Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   mbam findet C:\Program Files (x86)\DVBViewer TE2\update.exe (Spyware.Zbot) (https://www.trojaner-board.de/126110-mbam-findet-c-program-files-x86-dvbviewer-te2-update-exe-spyware-zbot.html)

magnus65 25.10.2012 08:40

mbam findet C:\Program Files (x86)\DVBViewer TE2\update.exe (Spyware.Zbot)
 
Hall Forum,
ich stehe vor einem Problem, seit ein paar Tagen läuft das Sicherheitscenter unter Win7 64 Bit nicht mehr, Startversucher scheitern mit der Meldung "Zugriff verweigert"

Hab daraufhin hier den Tipp bezüglich MBAM gefunden und einen Suchlauf gestartet. Die Logdate hänge ich an :
Wie werde ich das Ding wieder los und ist das mein einziges Problem ? Den Technisat Kram habe ich vor einigen Jahren installiert.

Schonmal im Voraus Danke für Tipps und Hilfe.

gruß

Magnus

cosinus 25.10.2012 13:23

Im DVBViewer? Sieht sehr schwer nach Fehlalarm aus

magnus65 25.10.2012 14:11

Fehlalarm wäre natürlich das Beste.
Aber warum streikt der Sicherheitscenter Dienst seit ein paar Tagen ?

cosinus 25.10.2012 14:58

Hast du noch weitere Logs von Malwarebytes? Siehe http://www.trojaner-board.de/125889-...tml#post941520

magnus65 25.10.2012 15:58

Dieses hier von gestern ist wieder das gleiche Teil und wurde angeblich in Quarantäne gestellt, aber bei dem späteren Lauf wieder gefunden.

Code:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.10.24.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
admin :: GOLLUM [Administrator]

24.10.2012 20:48:01
mbam-log-2012-10-24 (20-48-01).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 906267
Laufzeit: 2 Stunde(n), 47 Minute(n), 49 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Program Files (x86)\DVBViewer TE2\update.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Code:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.10.23.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
admin :: GOLLUM [Administrator]

23.10.2012 13:57:50
mbam-log-2012-10-23 (13-57-50).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 727497
Laufzeit: 2 Stunde(n), 3 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Program Files (x86)\DVBViewer TE2\update.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)





Vor ein paar Tagen hatte ich im Firefox plätzlich ein Popup nach dem Motto "Wollen sie die Seite verlassen Ja / nein " .
Normalerweise beende ich dann vorsichtshalber den Prozess im Prozessmanager, diesmal habe ich dummerweise auf das Schliessen kreutz oben rechts im Fenster geclickt.

Ich hab noch ältere Mailware logs, da wurde aber das technisat Teil nicht bemängelt.

Hab grad mal das Eventlog durchgeflöht, der Dienst läuft seit dem 17.10. nicht mehr.

cosinus 25.10.2012 19:19

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

magnus65 25.10.2012 20:17

Hallo,
anbei die gewünschte Datei.

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-25 20:48:33
-----------------------------
20:48:33.593    OS Version: Windows x64 6.1.7601 Service Pack 1
20:48:33.593    Number of processors: 4 586 0x1E05
20:48:33.593    ComputerName: GOLLUM  UserName: admin
20:48:35.277    Initialize success
20:51:02.557    AVAST engine defs: 12102501
20:51:10.591    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-6
20:51:10.591    Disk 0 Vendor: WDC_WD20EARX-00PASB0 51.0AB51 Size: 1907729MB BusType: 3
20:51:10.591    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-4
20:51:10.591    Disk 1 Vendor: SAMSUNG_HE103UJ 1AA01118 Size: 953869MB BusType: 3
20:51:10.607    Disk 1 MBR read successfully
20:51:10.607    Disk 1 MBR scan
20:51:10.622    Disk 1 Windows 7 default MBR code
20:51:10.622    Disk 1 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
20:51:10.638    Disk 1 Partition 2 00    07    HPFS/NTFS NTFS      953767 MB offset 206848
20:51:10.653    Disk 1 scanning C:\Windows\system32\drivers
20:51:18.750    Service scanning
20:51:33.601    Modules scanning
20:51:33.601    Disk 1 trace - called modules:
20:51:33.617    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
20:51:33.617    1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8007af1060]
20:51:33.632    3 CLASSPNP.SYS[fffff8800194343f] -> nt!IofCallDriver -> [0xfffffa80077a7790]
20:51:33.632    5 ACPI.sys[fffff88000fa67a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-4[0xfffffa8007809060]
20:51:34.943    AVAST engine scan C:\Windows
20:51:38.406    AVAST engine scan C:\Windows\system32
20:53:50.587    AVAST engine scan C:\Windows\system32\drivers
20:54:12.271    AVAST engine scan C:\Users\admin
20:54:50.836    AVAST engine scan C:\ProgramData
20:58:32.622    Scan finished successfully
21:13:38.453    Disk 1 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat"
21:13:38.469    The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
21:14:58.919    Disk 1 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat"
21:14:58.935    The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
21:15:22.035    Disk 1 MBR has been saved successfully to "C:\Temp\MBR.dat"
21:15:22.035    The log file has been saved successfully to "C:\Temp\aswMBR.txt"

