Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Win64/Sirefef.w - Sirefef.ab und Sirefef.M eingefangen (https://www.trojaner-board.de/119421-win64-sirefef-w-sirefef-ab-sirefef-m-eingefangen.html)

bleibdoof 13.07.2012 21:12

Win64/Sirefef.w - Sirefef.ab und Sirefef.M eingefangen
 
Hallo zusammen,

gestern habe ich mir anscheinend beim "Googlen"!? Win64/Sirefef.W eingefangen oder zumindest ist in dem Moment der Microsoft Security Essentials angeschlagen. Es meldete zwar, dass es eine Gefahr abgewehrt hätte aber da der IE hing und ich auch den Scanner nicht aufmachen konnte, startete ich neu.

Leider ging dann nach dem Neustart ein Fake Virenscanner auf und lies sich nicht abstellen. Nach jetzigem Nachforschen handelte es sich um Windows Secure Web Patch. In meiner Aufregung habe ich aber erst einmal das System von einem früheren Zeitpunkt den Tag wieder hergestellt. Nach erneutem Reboot war die Fake Software dann nicht mehr vorhanden und Security Essentials, Firewall usw. war auch alles wieder am laufen. Als Funde zeigte MS Security Essentials folgendes:

Win64/Sirefef.AB
Win64/Sirefef.W
Win64/Sirefef.M
Win32/Injector.CB

Danach bin ich nach dieser Anleitung vorgegangen:

http://www.trojaner-board.de/117424-...entfernen.html

Ich habe keine falsche Proxy Einstellung gefunden und auch weder rkill noch Malewarebytes hat ein schlechtes Ergebnis geliefert. Ich habe ansonsten auch noch Spybot Search and Destroy drüber laufen lassen, was auch nichts fand.

Ich wäre jetzt also an dem Punkt "weitergehende Prüfung" angelangt und habe mir OTL geladen und laufen lassen.

OTL.txt:

Code:

OTL logfile created on: 13.07.2012 19:58:53 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Bleibdoof_2\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,95 Gb Available Physical Memory | 73,79% Memory free
8,00 Gb Paging File | 6,78 Gb Available in Paging File | 84,79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,83 Gb Total Space | 9,02 Gb Free Space | 18,48% Space Free | Partition Type: NTFS
Drive D: | 323,77 Gb Total Space | 96,00 Gb Free Space | 29,65% Space Free | Partition Type: NTFS
 
Computer Name: BLEIBDOOF-PC | User Name: Bleibdoof | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Bleibdoof_2\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NisSrv) -- C:\Programme\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0CC3) -- C:\Windows\SysNative\drivers\SaiK0CC3.sys (Saitek)
DRV:64bit: - (SaiU0CC3) -- C:\Windows\SysNative\drivers\SaiU0CC3.sys (Saitek)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6B 5F 93 3B 57 1F CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
 
O1 HOSTS File: ([2012.04.14 00:42:35 | 000,442,669 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.123fporn.info
O1 - Hosts: 15208 more lines...
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Programme\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Programme\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Tools\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4:64bit: - HKLM..\RunOnce: [*Restore] C:\Windows\SysNative\rstrui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\SysNative\WerFault.exe (Microsoft Corporation)
O4:64bit: - HKLM..\RunOnce: [BrowserChoice] C:\Windows\SysNative\browserchoice.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] D:\Tools\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8BE75A4-FEB1-4115-AB9A-C204072E2796}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell - "" = AutoRun
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\AutoRun\command - "" = F:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.12 21:07:44 | 000,000,000 | ---D | C] -- C:\Users\Bleibdoof\AppData\Roaming\Malwarebytes
[2012.07.12 21:06:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.12 21:06:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.12 21:06:29 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.12 20:04:54 | 000,000,000 | ---D | C] -- C:\ProgramData\0C1CFAE730E3C3E7F70FE066F875F002
[2012.07.12 18:19:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2012.07.11 23:18:06 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.07.11 23:18:06 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.07.11 23:18:05 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.07.11 23:18:05 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.07.11 23:18:04 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.07.11 23:18:04 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.07.11 23:18:03 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.07.11 23:18:03 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.07.11 23:18:02 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.07.11 23:18:01 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.07.11 23:18:01 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.07.11 23:18:01 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.07.11 23:18:01 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.07.11 21:00:08 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2012.07.11 21:00:08 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2012.07.11 21:00:04 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012.07.11 21:00:02 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll
[2012.07.11 21:00:01 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll
[2012.07.09 23:15:45 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe
[2012.07.02 12:47:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2012.07.01 23:10:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012.07.01 23:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012.07.01 23:09:00 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.07.01 23:09:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012.07.01 23:04:22 | 000,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Difxe4fc.rra
[2012.07.01 23:04:05 | 000,000,000 | ---D | C] -- C:\Windows\RaidTool
[2012.07.01 22:59:24 | 000,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Difx9f59.rra
[2012.07.01 22:50:11 | 000,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Difx6f92.rra
[2012.06.25 08:27:42 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012.06.25 08:27:42 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012.06.25 08:03:04 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012.06.25 08:03:04 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012.06.25 08:03:04 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012.06.25 08:02:54 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012.06.25 08:02:54 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012.06.25 08:02:54 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012.06.25 08:02:43 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012.06.25 08:02:42 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012.06.14 19:33:02 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.06.14 19:33:02 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.06.14 19:33:02 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.06.14 19:32:43 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.06.14 19:32:43 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.06.14 19:32:42 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.06.14 19:32:38 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012.06.14 19:32:37 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012.06.14 19:32:32 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.13 20:00:29 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.13 20:00:29 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.13 19:53:29 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.13 19:53:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.13 19:53:08 | 3220,033,536 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.12 22:03:22 | 1091,325,490 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.07.12 21:07:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.12 20:33:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.12 17:33:11 | 000,335,608 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.11 22:08:16 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.07.11 22:08:16 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.02 12:34:45 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2012.06.14 22:48:16 | 001,640,188 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.14 22:48:16 | 000,698,748 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.14 22:48:16 | 000,654,066 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.14 22:48:16 | 000,148,944 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.14 22:48:16 | 000,121,898 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
 
========== Files Created - No Company Name ==========
 
[2012.07.12 22:03:22 | 1091,325,490 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.07.12 20:05:04 | 000,001,696 | ---- | C] () -- C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\U\00000001.@
[2012.07.01 23:11:19 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.06.15 18:03:06 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.21 15:04:39 | 002,250,024 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012.04.21 02:46:37 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.21 02:46:34 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.04.21 02:46:23 | 000,000,279 | ---- | C] () -- C:\Windows\game.ini
[2012.04.14 01:12:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.14 00:02:34 | 001,640,718 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.04.13 23:51:09 | 000,002,048 | -HS- | C] () -- C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\@
[2012.03.09 06:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 06:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

< End of report >

Extras.txt:

Code:

OTL Extras logfile created on: 13.07.2012 19:58:53 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Bleibdoof_2\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,95 Gb Available Physical Memory | 73,79% Memory free
8,00 Gb Paging File | 6,78 Gb Available in Paging File | 84,79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,83 Gb Total Space | 9,02 Gb Free Space | 18,48% Space Free | Partition Type: NTFS
Drive D: | 323,77 Gb Total Space | 96,00 Gb Free Space | 29,65% Space Free | Partition Type: NTFS
 
