich mir demnächst eine große SSD hole, hat das ein Ende. Werde sicher auch bald auf Windows 7 umsteigen.

So, was ist jetzt mit den Bösewichten? Muss ich jetzt noch irgendwie... :kloppen:


Gruß
gr.nagus

cosinus 09.07.2012 10:01

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=DE&ver=6
FF - user.js - File not found
[2011.06.22 21:29:50 | 000,002,448 | ---- | M] () -- J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\searchplugins\safesearch.xml
[2011.10.30 17:35:34 | 000,002,048 | ---- | M] () -- J:\Programme\mozilla firefox\searchplugins\fcmdSrch.xml
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
O4 - HKLM..\Run: []  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1229272821-1770027372-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.05 18:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
@Alternate Data Stream - 24 bytes -> J:\WINDOWS:AA0B7C486F752FC7
:Files
J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

gr.nagus 09.07.2012 11:32

Hallo, habe ich gemacht wie beschrieben. Habe dann "Fix" gedruckt. Unten stand dann "killing in processes - DO NOT INTERRUPT"

Das ist ca. eine halbe Stunde so geblieben und nix ist passiert. System hing fest, habe dann ausgeschaltet.

Was nun?

Gruß
gr.nagus

cosinus 09.07.2012 13:01

Starte Windows neu im abgesicherten Modus (mit Netzwerktreibern nach Möglichkeit), manchmal hakt das Fixen mit OTL im normalen Modus aber sehr oft funktioniert der Fix im abgesicherte Modus.

gr.nagus 09.07.2012 19:27

Zitat:

Zitat von cosinus (Beitrag 860188)
Starte Windows neu im abgesicherten Modus (mit Netzwerktreibern nach Möglichkeit), manchmal hakt das Fixen mit OTL im normalen Modus aber sehr oft funktioniert der Fix im abgesicherte Modus.

Befehl ausgeführt!

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1229272821-1770027372-1177238915-1003\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1229272821-1770027372-1177238915-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.
J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\Mozilla\Firefox\Profiles\mc4vrqv5.default\searchplugins\safesearch.xml moved successfully.
J:\Programme\Mozilla Firefox\searchplugins\fcmdSrch.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}\ deleted successfully.
J:\Programme\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found.
Registry key HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer not found.
Registry value HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1229272821-1770027372-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\AUTOEXEC.BAT moved successfully.
ADS J:\WINDOWS:AA0B7C486F752FC7 deleted successfully.
========== FILES ==========
J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com\facemoods folder moved successfully.
J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
->Flash cache emptied: 84 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes
 
User: e
->Temp folder emptied: 583659 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 84 bytes
 
User: Kuschelbär
->Temp folder emptied: 17415355 bytes
->Temporary Internet Files folder emptied: 1392002 bytes
->Java cache emptied: 44958491 bytes
->FireFox cache emptied: 49251107 bytes
->Flash cache emptied: 98546 bytes
 
User: LocalService
->Temp folder emptied: 82513 bytes
->Temporary Internet Files folder emptied: 49286 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Spatzl
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 469 bytes
->Java cache emptied: 618662 bytes
->FireFox cache emptied: 168869038 bytes
->Flash cache emptied: 8833 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3713927 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1358745 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 275,00 mb
 
 
[EMPTYFLASH]
 
User: Administrator
->Flash cache emptied: 0 bytes
 
User: All Users
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: e
->Flash cache emptied: 0 bytes
 
User: Kuschelbär
->Flash cache emptied: 0 bytes
 
User: LocalService
 
User: NetworkService
 
User: Spatzl
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
J:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.53.1 log created on 07092012_202019

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Was hab ich jetzt eigentlich gemacht? :wtf:

Gruß
gr.nagus

cosinus 10.07.2012 10:40

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

gr.nagus 12.07.2012 06:35

Hallo Cosinus,

hier ist der Log:
Code:

# AdwCleaner v1.701 - Logfile created 07/12/2012 at 07:33:08
# Updated 02/07/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Kuschelbär - KUSCHELBAER
# Running from : J:\Dokumente und Einstellungen\Kuschelbär\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
Folder Found : J:\Dokumente und Einstellungen\Spatzl\Anwendungsdaten\facemoods.com
Folder Found : J:\Programme\facemoods.com

***** [Registry] *****

Key Found : HKCU\Software\facemoods.com
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd
Key Found : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Key Found : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Found : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Found : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\facemoods.com
Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{38EE5CEE-4B62-11D3-854F-00A0C9C898E7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8D670533-270B-4549-B19B-414FB9C6EBDB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}
Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [5441 octets] - [12/07/2012 07:33:08]

########## EOF - J:\AdwCleaner[R1].txt - [5569 octets] ##########

Gruß
gr.nagus

cosinus 12.07.2012 10:33

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

gr.nagus 12.07.2012 21:28

Hallo Cosinus,

wieder alles ausgeführt. Langsam werde ich zum Profi :rolleyes:

Code:

# AdwCleaner v1.701 - Logfile created 07/12/2012 at 22:22:06
# Updated 02/07/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Kuschelbär - KUSCHELBAER
# Running from : J:\Dokumente und Einstellungen\Kuschelbär\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : J:\Dokumente und Einstellungen\Kuschelbär\Anwendungsdaten\facemoods.com
Folder Deleted : J:\Dokumente und Einstellungen\Spatzl\Anwendungsdaten\facemoods.com
Folder Deleted : J:\Programme\facemoods.com

***** [Registry] *****

Key Deleted : HKCU\Software\facemoods.com
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.facemoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl
Key Deleted : HKLM\SOFTWARE\Classes\facemoods.xtrnl.1
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\facemoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\facemoods.com
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [facemoods]

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{38EE5CEE-4B62-11D3-854F-00A0C9C898E7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8D670533-270B-4549-B19B-414FB9C6EBDB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AD20D01C-C939-4DD2-8C55-56935A48987E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E95EAD3F-18C6-4304-9DC6-BD6FD8E11D37}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{12A5F606-B1EC-474C-83ED-95E99FD8058E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AD25754E-D76C-42B3-A335-2F81478B722F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4F05-9A6E-5D3B778EC567}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [5570 octets] - [12/07/2012 07:33:08]
AdwCleaner[S1].txt - [5612 octets] - [12/07/2012 22:22:06]

########## EOF - J:\AdwCleaner[S1].txt - [5740 octets] ##########

Wie viele Programme gibts denn noch, die was finden können?

Gruß
gr.nagus

cosinus 13.07.2012 11:06

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

gr.nagus 13.07.2012 11:29

Hey,

ich werde immer schneller! :singsing:

...auch wenn ich nicht weiß, was ich da eigentlich mache....

Code:

12:23:53.0156 3716        TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
12:23:53.0343 3716        ============================================================
12:23:53.0343 3716        Current date / time: 2012/07/13 12:23:53.0343
12:23:53.0343 3716        SystemInfo:
12:23:53.0343 3716       
12:23:53.0343 3716        OS Version: 5.1.2600 ServicePack: 3.0
12:23:53.0343 3716        Product type: Workstation
12:23:53.0343 3716        ComputerName: KUSCHELBAER
12:23:53.0343 3716        UserName: Kuschelbär
12:23:53.0343 3716        Windows directory: J:\WINDOWS
12:23:53.0343 3716        System windows directory: J:\WINDOWS
12:23:53.0343 3716        Processor architecture: Intel x86
12:23:53.0343 3716        Number of processors: 2
12:23:53.0343 3716        Page size: 0x1000
12:23:53.0343 3716        Boot type: Normal boot
12:23:53.0343 3716        ============================================================
12:23:56.0468 3716        Drive \Device\Harddisk1\DR1 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
12:23:56.0468 3716        Drive \Device\Harddisk2\DR2 - Size: 0x3B9C00000 (14.90 Gb), SectorSize: 0x200, Cylinders: 0x799, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
12:23:56.0468 3716        Drive \Device\Harddisk0\DR0 - Size: 0x773800000 (29.80 Gb), SectorSize: 0x200, Cylinders: 0xF32, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
12:23:56.0484 3716        ============================================================
12:23:56.0484 3716        \Device\Harddisk1\DR1:
12:23:56.0484 3716        MBR partitions:
12:23:56.0484 3716        \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xBCC043
12:23:56.0484 3716        \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0xBCC082, BlocksNum 0x4745B2C
12:23:56.0484 3716        \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x5311BED, BlocksNum 0x27FCB73
12:23:56.0500 3716        \Device\Harddisk1\DR1\Partition3: MBR, Type 0x7, StartLBA 0x7B0E79F, BlocksNum 0x4E036A5
12:23:56.0515 3716        \Device\Harddisk1\DR1\Partition4: MBR, Type 0x7, StartLBA 0xC911E83, BlocksNum 0x36ECC82
12:23:56.0515 3716        \Device\Harddisk1\DR1\Partition5: MBR, Type 0x7, StartLBA 0xFFFEB05, BlocksNum 0x2A19FBC
12:23:56.0515 3716        \Device\Harddisk2\DR2:
12:23:56.0515 3716        MBR partitions:
12:23:56.0515 3716        \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1DCC81A
12:23:56.0515 3716        \Device\Harddisk0\DR0:
12:23:56.0515 3716        MBR partitions:
12:23:56.0515 3716        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3B951B2
12:23:56.0515 3716        ============================================================
12:23:56.0546 3716        C: <-> \Device\Harddisk1\DR1\Partition0
12:23:56.0656 3716        D: <-> \Device\Harddisk1\DR1\Partition2
12:23:56.0687 3716        E: <-> \Device\Harddisk1\DR1\Partition3
12:23:56.0703 3716        F: <-> \Device\Harddisk1\DR1\Partition4
12:23:56.0734 3716        G: <-> \Device\Harddisk1\DR1\Partition1
12:23:56.0734 3716        J: <-> \Device\Harddisk0\DR0\Partition0
12:23:56.0734 3716        K: <-> \Device\Harddisk2\DR2\Partition0
12:23:56.0781 3716        L: <-> \Device\Harddisk1\DR1\Partition5
12:23:56.0781 3716        ============================================================
12:23:56.0781 3716        Initialize success
12:23:56.0781 3716        ============================================================
12:24:39.0187 0760        ============================================================
12:24:39.0187 0760        Scan started
12:24:39.0187 0760        Mode: Manual; SigCheck; TDLFS;
12:24:39.0187 0760        ============================================================
12:24:40.0390 0760        Abiosdsk - ok
12:24:40.0390 0760        abp480n5 - ok
12:24:40.0406 0760        ACPI            (ac407f1a62c3a300b4f2b5a9f1d55b2c) J:\WINDOWS\system32\DRIVERS\ACPI.sys
12:24:41.0250 0760        ACPI - ok
12:24:41.0250 0760        ACPIEC          (9e1ca3160dafb159ca14f83b1e317f75) J:\WINDOWS\system32\drivers\ACPIEC.sys
12:24:41.0312 0760        ACPIEC - ok
12:24:41.0312 0760        Adobe LM Service (6d182c31acf16213407f2768f1107fe3) J:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
12:24:41.0312 0760        Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
12:24:41.0312 0760        Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
12:24:41.0328 0760        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) J:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
12:24:41.0343 0760        AdobeFlashPlayerUpdateSvc - ok
12:24:41.0343 0760        adpu160m - ok
12:24:41.0343 0760        aec            (8bed39e3c35d6a489438b8141717a557) J:\WINDOWS\system32\drivers\aec.sys
12:24:41.0406 0760        aec - ok
12:24:41.0484 0760        AFD            (1e44bc1e83d8fd2305f8d452db109cf9) J:\WINDOWS\System32\drivers\afd.sys
12:24:41.0500 0760        AFD - ok
12:24:41.0500 0760        Aha154x - ok
12:24:41.0500 0760        aic78u2 - ok
12:24:41.0515 0760        aic78xx - ok
12:24:41.0515 0760        Alerter        (738d80cc01d7bc7584be917b7f544394) J:\WINDOWS\system32\alrsvc.dll
12:24:41.0562 0760        Alerter - ok
12:24:41.0578 0760        ALG            (190cd73d4984f94d823f9444980513e5) J:\WINDOWS\System32\alg.exe
12:24:41.0609 0760        ALG - ok
12:24:41.0609 0760        AliIde - ok
12:24:41.0609 0760        Amfilter        (0984b58956a211c3675d116bc2a750bc) J:\WINDOWS\system32\DRIVERS\Amfilter.sys
12:24:41.0609 0760        Amfilter ( UnsignedFile.Multi.Generic ) - warning
12:24:41.0609 0760        Amfilter - detected UnsignedFile.Multi.Generic (1)
12:24:41.0609 0760        amsint - ok
12:24:41.0625 0760        Amusbprt        (27d4ebb04adabbfec6352add579fa746) J:\WINDOWS\system32\DRIVERS\Amusbprt.sys
12:24:41.0625 0760        Amusbprt ( UnsignedFile.Multi.Generic ) - warning
12:24:41.0625 0760        Amusbprt - detected UnsignedFile.Multi.Generic (1)
12:24:41.0625 0760        AppMgmt        (d45960be52c3c610d361977057f98c54) J:\WINDOWS\System32\appmgmts.dll
12:24:41.0656 0760        AppMgmt - ok
12:24:41.0656 0760        asc - ok
12:24:41.0656 0760        asc3350p - ok
12:24:41.0671 0760        asc3550 - ok
12:24:41.0671 0760        aspnet_state    (776acefa0ca9df0faa51a5fb2f435705) J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
12:24:41.0687 0760        aspnet_state - ok
12:24:41.0687 0760        Asset Management Daemon (20adf8a7e99baab64bdca272fcfd0db2) J:\Programme\Gemeinsame Dateien\Portrait Displays\Plugins\AM\dtsslsrv.exe
12:24:41.0687 0760        Asset Management Daemon ( UnsignedFile.Multi.Generic ) - warning
12:24:41.0687 0760        Asset Management Daemon - detected UnsignedFile.Multi.Generic (1)
12:24:41.0687 0760        AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) J:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:24:41.0750 0760        AsyncMac - ok
12:24:41.0750 0760        atapi          (9f3a2f5aa6875c72bf062c712cfa2674) J:\WINDOWS\system32\DRIVERS\atapi.sys
12:24:41.0812 0760        atapi - ok
12:24:41.0812 0760        Atdisk - ok
12:24:41.0812 0760        Atmarpc        (9916c1225104ba14794209cfa8012159) J:\WINDOWS\system32\DRIVERS\atmarpc.sys
12:24:41.0875 0760        Atmarpc - ok
12:24:41.0875 0760        AudioSrv        (58ed0d5452df7be732193e7999c6b9a4) J:\WINDOWS\System32\audiosrv.dll
12:24:41.0921 0760        AudioSrv - ok
12:24:41.0937 0760        audstub        (d9f724aa26c010a217c97606b160ed68) J:\WINDOWS\system32\DRIVERS\audstub.sys
12:24:41.0984 0760        audstub - ok