Vielen Dank übrigens bisher für Deine Mühen

cosinus 25.10.2012 22:02

Ist auch unauffällig, tiefere Scans sind imho nicht nötig.
Ich war mir schon am Anfang sicher, dass es hier ein Fehlalarm ist.

magnus65 25.10.2012 23:22

Liste der Anhänge anzeigen (Anzahl: 1)
Ok, eigentlich eine gute Nachricht, stellt sich noch die Frage, wie man das Sicherheitscenter wieder zum laufen kriegt.

Wenn da noch jemand eine Idee hat . . . . .


Cosinus, mir bleibt nur, mich für die Superunterstützung und Deine Mühe zu bedanken. Ist ein klasse Forum hier.

Gruß
Magnus

cosinus 26.10.2012 12:51

Du hast die COmputerverwaltung als Admin ausgeführt?
Leg dir mal eine Verknüpfug zu services.msc auf dem Desktop, diese per Rechtsklick => als Administrator ausführen
Versuch dann den besagten Dienst nochmal zu starten
Klappt das immer noch nicht, schaust du mal nach, ob die abhängigen Dienste zum Sicherheitscenter gestartet sind.

magnus65 26.10.2012 20:36

Liste der Anhänge anzeigen (Anzahl: 1)
Danke,
geht leider weder als Admin angemeldet, noch wenn Services.msc als Admin gestartet wird.

Was mir aufgefallen ist :

Die Anmeldeinformationen waren ursprünglich leer. Slao dieses Konto, aber dann war kein Kontoname hinterlegt.

Hab jetzt wieder Lokaler Service mit dem Admin Kenwort eingegeben , bin mir aber nicht sicher, ob das ADmin kennwort da rein muss oder was anderes.
Mit leerem Kennwort gleicher Fehler 5 Zugriff verweigert.
DCOM, RPC und RPC Endpunktzuordnung laufen.

cosinus 27.10.2012 14:24

Hm...

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

magnus65 27.10.2012 20:11

Danke für die Unterstützung, anbei das log :

Code:

21:08:28.0030 2552  TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
21:08:28.0046 2552  ============================================================
21:08:28.0046 2552  Current date / time: 2012/10/27 21:08:28.0046
21:08:28.0046 2552  SystemInfo:
21:08:28.0046 2552 
21:08:28.0046 2552  OS Version: 6.1.7601 ServicePack: 1.0
21:08:28.0046 2552  Product type: Workstation
21:08:28.0046 2552  ComputerName: GOLLUM
21:08:28.0046 2552  UserName: admin
21:08:28.0046 2552  Windows directory: C:\Windows
21:08:28.0046 2552  System windows directory: C:\Windows
21:08:28.0046 2552  Running under WOW64
21:08:28.0046 2552  Processor architecture: Intel x64
21:08:28.0046 2552  Number of processors: 4
21:08:28.0046 2552  Page size: 0x1000
21:08:28.0046 2552  Boot type: Normal boot
21:08:28.0046 2552  ============================================================
21:08:29.0013 2552  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:08:29.0013 2552  Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:08:29.0044 2552  ============================================================
21:08:29.0044 2552  \Device\Harddisk0\DR0:
21:08:29.0044 2552  MBR partitions:
21:08:29.0044 2552  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
21:08:29.0044 2552  \Device\Harddisk1\DR1:
21:08:29.0044 2552  MBR partitions:
21:08:29.0044 2552  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
21:08:29.0044 2552  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
21:08:29.0044 2552  ============================================================
21:08:29.0091 2552  C: <-> \Device\Harddisk1\DR1\Partition2
21:08:29.0106 2552  D: <-> \Device\Harddisk0\DR0\Partition1
21:08:29.0106 2552  ============================================================
21:08:29.0106 2552  Initialize success
21:08:29.0106 2552  ============================================================
21:08:42.0460 0792  ============================================================
21:08:42.0460 0792  Scan started
21:08:42.0460 0792  Mode: Manual; SigCheck; TDLFS;
21:08:42.0460 0792  ============================================================
21:08:43.0895 0792  ================ Scan system memory ========================
21:08:43.0895 0792  System memory - ok
21:08:43.0895 0792  ================ Scan services =============================
21:08:44.0020 0792  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
21:08:44.0160 0792  1394ohci - ok
21:08:44.0192 0792  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:08:44.0207 0792  ACPI - ok
21:08:44.0238 0792  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
21:08:44.0285 0792  AcpiPmi - ok
21:08:44.0348 0792  [ D44BCAF639E4E45307C2BC80715273D5 ] adfs            C:\Windows\system32\drivers\adfs.sys
21:08:44.0394 0792  adfs - ok
21:08:44.0504 0792  [ 9444A3530C2E88B7ED96A566FF9CCC13 ] Adobe Version Cue CS4 C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
21:08:44.0519 0792  Adobe Version Cue CS4 - ok
21:08:44.0535 0792  [ 3FD8DC2C9735C2AA70155102CFB93EDA ] AdobeActiveFileMonitor7.0 C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
21:08:44.0550 0792  AdobeActiveFileMonitor7.0 - ok
21:08:44.0675 0792  [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:08:44.0675 0792  AdobeFlashPlayerUpdateSvc - ok
21:08:44.0722 0792  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
21:08:44.0738 0792  adp94xx - ok
21:08:44.0753 0792  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
21:08:44.0769 0792  adpahci - ok
21:08:44.0769 0792  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
21:08:44.0784 0792  adpu320 - ok
21:08:44.0816 0792  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
21:08:44.0925 0792  AeLookupSvc - ok
21:08:44.0972 0792  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
21:08:45.0018 0792  AFD - ok
21:08:45.0050 0792  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
21:08:45.0065 0792  agp440 - ok
21:08:45.0096 0792  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
21:08:45.0128 0792  ALG - ok
21:08:45.0143 0792  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
21:08:45.0143 0792  aliide - ok
21:08:45.0190 0792  [ B4143CB1DD16AE73C6177C72F33450A6 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:08:45.0237 0792  AMD External Events Utility - ok
21:08:45.0252 0792  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
21:08:45.0268 0792  amdide - ok
21:08:45.0268 0792  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
21:08:45.0315 0792  AmdK8 - ok
21:08:45.0424 0792  [ D1D06810BF7E21F5763EB06CB7E7262B ] amdkmdag        C:\Windows\system32\DRIVERS\atipmdag.sys
21:08:45.0518 0792  amdkmdag - ok
21:08:45.0549 0792  [ 6BA71D6616B56816E57394D77DD1BB6F ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
21:08:45.0564 0792  amdkmdap - ok
21:08:45.0564 0792  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
21:08:45.0596 0792  AmdPPM - ok
21:08:45.0627 0792  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