Computer Name: BLEIBDOOF-PC | User Name: Bleibdoof | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{056DC22B-B623-4A07-B6F4-F100054DC0A0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0C59F5E0-B51B-49F3-A987-771F44B806E0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1C1D6A02-645C-4AF4-92AC-6CD685B8C65A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{1C4055A6-F2BC-4E6D-AF78-AFE1E7EDA4B5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5BB0C50A-39F8-450D-8D8A-3E78388E0639}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{684C0038-C213-44FD-B67D-95048AF3C4C4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9FA0E354-93F8-4BAB-8D2B-DD9975490EFF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E269D46B-A5C1-4CE6-8C52-C6B923555A09}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F6105D79-A0C2-4AFF-906E-E4CCD5F3DF30}" = lport=10243 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03D4CB13-FAC0-4665-891F-1AC02FD86419}" = protocol=6 | dir=in | app=d:\games\cod4\iw3mp.exe |
"{03E2DA23-CDFC-427B-8D75-15A2BFB0CCF5}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0613F84A-53C8-4525-8525-E93A60BED2D4}" = protocol=17 | dir=in | app=d:\games\diablo iii\diablo iii.exe |
"{0C128B66-0451-4A6C-9EC4-B4296BE9B6B3}" = protocol=6 | dir=out | app=system |
"{1A1E3FC9-C110-4759-BD34-29FADD0C32AA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1A4DB4F3-6BFB-4D38-ACC9-DAFA678BA190}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1C9FFBED-FA63-44E7-B0EA-7130A9C3B1C6}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{20A86954-A420-48F5-83EF-A1E61A3E7521}" = protocol=17 | dir=in | app=d:\games\lotr\game.dat |
"{33557123-99A2-46F5-94B4-DD4334883272}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{349CBCE4-2FC6-4E89-9630-1C29A4CDB5AB}" = dir=in | app=c:\program files (x86)\electronic arts\command & conquer 3 kanes rache\retailexe\1.2\cnc3ep1.dat |
"{38BAC060-5E2B-479E-A48C-4937D2B4F923}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{39DC7748-4034-4CBA-B524-F9FD7A69E9E5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{3E15C86B-7935-4C12-8596-C72553FD556E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{41D3D1EE-DE8E-494C-B1A4-2CD9656CF3B5}" = protocol=6 | dir=in | app=d:\games\diablo-iii-8370-dede-installer-downloader.exe |
"{5997D927-8655-4390-B4FC-159D5044E0A8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5AD37E78-3127-442E-B2B0-BEC02FB6DBE7}" = protocol=6 | dir=in | app=c:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe |
"{7A81EC17-23C3-4CD6-8580-58F366FEB3DC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{870C4E18-F8C5-4570-B743-EEEB33C8FACE}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{947541D1-5CB4-421F-AA48-48B99C5954BF}" = protocol=6 | dir=in | app=d:\games\starcraft ii\starcraft ii.exe |
"{95B049F1-CE4A-4783-B90A-01B1E4D720C2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{97FE9954-3CA5-4D93-8640-04F898393BB0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A462AED6-74F7-4059-BF79-85C5E9D74B55}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{A4897AE4-C68F-45B2-AA65-A51CAD2CFCD3}" = protocol=6 | dir=in | app=d:\tools\neuer ordner\opera.exe |
"{ABC8EBB5-AB82-4527-9C0E-0FF92CBBCA71}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{AE2E3917-B2CB-41A0-94BF-8922CD2AD6B7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{B8823F9E-C1DD-4C31-BD4D-F828C29DE9DF}" = protocol=17 | dir=in | app=d:\games\diablo-iii-8370-dede-installer-downloader.exe |
"{B9133217-A26E-4539-AFF0-278947B8A6F7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe |
"{BA699BCD-219F-42FC-B22E-1E085226B659}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BD5DBC94-D40E-4E87-85C7-A8E95C7728AE}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe |
"{BE26F805-07E2-4035-8B4B-F7EF89ED0CA1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{BF145D78-A743-4BF0-9789-B780CB16C436}" = protocol=17 | dir=in | app=c:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe |
"{C009F136-AD61-4C10-9FF5-9FC4EDF9E3A0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C5A57C1D-5769-4203-A5D7-F082040320A1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{C7235464-F8A2-473C-89F5-1C24501031C2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C7695935-0CF2-4033-8264-14FB9B169E3F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{C95929DB-9415-419F-B98D-1EDE8C2AD771}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{CECC2FEE-83CB-4C1C-96EF-153E38553C03}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{D2F7EA0D-62A7-4FA3-9612-A9E5AB75811C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D8198D5B-83BE-408A-82E3-AB0B2F83CCA8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D908FF2F-DFF7-4A1E-A63C-1077EFCD63EB}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe |
"{DCAF30CF-6581-486D-A9E0-F78F824F315B}" = protocol=17 | dir=in | app=d:\games\starcraft ii\starcraft ii.exe |
"{DD026B45-CBDA-4817-89B4-02F2AD75920B}" = protocol=6 | dir=in | app=d:\games\lotr\game.dat |
"{E080C29A-0B9B-41F9-AA7E-CDCBB4215C67}" = protocol=6 | dir=in | app=d:\games\diablo iii\diablo iii.exe |
"{E33D1EA7-4304-400C-A25D-C41F7CB936C7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E930E349-B569-41D4-BCCA-0DF2BEEFE7ED}" = protocol=17 | dir=in | app=d:\games\cod4\iw3mp.exe |
"{EB6DDFEF-6EE0-4208-B9F1-09603C278A9C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe |
"{EBA30A87-B88C-4AA2-8758-631E58D3A5D6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe |
"{F2948757-101A-407F-A0E8-ADBDD80728C0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F51DDC4D-EE08-4358-9097-95F5F44D383F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FBF33333-60EF-49B6-8478-7FB6119DEA38}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe |
"{FF202659-F337-4315-8D64-F880AA53817E}" = protocol=17 | dir=in | app=d:\tools\neuer ordner\opera.exe |
"TCP Query User{1E7C1DCD-F324-46CD-8428-C5BB39E7486A}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"TCP Query User{288CA671-A9F5-4385-BBFB-4396E65D1302}D:\games\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=d:\games\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{339F38E0-2C91-4315-8AD0-B99AC56724E1}D:\games\flatout2\flatout2.exe" = protocol=6 | dir=in | app=d:\games\flatout2\flatout2.exe |
"TCP Query User{349F6539-1428-4175-ADA1-FD8D48B5D786}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"TCP Query User{5B6D0687-6D45-4ED0-8C9D-8AEB1220C74A}D:\games\diablo-iii-8370-dede-installer-downloader.exe" = protocol=6 | dir=in | app=d:\games\diablo-iii-8370-dede-installer-downloader.exe |
"TCP Query User{5D3D7352-8F9A-42DF-81DC-788B59E40F85}D:\games\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=d:\games\starcraft ii\versions\base21029\sc2.exe |
"TCP Query User{5DDA7482-C182-48DB-9AC7-A23F1A2569B3}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"TCP Query User{731BC905-36BC-42C0-BA8F-4F901E585980}C:\programdata\battle.net\agent\agent.954\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"TCP Query User{7C05993C-5C51-401B-B68C-8AAFDC8744F6}D:\games\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"TCP Query User{8083A661-64FA-4665-8763-C384EBB3E2F8}C:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe |
"TCP Query User{8902D0A2-8BEC-4D30-9970-F3D3B75A7A17}D:\games\lfd2steamless\left4dead2.exe" = protocol=6 | dir=in | app=d:\games\lfd2steamless\left4dead2.exe |
"TCP Query User{CFF81832-5201-4EB8-AEA4-F0314BF3459E}D:\tools\neuer ordner\opera.exe" = protocol=6 | dir=in | app=d:\tools\neuer ordner\opera.exe |
"TCP Query User{D284A313-0E35-4F89-9254-F9BF8DE57E3B}D:\games\diablo iii\diablo iii.exe" = protocol=6 | dir=in | app=d:\games\diablo iii\diablo iii.exe |
"TCP Query User{D32672EB-7371-4F97-8BAF-8606438D58F5}C:\users\bleibdoof_2\appdata\local\programs\opera\opera.exe" = protocol=6 | dir=in | app=c:\users\bleibdoof_2\appdata\local\programs\opera\opera.exe |
"UDP Query User{1C8C7404-90E4-462F-8483-3B420CC6EB63}C:\users\bleibdoof_2\appdata\local\programs\opera\opera.exe" = protocol=17 | dir=in | app=c:\users\bleibdoof_2\appdata\local\programs\opera\opera.exe |
"UDP Query User{1D7D1C7E-F199-49CB-B3FB-C334A0C7C255}D:\tools\neuer ordner\opera.exe" = protocol=17 | dir=in | app=d:\tools\neuer ordner\opera.exe |
"UDP Query User{2B3C95B6-A170-4A88-886A-946A6DF22763}D:\games\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=d:\games\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{478BF1F8-580A-4D25-88E7-0C894C8FC5BC}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"UDP Query User{4FD1B35E-397A-4D38-B643-377DDDFC607D}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"UDP Query User{71800D5D-00DD-4874-8973-699962B807A3}D:\games\flatout2\flatout2.exe" = protocol=17 | dir=in | app=d:\games\flatout2\flatout2.exe |
"UDP Query User{7231B6A3-26D6-4D9C-8A59-FA98548C5434}D:\games\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=d:\games\starcraft ii\versions\base21029\sc2.exe |
"UDP Query User{730F3547-BB29-41AC-B1E3-C43DCE478BAE}D:\games\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\games\counter-strike source\hl2.exe |
"UDP Query User{77C1E06B-D519-4D2E-8AAD-CD96EEA0AF25}D:\games\lfd2steamless\left4dead2.exe" = protocol=17 | dir=in | app=d:\games\lfd2steamless\left4dead2.exe |
"UDP Query User{7B54B3BB-C000-45B3-9B61-C1B2B9598E94}D:\games\diablo-iii-8370-dede-installer-downloader.exe" = protocol=17 | dir=in | app=d:\games\diablo-iii-8370-dede-installer-downloader.exe |
"UDP Query User{AB6D031C-A67D-4AE5-A1DB-F086A98F9514}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"UDP Query User{EC669FA8-F999-4677-A017-2ACF9210FD5B}D:\games\diablo iii\diablo iii.exe" = protocol=17 | dir=in | app=d:\games\diablo iii\diablo iii.exe |
"UDP Query User{F1074749-FFBE-4045-AB1A-E3157CBF64CB}C:\programdata\battle.net\agent\agent.954\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"UDP Query User{FCFFB5DB-6DE5-4CCF-8281-249A42B1EB8A}C:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\bleibdoof_2\appdata\roaming\spotify\spotify.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{06DB2C4C-DC29-DA42-3B00-5581CBF545BB}" = AMD Drag and Drop Transcoding
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{2E8D6204-D656-8355-1ED3-2988AC52EB0F}" = ccc-utility64
"{3987279A-3504-2916-D063-741B910F0747}" = AMD Accelerated Video Transcoding
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}" = AMD Catalyst Install Manager
"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{96B0B2F7-1853-464D-B520-CA08F9CA8002}" = Smart Technology Programming Software 7.0.0.26
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian
"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish
"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3F290582-3F4E-4B96-009C-E0BABAA40C42}" = Die Schlacht um Mittelerde(tm)
"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy
"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese
"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech
"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai
"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional
"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German
"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek
"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{91CA0407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{91CB5B8B-4EC8-DBA1-A88D-99FD480567B0}" = CCC Help English
"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish
"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish
"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French
"{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}" = FlatOut2
"{CC2422C9-F7B5-4175-B295-5EC2283AA674}" = Command & Conquer™ 3: Kanes Rache
"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean
"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian
"{D544AE4C-4152-225B-A897-6756C8986B14}" = Catalyst Control Center
"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"BitBox" = Browser in the Box
"Counter-Strike: Source" = Counter-Strike: Source
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo III" = Diablo III
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.62.0.1300
"Opera 11.62.1347" = Opera 11.62
"PunkBusterSvc" = PunkBuster Services
"Steam App 105600" = Terraria
"Steamless Left4Dead2 Pack" = Steamless Left4Dead2 Pack
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 11.07.2012 14:52:09 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 11:12:50 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 11:33:20 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 12:03:35 | Computer Name = Bleibdoof-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" in Zeile 8.  Der
 Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 12.07.2012 14:06:52 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 14:12:04 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 15:15:56 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.07.2012 16:05:06 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 13.07.2012 13:45:48 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 13.07.2012 13:53:24 | Computer Name = Bleibdoof-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 12.07.2012 16:04:02 | Computer Name = Bleibdoof-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.07.2012 16:04:08 | Computer Name = Bleibdoof-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.07.2012 16:04:10 | Computer Name = Bleibdoof-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.07.2012 16:04:10 | Computer Name = Bleibdoof-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.07.2012 16:04:10 | Computer Name = Bleibdoof-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 12.07.2012 16:04:10 | Computer Name = Bleibdoof-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der
 aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 12.07.2012 16:04:10 | Computer Name = Bleibdoof-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der
 aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 12.07.2012 16:05:37 | Computer Name = Bleibdoof-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "PnP-X-IP-Busenumerator" ist vom Dienst "Funktionssuchanbieter-Host"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 12.07.2012 16:08:51 | Computer Name = Bleibdoof-PC | Source = DCOM | ID = 10005
Description =
 
Error - 13.07.2012 13:52:12 | Computer Name = Bleibdoof-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  discache  MpFilter  spldr  Wanarpv6
 
 
< End of report >

Ansonsten füge ich noch einmal das Scanergebnis von MWB an.

Für mich stellt sich jetzt die Frage, ob der Rechner überhaupt trotzdem wieder sauber sein kann und ich "nur" Passwörter ändern muss (kein Onlinebanking, kein Arbeitsrechner nur Ebay/amazon usw.) oder ob neu aufgesetzt werden muss. Es wurden ja vier Funde gemeldet und ich weiß jetzt nicht, ob alle mit dieser Fake Software zu tun haben.

Ich hoffe, ich habe soweit alles richtig gepostet und vielen Dank im Voraus!

mfg

Sebastian

cosinus 14.07.2012 17:22

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

bleibdoof 14.07.2012 19:46

Moin und danke für die schnelle Rückmeldung!

Bevor mir der Kram jetzt passiert ist, habe ich nur Security Essentials und Spybot SD hin und wieder mal drüber laufen lassen.

Das war also mein erster Scan mit MWB bzw. beim wirklich ersten Versuch ist mir der Rechner abgestürzt, davon scheinen auch keine Teil-Logs zu existieren, dies ist das einzige, das gelistet ist.

mfg

Sebastian

Edit: Ich weiß nicht, ob es wichtig ist: Aber eigentlich benutze ich den Rechner nur mit einem eingeschränkten Konto ohne Administrator Rechte... Hat wohl trotzdem nicht geholfen :(

cosinus 14.07.2012 22:09

Natürlich sind eingeschränkte kein Allheimmittel! Und v.a. helfen eingeschränkte auch nicht allein, man muss mehrere Maßnahmen gleichzeitig/parallel haben!

Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://img695.imageshack.us/img695/1599/eset1l.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.

bleibdoof 15.07.2012 12:19

Guten Morgen,

ich habe Eset jetzt mal durchlaufen lassen, es hat auch zwei Meldungen gegeben, die ich dann auch im Log erwartet hätte, aber das sieht irgendwie nur so aus:

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

Mehr steht da nicht drin. Ich habe mir die Funde jetzt natürlich auch nicht aufgeschrieben... Im Verzeichnis habe ich auch geschaut, dort gibt es keine weitere Log Datei.

Soll ich noch einmal ausführen, hoffen, dass das Log dann stimmt und auf jeden Fall die Funde notieren?

cosinus 15.07.2012 17:20

ESET hast du wahrscheinlich falsch gemacht, da gab es extra einen dicken Hinweis zu

Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen

bleibdoof 16.07.2012 18:14

Sorry, das wirds wohl gewesen sein. Ich hatte zwar den Text gelesen, aber völlig falsch geschlussfolgert, dass ich mich besser als Adminstrator anmelde und dann laufen lasse. Kann ja keiner ahnen, dass man als Administrator noch als Administrator ausführen wählen muss :crazy: Naja manchmal sollte man weniger denken.

So hier also das jetzige Ergebnis mit den zwei Funden:

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-16 04:02:39
# local_time=2012-07-16 06:02:39 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 8094503 94078837 0 0
# compatibility_mode=8192 67108863 100 0 105313 105313 0 0
# scanned=292471
# found=2
# cleaned=0
# scan_time=5571
C:\Users\Bleibdoof_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AY2ORH61\11354360[1].htm        HTML/Iframe.B.Gen virus (unable to clean)        00000000000000000000000000000000        I
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\51141ad8-7ab19b28        a variant of Win32/Injector.TXA trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 17.07.2012 08:38

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

bleibdoof 17.07.2012 15:38

1.) Bis auf eine Sache läuft Windows wieder ganz normal. Auffällig war jedoch, dass ich auf einmal ein neues Item auf dem Desktop hatte um beim Start eine Meldung dazu erschien zur "Browserwahl". Scheint ja eine Windows Geschichte zu sein, allerdings hatte ich diese davor nicht.

2.) Im Startmenü scheint nichts zu fehlen.

cosinus 18.07.2012 15:19

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

bleibdoof 18.07.2012 17:27

Moin!