12:24:41.0984 0760        Beep            (da1f27d85e0d1525f6621372e7b685e9) J:\WINDOWS\system32\drivers\Beep.sys
12:24:42.0046 0760        Beep - ok
12:24:42.0062 0760        BHDrvx86        (a9e111a358ac5f7eba7ac61e43fc6725) J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120711.002\BHDrvx86.sys
12:24:42.0109 0760        BHDrvx86 - ok
12:24:42.0109 0760        BITS            (d6f603772a789bb3228f310d650b8bd1) J:\WINDOWS\system32\qmgr.dll
12:24:42.0187 0760        BITS - ok
12:24:42.0187 0760        Browser        (b42057f06bbb98b31876c0b3f2b54e33) J:\WINDOWS\System32\browser.dll
12:24:42.0234 0760        Browser - ok
12:24:42.0250 0760        cbidf2k        (90a673fc8e12a79afbed2576f6a7aaf9) J:\WINDOWS\system32\drivers\cbidf2k.sys
12:24:42.0296 0760        cbidf2k - ok
12:24:42.0296 0760        ccSet_N360      (599e7f6259a127c174c49938d2aa6a60) J:\WINDOWS\system32\drivers\N360\0602010.005\ccSetx86.sys
12:24:42.0312 0760        ccSet_N360 - ok
12:24:42.0312 0760        cd20xrnt - ok
12:24:42.0312 0760        Cdaudio        (c1b486a7658353d33a10cc15211a873b) J:\WINDOWS\system32\drivers\Cdaudio.sys
12:24:42.0375 0760        Cdaudio - ok
12:24:42.0375 0760        Cdfs            (c885b02847f5d2fd45a24e219ed93b32) J:\WINDOWS\system32\drivers\Cdfs.sys
12:24:42.0437 0760        Cdfs - ok
12:24:42.0437 0760        Cdrom          (1f4260cc5b42272d71f79e570a27a4fe) J:\WINDOWS\system32\DRIVERS\cdrom.sys
12:24:42.0500 0760        Cdrom - ok
12:24:42.0500 0760        Changer - ok
12:24:42.0500 0760        CiSvc          (28e3040d1f1ca2008cd6b29dfebc9a5e) J:\WINDOWS\system32\cisvc.exe
12:24:42.0562 0760        CiSvc - ok
12:24:42.0562 0760        ClipSrv        (778a30ed3c134eb7e406afc407e9997d) J:\WINDOWS\system32\clipsrv.exe
12:24:42.0609 0760        ClipSrv - ok
12:24:42.0625 0760        clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) J:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:24:42.0640 0760        clr_optimization_v2.0.50727_32 - ok
12:24:42.0640 0760        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:24:42.0656 0760        clr_optimization_v4.0.30319_32 - ok
12:24:42.0656 0760        CmdIde - ok
12:24:42.0656 0760        COMSysApp - ok
12:24:42.0656 0760        Cpqarray - ok
12:24:42.0656 0760        CryptSvc        (611f824e5c703a5a899f84c5f1699e4d) J:\WINDOWS\System32\cryptsvc.dll
12:24:42.0718 0760        CryptSvc - ok
12:24:42.0718 0760        dac2w2k - ok
12:24:42.0718 0760        dac960nt - ok
12:24:42.0734 0760        DcomLaunch      (3127afbf2c1ed0ab14a1bbb7aaecb85b) J:\WINDOWS\system32\rpcss.dll
12:24:42.0750 0760        DcomLaunch - ok
12:24:42.0750 0760        DgiVecp        (770471de2550820feeb7e5d24bf2e273) J:\WINDOWS\system32\Drivers\DgiVecp.sys
12:24:42.0750 0760        DgiVecp ( UnsignedFile.Multi.Generic ) - warning
12:24:42.0750 0760        DgiVecp - detected UnsignedFile.Multi.Generic (1)
12:24:42.0765 0760        Dhcp            (c29a1c9b75ba38fa37f8c44405dec360) J:\WINDOWS\System32\dhcpcsvc.dll
12:24:42.0828 0760        Dhcp - ok
12:24:42.0828 0760        Disk            (044452051f3e02e7963599fc8f4f3e25) J:\WINDOWS\system32\DRIVERS\disk.sys
12:24:42.0890 0760        Disk - ok
12:24:42.0890 0760        dmadmin - ok
12:24:42.0921 0760        dmboot          (0dcfc8395a99fecbb1ef771cec7fe4ea) J:\WINDOWS\system32\drivers\dmboot.sys
12:24:43.0000 0760        dmboot - ok
12:24:43.0015 0760        dmio            (53720ab12b48719d00e327da470a619a) J:\WINDOWS\system32\drivers\dmio.sys
12:24:43.0062 0760        dmio - ok
12:24:43.0062 0760        dmload          (e9317282a63ca4d188c0df5e09c6ac5f) J:\WINDOWS\system32\drivers\dmload.sys
12:24:43.0125 0760        dmload - ok
12:24:43.0125 0760        dmserver        (25c83ffbba13b554eb6d59a9b2e2ee78) J:\WINDOWS\System32\dmserver.dll
12:24:43.0187 0760        dmserver - ok
12:24:43.0187 0760        DMusic          (8a208dfcf89792a484e76c40e5f50b45) J:\WINDOWS\system32\drivers\DMusic.sys
12:24:43.0250 0760        DMusic - ok
12:24:43.0250 0760        Dnscache        (407f3227ac618fd1ca54b335b083de07) J:\WINDOWS\System32\dnsrslvr.dll
12:24:43.0250 0760        Dnscache - ok
12:24:43.0265 0760        Dot3svc        (676e36c4ff5bcea1900f44182b9723e6) J:\WINDOWS\System32\dot3svc.dll
12:24:43.0312 0760        Dot3svc - ok
12:24:43.0312 0760        dpti2o - ok
12:24:43.0328 0760        drmkaud        (8f5fcff8e8848afac920905fbd9d33c8) J:\WINDOWS\system32\drivers\drmkaud.sys
12:24:43.0375 0760        drmkaud - ok
12:24:43.0375 0760        DTSRVC          (a564c3b47cb376163705106cc53f6283) J:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
12:24:43.0390 0760        DTSRVC ( UnsignedFile.Multi.Generic ) - warning
12:24:43.0390 0760        DTSRVC - detected UnsignedFile.Multi.Generic (1)
12:24:43.0390 0760        EapHost        (4e4f2fddab0a0736d7671134dcce91fb) J:\WINDOWS\System32\eapsvc.dll
12:24:43.0437 0760        EapHost - ok
12:24:43.0453 0760        eeCtrl          (fce87ba643d5e9a8b6e0378508d1b22d) J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys
12:24:43.0468 0760        eeCtrl - ok
12:24:43.0468 0760        EraserUtilRebootDrv (115dc729465a8c386615207f28875255) J:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
12:24:43.0484 0760        EraserUtilRebootDrv - ok
12:24:43.0484 0760        ERSvc          (877c18558d70587aa7823a1a308ac96b) J:\WINDOWS\System32\ersvc.dll
12:24:43.0531 0760        ERSvc - ok
12:24:43.0546 0760        Eventlog        (a3edbe9053889fb24ab22492472b39dc) J:\WINDOWS\system32\services.exe
12:24:43.0546 0760        Eventlog - ok
12:24:43.0562 0760        EventSystem    (af4f6b5739d18ca7972ab53e091cbc74) J:\WINDOWS\system32\es.dll
12:24:43.0578 0760        EventSystem - ok
12:24:43.0578 0760        Fastfat        (38d332a6d56af32635675f132548343e) J:\WINDOWS\system32\drivers\Fastfat.sys
12:24:43.0625 0760        Fastfat - ok
12:24:43.0640 0760        FastUserSwitchingCompatibility (2db7d303c36ddd055215052f118e8e75) J:\WINDOWS\System32\shsvcs.dll
12:24:43.0640 0760        FastUserSwitchingCompatibility - ok
12:24:43.0656 0760        Fdc            (92cdd60b6730b9f50f6a1a0c1f8cdc81) J:\WINDOWS\system32\DRIVERS\fdc.sys
12:24:43.0703 0760        Fdc - ok
12:24:43.0718 0760        FinePrint Dispatcher v5 (eb6dffd7174054c9ed56d6ef68057eaf) J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
12:24:43.0734 0760        FinePrint Dispatcher v5 ( UnsignedFile.Multi.Generic ) - warning
12:24:43.0734 0760        FinePrint Dispatcher v5 - detected UnsignedFile.Multi.Generic (1)
12:24:43.0734 0760        Fips            (b0678a548587c5f1967b0d70bacad6c1) J:\WINDOWS\system32\drivers\Fips.sys
12:24:43.0796 0760        Fips - ok
12:24:43.0796 0760        Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) J:\WINDOWS\system32\DRIVERS\flpydisk.sys
12:24:43.0859 0760        Flpydisk - ok
12:24:43.0859 0760        FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) J:\WINDOWS\system32\DRIVERS\fltMgr.sys
12:24:43.0921 0760        FltMgr - ok
12:24:43.0921 0760        FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) J:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
12:24:43.0937 0760        FontCache3.0.0.0 - ok
12:24:43.0937 0760        Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) J:\WINDOWS\system32\drivers\Fs_Rec.sys
12:24:43.0984 0760        Fs_Rec - ok
12:24:44.0000 0760        Ftdisk          (8f1955ce42e1484714b542f341647778) J:\WINDOWS\system32\DRIVERS\ftdisk.sys
12:24:44.0046 0760        Ftdisk - ok
12:24:44.0046 0760        gdrv            (d556cb79967e92b5cc69686d16c1d846) J:\WINDOWS\gdrv.sys