21:08:45.0627 0792  amdsata - ok
21:08:45.0658 0792  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
21:08:45.0674 0792  amdsbs - ok
21:08:45.0689 0792  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
21:08:45.0689 0792  amdxata - ok
21:08:45.0783 0792  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
21:08:45.0798 0792  AntiVirSchedulerService - ok
21:08:45.0845 0792  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
21:08:45.0845 0792  AntiVirService - ok
21:08:45.0892 0792  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
21:08:46.0001 0792  AppID - ok
21:08:46.0017 0792  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:08:46.0064 0792  AppIDSvc - ok
21:08:46.0095 0792  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
21:08:46.0126 0792  Appinfo - ok
21:08:46.0204 0792  [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:08:46.0220 0792  Apple Mobile Device - ok
21:08:46.0235 0792  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt        C:\Windows\System32\appmgmts.dll
21:08:46.0282 0792  AppMgmt - ok
21:08:46.0313 0792  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\DRIVERS\arc.sys
21:08:46.0329 0792  arc - ok
21:08:46.0329 0792  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
21:08:46.0344 0792  arcsas - ok
21:08:46.0454 0792  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
21:08:46.0485 0792  aspnet_state - ok
21:08:46.0500 0792  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:08:46.0547 0792  AsyncMac - ok
21:08:46.0578 0792  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
21:08:46.0578 0792  atapi - ok
21:08:46.0610 0792  [ 506934DF94E3197F4A1BBE8FBEAB0CCD ] AtiHdmiService  C:\Windows\system32\drivers\AtiHdmi.sys
21:08:46.0641 0792  AtiHdmiService - ok
21:08:46.0734 0792  [ D1D06810BF7E21F5763EB06CB7E7262B ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
21:08:46.0828 0792  atikmdag - ok
21:08:46.0875 0792  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:08:46.0922 0792  AudioEndpointBuilder - ok
21:08:46.0922 0792  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
21:08:46.0953 0792  AudioSrv - ok
21:08:47.0140 0792  [ 3CE07FB20B84734CCE81CF10D1D7F803 ] AVGIDSAgent    C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
21:08:47.0265 0792  AVGIDSAgent - ok
21:08:47.0312 0792  [ E6671E90D38C88764412E07C9D9B3D63 ] AVGIDSDriver    C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
21:08:47.0343 0792  AVGIDSDriver - ok
21:08:47.0374 0792  [ 1553B388E0F0462C25AD8F30C3C29E83 ] AVGIDSEH        C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
21:08:47.0405 0792  AVGIDSEH - ok
21:08:47.0421 0792  [ DCA426A66739E75F51A72160DFB945AD ] AVGIDSFilter    C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
21:08:47.0452 0792  AVGIDSFilter - ok
21:08:47.0483 0792  [ FF7383388A7D2283DAE5831ABC2B0720 ] Avgldx64        C:\Windows\system32\DRIVERS\avgldx64.sys
21:08:47.0514 0792  Avgldx64 - ok
21:08:47.0530 0792  [ 997D002827D3E3DCBBB25BF46DB161AB ] Avgmfx64        C:\Windows\system32\DRIVERS\avgmfx64.sys
21:08:47.0561 0792  Avgmfx64 - ok
21:08:47.0577 0792  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
21:08:47.0608 0792  avgntflt - ok
21:08:47.0624 0792  [ BCCFE3374C887075CDE2AC8FDB1CB2F8 ] Avgrkx64        C:\Windows\system32\DRIVERS\avgrkx64.sys
21:08:47.0639 0792  Avgrkx64 - ok
21:08:47.0655 0792  [ 0D49ADCEBE243B79366EA523B647519A ] Avgtdia        C:\Windows\system32\DRIVERS\avgtdia.sys
21:08:47.0686 0792  Avgtdia - ok
21:08:47.0702 0792  [ FC2BC51120A945F7C70376495E4E7737 ] avgwd          C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
21:08:47.0733 0792  avgwd - ok
21:08:47.0764 0792  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
21:08:47.0780 0792  avipbb - ok
21:08:47.0795 0792  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
21:08:47.0826 0792  avkmgr - ok
21:08:47.0858 0792  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:08:47.0920 0792  AxInstSV - ok
21:08:47.0951 0792  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbda.sys
21:08:47.0998 0792  b06bdrv - ok
21:08:48.0014 0792  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
21:08:48.0045 0792  b57nd60a - ok
21:08:48.0076 0792  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
21:08:48.0107 0792  BDESVC - ok
21:08:48.0123 0792  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:08:48.0154 0792  Beep - ok
21:08:48.0201 0792  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
21:08:48.0263 0792  BFE - ok
21:08:48.0279 0792  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
21:08:48.0372 0792  BITS - ok
21:08:48.0388 0792  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
21:08:48.0404 0792  blbdrive - ok
21:08:48.0482 0792  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:08:48.0497 0792  Bonjour Service - ok
21:08:48.0528 0792  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:08:48.0560 0792  bowser - ok