Hier die Ergebnisse des Durchlaufes:

Code:

# AdwCleaner v1.702 - Logfile created 07/18/2012 at 18:20:41
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Bleibdoof - BLEIBDOOF-PC
# Running from : C:\Users\Bleibdoof\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Found : HKLM\SOFTWARE\DT Soft
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
[x64] Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [821 octets] - [18/07/2012 18:20:41]

########## EOF - C:\AdwCleaner[R1].txt - [948 octets] ##########


cosinus 19.07.2012 09:22

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

bleibdoof 19.07.2012 18:35

Guten Abend,

hier die Log-Datei:

Code:

# AdwCleaner v1.702 - Logfile created 07/19/2012 at 19:28:46
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Bleibdoof - BLEIBDOOF-PC
# Running from : C:\Users\Bleibdoof\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKLM\SOFTWARE\DT Soft
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [946 octets] - [18/07/2012 18:20:41]
AdwCleaner[S1].txt - [757 octets] - [19/07/2012 19:28:46]

########## EOF - C:\AdwCleaner[S1].txt - [884 octets] ##########


cosinus 19.07.2012 20:10

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


bleibdoof 20.07.2012 17:32

Moin!

Nach einem Absturz (der Ram hat vielleicht einen weg?) hier jetzt das Log vom zweiten Durchlauf:

Code:

OTL logfile created on: 20.07.2012 18:13:34 - Run 2
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Bleibdoof_2\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,87 Gb Available Physical Memory | 71,71% Memory free
8,00 Gb Paging File | 6,67 Gb Available in Paging File | 83,40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,83 Gb Total Space | 10,41 Gb Free Space | 21,32% Space Free | Partition Type: NTFS
Drive D: | 323,77 Gb Total Space | 96,00 Gb Free Space | 29,65% Space Free | Partition Type: NTFS
 
Computer Name: BLEIBDOOF-PC | User Name: Bleibdoof | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Bleibdoof_2\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NisSrv) -- C:\Programme\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0CC3) -- C:\Windows\SysNative\drivers\SaiK0CC3.sys (Saitek)
DRV:64bit: - (SaiU0CC3) -- C:\Windows\SysNative\drivers\SaiU0CC3.sys (Saitek)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CF 63 F4 BD 69 62 CD 01  [binary data]
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A7 47 AF 0D 1F 1A CD 01  [binary data]
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3719525052-158936444-3296064491-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
 
O1 HOSTS File: ([2012.04.14 00:42:35 | 000,442,669 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.123fporn.info
O1 - Hosts: 15208 more lines...
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Programme\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Programme\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1000..\Run: [DAEMON Tools Lite] D:\Tools\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1003..\Run: [DAEMON Tools Lite] D:\Tools\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1003..\Run: [Spotify] C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1003..\Run: [Spotify Web Helper] C:\Users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1003..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8BE75A4-FEB1-4115-AB9A-C204072E2796}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell - "" = AutoRun
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\AutoRun\command - "" = F:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - C:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.16 20:41:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2012.07.15 11:24:34 | 000,000,000 | ---D | C] -- C:\Users\Bleibdoof\AppData\Roaming\Skype
[2012.07.15 11:14:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.12 21:07:44 | 000,000,000 | ---D | C] -- C:\Users\Bleibdoof\AppData\Roaming\Malwarebytes
[2012.07.12 21:06:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.12 21:06:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.12 21:06:29 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.12 20:04:54 | 000,000,000 | ---D | C] -- C:\ProgramData\0C1CFAE730E3C3E7F70FE066F875F002
[2012.07.12 18:19:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2012.07.02 12:47:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2012.07.01 23:10:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012.07.01 23:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012.07.01 23:09:00 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.07.01 23:09:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012.07.01 23:04:05 | 000,000,000 | ---D | C] -- C:\Windows\RaidTool
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.20 18:12:24 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.20 18:12:24 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.20 18:10:49 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.20 18:07:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.20 18:04:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.20 18:04:50 | 3220,033,536 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.19 22:38:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.18 18:20:21 | 000,624,883 | ---- | M] () -- C:\Users\Bleibdoof\Desktop\adwcleaner.exe
[2012.07.15 11:24:18 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.07.12 17:33:11 | 000,335,608 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.02 12:34:45 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
 
========== Files Created - No Company Name ==========
 
[2012.07.18 18:19:48 | 000,624,883 | ---- | C] () -- C:\Users\Bleibdoof\Desktop\adwcleaner.exe
[2012.07.15 11:24:18 | 000,001,750 | ---- | C] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.07.12 20:05:04 | 000,001,696 | ---- | C] () -- C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\U\00000001.@
[2012.07.01 23:11:19 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.04.21 15:04:39 | 002,250,024 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012.04.21 02:46:37 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.04.21 02:46:34 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.04.21 02:46:23 | 000,000,279 | ---- | C] () -- C:\Windows\game.ini
[2012.04.14 01:12:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.14 00:02:34 | 001,640,718 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.04.13 23:51:09 | 000,002,048 | -HS- | C] () -- C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\@
[2012.03.09 06:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 06:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.04.20 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\DAEMON Tools Lite
[2012.07.12 20:03:47 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Ahux
[2012.04.21 01:09:12 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Command & Conquer 3 Kanes Rache
[2012.04.20 23:10:34 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\DAEMON Tools Lite
[2012.04.21 17:57:37 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Meine Die Schlacht um Mittelerde-Dateien
[2012.04.24 22:09:53 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Opera
[2012.04.24 23:11:35 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Sirrix AG
[2012.07.20 18:11:06 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Spotify
[2012.07.12 20:07:28 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof_2\AppData\Roaming\Usyze
[2009.07.14 07:08:49 | 000,030,366 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.04.20 19:27:32 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Adobe
[2012.04.14 14:33:51 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\ATI
[2012.04.20 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\DAEMON Tools Lite
[2012.04.13 23:38:40 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Identities
[2012.04.21 00:04:24 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Macromedia
[2012.07.12 21:07:44 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Malwarebytes
[2011.04.12 09:54:43 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Media Center Programs
[2012.04.20 19:34:28 | 000,000,000 | --SD | M] -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft
[2012.07.20 18:10:25 | 000,000,000 | ---D | M] -- C:\Users\Bleibdoof\AppData\Roaming\Skype
 
< %APPDATA%\*.exe /s >
[2012.04.20 19:34:28 | 000,011,502 | R--- | M] () -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Installer\{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}\ARPPRODUCTICON.exe
[2012.04.20 19:34:28 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Installer\{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}\FlatOut2.exe1_C884B05AF5D94AE49D84E6BD9F6E7890.exe
[2012.04.20 19:34:28 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Installer\{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}\FlatOut2.exe_C884B05AF5D94AE49D84E6BD9F6E7890.exe
[2012.04.20 19:34:28 | 000,015,086 | R--- | M] () -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Installer\{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}\NewShortcut5_C884B05AF5D94AE49D84E6BD9F6E7890.exe
[2012.04.20 19:34:28 | 000,008,854 | R--- | M] () -- C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Installer\{C884B05A-F5D9-4AE4-9D84-E6BD9F6E7890}\Uninstall_FlatOut2_C884B05AF5D94AE49D84E6BD9F6E7890.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Bleibdoof\AppData\Local\Temp\RarSFX0\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Bleibdoof\AppData\Local\Temp\RarSFX1\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Bleibdoof\AppData\Local\Temp\RarSFX0\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Bleibdoof\AppData\Local\Temp\RarSFX1\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >


cosinus 21.07.2012 14:54

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O4 - HKU\S-1-5-21-3719525052-158936444-3296064491-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell - "" = AutoRun
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\AutoRun\command - "" = F:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe
:Files
C:\ProgramData\0C1CFAE730E3C3E7F70FE066F875F002
C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\U
C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\@
C:\Users\Bleibdoof_2\AppData\Roaming\Ahux
C:\Users\Bleibdoof_2\AppData\Roaming\Usyze
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

bleibdoof 21.07.2012 18:39

Moin!

Nach dem Durchlauf wurde ich aufgefordert neu zu starten, es wurde aber kein Log-File geöffnet. Der Neustart hing irgendwie, da musste ich manuell nachhelfen.

Danach wurde auch kein Log-File geöffnet. Ich habe mal in dem von dir beschriebenen Ordner geschaut, da ist das folgende Textdokument drin:

Code:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-3719525052-158936444-3296064491-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer deleted successfully.
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ not found.
File F:\setup\rsrc\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa80945e-8b03-11e1-a81e-001617ef09bb}\ not found.
File F:\Directx\dxsetup.exe not found.
========== FILES ==========
C:\ProgramData\0C1CFAE730E3C3E7F70FE066F875F002 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\U folder moved successfully.
C:\Users\Bleibdoof_2\AppData\Local\{867760fd-04c3-f3d9-19c3-4af6794328c3}\@ moved successfully.
C:\Users\Bleibdoof_2\AppData\Roaming\Ahux folder moved successfully.
C:\Users\Bleibdoof_2\AppData\Roaming\Usyze folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Bleibdoof
->Temp folder emptied: 368055782 bytes
->Temporary Internet Files folder emptied: 45213387 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1135 bytes
 
User: Bleibdoof_2
->Temp folder emptied: 6326513 bytes
->Temporary Internet Files folder emptied: 237622928 bytes
->Opera cache emptied: 22325359 bytes
->Flash cache emptied: 8276 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 220844638 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36028471 bytes
RecycleBin emptied: 14692711860 bytes
 
Total Files Cleaned = 14.905,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Bleibdoof
->Flash cache emptied: 0 bytes
 
User: Bleibdoof_2
->Flash cache emptied: 0 bytes
 
User: Default
 
User: Default User
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.54.0 log created on 07212012_191402

Ich hoffe, das ist das richtige?

Danke mal wieder!

cosinus 23.07.2012 13:59

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

bleibdoof 23.07.2012 19:16

Hier das Ergebnis:

Code:

20:10:41.0006 1944        TDSS rootkit removing tool 2.7.47.0 Jul 20 2012 20:36:30
20:10:41.0240 1944        ============================================================
20:10:41.0240 1944        Current date / time: 2012/07/23 20:10:41.0240
20:10:41.0240 1944        SystemInfo:
20:10:41.0240 1944       
20:10:41.0240 1944        OS Version: 6.1.7601 ServicePack: 1.0
20:10:41.0240 1944        Product type: Workstation
20:10:41.0240 1944        ComputerName: BLEIBDOOF-PC
20:10:41.0240 1944        UserName: Bleibdoof
20:10:41.0240 1944        Windows directory: C:\Windows
20:10:41.0240 1944        System windows directory: C:\Windows
20:10:41.0240 1944        Running under WOW64
20:10:41.0240 1944        Processor architecture: Intel x64
20:10:41.0240 1944        Number of processors: 2
20:10:41.0240 1944        Page size: 0x1000
20:10:41.0240 1944        Boot type: Normal boot
20:10:41.0240 1944        ============================================================
20:10:42.0303 1944        Drive \Device\Harddisk0\DR0 - Size: 0x5D27216000 (372.61 Gb), SectorSize: 0x200, Cylinders: 0xBE01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:10:42.0318 1944        ============================================================
20:10:42.0318 1944        \Device\Harddisk0\DR0:
20:10:42.0334 1944        MBR partitions:
20:10:42.0334 1944        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x61A7927
20:10:42.0334 1944        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x61A79A5, BlocksNum 0x2878C45B
20:10:42.0334 1944        ============================================================
20:10:42.0365 1944        C: <-> \Device\Harddisk0\DR0\Partition0
20:10:42.0381 1944        D: <-> \Device\Harddisk0\DR0\Partition1
20:10:42.0381 1944        ============================================================
20:10:42.0381 1944        Initialize success
20:10:42.0381 1944        ============================================================
20:11:08.0428 3008        ============================================================
20:11:08.0428 3008        Scan started
20:11:08.0428 3008        Mode: Manual; SigCheck; TDLFS;
20:11:08.0428 3008        ============================================================
20:11:09.0287 3008        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
20:11:09.0365 3008        1394ohci - ok
20:11:09.0412 3008        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
20:11:09.0428 3008        ACPI - ok
20:11:09.0443 3008        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
20:11:09.0506 3008        AcpiPmi - ok
20:11:09.0599 3008        AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:11:09.0615 3008        AdobeARMservice - ok
20:11:09.0709 3008        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:11:09.0709 3008        AdobeFlashPlayerUpdateSvc - ok
20:11:09.0771 3008        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
20:11:09.0787 3008        adp94xx - ok
20:11:09.0849 3008        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
20:11:09.0865 3008        adpahci - ok
20:11:09.0896 3008        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
20:11:09.0912 3008        adpu320 - ok
20:11:09.0943 3008        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
20:11:10.0053 3008        AeLookupSvc - ok
20:11:10.0115 3008        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
20:11:10.0162 3008        AFD - ok
20:11:10.0193 3008        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
20:11:10.0209 3008        agp440 - ok
20:11:10.0240 3008        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
20:11:10.0287 3008        ALG - ok
20:11:10.0303 3008        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
20:11:10.0318 3008        aliide - ok
20:11:10.0365 3008        AMD External Events Utility (20c8a3e435a47f0408a1ea674afa6194) C:\Windows\system32\atiesrxx.exe
20:11:10.0428 3008        AMD External Events Utility - ok
20:11:10.0443 3008        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
20:11:10.0443 3008        amdide - ok
20:11:10.0474 3008        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
20:11:10.0506 3008        AmdK8 - ok
20:11:11.0021 3008        amdkmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
20:11:11.0334 3008        amdkmdag - ok
20:11:11.0474 3008        amdkmdap        (0e57258e5cc4cc7a9a9a877afdf0cec6) C:\Windows\system32\DRIVERS\atikmpag.sys
20:11:11.0506 3008        amdkmdap - ok
20:11:11.0537 3008        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
20:11:11.0568 3008        AmdPPM - ok
20:11:11.0584 3008        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
20:11:11.0599 3008        amdsata - ok
20:11:11.0631 3008        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
20:11:11.0646 3008        amdsbs - ok
20:11:11.0662 3008        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
20:11:11.0662 3008        amdxata - ok
20:11:11.0693 3008        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
20:11:11.0834 3008        AppID - ok
20:11:11.0849 3008        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
20:11:11.0896 3008        AppIDSvc - ok
20:11:11.0912 3008        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
20:11:11.0974 3008        Appinfo - ok
20:11:12.0006 3008        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
20:11:12.0021 3008        arc - ok
20:11:12.0037 3008        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
20:11:12.0053 3008        arcsas - ok
20:11:12.0131 3008        aspnet_state    (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:11:12.0146 3008        aspnet_state - ok
20:11:12.0178 3008        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
20:11:12.0224 3008        AsyncMac - ok
20:11:12.0240 3008        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
20:11:12.0240 3008        atapi - ok
20:11:12.0303 3008        AtiHDAudioService (24464b908e143d2561e9e452fee97309) C:\Windows\system32\drivers\AtihdW76.sys
20:11:12.0318 3008        AtiHDAudioService - ok
20:11:12.0396 3008        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:11:12.0459 3008        AudioEndpointBuilder - ok
20:11:12.0459 3008        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:11:12.0490 3008        AudioSrv - ok
20:11:12.0521 3008        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
20:11:12.0599 3008        AxInstSV - ok
20:11:12.0662 3008        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
20:11:12.0693 3008        b06bdrv - ok
20:11:12.0740 3008        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
20:11:12.0771 3008        b57nd60a - ok
20:11:12.0818 3008        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
20:11:12.0849 3008        BDESVC - ok
20:11:12.0865 3008        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
20:11:12.0928 3008        Beep - ok
20:11:13.0021 3008        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
20:11:13.0084 3008        BFE - ok
20:11:13.0146 3008        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
20:11:13.0224 3008        BITS - ok
20:11:13.0271 3008        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
20:11:13.0303 3008        blbdrive - ok
20:11:13.0334 3008        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
20:11:13.0381 3008        bowser - ok
20:11:13.0396 3008        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
20:11:13.0428 3008        BrFiltLo - ok
20:11:13.0443 3008        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
20:11:13.0459 3008        BrFiltUp - ok
20:11:13.0490 3008        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
20:11:13.0537 3008        Browser - ok
20:11:13.0568 3008        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
20:11:13.0615 3008        Brserid - ok
20:11:13.0615 3008        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
20:11:13.0646 3008        BrSerWdm - ok
20:11:13.0662 3008        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:11:13.0693 3008        BrUsbMdm - ok
20:11:13.0709 3008        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
20:11:13.0724 3008        BrUsbSer - ok
20:11:13.0740 3008        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
20:11:13.0771 3008        BTHMODEM - ok
20:11:13.0803 3008        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
20:11:13.0834 3008        bthserv - ok
20:11:13.0849 3008        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
20:11:13.0881 3008        cdfs - ok
20:11:13.0928 3008        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
20:11:13.0959 3008        cdrom - ok
20:11:13.0974 3008        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:11:14.0037 3008        CertPropSvc - ok
20:11:14.0068 3008        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
20:11:14.0084 3008        circlass - ok
20:11:14.0115 3008        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
20:11:14.0131 3008        CLFS - ok
20:11:14.0193 3008        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:11:14.0209 3008        clr_optimization_v2.0.50727_32 - ok
20:11:14.0256 3008        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:11:14.0256 3008        clr_optimization_v2.0.50727_64 - ok
20:11:14.0334 3008        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:11:14.0349 3008        clr_optimization_v4.0.30319_32 - ok
20:11:14.0553 3008        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:11:14.0553 3008        clr_optimization_v4.0.30319_64 - ok
20:11:14.0584 3008        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
20:11:14.0599 3008        CmBatt - ok
20:11:14.0615 3008        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
20:11:14.0631 3008        cmdide - ok
20:11:14.0678 3008        CNG            (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
20:11:14.0724 3008        CNG - ok
20:11:14.0740 3008        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
20:11:14.0740 3008        Compbatt - ok
20:11:14.0787 3008        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
20:11:14.0803 3008        CompositeBus - ok
20:11:14.0818 3008        COMSysApp - ok
20:11:14.0818 3008        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
20:11:14.0834 3008        crcdisk - ok
20:11:14.0865 3008        CryptSvc        (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
20:11:14.0896 3008        CryptSvc - ok
20:11:14.0943 3008        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:11:14.0990 3008        DcomLaunch - ok
20:11:15.0021 3008        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
20:11:15.0084 3008        defragsvc - ok
20:11:15.0115 3008        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
20:11:15.0162 3008        DfsC - ok
20:11:15.0193 3008        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
20:11:15.0240 3008        Dhcp - ok
20:11:15.0240 3008        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
20:11:15.0287 3008        discache - ok
20:11:15.0318 3008        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
20:11:15.0318 3008        Disk - ok
20:11:15.0349 3008        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
20:11:15.0396 3008        Dnscache - ok
20:11:15.0412 3008        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
20:11:15.0459 3008        dot3svc - ok
20:11:15.0474 3008        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
20:11:15.0521 3008        DPS - ok
20:11:15.0553 3008        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
20:11:15.0584 3008        drmkaud - ok
20:11:15.0631 3008        dtsoftbus01    (46571ed73ae84469dca53081d33cf3c8) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
20:11:15.0631 3008        dtsoftbus01 - ok
20:11:15.0709 3008        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
20:11:15.0724 3008        DXGKrnl - ok
20:11:15.0756 3008        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
20:11:15.0803 3008        EapHost - ok
20:11:15.0974 3008        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
20:11:16.0037 3008        ebdrv - ok
20:11:16.0131 3008        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
20:11:16.0178 3008        EFS - ok
20:11:16.0256 3008        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
20:11:16.0303 3008        ehRecvr - ok
20:11:16.0334 3008        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
20:11:16.0349 3008        ehSched - ok
20:11:16.0428 3008        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
20:11:16.0459 3008        elxstor - ok
20:11:16.0474 3008        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
20:11:16.0490 3008        ErrDev - ok
20:11:16.0537 3008        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
20:11:16.0584 3008        EventSystem - ok
20:11:16.0615 3008        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
20:11:16.0646 3008        exfat - ok
20:11:16.0662 3008        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
20:11:16.0709 3008        fastfat - ok
20:11:16.0771 3008        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
20:11:16.0803 3008        Fax - ok
20:11:16.0834 3008        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
20:11:16.0849 3008        fdc - ok
20:11:16.0896 3008        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
20:11:16.0943 3008        fdPHost - ok
20:11:16.0959 3008        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
20:11:17.0006 3008        FDResPub - ok
20:11:17.0037 3008        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
20:11:17.0037 3008        FileInfo - ok
20:11:17.0053 3008        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
20:11:17.0084 3008        Filetrace - ok
20:11:17.0115 3008        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
20:11:17.0131 3008        flpydisk - ok
20:11:17.0146 3008        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
20:11:17.0162 3008        FltMgr - ok
20:11:17.0240 3008        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
20:11:17.0287 3008        FontCache - ok
20:11:17.0334 3008        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:11:17.0349 3008        FontCache3.0.0.0 - ok
20:11:17.0412 3008        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
20:11:17.0412 3008        FsDepends - ok
20:11:17.0459 3008        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
20:11:17.0459 3008        Fs_Rec - ok
20:11:17.0506 3008        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
20:11:17.0521 3008        fvevol - ok
20:11:17.0537 3008        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
20:11:17.0553 3008        gagp30kx - ok
20:11:17.0615 3008        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
20:11:17.0662 3008        gpsvc - ok
20:11:17.0756 3008        gupdate        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:11:17.0771 3008        gupdate - ok
20:11:17.0771 3008        gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:11:17.0771 3008        gupdatem - ok
20:11:17.0818 3008        gusvc          (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
20:11:17.0834 3008        gusvc - ok
20:11:17.0865 3008        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
20:11:17.0896 3008        hcw85cir - ok
20:11:17.0974 3008        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
20:11:18.0006 3008        HdAudAddService - ok
20:11:18.0037 3008        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:11:18.0068 3008        HDAudBus - ok
20:11:18.0068 3008        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
20:11:18.0084 3008        HidBatt - ok
20:11:18.0115 3008        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
20:11:18.0131 3008        HidBth - ok
20:11:18.0146 3008        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
20:11:18.0162 3008        HidIr - ok
20:11:18.0193 3008        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
20:11:18.0240 3008        hidserv - ok
20:11:18.0271 3008        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
20:11:18.0287 3008        HidUsb - ok
20:11:18.0318 3008        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
20:11:18.0381 3008        hkmsvc - ok
20:11:18.0412 3008        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
20:11:18.0459 3008        HomeGroupListener - ok
20:11:18.0490 3008        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
20:11:18.0506 3008        HomeGroupProvider - ok
20:11:18.0537 3008        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
20:11:18.0553 3008        HpSAMD - ok
20:11:18.0599 3008        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
20:11:18.0678 3008        HTTP - ok
20:11:18.0693 3008        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
20:11:18.0693 3008        hwpolicy - ok
20:11:18.0740 3008        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
20:11:18.0740 3008        i8042prt - ok