12:24:44.0062 0760        gdrv - ok
12:24:44.0062 0760        GEST Service    (2ddd5cbb203c3c3fd6f74979ebd8cc92) J:\Programme\GIGABYTE\EnergySaver\GSvr.exe
12:24:44.0078 0760        GEST Service - ok
12:24:44.0078 0760        giveio          (77ebf3e9386daa51551af429052d88d0) J:\WINDOWS\system32\giveio.sys
12:24:44.0078 0760        giveio ( UnsignedFile.Multi.Generic ) - warning
12:24:44.0078 0760        giveio - detected UnsignedFile.Multi.Generic (1)
12:24:44.0078 0760        Gpc            (0a02c63c8b144bd8c86b103dee7c86a2) J:\WINDOWS\system32\DRIVERS\msgpc.sys
12:24:44.0140 0760        Gpc - ok
12:24:44.0140 0760        gupdate1c9aa7918f7f3bc (626a24ed1228580b9518c01930936df9) J:\Programme\Google\Update\GoogleUpdate.exe
12:24:44.0156 0760        gupdate1c9aa7918f7f3bc - ok
12:24:44.0156 0760        gupdatem        (626a24ed1228580b9518c01930936df9) J:\Programme\Google\Update\GoogleUpdate.exe
12:24:44.0156 0760        gupdatem - ok
12:24:44.0171 0760        HDAudBus        (573c7d0a32852b48f3058cfd8026f511) J:\WINDOWS\system32\DRIVERS\HDAudBus.sys
12:24:44.0218 0760        HDAudBus - ok
12:24:44.0218 0760        helpsvc        (cb66bf85bf599befd6c6a57c2e20357f) J:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
12:24:44.0281 0760        helpsvc - ok
12:24:44.0281 0760        HidServ        (b35da85e60c0103f2e4104532da2f12b) J:\WINDOWS\System32\hidserv.dll
12:24:44.0343 0760        HidServ - ok
12:24:44.0343 0760        hidusb          (ccf82c5ec8a7326c3066de870c06daf1) J:\WINDOWS\system32\DRIVERS\hidusb.sys
12:24:44.0390 0760        hidusb - ok
12:24:44.0406 0760        hkmsvc          (ed29f14101523a6e0e808107405d452c) J:\WINDOWS\System32\kmsvc.dll
12:24:44.0453 0760        hkmsvc - ok
12:24:44.0468 0760        HPM1210RcvFaxSrvc (9442228d256ce6c874cfb5dc39a20540) J:\Programme\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
12:24:44.0468 0760        HPM1210RcvFaxSrvc ( UnsignedFile.Multi.Generic ) - warning
12:24:44.0468 0760        HPM1210RcvFaxSrvc - detected UnsignedFile.Multi.Generic (1)
12:24:44.0468 0760        hpn - ok
12:24:44.0468 0760        HPSIService    (61bffbf840eb7285f630b5b4f1ccbc08) J:\WINDOWS\system32\HPSIsvc.exe
12:24:44.0484 0760        HPSIService - ok
12:24:44.0484 0760        HTTP            (f80a415ef82cd06ffaf0d971528ead38) J:\WINDOWS\system32\Drivers\HTTP.sys
12:24:44.0500 0760        HTTP - ok
12:24:44.0500 0760        HTTPFilter      (9e4adb854cebcfb81a4b36718feecd16) J:\WINDOWS\System32\w3ssl.dll
12:24:44.0562 0760        HTTPFilter - ok
12:24:44.0562 0760        i2omgmt - ok
12:24:44.0562 0760        i2omp - ok
12:24:44.0578 0760        i8042prt        (e283b97cfbeb86c1d86baed5f7846a92) J:\WINDOWS\system32\DRIVERS\i8042prt.sys
12:24:44.0625 0760        i8042prt - ok
12:24:44.0656 0760        idsvc          (c01ac32dc5c03076cfb852cb5da5229c) J:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:24:44.0687 0760        idsvc - ok
12:24:44.0703 0760        IDSxpx86        (eeebf3616db90124c1c57019d39aa9a2) J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120711.001\IDSxpx86.sys
12:24:44.0718 0760        IDSxpx86 - ok
12:24:44.0718 0760        Imapi          (083a052659f5310dd8b6a6cb05edcf8e) J:\WINDOWS\system32\DRIVERS\imapi.sys
12:24:44.0781 0760        Imapi - ok
12:24:44.0781 0760        ImapiService    (d4b413aa210c21e46aedd2ba5b68d38e) J:\WINDOWS\system32\imapi.exe
12:24:44.0843 0760        ImapiService - ok
12:24:44.0843 0760        ini910u - ok
12:24:44.0968 0760        IntcAzAudAddService (557e20484a095d949912883f5ab29e88) J:\WINDOWS\system32\drivers\RtkHDAud.sys
12:24:45.0062 0760        IntcAzAudAddService - ok
12:24:45.0109 0760        IntelIde - ok
12:24:45.0109 0760        intelppm        (4c7d2750158ed6e7ad642d97bffae351) J:\WINDOWS\system32\DRIVERS\intelppm.sys
12:24:45.0171 0760        intelppm - ok
12:24:45.0171 0760        Ip6Fw          (3bb22519a194418d5fec05d800a19ad0) J:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
12:24:45.0234 0760        Ip6Fw - ok
12:24:45.0234 0760        IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) J:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:24:45.0281 0760        IpFilterDriver - ok
12:24:45.0296 0760        IpInIp          (b87ab476dcf76e72010632b5550955f5) J:\WINDOWS\system32\DRIVERS\ipinip.sys
12:24:45.0343 0760        IpInIp - ok
12:24:45.0343 0760        IpNat          (cc748ea12c6effde940ee98098bf96bb) J:\WINDOWS\system32\DRIVERS\ipnat.sys
12:24:45.0406 0760        IpNat - ok
12:24:45.0406 0760        IPSec          (23c74d75e36e7158768dd63d92789a91) J:\WINDOWS\system32\DRIVERS\ipsec.sys
12:24:45.0468 0760        IPSec - ok
12:24:45.0468 0760        IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) J:\WINDOWS\system32\DRIVERS\irenum.sys
12:24:45.0500 0760        IRENUM - ok
12:24:45.0500 0760        isapnp          (6dfb88f64135c525433e87648bda30de) J:\WINDOWS\system32\DRIVERS\isapnp.sys
12:24:45.0562 0760        isapnp - ok
12:24:45.0562 0760        JavaQuickStarterService (de5d05fd449798ef88cc34ad4b1e7f85) J:\Programme\Java\jre6\bin\jqs.exe
12:24:45.0578 0760        JavaQuickStarterService - ok
12:24:45.0578 0760        Kbdclass        (1704d8c4c8807b889e43c649b478a452) J:\WINDOWS\system32\DRIVERS\kbdclass.sys
12:24:45.0640 0760        Kbdclass - ok
12:24:45.0640 0760        kbdhid          (b6d6c117d771c98130497265f26d1882) J:\WINDOWS\system32\DRIVERS\kbdhid.sys
12:24:45.0687 0760        kbdhid - ok
12:24:45.0703 0760        kmixer          (692bcf44383d056aed41b045a323d378) J:\WINDOWS\system32\drivers\kmixer.sys
12:24:45.0750 0760        kmixer - ok
12:24:45.0765 0760        KSecDD          (b467646c54cc746128904e1654c750c1) J:\WINDOWS\system32\drivers\KSecDD.sys
12:24:45.0765 0760        KSecDD - ok
12:24:45.0781 0760        LanmanServer    (2bbdcb79900990f0716dfcb714e72de7) J:\WINDOWS\System32\srvsvc.dll
12:24:45.0781 0760        LanmanServer - ok
12:24:45.0781 0760        lanmanworkstation (1869b14b06b44b44af70548e1ea3303f) J:\WINDOWS\System32\wkssvc.dll
12:24:45.0796 0760        lanmanworkstation - ok
12:24:45.0796 0760        lbrtfdc - ok
12:24:45.0796 0760        LGScsiCommandService (f2999ae01973f938a5ae1c69c7b0d7de) J:\WINDOWS\system32\LGScsiCommandService.exe
12:24:45.0812 0760        LGScsiCommandService ( UnsignedFile.Multi.Generic ) - warning
12:24:45.0812 0760        LGScsiCommandService - detected UnsignedFile.Multi.Generic (1)
12:24:45.0812 0760        LmHosts        (636714b7d43c8d0c80449123fd266920) J:\WINDOWS\System32\lmhsvc.dll
12:24:45.0859 0760        LmHosts - ok
12:24:45.0875 0760        MBAMProtector  (fb097bbc1a18f044bd17bd2fccf97865) J:\WINDOWS\system32\drivers\mbam.sys
12:24:45.0875 0760        MBAMProtector - ok
12:24:45.0890 0760        MBAMService    (ba400ed640bca1eae5c727ae17c10207) J:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
12:24:45.0921 0760        MBAMService - ok
12:24:45.0921 0760        Messenger      (b7550a7107281d170ce85524b1488c98) J:\WINDOWS\System32\msgsvc.dll
12:24:45.0984 0760        Messenger - ok
12:24:45.0984 0760        mnmdd          (4ae068242760a1fb6e1a44bf4e16afa6) J:\WINDOWS\system32\drivers\mnmdd.sys
12:24:46.0031 0760        mnmdd - ok
12:24:46.0031 0760        mnmsrvc        (c2f1d365fd96791b037ee504868065d3) J:\WINDOWS\system32\mnmsrvc.exe
12:24:46.0093 0760        mnmsrvc - ok
12:24:46.0093 0760        Modem          (6fb74ebd4ec57a6f1781de3852cc3362) J:\WINDOWS\system32\drivers\Modem.sys
12:24:46.0156 0760        Modem - ok