21:08:48.0575 0792  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:08:48.0622 0792  BrFiltLo - ok
21:08:48.0622 0792  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:08:48.0638 0792  BrFiltUp - ok
21:08:48.0669 0792  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
21:08:48.0700 0792  Browser - ok
21:08:48.0731 0792  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
21:08:48.0762 0792  Brserid - ok
21:08:48.0762 0792  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
21:08:48.0794 0792  BrSerWdm - ok
21:08:48.0809 0792  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
21:08:48.0825 0792  BrUsbMdm - ok
21:08:48.0840 0792  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
21:08:48.0856 0792  BrUsbSer - ok
21:08:48.0872 0792  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
21:08:48.0887 0792  BTHMODEM - ok
21:08:48.0918 0792  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
21:08:48.0950 0792  bthserv - ok
21:08:48.0965 0792  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:08:48.0996 0792  cdfs - ok
21:08:49.0028 0792  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\drivers\cdrom.sys
21:08:49.0059 0792  cdrom - ok
21:08:49.0090 0792  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
21:08:49.0121 0792  CertPropSvc - ok
21:08:49.0137 0792  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
21:08:49.0168 0792  circlass - ok
21:08:49.0199 0792  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
21:08:49.0215 0792  CLFS - ok
21:08:49.0262 0792  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:08:49.0277 0792  clr_optimization_v2.0.50727_32 - ok
21:08:49.0293 0792  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:08:49.0293 0792  clr_optimization_v2.0.50727_64 - ok
21:08:49.0371 0792  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:08:49.0449 0792  clr_optimization_v4.0.30319_32 - ok
21:08:49.0449 0792  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:08:49.0480 0792  clr_optimization_v4.0.30319_64 - ok
21:08:49.0496 0792  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
21:08:49.0527 0792  CmBatt - ok
21:08:49.0542 0792  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
21:08:49.0558 0792  cmdide - ok
21:08:49.0589 0792  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
21:08:49.0620 0792  CNG - ok
21:08:49.0636 0792  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
21:08:49.0652 0792  Compbatt - ok
21:08:49.0683 0792  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
21:08:49.0698 0792  CompositeBus - ok
21:08:49.0714 0792  COMSysApp - ok
21:08:49.0730 0792  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
21:08:49.0745 0792  crcdisk - ok
21:08:49.0776 0792  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:08:49.0823 0792  CryptSvc - ok
21:08:49.0854 0792  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC            C:\Windows\system32\drivers\csc.sys
21:08:49.0917 0792  CSC - ok
21:08:49.0932 0792  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\Windows\System32\cscsvc.dll
21:08:49.0964 0792  CscService - ok
21:08:49.0995 0792  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:08:50.0042 0792  DcomLaunch - ok
21:08:50.0057 0792  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
21:08:50.0104 0792  defragsvc - ok
21:08:50.0135 0792  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
21:08:50.0166 0792  DfsC - ok
21:08:50.0198 0792  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:08:50.0244 0792  Dhcp - ok
21:08:50.0260 0792  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
21:08:50.0291 0792  discache - ok
21:08:50.0307 0792  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
21:08:50.0322 0792  Disk - ok
21:08:50.0338 0792  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:08:50.0400 0792  Dnscache - ok
21:08:50.0416 0792  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
21:08:50.0447 0792  dot3svc - ok
21:08:50.0478 0792  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
21:08:50.0510 0792  DPS - ok
21:08:50.0541 0792  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
21:08:50.0572 0792  drmkaud - ok
21:08:50.0603 0792  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
21:08:50.0619 0792  DXGKrnl - ok
21:08:50.0634 0792  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
21:08:50.0666 0792  EapHost - ok
21:08:50.0712 0792  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\DRIVERS\evbda.sys
21:08:50.0775 0792  ebdrv - ok
21:08:50.0790 0792  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
21:08:50.0853 0792  EFS - ok
21:08:50.0884 0792  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
21:08:50.0915 0792  ehRecvr - ok
21:08:50.0931 0792  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
21:08:50.0962 0792  ehSched - ok
21:08:50.0993 0792  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
21:08:51.0009 0792  elxstor - ok