20:11:18.0803 3008        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
20:11:18.0818 3008        iaStorV - ok
20:11:18.0928 3008        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:11:18.0959 3008        idsvc - ok
20:11:18.0974 3008        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
20:11:18.0990 3008        iirsp - ok
20:11:19.0053 3008        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
20:11:19.0115 3008        IKEEXT - ok
20:11:19.0334 3008        IntcAzAudAddService (5f6a3ea5bd7ca861863a3a06cecc115c) C:\Windows\system32\drivers\RTKVHD64.sys
20:11:19.0396 3008        IntcAzAudAddService - ok
20:11:19.0646 3008        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
20:11:19.0662 3008        intelide - ok
20:11:19.0693 3008        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
20:11:19.0709 3008        intelppm - ok
20:11:19.0740 3008        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
20:11:19.0787 3008        IPBusEnum - ok
20:11:19.0803 3008        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:11:19.0834 3008        IpFilterDriver - ok
20:11:19.0881 3008        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
20:11:19.0928 3008        iphlpsvc - ok
20:11:19.0928 3008        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
20:11:19.0943 3008        IPMIDRV - ok
20:11:19.0959 3008        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
20:11:19.0990 3008        IPNAT - ok
20:11:20.0021 3008        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
20:11:20.0053 3008        IRENUM - ok
20:11:20.0053 3008        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
20:11:20.0068 3008        isapnp - ok
20:11:20.0099 3008        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
20:11:20.0115 3008        iScsiPrt - ok
20:11:20.0178 3008        JRAID          (c0d9ba660a41ee8a269ef804e6cd0d7b) C:\Windows\system32\DRIVERS\jraid.sys
20:11:20.0193 3008        JRAID - ok
20:11:20.0224 3008        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
20:11:20.0240 3008        kbdclass - ok
20:11:20.0271 3008        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
20:11:20.0303 3008        kbdhid - ok
20:11:20.0318 3008        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:11:20.0334 3008        KeyIso - ok
20:11:20.0365 3008        KSecDD          (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
20:11:20.0365 3008        KSecDD - ok
20:11:20.0396 3008        KSecPkg        (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
20:11:20.0412 3008        KSecPkg - ok
20:11:20.0443 3008        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
20:11:20.0490 3008        ksthunk - ok
20:11:20.0537 3008        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
20:11:20.0584 3008        KtmRm - ok
20:11:20.0631 3008        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
20:11:20.0678 3008        LanmanServer - ok
20:11:20.0709 3008        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
20:11:20.0740 3008        LanmanWorkstation - ok
20:11:20.0771 3008        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
20:11:20.0818 3008        lltdio - ok
20:11:20.0849 3008        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
20:11:20.0896 3008        lltdsvc - ok
20:11:20.0912 3008        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
20:11:20.0943 3008        lmhosts - ok
20:11:20.0990 3008        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
20:11:21.0006 3008        LSI_FC - ok
20:11:21.0021 3008        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
20:11:21.0037 3008        LSI_SAS - ok
20:11:21.0053 3008        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
20:11:21.0068 3008        LSI_SAS2 - ok
20:11:21.0084 3008        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
20:11:21.0099 3008        LSI_SCSI - ok
20:11:21.0131 3008        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
20:11:21.0178 3008        luafv - ok
20:11:21.0193 3008        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
20:11:21.0224 3008        Mcx2Svc - ok
20:11:21.0240 3008        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
20:11:21.0256 3008        megasas - ok
20:11:21.0287 3008        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
20:11:21.0303 3008        MegaSR - ok
20:11:21.0334 3008        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:11:21.0365 3008        MMCSS - ok
20:11:21.0381 3008        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
20:11:21.0428 3008        Modem - ok
20:11:21.0459 3008        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
20:11:21.0490 3008        monitor - ok
20:11:21.0506 3008        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
20:11:21.0521 3008        mouclass - ok
20:11:21.0553 3008        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
20:11:21.0568 3008        mouhid - ok
20:11:21.0584 3008        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
20:11:21.0599 3008        mountmgr - ok
20:11:21.0646 3008        MpFilter        (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
20:11:21.0662 3008        MpFilter - ok
20:11:21.0693 3008        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
20:11:21.0709 3008        mpio - ok
20:11:21.0724 3008        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
20:11:21.0756 3008        mpsdrv - ok
20:11:21.0818 3008        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
20:11:21.0865 3008        MpsSvc - ok
20:11:21.0881 3008        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
20:11:21.0912 3008        MRxDAV - ok
20:11:21.0943 3008        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:11:21.0974 3008        mrxsmb - ok
20:11:22.0006 3008        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:11:22.0037 3008        mrxsmb10 - ok
20:11:22.0053 3008        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:11:22.0053 3008        mrxsmb20 - ok
20:11:22.0084 3008        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
20:11:22.0099 3008        msahci - ok
20:11:22.0115 3008        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
20:11:22.0131 3008        msdsm - ok
20:11:22.0162 3008        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
20:11:22.0193 3008        MSDTC - ok
20:11:22.0209 3008        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
20:11:22.0256 3008        Msfs - ok
20:11:22.0271 3008        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
20:11:22.0318 3008        mshidkmdf - ok
20:11:22.0318 3008        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
20:11:22.0334 3008        msisadrv - ok
20:11:22.0381 3008        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
20:11:22.0428 3008        MSiSCSI - ok
20:11:22.0428 3008        msiserver - ok
20:11:22.0459 3008        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
20:11:22.0506 3008        MSKSSRV - ok
20:11:22.0584 3008        MsMpSvc        (59faaf2c83c8169ea20f9e335e418907) C:\Program Files\Microsoft Security Client\MsMpEng.exe
20:11:22.0599 3008        MsMpSvc - ok
20:11:22.0615 3008        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
20:11:22.0662 3008        MSPCLOCK - ok
20:11:22.0678 3008        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
20:11:22.0724 3008        MSPQM - ok
20:11:22.0756 3008        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
20:11:22.0771 3008        MsRPC - ok
20:11:22.0787 3008        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
20:11:22.0803 3008        mssmbios - ok
20:11:22.0803 3008        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
20:11:22.0834 3008        MSTEE - ok
20:11:22.0849 3008        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
20:11:22.0865 3008        MTConfig - ok
20:11:22.0881 3008        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
20:11:22.0896 3008        Mup - ok
20:11:22.0928 3008        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
20:11:22.0974 3008        napagent - ok
20:11:23.0021 3008        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
20:11:23.0053 3008        NativeWifiP - ok
20:11:23.0115 3008        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
20:11:23.0146 3008        NDIS - ok
20:11:23.0162 3008        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
20:11:23.0209 3008        NdisCap - ok
20:11:23.0240 3008        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
20:11:23.0271 3008        NdisTapi - ok
20:11:23.0287 3008        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
20:11:23.0334 3008        Ndisuio - ok
20:11:23.0349 3008        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
20:11:23.0396 3008        NdisWan - ok
20:11:23.0412 3008        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
20:11:23.0459 3008        NDProxy - ok
20:11:23.0474 3008        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
20:11:23.0521 3008        NetBIOS - ok
20:11:23.0553 3008        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
20:11:23.0584 3008        NetBT - ok
20:11:23.0615 3008        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:11:23.0631 3008        Netlogon - ok
20:11:23.0678 3008        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
20:11:23.0724 3008        Netman - ok
20:11:23.0803 3008        NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:23.0818 3008        NetMsmqActivator - ok
20:11:23.0834 3008        NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:23.0834 3008        NetPipeActivator - ok
20:11:23.0865 3008        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
20:11:23.0912 3008        netprofm - ok
20:11:23.0928 3008        NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:23.0943 3008        NetTcpActivator - ok
20:11:23.0943 3008        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:23.0943 3008        NetTcpPortSharing - ok
20:11:24.0006 3008        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
20:11:24.0021 3008        nfrd960 - ok
20:11:24.0084 3008        NisDrv          (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
20:11:24.0099 3008        NisDrv - ok
20:11:24.0178 3008        NisSrv          (10a43829a9e606af3eef25a1c1665923) C:\Program Files\Microsoft Security Client\NisSrv.exe
20:11:24.0193 3008        NisSrv - ok
20:11:24.0240 3008        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
20:11:24.0287 3008        NlaSvc - ok
20:11:24.0303 3008        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
20:11:24.0334 3008        Npfs - ok
20:11:24.0349 3008        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
20:11:24.0396 3008        nsi - ok
20:11:24.0428 3008        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
20:11:24.0459 3008        nsiproxy - ok
20:11:24.0568 3008        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
20:11:24.0599 3008        Ntfs - ok
20:11:24.0787 3008        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
20:11:24.0834 3008        Null - ok
20:11:24.0865 3008        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
20:11:24.0881 3008        nvraid - ok
20:11:24.0896 3008        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
20:11:24.0912 3008        nvstor - ok
20:11:24.0928 3008        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
20:11:24.0943 3008        nv_agp - ok
20:11:24.0959 3008        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
20:11:24.0974 3008        ohci1394 - ok
20:11:25.0037 3008        ose            (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:11:25.0053 3008        ose - ok
20:11:25.0084 3008        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:11:25.0131 3008        p2pimsvc - ok
20:11:25.0178 3008        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
20:11:25.0193 3008        p2psvc - ok
20:11:25.0224 3008        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
20:11:25.0256 3008        Parport - ok
20:11:25.0271 3008        partmgr        (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
20:11:25.0287 3008        partmgr - ok
20:11:25.0303 3008        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
20:11:25.0334 3008        PcaSvc - ok
20:11:25.0365 3008        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
20:11:25.0381 3008        pci - ok
20:11:25.0381 3008        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
20:11:25.0396 3008        pciide - ok
20:11:25.0428 3008        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
20:11:25.0443 3008        pcmcia - ok
20:11:25.0459 3008        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
20:11:25.0459 3008        pcw - ok
20:11:25.0506 3008        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
20:11:25.0553 3008        PEAUTH - ok
20:11:25.0631 3008        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
20:11:25.0646 3008        PerfHost - ok
20:11:25.0740 3008        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
20:11:25.0803 3008        pla - ok
20:11:25.0865 3008        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
20:11:25.0896 3008        PlugPlay - ok
20:11:25.0912 3008        PnkBstrA - ok
20:11:25.0928 3008        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
20:11:25.0959 3008        PNRPAutoReg - ok
20:11:25.0990 3008        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:11:26.0006 3008        PNRPsvc - ok
20:11:26.0053 3008        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
20:11:26.0099 3008        PolicyAgent - ok
20:11:26.0146 3008        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
20:11:26.0178 3008        Power - ok
20:11:26.0256 3008        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
20:11:26.0287 3008        PptpMiniport - ok
20:11:26.0303 3008        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
20:11:26.0334 3008        Processor - ok
20:11:26.0365 3008        ProfSvc        (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
20:11:26.0396 3008        ProfSvc - ok
20:11:26.0412 3008        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:11:26.0428 3008        ProtectedStorage - ok
20:11:26.0459 3008        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
20:11:26.0490 3008        Psched - ok
20:11:26.0584 3008        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
20:11:26.0631 3008        ql2300 - ok
20:11:26.0756 3008        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
20:11:26.0771 3008        ql40xx - ok
20:11:26.0803 3008        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
20:11:26.0818 3008        QWAVE - ok
20:11:26.0834 3008        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
20:11:26.0865 3008        QWAVEdrv - ok
20:11:26.0881 3008        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
20:11:26.0912 3008        RasAcd - ok
20:11:26.0943 3008        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:11:26.0974 3008        RasAgileVpn - ok
20:11:26.0990 3008        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
20:11:27.0037 3008        RasAuto - ok
20:11:27.0053 3008        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:11:27.0099 3008        Rasl2tp - ok
20:11:27.0131 3008        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
20:11:27.0162 3008        RasMan - ok
20:11:27.0193 3008        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
20:11:27.0240 3008        RasPppoe - ok
20:11:27.0256 3008        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
20:11:27.0303 3008        RasSstp - ok
20:11:27.0318 3008        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
20:11:27.0365 3008        rdbss - ok
20:11:27.0381 3008        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
20:11:27.0396 3008        rdpbus - ok
20:11:27.0412 3008        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:11:27.0459 3008        RDPCDD - ok
20:11:27.0474 3008        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
20:11:27.0506 3008        RDPENCDD - ok
20:11:27.0521 3008        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
20:11:27.0553 3008        RDPREFMP - ok
20:11:27.0584 3008        RDPWD          (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
20:11:27.0615 3008        RDPWD - ok
20:11:27.0662 3008        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
20:11:27.0678 3008        rdyboost - ok
20:11:27.0709 3008        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
20:11:27.0756 3008        RemoteAccess - ok
20:11:27.0787 3008        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
20:11:27.0834 3008        RemoteRegistry - ok
20:11:27.0849 3008        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
20:11:27.0881 3008        RpcEptMapper - ok
20:11:27.0896 3008        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
20:11:27.0928 3008        RpcLocator - ok
20:11:27.0959 3008        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:11:28.0006 3008        RpcSs - ok