12:24:46.0156 0760        Mouclass        (b24ce8005deab254c0251e15cb71d802) J:\WINDOWS\system32\DRIVERS\mouclass.sys
12:24:46.0218 0760        Mouclass - ok
12:24:46.0218 0760        mouhid          (66a6f73c74e1791464160a7065ce711a) J:\WINDOWS\system32\DRIVERS\mouhid.sys
12:24:46.0265 0760        mouhid - ok
12:24:46.0265 0760        MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) J:\WINDOWS\system32\drivers\MountMgr.sys
12:24:46.0328 0760        MountMgr - ok
12:24:46.0328 0760        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) J:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
12:24:46.0343 0760        MozillaMaintenance - ok
12:24:46.0343 0760        mraid35x - ok
12:24:46.0343 0760        MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) J:\WINDOWS\system32\DRIVERS\mrxdav.sys
12:24:46.0468 0760        MRxDAV - ok
12:24:46.0500 0760        MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) J:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:24:46.0515 0760        MRxSmb - ok
12:24:46.0515 0760        MSDTC          (35a031af38c55f92d28aa03ee9f12cc9) J:\WINDOWS\system32\msdtc.exe
12:24:46.0578 0760        MSDTC - ok
12:24:46.0578 0760        Msfs            (c941ea2454ba8350021d774daf0f1027) J:\WINDOWS\system32\drivers\Msfs.sys
12:24:46.0640 0760        Msfs - ok
12:24:46.0640 0760        MSIServer - ok
12:24:46.0640 0760        MSKSSRV        (d1575e71568f4d9e14ca56b7b0453bf1) J:\WINDOWS\system32\drivers\MSKSSRV.sys
12:24:46.0687 0760        MSKSSRV - ok
12:24:46.0703 0760        MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) J:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:24:46.0750 0760        MSPCLOCK - ok
12:24:46.0750 0760        MSPQM          (bad59648ba099da4a17680b39730cb3d) J:\WINDOWS\system32\drivers\MSPQM.sys
12:24:46.0796 0760        MSPQM - ok
12:24:46.0812 0760        mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) J:\WINDOWS\system32\DRIVERS\mssmbios.sys
12:24:46.0859 0760        mssmbios - ok
12:24:46.0859 0760        Mup            (de6a75f5c270e756c5508d94b6cf68f5) J:\WINDOWS\system32\drivers\Mup.sys
12:24:46.0875 0760        Mup - ok
12:24:46.0875 0760        N360            (c6948f034d7edabcfa2234d399fc78bc) J:\Programme\Norton 360\Engine\6.2.1.5\ccSvcHst.exe
12:24:46.0890 0760        N360 - ok
12:24:46.0906 0760        napagent        (46bb15ae2ac7d025d6d2567b876817bd) J:\WINDOWS\System32\qagentrt.dll
12:24:46.0953 0760        napagent - ok
12:24:46.0968 0760        NAVENG          (f11033730b38260b6892e837c457fb4b) J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120711.018\NAVENG.SYS
12:24:46.0968 0760        NAVENG - ok
12:24:47.0015 0760        NAVEX15        (4e4e7c0259d3bb97de24a636c0e06aba) J:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120711.018\NAVEX15.SYS
12:24:47.0046 0760        NAVEX15 - ok
12:24:47.0078 0760        NDIS            (1df7f42665c94b825322fae71721130d) J:\WINDOWS\system32\drivers\NDIS.sys
12:24:47.0125 0760        NDIS - ok
12:24:47.0140 0760        NdisTapi        (0109c4f3850dfbab279542515386ae22) J:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:24:47.0140 0760        NdisTapi - ok
12:24:47.0140 0760        Ndisuio        (f927a4434c5028758a842943ef1a3849) J:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:24:47.0203 0760        Ndisuio - ok
12:24:47.0203 0760        NdisWan        (edc1531a49c80614b2cfda43ca8659ab) J:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:24:47.0265 0760        NdisWan - ok
12:24:47.0265 0760        NDProxy        (9282bd12dfb069d3889eb3fcc1000a9b) J:\WINDOWS\system32\drivers\NDProxy.sys
12:24:47.0265 0760        NDProxy - ok
12:24:47.0281 0760        Nero BackItUp Scheduler 4.0 - ok
12:24:47.0281 0760        NetBIOS        (5d81cf9a2f1a3a756b66cf684911cdf0) J:\WINDOWS\system32\DRIVERS\netbios.sys
12:24:47.0328 0760        NetBIOS - ok
12:24:47.0343 0760        NetBT          (74b2b2f5bea5e9a3dc021d685551bd3d) J:\WINDOWS\system32\DRIVERS\netbt.sys
12:24:47.0390 0760        NetBT - ok
12:24:47.0406 0760        NetDDE          (8ace4251bffd09ce75679fe940e996cc) J:\WINDOWS\system32\netdde.exe
12:24:47.0453 0760        NetDDE - ok
12:24:47.0453 0760        NetDDEdsdm      (8ace4251bffd09ce75679fe940e996cc) J:\WINDOWS\system32\netdde.exe
12:24:47.0515 0760        NetDDEdsdm - ok
12:24:47.0515 0760        Netlogon        (afb8261b56cba0d86aeb6df682af9785) J:\WINDOWS\system32\lsass.exe
12:24:47.0562 0760        Netlogon - ok
12:24:47.0578 0760        Netman          (e6d88f1f6745bf00b57e7855a2ab696c) J:\WINDOWS\System32\netman.dll
12:24:47.0625 0760        Netman - ok
12:24:47.0640 0760        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
12:24:47.0656 0760        NetTcpPortSharing - ok
12:24:47.0656 0760        Nla            (f1b67b6b0751ae0e6e964b02821206a3) J:\WINDOWS\System32\mswsock.dll
12:24:47.0671 0760        Nla - ok
12:24:47.0687 0760        NMIndexingService (cb992ae1506985d9167e85883b4c3240) J:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
12:24:47.0703 0760        NMIndexingService - ok
12:24:47.0703 0760        Npfs            (3182d64ae053d6fb034f44b6def8034a) J:\WINDOWS\system32\drivers\Npfs.sys
12:24:47.0765 0760        Npfs - ok
12:24:47.0781 0760        Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) J:\WINDOWS\system32\drivers\Ntfs.sys
12:24:47.0843 0760        Ntfs - ok
12:24:47.0843 0760        NtLmSsp        (afb8261b56cba0d86aeb6df682af9785) J:\WINDOWS\system32\lsass.exe
12:24:47.0906 0760        NtLmSsp - ok
12:24:47.0968 0760        NtmsSvc        (56af4064996fa5bac9c449b1514b4770) J:\WINDOWS\system32\ntmssvc.dll
12:24:48.0031 0760        NtmsSvc - ok
12:24:48.0031 0760        Null            (73c1e1f395918bc2c6dd67af7591a3ad) J:\WINDOWS\system32\drivers\Null.sys
12:24:48.0093 0760        Null - ok
12:24:48.0250 0760        nv              (0ae3a22dbe88dc219f8c0fdd30239e4f) J:\WINDOWS\system32\DRIVERS\nv4_mini.sys
12:24:48.0421 0760        nv - ok
12:24:48.0484 0760        NVSvc          (b54c19b0cda652a65f99701490c9d20f) J:\WINDOWS\system32\nvsvc32.exe
12:24:48.0484 0760        NVSvc - ok
12:24:48.0500 0760        NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) J:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
12:24:48.0546 0760        NwlnkFlt - ok
12:24:48.0546 0760        NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) J:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
12:24:48.0609 0760        NwlnkFwd - ok
12:24:48.0609 0760        Parport        (f84785660305b9b903fb3bca8ba29837) J:\WINDOWS\system32\DRIVERS\parport.sys
12:24:48.0671 0760        Parport - ok
12:24:48.0671 0760        PartMgr        (beb3ba25197665d82ec7065b724171c6) J:\WINDOWS\system32\drivers\PartMgr.sys
12:24:48.0718 0760        PartMgr - ok
12:24:48.0718 0760        ParVdm          (c2bf987829099a3eaa2ca6a0a90ecb4f) J:\WINDOWS\system32\drivers\ParVdm.sys
12:24:48.0781 0760        ParVdm - ok
12:24:48.0781 0760        PCI            (387e8dedc343aa2d1efbc30580273acd) J:\WINDOWS\system32\DRIVERS\pci.sys
12:24:48.0843 0760        PCI - ok
12:24:48.0843 0760        PCIDump - ok
12:24:48.0843 0760        PCIIde          (59ba86d9a61cbcf4df8e598c331f5b82) J:\WINDOWS\system32\DRIVERS\pciide.sys
12:24:48.0890 0760        PCIIde - ok
12:24:48.0890 0760        Pcmcia          (a2a966b77d61847d61a3051df87c8c97) J:\WINDOWS\system32\drivers\Pcmcia.sys
12:24:48.0953 0760        Pcmcia - ok
12:24:48.0953 0760        pcouffin        (5b6c11de7e839c05248ced8825470fef) J:\WINDOWS\system32\Drivers\pcouffin.sys