21:08:51.0024 0792  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
21:08:51.0024 0792  ErrDev - ok
21:08:51.0056 0792  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
21:08:51.0087 0792  EventSystem - ok
21:08:51.0118 0792  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
21:08:51.0149 0792  exfat - ok
21:08:51.0165 0792  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
21:08:51.0212 0792  fastfat - ok
21:08:51.0258 0792  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
21:08:51.0305 0792  Fax - ok
21:08:51.0305 0792  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
21:08:51.0321 0792  fdc - ok
21:08:51.0336 0792  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
21:08:51.0368 0792  fdPHost - ok
21:08:51.0383 0792  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:08:51.0430 0792  FDResPub - ok
21:08:51.0446 0792  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:08:51.0446 0792  FileInfo - ok
21:08:51.0446 0792  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
21:08:51.0477 0792  Filetrace - ok
21:08:51.0524 0792  [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
21:08:51.0539 0792  FLEXnet Licensing Service - ok
21:08:51.0586 0792  [ 1C3FB052A0BB72EDAED90785C34D6EED ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
21:08:51.0617 0792  FLEXnet Licensing Service 64 - ok
21:08:51.0617 0792  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
21:08:51.0633 0792  flpydisk - ok
21:08:51.0664 0792  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:08:51.0680 0792  FltMgr - ok
21:08:51.0726 0792  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache      C:\Windows\system32\FntCache.dll
21:08:51.0758 0792  FontCache - ok
21:08:51.0789 0792  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:08:51.0804 0792  FontCache3.0.0.0 - ok
21:08:51.0804 0792  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
21:08:51.0820 0792  FsDepends - ok
21:08:51.0836 0792  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:08:51.0851 0792  Fs_Rec - ok
21:08:51.0867 0792  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:08:51.0882 0792  fvevol - ok
21:08:51.0898 0792  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
21:08:51.0898 0792  gagp30kx - ok
21:08:51.0929 0792  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:08:51.0945 0792  GEARAspiWDM - ok
21:08:51.0976 0792  [ B93252C4C5A3733ECD5522CAF88DE02D ] GigasetGenericUSB_x64 C:\Windows\system32\DRIVERS\GigasetGenericUSB_x64.sys
21:08:52.0023 0792  GigasetGenericUSB_x64 - ok
21:08:52.0070 0792  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
21:08:52.0101 0792  gpsvc - ok
21:08:52.0116 0792  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
21:08:52.0163 0792  hcw85cir - ok
21:08:52.0210 0792  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:08:52.0241 0792  HdAudAddService - ok
21:08:52.0272 0792  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
21:08:52.0288 0792  HDAudBus - ok
21:08:52.0304 0792  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
21:08:52.0304 0792  HidBatt - ok
21:08:52.0319 0792  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
21:08:52.0366 0792  HidBth - ok
21:08:52.0382 0792  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
21:08:52.0428 0792  HidIr - ok
21:08:52.0444 0792  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\system32\hidserv.dll
21:08:52.0491 0792  hidserv - ok
21:08:52.0506 0792  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
21:08:52.0522 0792  HidUsb - ok
21:08:52.0538 0792  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:08:52.0569 0792  hkmsvc - ok
21:08:52.0600 0792  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:08:52.0647 0792  HomeGroupListener - ok
21:08:52.0662 0792  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:08:52.0694 0792  HomeGroupProvider - ok
21:08:52.0709 0792  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:08:52.0709 0792  HpSAMD - ok
21:08:52.0740 0792  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:08:52.0772 0792  HTTP - ok
21:08:52.0787 0792  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:08:52.0803 0792  hwpolicy - ok
21:08:52.0818 0792  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
21:08:52.0818 0792  i8042prt - ok
21:08:52.0850 0792  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
21:08:52.0865 0792  iaStorV - ok
21:08:52.0928 0792  [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
21:08:52.0943 0792  IDriverT ( UnsignedFile.Multi.Generic ) - warning
21:08:52.0943 0792  IDriverT - detected UnsignedFile.Multi.Generic (1)
21:08:52.0974 0792  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:08:52.0990 0792  idsvc - ok
21:08:53.0021 0792  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
21:08:53.0021 0792  iirsp - ok
21:08:53.0052 0792  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
21:08:53.0084 0792  IKEEXT - ok