20:11:28.0037 3008        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
20:11:28.0068 3008        rspndr - ok
20:11:28.0115 3008        RTL8167        (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
20:11:28.0146 3008        RTL8167 - ok
20:11:28.0193 3008        SaiK0CC3        (3c24436f091369ec4b91eb8294f53304) C:\Windows\system32\DRIVERS\SaiK0CC3.sys
20:11:28.0193 3008        SaiK0CC3 - ok
20:11:28.0209 3008        SaiMini        (64bc6cc8fd3408df37ea488d88d54a4a) C:\Windows\system32\DRIVERS\SaiMini.sys
20:11:28.0224 3008        SaiMini - ok
20:11:28.0240 3008        SaiNtBus        (6a78c024625926cc4b67b3e6ad14910a) C:\Windows\system32\drivers\SaiBus.sys
20:11:28.0240 3008        SaiNtBus - ok
20:11:28.0271 3008        SaiU0CC3        (e99885666b9daf934c353e0681bce7da) C:\Windows\system32\DRIVERS\SaiU0CC3.sys
20:11:28.0287 3008        SaiU0CC3 - ok
20:11:28.0303 3008        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:11:28.0318 3008        SamSs - ok
20:11:28.0349 3008        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
20:11:28.0365 3008        sbp2port - ok
20:11:28.0490 3008        SBSDWSCService  (794d4b48dfb6e999537c7c3947863463) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
20:11:28.0521 3008        SBSDWSCService - ok
20:11:28.0553 3008        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
20:11:28.0584 3008        SCardSvr - ok
20:11:28.0646 3008        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
20:11:28.0709 3008        scfilter - ok
20:11:28.0771 3008        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
20:11:28.0849 3008        Schedule - ok
20:11:28.0865 3008        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:11:28.0896 3008        SCPolicySvc - ok
20:11:28.0928 3008        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
20:11:28.0943 3008        SDRSVC - ok
20:11:29.0006 3008        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
20:11:29.0068 3008        secdrv - ok
20:11:29.0084 3008        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
20:11:29.0115 3008        seclogon - ok
20:11:29.0146 3008        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
20:11:29.0178 3008        SENS - ok
20:11:29.0193 3008        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
20:11:29.0224 3008        SensrSvc - ok
20:11:29.0256 3008        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
20:11:29.0271 3008        Serenum - ok
20:11:29.0303 3008        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
20:11:29.0318 3008        Serial - ok
20:11:29.0334 3008        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
20:11:29.0349 3008        sermouse - ok
20:11:29.0381 3008        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
20:11:29.0428 3008        SessionEnv - ok
20:11:29.0428 3008        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
20:11:29.0443 3008        sffdisk - ok
20:11:29.0443 3008        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
20:11:29.0474 3008        sffp_mmc - ok
20:11:29.0474 3008        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
20:11:29.0490 3008        sffp_sd - ok
20:11:29.0490 3008        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
20:11:29.0521 3008        sfloppy - ok
20:11:29.0568 3008        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
20:11:29.0631 3008        SharedAccess - ok
20:11:29.0662 3008        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
20:11:29.0693 3008        ShellHWDetection - ok
20:11:29.0709 3008        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
20:11:29.0724 3008        SiSRaid2 - ok
20:11:29.0740 3008        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
20:11:29.0756 3008        SiSRaid4 - ok
20:11:29.0818 3008        SkypeUpdate    (579ba0a911ff5ea70cb604cd3b744b0a) C:\Program Files (x86)\Skype\Updater\Updater.exe
20:11:29.0834 3008        SkypeUpdate - ok
20:11:29.0865 3008        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
20:11:29.0928 3008        Smb - ok
20:11:29.0959 3008        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
20:11:29.0974 3008        SNMPTRAP - ok
20:11:30.0006 3008        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
20:11:30.0021 3008        spldr - ok
20:11:30.0053 3008        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
20:11:30.0099 3008        Spooler - ok
20:11:30.0271 3008        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
20:11:30.0365 3008        sppsvc - ok
20:11:30.0474 3008        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
20:11:30.0506 3008        sppuinotify - ok
20:11:30.0584 3008        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
20:11:30.0615 3008        srv - ok
20:11:30.0646 3008        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
20:11:30.0678 3008        srv2 - ok
20:11:30.0693 3008        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
20:11:30.0709 3008        srvnet - ok
20:11:30.0756 3008        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
20:11:30.0787 3008        SSDPSRV - ok
20:11:30.0803 3008        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
20:11:30.0849 3008        SstpSvc - ok
20:11:30.0881 3008        Steam Client Service - ok
20:11:30.0896 3008        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
20:11:30.0912 3008        stexstor - ok
20:11:30.0974 3008        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
20:11:31.0006 3008        stisvc - ok
20:11:31.0021 3008        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
20:11:31.0021 3008        swenum - ok
20:11:31.0068 3008        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
20:11:31.0115 3008        swprv - ok
20:11:31.0209 3008        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
20:11:31.0256 3008        SysMain - ok
20:11:31.0349 3008        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
20:11:31.0396 3008        TabletInputService - ok
20:11:31.0412 3008        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
20:11:31.0474 3008        TapiSrv - ok
20:11:31.0506 3008        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
20:11:31.0537 3008        TBS - ok
20:11:31.0678 3008        Tcpip          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
20:11:31.0724 3008        Tcpip - ok
20:11:31.0928 3008        TCPIP6          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
20:11:31.0974 3008        TCPIP6 - ok
20:11:32.0021 3008        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
20:11:32.0068 3008        tcpipreg - ok
20:11:32.0084 3008        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
20:11:32.0115 3008        TDPIPE - ok
20:11:32.0146 3008        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
20:11:32.0162 3008        TDTCP - ok
20:11:32.0178 3008        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
20:11:32.0224 3008        tdx - ok
20:11:32.0240 3008        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
20:11:32.0256 3008        TermDD - ok
20:11:32.0303 3008        TermService    (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
20:11:32.0349 3008        TermService - ok
20:11:32.0365 3008        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
20:11:32.0381 3008        Themes - ok
20:11:32.0412 3008        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:11:32.0459 3008        THREADORDER - ok
20:11:32.0474 3008        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
20:11:32.0506 3008        TrkWks - ok
20:11:32.0568 3008        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
20:11:32.0615 3008        TrustedInstaller - ok
20:11:32.0631 3008        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:11:32.0678 3008        tssecsrv - ok
20:11:32.0709 3008        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
20:11:32.0724 3008        TsUsbFlt - ok
20:11:32.0740 3008        TsUsbGD        (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
20:11:32.0771 3008        TsUsbGD - ok
20:11:32.0787 3008        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
20:11:32.0818 3008        tunnel - ok
20:11:32.0818 3008        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
20:11:32.0834 3008        uagp35 - ok
20:11:32.0865 3008        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
20:11:32.0928 3008        udfs - ok
20:11:32.0959 3008        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
20:11:32.0974 3008        UI0Detect - ok
20:11:33.0006 3008        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
20:11:33.0006 3008        uliagpkx - ok
20:11:33.0037 3008        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
20:11:33.0053 3008        umbus - ok
20:11:33.0099 3008        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
20:11:33.0115 3008        UmPass - ok
20:11:33.0146 3008        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
20:11:33.0193 3008        upnphost - ok
20:11:33.0240 3008        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
20:11:33.0271 3008        usbccgp - ok
20:11:33.0287 3008        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
20:11:33.0303 3008        usbcir - ok
20:11:33.0334 3008        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
20:11:33.0349 3008        usbehci - ok
20:11:33.0396 3008        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
20:11:33.0412 3008        usbhub - ok
20:11:33.0428 3008        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
20:11:33.0459 3008        usbohci - ok
20:11:33.0474 3008        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys
20:11:33.0490 3008        usbprint - ok
20:11:33.0521 3008        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:11:33.0568 3008        USBSTOR - ok
20:11:33.0584 3008        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
20:11:33.0599 3008        usbuhci - ok
20:11:33.0615 3008        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
20:11:33.0662 3008        UxSms - ok
20:11:33.0678 3008        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:11:33.0693 3008        VaultSvc - ok
20:11:33.0724 3008        VBoxNetAdp      (01f5ff577ca9d3555941c5c266af4385) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
20:11:33.0740 3008        VBoxNetAdp - ok
20:11:33.0756 3008        VBoxNetFlt - ok
20:11:33.0787 3008        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
20:11:33.0803 3008        vdrvroot - ok
20:11:33.0849 3008        vds            (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
20:11:33.0896 3008        vds - ok
20:11:33.0912 3008        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
20:11:33.0928 3008        vga - ok
20:11:33.0943 3008        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
20:11:33.0974 3008        VgaSave - ok
20:11:33.0990 3008        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
20:11:34.0006 3008        vhdmp - ok
20:11:34.0021 3008        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
20:11:34.0021 3008        viaide - ok
20:11:34.0053 3008        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
20:11:34.0053 3008        volmgr - ok
20:11:34.0099 3008        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
20:11:34.0115 3008        volmgrx - ok
20:11:34.0131 3008        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
20:11:34.0146 3008        volsnap - ok
20:11:34.0178 3008        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
20:11:34.0193 3008        vsmraid - ok
20:11:34.0287 3008        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
20:11:34.0349 3008        VSS - ok
20:11:34.0474 3008        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
20:11:34.0490 3008        vwifibus - ok
20:11:34.0537 3008        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
20:11:34.0568 3008        W32Time - ok
20:11:34.0584 3008        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
20:11:34.0615 3008        WacomPen - ok
20:11:34.0631 3008        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:11:34.0678 3008        WANARP - ok
20:11:34.0678 3008        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:11:34.0709 3008        Wanarpv6 - ok
20:11:34.0818 3008        WatAdminSvc    (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
20:11:34.0865 3008        WatAdminSvc - ok
20:11:34.0959 3008        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
20:11:35.0021 3008        wbengine - ok
20:11:35.0099 3008        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
20:11:35.0131 3008        WbioSrvc - ok
20:11:35.0162 3008        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
20:11:35.0209 3008        wcncsvc - ok
20:11:35.0224 3008        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
20:11:35.0256 3008        WcsPlugInService - ok
20:11:35.0303 3008        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
20:11:35.0318 3008        Wd - ok
20:11:35.0365 3008        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
20:11:35.0381 3008        Wdf01000 - ok
20:11:35.0412 3008        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:11:35.0474 3008        WdiServiceHost - ok
20:11:35.0474 3008        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:11:35.0490 3008        WdiSystemHost - ok
20:11:35.0521 3008        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
20:11:35.0553 3008        WebClient - ok
20:11:35.0568 3008        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
20:11:35.0615 3008        Wecsvc - ok
20:11:35.0631 3008        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
20:11:35.0678 3008        wercplsupport - ok
20:11:35.0693 3008        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
20:11:35.0724 3008        WerSvc - ok
20:11:35.0787 3008        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
20:11:35.0818 3008        WfpLwf - ok
20:11:35.0834 3008        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
20:11:35.0849 3008        WIMMount - ok
20:11:35.0896 3008        WinDefend - ok
20:11:35.0896 3008        WinHttpAutoProxySvc - ok
20:11:35.0974 3008        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
20:11:36.0006 3008        Winmgmt - ok
20:11:36.0115 3008        WinRM          (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
20:11:36.0178 3008        WinRM - ok
20:11:36.0318 3008        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
20:11:36.0365 3008        Wlansvc - ok
20:11:36.0412 3008        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
20:11:36.0443 3008        WmiAcpi - ok
20:11:36.0506 3008        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
20:11:36.0537 3008        wmiApSrv - ok
20:11:36.0584 3008        WMPNetworkSvc - ok
20:11:36.0615 3008        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
20:11:36.0646 3008        WPCSvc - ok
20:11:36.0678 3008        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
20:11:36.0693 3008        WPDBusEnum - ok
20:11:36.0724 3008        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
20:11:36.0771 3008        ws2ifsl - ok
20:11:36.0787 3008        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
20:11:36.0803 3008        wscsvc - ok
20:11:36.0803 3008        WSearch - ok
20:11:36.0959 3008        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
20:11:37.0021 3008        wuauserv - ok
20:11:37.0146 3008        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
20:11:37.0193 3008        WudfPf - ok
20:11:37.0240 3008        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:11:37.0271 3008        WUDFRd - ok
20:11:37.0303 3008        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
20:11:37.0334 3008        wudfsvc - ok
20:11:37.0381 3008        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
20:11:37.0412 3008        WwanSvc - ok
20:11:37.0443 3008        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:11:37.0646 3008        \Device\Harddisk0\DR0 ( TDSS File System ) - warning
20:11:37.0646 3008        \Device\Harddisk0\DR0 - detected TDSS File System (1)
20:11:37.0678 3008        Boot (0x1200)  (17819b15850eb98b560652f58b135142) \Device\Harddisk0\DR0\Partition0
20:11:37.0678 3008        \Device\Harddisk0\DR0\Partition0 - ok
20:11:37.0693 3008        Boot (0x1200)  (f4d788bba0afe6d7b986332a4cb9830b) \Device\Harddisk0\DR0\Partition1
20:11:37.0709 3008        \Device\Harddisk0\DR0\Partition1 - ok
20:11:37.0709 3008        ============================================================
20:11:37.0709 3008        Scan finished
20:11:37.0709 3008        ============================================================
20:11:37.0756 0980        Detected object count: 1
20:11:37.0756 0980        Actual detected object count: 1
20:12:17.0724 0980        \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
20:12:17.0724 0980        \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip


cosinus 24.07.2012 14:58

Ok, da ist noch ein TDSS aktiv, aber den soll man nicht mit dem TDSS-Killer beim ersten Lauf fixen

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

bleibdoof 25.07.2012 20:05

Guten Abend,

so nachdem der Rechner auch bei dem Scan stehen geblieben ist, hier nun die Datei. Ich hoffe sie ist soweit vollständing:

Code:

ComboFix 12-07-26.03 - Bleibdoof 25.07.2012  17:32:49.1.2 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4094.2816 [GMT 2:00]
ausgeführt von:: c:\users\Bleibdoof_2\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-25 bis 2012-07-25  ))))))))))))))))))))))))))))))
.
.
2012-07-24 17:48 . 2012-06-29 10:04        9133488        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{44B88E82-7D14-4517-A407-EF8DAC3DA6DB}\mpengine.dll
2012-07-23 19:52 . 2012-06-29 10:04        9133488        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-22 19:54 . 2012-07-24 21:11        --------        d-----w-        c:\users\Bleibdoof_2\AppData\Roaming\FreeDoko
2012-07-21 17:14 . 2012-07-21 17:14        --------        d-----w-        C:\_OTL
2012-07-15 09:24 . 2012-07-21 17:01        --------        d-----w-        c:\users\Bleibdoof\AppData\Roaming\Skype
2012-07-15 09:14 . 2012-07-15 09:14        --------        d-----w-        c:\program files (x86)\ESET
2012-07-12 19:22 . 2012-07-12 19:22        --------        d-----w-        c:\users\Bleibdoof_2\AppData\Roaming\Malwarebytes
2012-07-12 19:07 . 2012-07-12 19:07        --------        d-----w-        c:\users\Bleibdoof\AppData\Roaming\Malwarebytes
2012-07-12 19:06 . 2012-07-12 19:06        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-12 19:06 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-12 16:19 . 2012-07-12 16:19        --------        d-----w-        c:\program files (x86)\Microsoft
2012-07-12 15:20 . 2012-06-12 03:08        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 21:17 . 2012-06-02 12:49        17807360        ----a-w-        c:\windows\system32\mshtml.dll
2012-07-11 21:17 . 2012-06-02 12:17        10924032        ----a-w-        c:\windows\system32\ieframe.dll
2012-07-09 21:15 . 2010-02-23 08:16        294912        ----a-w-        c:\windows\system32\browserchoice.exe
2012-07-04 09:01 . 2012-04-13 22:08        927800        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2CD22DA1-F366-41DA-BFC7-063144BD571B}\gapaengine.dll
2012-07-02 10:47 . 2012-07-02 10:47        --------        d-----w-        c:\program files (x86)\MSECache
2012-07-01 21:09 . 2012-07-01 21:09        --------        d-----w-        c:\windows\PCHEALTH
2012-07-01 21:04 . 2009-07-14 01:15        315904        ----a-w-        c:\windows\SysWow64\Difxe4fc.rra
2012-07-01 21:04 . 2012-07-01 21:04        --------        d-----w-        c:\windows\RaidTool
2012-07-01 21:03 . 2005-04-03 21:02        69714        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2012-07-01 21:03 . 2005-04-03 21:01        274432        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2012-07-01 21:03 . 2005-04-03 21:00        184320        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2012-07-01 21:03 . 2005-04-03 21:00        63488        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2012-07-01 21:03 . 2005-04-03 20:59        5632        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2012-07-01 21:03 . 2005-04-03 21:02        753664        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2012-07-01 21:03 . 2012-07-01 21:03        331908        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2012-07-01 21:03 . 2012-07-01 21:03        200836        ----a-w-        c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2012-07-01 20:59 . 2009-07-14 01:15        315904        ----a-w-        c:\windows\SysWow64\Difx9f59.rra
2012-07-01 20:50 . 2009-07-14 01:15        315904        ----a-w-        c:\windows\SysWow64\Difx6f92.rra
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 15:17 . 2012-04-13 21:56        59701280        ----a-w-        c:\windows\system32\MRT.exe
2012-07-11 20:08 . 2012-04-14 15:04        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-11 20:08 . 2012-04-14 15:04        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-02 22:19 . 2012-06-25 06:02        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-25 06:03        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-25 06:03        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-25 06:03        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-25 06:02        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-25 06:03        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-25 06:02        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-25 06:02        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-25 06:02        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-05-04 11:06 . 2012-06-14 17:32        5559664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-25 06:27        366592        ----a-w-        c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-14 17:32        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 17:32        3913072        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-25 06:27        514560        ----a-w-        c:\windows\SysWow64\qdvd.dll
2012-05-01 05:40 . 2012-06-14 17:32        209920        ----a-w-        c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-14 17:32        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\tools\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-05-03 17355912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 136176]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 250056]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 136176]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-06-24 144688]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-14 1255736]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-04-20 283200]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-06 236544]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-04-06 11174400]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-04-06 343040]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 RTL8167;Realtek 8167 NT-Treiber;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 SaiK0CC3;SaiK0CC3;c:\windows\system32\DRIVERS\SaiK0CC3.sys [2010-04-22 171016]
S3 SaiU0CC3;SaiU0CC3;c:\windows\system32\DRIVERS\SaiU0CC3.sys [2010-04-22 41096]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 20:08]
.
2012-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:23]
.
2012-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-02 00:23]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-27 12459112]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2010-04-21 378880]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2010-04-21 195072]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-BitBox - d:\tools\BitBox\BitBoxuninstall.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\users\Bleibdoof_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-07-25  20:53:13 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-07-25 18:53
.
Vor Suchlauf: 8 Verzeichnis(se), 11.589.177.344 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 11.113.979.904 Bytes frei
.
- - End Of File - - 649249472F3387AC5F1D1DAAB2300F7B


cosinus 26.07.2012 13:37

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

bleibdoof 26.07.2012 21:35

Moin,

ich habe jetzt alle drei Programme ausgeführt:

GMER hat kein Log erzeugt, nur eine Meldung, dass keine Modifikationen am System gefunden werden konnten.

OSAM Log:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:58:58 on 26.07.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"VBoxNetFlt Service" (VBoxNetFlt) - ? - C:\Windows\System32\DRIVERS\VBoxNetFlt.sys  (File not found)
"VirtualBox Host-Only Ethernet Adapter" (VBoxNetAdp) - "Oracle Corporation" - C:\Windows\System32\DRIVERS\VBoxNetAdp.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height64 "ITBar7Height64" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{7530BFB8-7293-4D34-9923-61A11451AFC5} "OnlineScanner Control" - "ESET" - C:\PROGRA~2\ESET\ESETON~1\ONLINE~1.OCX / hxxp://download.eset.com/special/eos/OnlineScanner.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_3_300_265.ocx / https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\OFFICE11\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"DAEMON Tools Lite" - "DT Soft Ltd" - "D:\Tools\DAEMON Tools Lite\DTLite.exe" -autorun
"Skype" - "Skype Technologies S.A." - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"JMB36X IDE Setup" - ? - C:\Windows\RaidTool\xInsIDE.exe  (File found, but it contains no detailed information)
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"@%SystemRoot%\System32\shsvcs.dll,-12288" (ShellHWDetection) - "Microsoft Corporation" - C:\Windows\System32\shsvcs.dll  (Data mismatch, rootkit activity)
"@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\NisSrv.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Security Client\MsMpEng.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File not found)
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Und hier aswMBR:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-26 21:23:33
-----------------------------
21:23:33.884    OS Version: Windows x64 6.1.7601 Service Pack 1
21:23:33.884    Number of processors: 2 586 0xF06
21:23:33.884    ComputerName: BLEIBDOOF-PC  UserName: Bleibdoof
21:23:34.181    Initialize success
21:28:29.206    AVAST engine defs: 12072601
21:28:35.581    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
21:28:35.581    Disk 0 Vendor: SAMSUNG_HD400LJ ZZ100-15 Size: 381554MB BusType: 3
21:28:35.596    Disk 0 MBR read successfully
21:28:35.596    Disk 0 MBR scan
21:28:35.596    Disk 0 Windows 7 default MBR code
21:28:35.612    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS        49999 MB offset 63
21:28:35.612    Disk 0 Partition - 00    0F Extended LBA            331544 MB offset 102398310
21:28:35.627    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      331544 MB offset 102398373
21:28:35.643    Disk 0 scanning C:\Windows\system32\drivers
21:28:42.174    Service scanning
21:28:56.909    Modules scanning
21:28:56.909    Disk 0 trace - called modules:
21:28:56.924    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
21:28:56.940    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80048ed790]
21:28:56.940    3 CLASSPNP.SYS[fffff8800197e43f] -> nt!IofCallDriver -> [0xfffffa8003958e40]
21:28:56.940    5 ACPI.sys[fffff88000ef07a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80047a1680]
21:28:57.206    AVAST engine scan C:\Windows
21:28:58.784    AVAST engine scan C:\Windows\system32
21:30:56.768    AVAST engine scan C:\Windows\system32\drivers
21:31:04.002    AVAST engine scan C:\Users\Bleibdoof
21:31:16.127    File: C:\Users\Bleibdoof\AppData\Local\temp\{5A0389C7-EB2F-4CCE-8F0E-4223065AE3ED}\fpb.tmp **HIDDEN**
21:31:16.252    AVAST engine scan C:\ProgramData
21:32:51.206    Scan finished successfully
21:33:13.581    Disk 0 MBR has been saved successfully to "C:\Users\Bleibdoof\Desktop\MBR.dat"
21:33:13.596    The log file has been saved successfully to "C:\Users\Bleibdoof\Desktop\aswMBR.txt"


cosinus 26.07.2012 23:12

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

bleibdoof 30.07.2012 22:18

Moin!

Hier die Ergebnisse der Logs.

MWB:

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.29.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Bleibdoof :: BLEIBDOOF-PC [Administrator]

29.07.2012 22:17:21
mbam-log-2012-07-29 (23-13-49).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 447891
Laufzeit: 44 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\_OTL\MovedFiles\07212012_191402\C_Users\Bleibdoof_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\51141ad8-7ab19b28 (Trojan.Agent.H) -> Keine Aktion durchgeführt.

(Ende)

Superantispyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/30/2012 at 10:58 PM

Application Version : 5.5.1012

Core Rules Database Version : 8981
Trace Rules Database Version: 6793

Scan type      : Complete Scan
Total Scan Time : 01:54:22

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 733
Memory threats detected  : 0
Registry items scanned    : 71117
Registry threats detected : 0
File items scanned        : 241182
File threats detected    : 130