12:24:48.0953 0760        pcouffin ( UnsignedFile.Multi.Generic ) - warning
12:24:48.0953 0760        pcouffin - detected UnsignedFile.Multi.Generic (1)
12:24:48.0953 0760        PDCOMP - ok
12:24:48.0968 0760        PDFRAME - ok
12:24:48.0968 0760        PdiPorts        (18ed1d71fef6f71d38c24263500bbd01) J:\WINDOWS\system32\Drivers\PdiPorts.sys
12:24:48.0968 0760        PdiPorts - ok
12:24:48.0968 0760        PDRELI - ok
12:24:48.0968 0760        PDRFRAME - ok
12:24:48.0984 0760        perc2 - ok
12:24:48.0984 0760        perc2hib - ok
12:24:48.0984 0760        PlugPlay        (a3edbe9053889fb24ab22492472b39dc) J:\WINDOWS\system32\services.exe
12:24:49.0000 0760        PlugPlay - ok
12:24:49.0000 0760        PolicyAgent    (afb8261b56cba0d86aeb6df682af9785) J:\WINDOWS\system32\lsass.exe
12:24:49.0046 0760        PolicyAgent - ok
12:24:49.0046 0760        PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) J:\WINDOWS\system32\DRIVERS\raspptp.sys
12:24:49.0109 0760        PptpMiniport - ok
12:24:49.0109 0760        ProtectedStorage (afb8261b56cba0d86aeb6df682af9785) J:\WINDOWS\system32\lsass.exe
12:24:49.0156 0760        ProtectedStorage - ok
12:24:49.0171 0760        PSched          (09298ec810b07e5d582cb3a3f9255424) J:\WINDOWS\system32\DRIVERS\psched.sys
12:24:49.0218 0760        PSched - ok
12:24:49.0234 0760        Ptilink        (80d317bd1c3dbc5d4fe7b1678c60cadd) J:\WINDOWS\system32\DRIVERS\ptilink.sys
12:24:49.0281 0760        Ptilink - ok
12:24:49.0281 0760        PxHelp20        (153d02480a0a2f45785522e814c634b6) J:\WINDOWS\system32\Drivers\PxHelp20.sys
12:24:49.0296 0760        PxHelp20 - ok
12:24:49.0296 0760        ql1080 - ok
12:24:49.0296 0760        Ql10wnt - ok
12:24:49.0296 0760        ql12160 - ok
12:24:49.0296 0760        ql1240 - ok
12:24:49.0296 0760        ql1280 - ok
12:24:49.0296 0760        RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) J:\WINDOWS\system32\DRIVERS\rasacd.sys
12:24:49.0359 0760        RasAcd - ok
12:24:49.0359 0760        RasAuto        (f5ba6caccdb66c8f048e867563203246) J:\WINDOWS\System32\rasauto.dll
12:24:49.0406 0760        RasAuto - ok
12:24:49.0406 0760        Rasl2tp        (11b4a627bc9614b885c4969bfa5ff8a6) J:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:24:49.0468 0760        Rasl2tp - ok
12:24:49.0468 0760        RasMan          (f9a7b66ea345726edb5862a46b1eccd5) J:\WINDOWS\System32\rasmans.dll
12:24:49.0531 0760        RasMan - ok
12:24:49.0531 0760        RasPppoe        (5bc962f2654137c9909c3d4603587dee) J:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:24:49.0578 0760        RasPppoe - ok
12:24:49.0578 0760        Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) J:\WINDOWS\system32\DRIVERS\raspti.sys
12:24:49.0625 0760        Raspti - ok
12:24:49.0640 0760        Rdbss          (7ad224ad1a1437fe28d89cf22b17780a) J:\WINDOWS\system32\DRIVERS\rdbss.sys
12:24:49.0687 0760        Rdbss - ok
12:24:49.0687 0760        RDPCDD          (4912d5b403614ce99c28420f75353332) J:\WINDOWS\system32\DRIVERS\RDPCDD.sys
12:24:49.0750 0760        RDPCDD - ok
12:24:49.0750 0760        rdpdr          (15cabd0f7c00c47c70124907916af3f1) J:\WINDOWS\system32\DRIVERS\rdpdr.sys
12:24:49.0812 0760        rdpdr - ok
12:24:49.0812 0760        RDPWD          (6589db6e5969f8eee594cf71171c5028) J:\WINDOWS\system32\drivers\RDPWD.sys
12:24:49.0828 0760        RDPWD - ok
12:24:49.0828 0760        RDSessMgr      (263af18af0f3db99f574c95f284ccec9) J:\WINDOWS\system32\sessmgr.exe
12:24:49.0890 0760        RDSessMgr - ok
12:24:49.0890 0760        redbook        (ed761d453856f795a7fe056e42c36365) J:\WINDOWS\system32\DRIVERS\redbook.sys
12:24:49.0937 0760        redbook - ok
12:24:49.0937 0760        RemoteAccess    (0e97ec96d6942ceec2d188cc2eb69a01) J:\WINDOWS\System32\mprdim.dll
12:24:50.0000 0760        RemoteAccess - ok
12:24:50.0000 0760        RemoteRegistry  (e4cd1f3d84e1c2ca0b8cf7501e201593) J:\WINDOWS\system32\regsvc.dll
12:24:50.0046 0760        RemoteRegistry - ok
12:24:50.0062 0760        RpcLocator      (2a02e21867497df20b8fc95631395169) J:\WINDOWS\system32\locator.exe
12:24:50.0109 0760        RpcLocator - ok
12:24:50.0125 0760        RpcSs          (3127afbf2c1ed0ab14a1bbb7aaecb85b) J:\WINDOWS\system32\rpcss.dll
12:24:50.0140 0760        RpcSs - ok
12:24:50.0140 0760        RSVP            (4bdd71b4b521521499dfd14735c4f398) J:\WINDOWS\system32\rsvp.exe
12:24:50.0187 0760        RSVP - ok
12:24:50.0203 0760        RTLE8023xp      (eeb84629064abcb6198864d25bf15b1a) J:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
12:24:50.0218 0760        RTLE8023xp - ok
12:24:50.0218 0760        SaiH075C        (99c7c809b34d2dbc383de491860eb4a3) J:\WINDOWS\system32\DRIVERS\SaiH075C.sys
12:24:50.0234 0760        SaiH075C - ok
12:24:50.0234 0760        SaiMini        (92b13996a122024374107605e34c6b59) J:\WINDOWS\system32\DRIVERS\SaiMini.sys
12:24:50.0234 0760        SaiMini ( UnsignedFile.Multi.Generic ) - warning
12:24:50.0234 0760        SaiMini - detected UnsignedFile.Multi.Generic (1)
12:24:50.0234 0760        SaiNtBus        (60bd55d3a37e94e7952af68c7f74d6b9) J:\WINDOWS\system32\drivers\SaiBus.sys
12:24:50.0234 0760        SaiNtBus ( UnsignedFile.Multi.Generic ) - warning
12:24:50.0234 0760        SaiNtBus - detected UnsignedFile.Multi.Generic (1)
12:24:50.0250 0760        SamSs          (afb8261b56cba0d86aeb6df682af9785) J:\WINDOWS\system32\lsass.exe
12:24:50.0296 0760        SamSs - ok
12:24:50.0296 0760        SANDRA          (230fd3749904ca045ea5ec0aa14006e9) J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\WNt500x86\Sandra.sys
12:24:50.0312 0760        SANDRA - ok
12:24:50.0312 0760        SandraAgentSrv  (dd063e84112e3cca3773d594d97259c8) J:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4a\RpcAgentSrv.exe
12:24:50.0312 0760        SandraAgentSrv ( UnsignedFile.Multi.Generic ) - warning
12:24:50.0312 0760        SandraAgentSrv - detected UnsignedFile.Multi.Generic (1)
12:24:50.0312 0760        SCardSvr        (dcec079fad95d36c8dd5cb6d779dfe32) J:\WINDOWS\System32\SCardSvr.exe
12:24:50.0375 0760        SCardSvr - ok
12:24:50.0375 0760        Schedule        (a050194a44d7fa8d7186ed2f4e8367ae) J:\WINDOWS\system32\schedsvc.dll
12:24:50.0437 0760        Schedule - ok
12:24:50.0437 0760        Secdrv          (90a3935d05b494a5a39d37e71f09a677) J:\WINDOWS\system32\DRIVERS\secdrv.sys
12:24:50.0468 0760        Secdrv - ok
12:24:50.0468 0760        seclogon        (bee4cfd1d48c23b44cf4b974b0b79b2b) J:\WINDOWS\System32\seclogon.dll
12:24:50.0515 0760        seclogon - ok
12:24:50.0515 0760        SENS            (2aac9b6ed9eddffb721d6452e34d67e3) J:\WINDOWS\system32\sens.dll
12:24:50.0578 0760        SENS - ok
12:24:50.0578 0760        serenum        (0f29512ccd6bead730039fb4bd2c85ce) J:\WINDOWS\system32\DRIVERS\serenum.sys
12:24:50.0625 0760        serenum - ok
12:24:50.0640 0760        Serial          (cf24eb4f0412c82bcd1f4f35a025e31d) J:\WINDOWS\system32\DRIVERS\serial.sys
12:24:50.0687 0760        Serial - ok
12:24:50.0687 0760        Sfloppy        (8e6b8c671615d126fdc553d1e2de5562) J:\WINDOWS\system32\drivers\Sfloppy.sys
12:24:50.0750 0760        Sfloppy - ok
12:24:50.0750 0760        SharedAccess    (cad058d5f8b889a87ca3eb3cf624dcef) J:\WINDOWS\System32\ipnathlp.dll
12:24:50.0812 0760        SharedAccess - ok
12:24:50.0812 0760        ShellHWDetection (2db7d303c36ddd055215052f118e8e75) J:\WINDOWS\System32\shsvcs.dll
12:24:50.0828 0760        ShellHWDetection - ok
12:24:50.0828 0760        Simbad - ok
12:24:50.0828 0760        Sparrow - ok