21:08:53.0115 0792  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
21:08:53.0115 0792  intelide - ok
21:08:53.0130 0792  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
21:08:53.0162 0792  intelppm - ok
21:08:53.0193 0792  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
21:08:53.0224 0792  IPBusEnum - ok
21:08:53.0240 0792  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:08:53.0255 0792  IpFilterDriver - ok
21:08:53.0286 0792  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:08:53.0333 0792  iphlpsvc - ok
21:08:53.0349 0792  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
21:08:53.0364 0792  IPMIDRV - ok
21:08:53.0380 0792  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
21:08:53.0411 0792  IPNAT - ok
21:08:53.0458 0792  [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
21:08:53.0489 0792  iPod Service - ok
21:08:53.0505 0792  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:08:53.0567 0792  IRENUM - ok
21:08:53.0567 0792  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:08:53.0583 0792  isapnp - ok
21:08:53.0598 0792  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
21:08:53.0614 0792  iScsiPrt - ok
21:08:53.0630 0792  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
21:08:53.0645 0792  kbdclass - ok
21:08:53.0661 0792  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
21:08:53.0692 0792  kbdhid - ok
21:08:53.0708 0792  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
21:08:53.0723 0792  KeyIso - ok
21:08:53.0754 0792  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:08:53.0754 0792  KSecDD - ok
21:08:53.0770 0792  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
21:08:53.0786 0792  KSecPkg - ok
21:08:53.0801 0792  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
21:08:53.0832 0792  ksthunk - ok
21:08:53.0848 0792  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
21:08:53.0895 0792  KtmRm - ok
21:08:53.0942 0792  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
21:08:53.0973 0792  LanmanServer - ok
21:08:54.0004 0792  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:08:54.0035 0792  LanmanWorkstation - ok
21:08:54.0066 0792  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:08:54.0098 0792  lltdio - ok
21:08:54.0129 0792  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
21:08:54.0160 0792  lltdsvc - ok
21:08:54.0176 0792  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
21:08:54.0207 0792  lmhosts - ok
21:08:54.0223 0792  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
21:08:54.0223 0792  LSI_FC - ok
21:08:54.0238 0792  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
21:08:54.0254 0792  LSI_SAS - ok
21:08:54.0269 0792  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:08:54.0269 0792  LSI_SAS2 - ok
21:08:54.0269 0792  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:08:54.0285 0792  LSI_SCSI - ok
21:08:54.0301 0792  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
21:08:54.0332 0792  luafv - ok
21:08:54.0347 0792  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
21:08:54.0363 0792  Mcx2Svc - ok
21:08:54.0379 0792  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
21:08:54.0379 0792  megasas - ok
21:08:54.0410 0792  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
21:08:54.0410 0792  MegaSR - ok
21:08:54.0457 0792  [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
21:08:54.0457 0792  Microsoft Office Groove Audit Service - ok
21:08:54.0472 0792  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
21:08:54.0503 0792  MMCSS - ok
21:08:54.0519 0792  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
21:08:54.0535 0792  Modem - ok
21:08:54.0550 0792  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
21:08:54.0566 0792  monitor - ok
21:08:54.0597 0792  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
21:08:54.0597 0792  mouclass - ok
21:08:54.0628 0792  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
21:08:54.0644 0792  mouhid - ok
21:08:54.0691 0792  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:08:54.0691 0792  mountmgr - ok
21:08:54.0706 0792  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
21:08:54.0722 0792  mpio - ok
21:08:54.0722 0792  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:08:54.0769 0792  mpsdrv - ok
21:08:54.0800 0792  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:08:54.0847 0792  MpsSvc - ok
21:08:54.0862 0792  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:08:54.0893 0792  MRxDAV - ok
21:08:54.0909 0792  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:08:54.0956 0792  mrxsmb - ok
21:08:54.0987 0792  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:08:55.0003 0792  mrxsmb10 - ok
21:08:55.0034 0792  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:08:55.0049 0792  mrxsmb20 - ok
21:08:55.0081 0792  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
21:08:55.0096 0792  msahci - ok