Adware.Tracking Cookie
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\3XO0KT0V.txt [ /adfarm1.adition.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\C4ONCOTO.txt [ /adtech.de ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\8P2IXXCP.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\M0HPDSCN.txt [ /track.effiliation.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\88241UJ2.txt [ /ad.zanox.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\T8SC5MM2.txt [ /imrworldwide.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\XVGHMVE4.txt [ /webmasterplan.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\O91WCRUP.txt [ /track.effiliation.com ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\CI9A6175.txt [ /zanox-affiliate.de ]
        C:\Users\Bleibdoof\AppData\Roaming\Microsoft\Windows\Cookies\T380FT47.txt [ /zanox.com ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\IC3T1KZ0.txt [ Cookie:bleibdoof@ad.yieldmanager.com/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\97JAX5IA.txt [ Cookie:bleibdoof@tracking.quisma.com/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\JI47OGX6.txt [ Cookie:bleibdoof@adfarm1.adition.com/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\30OP4TN5.txt [ Cookie:bleibdoof@adform.net/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\5UXJ7GKA.txt [ Cookie:bleibdoof@fl01.ct2.comclick.com/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\218Q510L.txt [ Cookie:bleibdoof@unitymedia.de/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\W8H4JS10.txt [ Cookie:bleibdoof@us.battle.net/account ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\R3DK4EE3.txt [ Cookie:bleibdoof@imrworldwide.com/cgi-bin ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\01S22A74.txt [ Cookie:bleibdoof@webmasterplan.com/ ]
        C:\USERS\BLEIBDOOF\AppData\Roaming\Microsoft\Windows\Cookies\Low\737SANS7.txt [ Cookie:bleibdoof@track.adform.net/ ]
        C:\USERS\BLEIBDOOF\Cookies\3XO0KT0V.txt [ Cookie:bleibdoof@adfarm1.adition.com/ ]
        C:\USERS\BLEIBDOOF\Cookies\C4ONCOTO.txt [ Cookie:bleibdoof@adtech.de/ ]
        C:\USERS\BLEIBDOOF\Cookies\8P2IXXCP.txt [ Cookie:bleibdoof@ad2.adfarm1.adition.com/ ]
        C:\USERS\BLEIBDOOF\Cookies\M0HPDSCN.txt [ Cookie:bleibdoof@track.effiliation.com/servlet/ ]
        C:\USERS\BLEIBDOOF\Cookies\88241UJ2.txt [ Cookie:bleibdoof@ad.zanox.com/ ]
        C:\USERS\BLEIBDOOF\Cookies\T8SC5MM2.txt [ Cookie:bleibdoof@imrworldwide.com/cgi-bin ]
        C:\USERS\BLEIBDOOF\Cookies\XVGHMVE4.txt [ Cookie:bleibdoof@webmasterplan.com/ ]
        C:\USERS\BLEIBDOOF\Cookies\O91WCRUP.txt [ Cookie:bleibdoof@track.effiliation.com/ ]
        C:\USERS\BLEIBDOOF\Cookies\CI9A6175.txt [ Cookie:bleibdoof@zanox-affiliate.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\5G0247FX.txt [ Cookie:bleibdoof_2@serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\T485UXVS.txt [ Cookie:bleibdoof_2@bs.serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\092F4VMO.txt [ Cookie:bleibdoof_2@gs-media.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\EMXNZ1N1.txt [ Cookie:bleibdoof_2@yieldmanager.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\B0JW02UU.txt [ Cookie:bleibdoof_2@atdmt.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\GU4O44T5.txt [ Cookie:bleibdoof_2@philips.112.2o7.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\P5LOF00U.txt [ Cookie:bleibdoof_2@a.revenuemax.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\MBA5BF5M.txt [ Cookie:bleibdoof_2@quartermedia.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\R4GLO2A7.txt [ Cookie:bleibdoof_2@ad.yieldmanager.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\DJ0U7HWW.txt [ Cookie:bleibdoof_2@deutschepostag.112.2o7.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\PED255GY.txt [ Cookie:bleibdoof_2@track.adform.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\X31YPBG6.txt [ Cookie:bleibdoof_2@eu.battle.net/account/management/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\FLVY4MSL.txt [ Cookie:bleibdoof_2@de.sitestat.com/sport1/sport1-de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\J88MJN58.txt [ Cookie:bleibdoof_2@adserver.gb5.motorpresse.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\H8U2JX94.txt [ Cookie:bleibdoof_2@media.quakelive.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\7UFCH2XL.txt [ Cookie:bleibdoof_2@server.adformdsp.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\YYSRDN8P.txt [ Cookie:bleibdoof_2@tracking.mobile.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\54NJRHM9.txt [ Cookie:bleibdoof_2@serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\NWLQ5Z71.txt [ Cookie:bleibdoof_2@interclick.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\MW6JQAQ0.txt [ Cookie:bleibdoof_2@at.atwola.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\XN0Q53Q8.txt [ Cookie:bleibdoof_2@c.atdmt.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\J1XQUWTD.txt [ Cookie:bleibdoof_2@rw.motorpresse-statistik.de/track/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\7ULNEYNB.txt [ Cookie:bleibdoof_2@tribalfusion.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\3J1RF54Z.txt [ Cookie:bleibdoof_2@adbrite.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\7DYTMT0Y.txt [ Cookie:bleibdoof_2@traffictrack.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\HCXJQKGO.txt [ Cookie:bleibdoof_2@webmasterplan.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\XWAMHTAP.txt [ Cookie:bleibdoof_2@unitymediaforum.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\DPA4265C.txt [ Cookie:bleibdoof_2@adxpose.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\YX62ZNCS.txt [ Cookie:bleibdoof_2@zanox.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\FBNNPYN1.txt [ Cookie:bleibdoof_2@www.zanox-affiliate.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\E1QI980R.txt [ Cookie:bleibdoof_2@tracking.mindshare.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\MDER849T.txt [ Cookie:bleibdoof_2@ad.adserver01.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\VJYERCH9.txt [ Cookie:bleibdoof_2@specificclick.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JWT8T7HZ.txt [ Cookie:bleibdoof_2@lucidmedia.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\L2ARC6SZ.txt [ Cookie:bleibdoof_2@stats.paypal.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\36U3F58H.txt [ Cookie:bleibdoof_2@tracking.quisma.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\8UURHWV2.txt [ Cookie:bleibdoof_2@insightexpressai.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\M2WITR51.txt [ Cookie:bleibdoof_2@server.cpmstar.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\5I1FU6JL.txt [ Cookie:bleibdoof_2@adx.chip.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\0NH24ARH.txt [ Cookie:bleibdoof_2@lfstmedia.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\0WZFPFRZ.txt [ Cookie:bleibdoof_2@ww251.smartadserver.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\01P7Z4AU.txt [ Cookie:bleibdoof_2@ad2.adfarm1.adition.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\K71M84HX.txt [ Cookie:bleibdoof_2@autoscout24.112.2o7.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\OTQP3THZ.txt [ Cookie:bleibdoof_2@zanox-affiliate.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JW0BITCD.txt [ Cookie:bleibdoof_2@revsci.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\LE0O6B1H.txt [ Cookie:bleibdoof_2@amazon-adsystem.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\UAS70JWB.txt [ Cookie:bleibdoof_2@adform.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\2S05N8UJ.txt [ Cookie:bleibdoof_2@ad.dyntracker.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZJEY6QXJ.txt [ Cookie:bleibdoof_2@adserver.unitedcolo.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\7ZHNNISF.txt [ Cookie:bleibdoof_2@de.sitestat.com/idgcom-de/gamestar/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\GTCEEOFY.txt [ Cookie:bleibdoof_2@unitymedia.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\RQ1SA9DH.txt [ Cookie:bleibdoof_2@2o7.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\9RV4FCK6.txt [ Cookie:bleibdoof_2@ad3.adfarm1.adition.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\APZQJXM7.txt [ Cookie:bleibdoof_2@banner.testberichte.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\RK761VHI.txt [ Cookie:bleibdoof_2@www.live-hobby.de/counter/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\S8MEX7CX.txt [ Cookie:bleibdoof_2@clickfuse.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\860F5BMX.txt [ Cookie:bleibdoof_2@liveperson.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\BHZM9M4X.txt [ Cookie:bleibdoof_2@www3.smartadserver.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\B5KFUBK3.txt [ Cookie:bleibdoof_2@tracking982.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\DEOH2VSM.txt [ Cookie:bleibdoof_2@clicksor.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\MWMMD9J5.txt [ Cookie:bleibdoof_2@adformdsp.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JTF38REH.txt [ Cookie:bleibdoof_2@butlers.traffective-tracking.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\DARF9OKN.txt [ Cookie:bleibdoof_2@de.at.atwola.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JE3H4UT3.txt [ Cookie:bleibdoof_2@de.sitestat.com/ndr/ndr/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\CBIJE4FJ.txt [ Cookie:bleibdoof_2@adinterax.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\U0GLONOT.txt [ Cookie:bleibdoof_2@liveperson.net/hc/85950269 ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\9N2KA8D8.txt [ Cookie:bleibdoof_2@ox-d.ad.repofadvertising.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\8MF04H2H.txt [ Cookie:bleibdoof_2@de.sitestat.com/ndr/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\YJ3VN344.txt [ Cookie:bleibdoof_2@mh.motorpresse-statistik.de/track/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\2NATXT36.txt [ Cookie:bleibdoof_2@www.googleadservices.com/pagead/conversion/1066625341/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JJJK1P1W.txt [ Cookie:bleibdoof_2@track.effiliation.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\WVX6Q14A.txt [ Cookie:bleibdoof_2@account.nokia.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\1X4041WL.txt [ Cookie:bleibdoof_2@ru4.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\F305N9AY.txt [ Cookie:bleibdoof_2@bs.serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\QGBAV4G8.txt [ Cookie:bleibdoof_2@guj.122.2o7.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\S7Z4AVZ9.txt [ Cookie:bleibdoof_2@ad6media.fr/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\H9GT2PTS.txt [ Cookie:bleibdoof_2@questionmarket.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\N0W2P8ZW.txt [ Cookie:bleibdoof_2@e-2dj6afkyglajolp.stats.esomniture.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\ITSQS2BO.txt [ Cookie:bleibdoof_2@urbia.wwe-media.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\0ME8EVCX.txt [ Cookie:bleibdoof_2@ad.adnet.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\29JSEI0E.txt [ Cookie:bleibdoof_2@eas.apm.emediate.eu/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\LQRV1I68.txt [ Cookie:bleibdoof_2@nextag.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\QFNSY6PG.txt [ Cookie:bleibdoof_2@www.traffective-tracking.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\T0FD0YRH.txt [ Cookie:bleibdoof_2@collective-media.net/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\2K9NIKAH.txt [ Cookie:bleibdoof_2@www.republicofadvertising.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\FVURY3HZ.txt [ Cookie:bleibdoof_2@e-2dj6wjkywjdjicq.stats.esomniture.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\WTUAAV4F.txt [ Cookie:bleibdoof_2@www.usenext.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\JT966NLE.txt [ Cookie:bleibdoof_2@in.getclicky.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\WS3OMY37.txt [ Cookie:bleibdoof_2@gs-media.de/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\4D4SYYA4.txt [ Cookie:bleibdoof_2@partners.webmasterplan.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\QIIHAGM3.txt [ Cookie:bleibdoof_2@www.googleadservices.com/pagead/conversion/1024107808/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\M8PCDIXB.txt [ Cookie:bleibdoof_2@track.effiliation.com/servlet/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\TKHV703B.txt [ Cookie:bleibdoof_2@de-fourmedia.videoplaza.tv/proxy/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\N91JK2BG.txt [ Cookie:bleibdoof_2@www.googleadservices.com/pagead/conversion/1036980325/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\9CYW4PQA.txt [ Cookie:bleibdoof_2@tomtailor.dyntracker.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\4O00R7IE.txt [ Cookie:bleibdoof_2@kontera.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\VG8P0135.txt [ Cookie:bleibdoof_2@myroitracking.com/ ]
        C:\USERS\BLEIBDOOF_2\AppData\Roaming\Microsoft\Windows\Cookies\Low\T90D52X3.txt [ Cookie:bleibdoof_2@traveladvertising.com/ ]
        C:\USERS\BLEIBDOOF_2\Cookies\5G0247FX.txt [ Cookie:bleibdoof_2@serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\Cookies\T485UXVS.txt [ Cookie:bleibdoof_2@bs.serving-sys.com/ ]
        C:\USERS\BLEIBDOOF_2\Cookies\092F4VMO.txt [ Cookie:bleibdoof_2@gs-media.de/ ]


cosinus 31.07.2012 10:18

Sieht ok aus, da wurden nur Cookies gefunden, und ein Schädling in der OTL-Q der da gut aufgehoben und so harmlos ist.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

bleibdoof 02.08.2012 21:54

Moin!

Danke für die Hinweise, ich werde den Hinweis mit der Hosts Datei befolgen und weiter hin immer den gesamten Browser löschen lassen. Viel bookmarken usw. tue ich eh nicht und die paar Websiten, die ich besuche, immer wieder einzuhacken, ist echt nicht wild.

Ansonsten habe ich keine weiteren Meldung bekommen, alles läuft unauffällig.

Eine Frage hätte ich aber noch: Ich habe jetzt ja Unmengen von Programmen installiert /benutzt, die dies und das geprüft haben (bekommt mal als Laie ja kaum zusammen). Macht es Sinn davon einige für regelmäßige Prüfungen installiert zu lassen (zusätzlich zum "Standard" AV Programm)? Wenn ja welche? MWB, Superantispyware, Spybot Search and Destroy... oder gar alle?

mfg!

cosinus 03.08.2012 18:18

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => http://www.adobe.com/products/flashp...ribution3.html

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

bleibdoof 13.08.2012 20:03

Guten Abend!

Hatte doch wirklich eine Woche den Rechner nicht an und dadurch die Antwort verpennt! Dann noch mal abschließend vielen Dank für die Hilfe und die Raschläge und Tips.

Auch generell beeindruckend wie vielen Leuten hier zeitgleich mit Rat und Tat zur Seite gestanden wird - top:daumenhoc

Spende geht raus!

cosinus 14.08.2012 14:00

Zitat:

Spende geht raus!
Danke! :daumenhoc


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131