12:24:50.0828 0760        speedfan        (3fa2e254bfbce52b3c6f1bf23aab6911) J:\WINDOWS\system32\speedfan.sys
12:24:50.0843 0760        speedfan - ok
12:24:50.0843 0760        splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) J:\WINDOWS\system32\drivers\splitter.sys
12:24:50.0890 0760        splitter - ok
12:24:50.0906 0760        Spooler        (60784f891563fb1b767f70117fc2428f) J:\WINDOWS\system32\spoolsv.exe
12:24:50.0906 0760        Spooler - ok
12:24:50.0921 0760        sr              (50fa898f8c032796d3b1b9951bb5a90f) J:\WINDOWS\system32\DRIVERS\sr.sys
12:24:50.0937 0760        sr - ok
12:24:50.0953 0760        srservice      (fe77a85495065f3ad59c5c65b6c54182) J:\WINDOWS\system32\srsvc.dll
12:24:50.0984 0760        srservice - ok
12:24:51.0000 0760        SRTSP          (9dd258ee034afd36259cb7357e19d0b1) J:\WINDOWS\System32\Drivers\N360\0602010.005\SRTSP.SYS
12:24:51.0015 0760        SRTSP - ok
12:24:51.0015 0760        SRTSPX          (0cc3a10f363436c7b478419eb73f8d91) J:\WINDOWS\system32\drivers\N360\0602010.005\SRTSPX.SYS
12:24:51.0015 0760        SRTSPX - ok
12:24:51.0031 0760        Srv            (47ddfc2f003f7f9f0592c6874962a2e7) J:\WINDOWS\system32\DRIVERS\srv.sys
12:24:51.0046 0760        Srv - ok
12:24:51.0046 0760        SSDPSRV        (4df5b05dfaec29e13e1ed6f6ee12c500) J:\WINDOWS\System32\ssdpsrv.dll
12:24:51.0078 0760        SSDPSRV - ok
12:24:51.0078 0760        SSPORT - ok
12:24:51.0093 0760        StillCam        (a2dbcc4c8860449df1ab758ea28b4de0) J:\WINDOWS\system32\DRIVERS\serscan.sys
12:24:51.0140 0760        StillCam - ok
12:24:51.0140 0760        stisvc          (bc2c5985611c5356b24aeb370953ded9) J:\WINDOWS\system32\wiaservc.dll
12:24:51.0203 0760        stisvc - ok
12:24:51.0203 0760        swenum          (3941d127aef12e93addf6fe6ee027e0f) J:\WINDOWS\system32\DRIVERS\swenum.sys
12:24:51.0265 0760        swenum - ok
12:24:51.0265 0760        swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) J:\WINDOWS\system32\drivers\swmidi.sys
12:24:51.0312 0760        swmidi - ok
12:24:51.0312 0760        SwPrv - ok
12:24:51.0312 0760        symc810 - ok
12:24:51.0312 0760        symc8xx - ok
12:24:51.0328 0760        SymDS          (690fa0e61b90084c4d9a721bd4f3d779) J:\WINDOWS\system32\drivers\N360\0602010.005\SYMDS.SYS
12:24:51.0343 0760        SymDS - ok
12:24:51.0375 0760        SymEFA          (4e55148a2e044d02245cbcdbb266b98c) J:\WINDOWS\system32\drivers\N360\0602010.005\SYMEFA.SYS
12:24:51.0453 0760        SymEFA - ok
12:24:51.0468 0760        SymEvent        (74e2521e96176a4449570e50be91954d) J:\WINDOWS\system32\Drivers\SYMEVENT.SYS
12:24:51.0484 0760        SymEvent - ok
12:24:51.0500 0760        SymIRON        (2c356cca706505cf63cbe39d532b9236) J:\WINDOWS\system32\drivers\N360\0602010.005\Ironx86.SYS
12:24:51.0515 0760        SymIRON - ok
12:24:51.0531 0760        SYMTDI          (508bd882040f9cb12319e3a4fc78edb9) J:\WINDOWS\System32\Drivers\N360\0602010.005\SYMTDI.SYS
12:24:51.0593 0760        SYMTDI - ok
12:24:51.0593 0760        sym_hi - ok
12:24:51.0593 0760        sym_u3 - ok
12:24:51.0609 0760        sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) J:\WINDOWS\system32\drivers\sysaudio.sys
12:24:51.0656 0760        sysaudio - ok
12:24:51.0656 0760        SysmonLog      (2903fffa2523926d6219428040dce6b9) J:\WINDOWS\system32\smlogsvc.exe
12:24:51.0718 0760        SysmonLog - ok
12:24:51.0734 0760        TapiSrv        (05903cac4b98908d55ea5774775b382e) J:\WINDOWS\System32\tapisrv.dll
12:24:51.0781 0760        TapiSrv - ok
12:24:51.0796 0760        Tcpip          (9aefa14bd6b182d61e3119fa5f436d3d) J:\WINDOWS\system32\DRIVERS\tcpip.sys
12:24:51.0812 0760        Tcpip - ok
12:24:51.0812 0760        TDPIPE          (6471a66807f5e104e4885f5b67349397) J:\WINDOWS\system32\drivers\TDPIPE.sys
12:24:51.0859 0760        TDPIPE - ok
12:24:51.0859 0760        TDTCP          (c56b6d0402371cf3700eb322ef3aaf61) J:\WINDOWS\system32\drivers\TDTCP.sys
12:24:51.0921 0760        TDTCP - ok
12:24:51.0921 0760        TermDD          (88155247177638048422893737429d9e) J:\WINDOWS\system32\DRIVERS\termdd.sys
12:24:51.0968 0760        TermDD - ok
12:24:51.0984 0760        TermService    (b7de02c863d8f5a005a7bf375375a6a4) J:\WINDOWS\System32\termsrv.dll
12:24:52.0031 0760        TermService - ok
12:24:52.0046 0760        Themes          (2db7d303c36ddd055215052f118e8e75) J:\WINDOWS\System32\shsvcs.dll
12:24:52.0046 0760        Themes - ok
12:24:52.0046 0760        TlntSvr        (03681a1ce77f51586903869a5ab1deab) J:\WINDOWS\system32\tlntsvr.exe
12:24:52.0078 0760        TlntSvr - ok
12:24:52.0078 0760        TosIde - ok
12:24:52.0093 0760        TrkWks          (626504572b175867f30f3215c04b3e2f) J:\WINDOWS\system32\trkwks.dll
12:24:52.0140 0760        TrkWks - ok
12:24:52.0156 0760        TUWinStylerThemeSvc (8f5d673617d0101fc85dd30a27fc20c4) J:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe
12:24:52.0156 0760        TUWinStylerThemeSvc ( UnsignedFile.Multi.Generic ) - warning
12:24:52.0156 0760        TUWinStylerThemeSvc - detected UnsignedFile.Multi.Generic (1)
12:24:52.0156 0760        Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) J:\WINDOWS\system32\drivers\Udfs.sys
12:24:52.0203 0760        Udfs - ok
12:24:52.0218 0760        ultra - ok
12:24:52.0218 0760        Update          (402ddc88356b1bac0ee3dd1580c76a31) J:\WINDOWS\system32\DRIVERS\update.sys
12:24:52.0281 0760        Update - ok
12:24:52.0296 0760        upnphost        (1dfd8975d8c89214b98d9387c1125b49) J:\WINDOWS\System32\upnphost.dll
12:24:52.0328 0760        upnphost - ok
12:24:52.0328 0760        UPS            (9b11e6118958e63e1fef129466e2bda7) J:\WINDOWS\System32\ups.exe
12:24:52.0375 0760        UPS - ok
12:24:52.0375 0760        usbbus          (9419faac6552a51542dbba02971c841c) J:\WINDOWS\system32\DRIVERS\lgusbbus.sys
12:24:52.0390 0760        usbbus - ok
12:24:52.0390 0760        usbccgp        (173f317ce0db8e21322e71b7e60a27e8) J:\WINDOWS\system32\DRIVERS\usbccgp.sys
12:24:52.0453 0760        usbccgp - ok
12:24:52.0453 0760        UsbDiag        (c0a466fa4ffec464320e159bc1bbdc0c) J:\WINDOWS\system32\DRIVERS\lgusbdiag.sys
12:24:52.0453 0760        UsbDiag - ok
12:24:52.0468 0760        usbehci        (65dcf09d0e37d4c6b11b5b0b76d470a7) J:\WINDOWS\system32\DRIVERS\usbehci.sys
12:24:52.0515 0760        usbehci - ok
12:24:52.0531 0760        usbhub          (1ab3cdde553b6e064d2e754efe20285c) J:\WINDOWS\system32\DRIVERS\usbhub.sys
12:24:52.0578 0760        usbhub - ok
12:24:52.0578 0760        USBModem        (f74a54774a9b0afeb3c40adec68aa600) J:\WINDOWS\system32\DRIVERS\lgusbmodem.sys
12:24:52.0593 0760        USBModem - ok
12:24:52.0593 0760        usbprint        (a717c8721046828520c9edf31288fc00) J:\WINDOWS\system32\DRIVERS\usbprint.sys
12:24:52.0640 0760        usbprint - ok
12:24:52.0640 0760        usbscan        (a0b8cf9deb1184fbdd20784a58fa75d4) J:\WINDOWS\system32\DRIVERS\usbscan.sys
12:24:52.0703 0760        usbscan - ok
12:24:52.0703 0760        USBSTOR        (a32426d9b14a089eaa1d922e0c5801a9) J:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:24:52.0750 0760        USBSTOR - ok
12:24:52.0750 0760        usbuhci        (26496f9dee2d787fc3e61ad54821ffe6) J:\WINDOWS\system32\DRIVERS\usbuhci.sys
12:24:52.0812 0760        usbuhci - ok
12:24:52.0812 0760        usb_rndisx      (b6cc50279d6cd28e090a5d33244adc9a) J:\WINDOWS\system32\DRIVERS\usb8023x.sys
12:24:52.0859 0760        usb_rndisx - ok
12:24:52.0859 0760        VgaSave        (0d3a8fafceacd8b7625cd549757a7df1) J:\WINDOWS\System32\drivers\vga.sys
12:24:52.0921 0760        VgaSave - ok
12:24:52.0921 0760        ViaIde - ok
12:24:52.0921 0760        VolSnap        (a5a712f4e880874a477af790b5186e1d) J:\WINDOWS\system32\drivers\VolSnap.sys
12:24:52.0968 0760        VolSnap - ok
12:24:52.0984 0760        VSS            (68f106273be29e7b7ef8266977268e78) J:\WINDOWS\System32\vssvc.exe
12:24:53.0015 0760        VSS - ok
12:24:53.0015 0760        W32Time        (7b353059e665f8b7ad2bbeaef597cf45) J:\WINDOWS\system32\w32time.dll
12:24:53.0078 0760        W32Time - ok
12:24:53.0078 0760        Wanarp          (e20b95baedb550f32dd489265c1da1f6) J:\WINDOWS\system32\DRIVERS\wanarp.sys
12:24:53.0125 0760        Wanarp - ok
12:24:53.0140 0760        wceusbsh        (46a247f6617526afe38b6f12f5512120) J:\WINDOWS\system32\DRIVERS\wceusbsh.sys
12:24:53.0140 0760        wceusbsh - ok
12:24:53.0140 0760        WDICA - ok
12:24:53.0156 0760        wdmaud          (6768acf64b18196494413695f0c3a00f) J:\WINDOWS\system32\drivers\wdmaud.sys
12:24:53.0203 0760        wdmaud - ok
12:24:53.0203 0760        WebClient      (81727c9873e3905a2ffc1ebd07265002) J:\WINDOWS\System32\webclnt.dll
12:24:53.0265 0760        WebClient - ok
12:24:53.0265 0760        winmgmt        (6f3f3973d97714cc5f906a19fe883729) J:\WINDOWS\system32\wbem\WMIsvc.dll
12:24:53.0328 0760        winmgmt - ok
12:24:53.0328 0760        WmdmPmSN        (c51b4a5c05a5475708e3c81c7765b71d) J:\WINDOWS\system32\MsPMSNSv.dll
12:24:53.0343 0760        WmdmPmSN - ok
12:24:53.0359 0760        Wmi            (ffa4d901d46d07a5bab2d8307fbb51a6) J:\WINDOWS\System32\advapi32.dll
12:24:53.0375 0760        Wmi - ok
12:24:53.0375 0760        WmiApSrv        (93908111ba57a6e60ec2fa2de202105c) J:\WINDOWS\system32\wbem\wmiapsrv.exe
12:24:53.0437 0760        WmiApSrv - ok
12:24:53.0468 0760        WMPNetworkSvc  (bf05650bb7df5e9ebdd25974e22403bb) J:\Programme\Windows Media Player\WMPNetwk.exe
12:24:53.0500 0760        WMPNetworkSvc - ok
12:24:53.0500 0760        WpdUsb          (cf4def1bf66f06964dc0d91844239104) J:\WINDOWS\system32\DRIVERS\wpdusb.sys
12:24:53.0500 0760        WpdUsb - ok
12:24:53.0531 0760        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:24:53.0562 0760        WPFFontCache_v0400 - ok
12:24:53.0562 0760        wscsvc          (300b3e84faf1a5c1f791c159ba28035d) J:\WINDOWS\system32\wscsvc.dll
12:24:53.0625 0760        wscsvc - ok
12:24:53.0625 0760        wuauserv        (7b4fe05202aa6bf9f4dfd0e6a0d8a085) J:\WINDOWS\system32\wuauserv.dll
12:24:53.0671 0760        wuauserv - ok
12:24:53.0671 0760        WudfPf          (f15feafffbb3644ccc80c5da584e6311) J:\WINDOWS\system32\DRIVERS\WudfPf.sys
12:24:53.0687 0760        WudfPf - ok
12:24:53.0703 0760        WudfRd          (28b524262bce6de1f7ef9f510ba3985b) J:\WINDOWS\system32\DRIVERS\wudfrd.sys
12:24:53.0718 0760        WudfRd - ok
12:24:53.0718 0760        WudfSvc        (05231c04253c5bc30b26cbaae680ed89) J:\WINDOWS\System32\WUDFSvc.dll
12:24:53.0734 0760        WudfSvc - ok
12:24:53.0796 0760        WZCSVC          (c4f109c005f6725162d2d12ca751e4a7) J:\WINDOWS\System32\wzcsvc.dll
12:24:53.0843 0760        WZCSVC - ok
12:24:53.0859 0760        xmlprov        (0ada34871a2e1cd2caafed1237a47750) J:\WINDOWS\System32\xmlprov.dll
12:24:53.0906 0760        xmlprov - ok
12:24:53.0906 0760        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk1\DR1
12:24:54.0078 0760        \Device\Harddisk1\DR1 - ok
12:24:54.0078 0760        MBR (0x1B8)    (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
12:24:54.0093 0760        \Device\Harddisk2\DR2 - ok
12:24:54.0093 0760        MBR (0x1B8)    (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0
12:24:54.0250 0760        \Device\Harddisk0\DR0 - ok
12:24:54.0250 0760        Boot (0x1200)  (844d369df2b32f2e05d3a3f7cd7f8a20) \Device\Harddisk1\DR1\Partition0
12:24:54.0250 0760        \Device\Harddisk1\DR1\Partition0 - ok
12:24:54.0250 0760        Boot (0x1200)  (62bee03d70dd5d71109ebe49b7c301f1) \Device\Harddisk1\DR1\Partition1
12:24:54.0250 0760        \Device\Harddisk1\DR1\Partition1 - ok
12:24:54.0250 0760        Boot (0x1200)  (6b1992f763183aaff3ee87c897d352ba) \Device\Harddisk1\DR1\Partition2
12:24:54.0250 0760        \Device\Harddisk1\DR1\Partition2 - ok
12:24:54.0265 0760        Boot (0x1200)  (cafa043c4ed054193114a9c121a81e52) \Device\Harddisk1\DR1\Partition3
12:24:54.0265 0760        \Device\Harddisk1\DR1\Partition3 - ok
12:24:54.0265 0760        Boot (0x1200)  (969f9f43b04d73cc2472eb8f8bb5b55d) \Device\Harddisk1\DR1\Partition4
12:24:54.0265 0760        \Device\Harddisk1\DR1\Partition4 - ok
12:24:54.0265 0760        Boot (0x1200)  (4a0c41a042620074f77991a09b05b6d9) \Device\Harddisk1\DR1\Partition5
12:24:54.0265 0760        \Device\Harddisk1\DR1\Partition5 - ok
12:24:54.0265 0760        Boot (0x1200)  (888bb6a16dbeafd2ba9847fc15778254) \Device\Harddisk2\DR2\Partition0
12:24:54.0265 0760        \Device\Harddisk2\DR2\Partition0 - ok
12:24:54.0265 0760        Boot (0x1200)  (30ba88ae0d89fd5540b6500b4dad25c8) \Device\Harddisk0\DR0\Partition0
12:24:54.0265 0760        \Device\Harddisk0\DR0\Partition0 - ok
12:24:54.0265 0760        ============================================================
12:24:54.0265 0760        Scan finished
12:24:54.0265 0760        ============================================================
12:24:54.0375 0768        Detected object count: 15
12:24:54.0375 0768        Actual detected object count: 15
12:25:08.0546 0768        Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        Amfilter ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        Amfilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        Amusbprt ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        Amusbprt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        Asset Management Daemon ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        Asset Management Daemon ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        DgiVecp ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        DgiVecp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        DTSRVC ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        DTSRVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0546 0768        FinePrint Dispatcher v5 ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0546 0768        FinePrint Dispatcher v5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        giveio ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        HPM1210RcvFaxSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        HPM1210RcvFaxSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        LGScsiCommandService ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        LGScsiCommandService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        SaiMini ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        SaiMini ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        SaiNtBus ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        SaiNtBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        SandraAgentSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        SandraAgentSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:08.0562 0768        TUWinStylerThemeSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:08.0562 0768        TUWinStylerThemeSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip

Gruß
gr.nagus

cosinus 13.07.2012 20:28

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19