21:08:55.0112 0792  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
21:08:55.0127 0792  msdsm - ok
21:08:55.0143 0792  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
21:08:55.0159 0792  MSDTC - ok
21:08:55.0174 0792  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:08:55.0190 0792  Msfs - ok
21:08:55.0221 0792  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
21:08:55.0237 0792  mshidkmdf - ok
21:08:55.0252 0792  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:08:55.0252 0792  msisadrv - ok
21:08:55.0283 0792  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
21:08:55.0315 0792  MSiSCSI - ok
21:08:55.0315 0792  msiserver - ok
21:08:55.0346 0792  MSI_MSIBIOS_010507 - ok
21:08:55.0377 0792  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
21:08:55.0393 0792  MSKSSRV - ok
21:08:55.0408 0792  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:08:55.0439 0792  MSPCLOCK - ok
21:08:55.0455 0792  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
21:08:55.0502 0792  MSPQM - ok
21:08:55.0533 0792  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
21:08:55.0549 0792  MsRPC - ok
21:08:55.0549 0792  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
21:08:55.0564 0792  mssmbios - ok
21:08:55.0580 0792  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
21:08:55.0595 0792  MSTEE - ok
21:08:55.0611 0792  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
21:08:55.0642 0792  MTConfig - ok
21:08:55.0642 0792  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
21:08:55.0658 0792  Mup - ok
21:08:55.0689 0792  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
21:08:55.0720 0792  napagent - ok
21:08:55.0751 0792  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
21:08:55.0783 0792  NativeWifiP - ok
21:08:55.0829 0792  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:08:55.0845 0792  NDIS - ok
21:08:55.0861 0792  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
21:08:55.0892 0792  NdisCap - ok
21:08:55.0907 0792  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:08:55.0954 0792  NdisTapi - ok
21:08:55.0970 0792  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
21:08:56.0001 0792  Ndisuio - ok
21:08:56.0032 0792  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
21:08:56.0063 0792  NdisWan - ok
21:08:56.0095 0792  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
21:08:56.0126 0792  NDProxy - ok
21:08:56.0157 0792  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
21:08:56.0204 0792  NetBIOS - ok
21:08:56.0219 0792  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
21:08:56.0251 0792  NetBT - ok
21:08:56.0251 0792  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
21:08:56.0266 0792  Netlogon - ok
21:08:56.0282 0792  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
21:08:56.0329 0792  Netman - ok
21:08:56.0375 0792  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:08:56.0407 0792  NetMsmqActivator - ok
21:08:56.0407 0792  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:08:56.0407 0792  NetPipeActivator - ok
21:08:56.0438 0792  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
21:08:56.0469 0792  netprofm - ok
21:08:56.0485 0792  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:08:56.0485 0792  NetTcpActivator - ok
21:08:56.0485 0792  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:08:56.0500 0792  NetTcpPortSharing - ok
21:08:56.0516 0792  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
21:08:56.0531 0792  nfrd960 - ok
21:08:56.0578 0792  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:08:56.0609 0792  NlaSvc - ok
21:08:56.0625 0792  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:08:56.0656 0792  Npfs - ok
21:08:56.0672 0792  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
21:08:56.0687 0792  nsi - ok
21:08:56.0703 0792  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:08:56.0734 0792  nsiproxy - ok
21:08:56.0765 0792  [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:08:56.0797 0792  Ntfs - ok
21:08:56.0875 0792  [ B0BAAC4D6CBAC384A633C71858B35A2E ] NTIOLib_1_0_0  C:\Program Files (x86)\MSI\DirectOC\NTIOLib_X64.sys
21:08:56.0906 0792  NTIOLib_1_0_0 - ok
21:08:56.0968 0792  [ C3FEA895FE95EA7A57D9F4D7ABED5E71 ] NTIOLib_1_0_1  C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys
21:08:56.0984 0792  NTIOLib_1_0_1 - ok
21:08:56.0999 0792  NTIOLib_1_0_4 - ok
21:08:57.0015 0792  [ C02F70960FA934B8DEFA16A03D7F6556 ] NTIOLib_1_0_6  C:\Program Files (x86)\Setup Files\Ms7583v1B0\NTIOLib_X64.sys
21:08:57.0062 0792  NTIOLib_1_0_6 ( UnsignedFile.Multi.Generic ) - warning
21:08:57.0062 0792  NTIOLib_1_0_6 - detected UnsignedFile.Multi.Generic (1)
21:08:57.0077 0792  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
21:08:57.0109 0792  Null - ok
21:08:57.0140 0792  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:08:57.0155 0792  nvraid - ok
21:08:57.0171 0792  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:08:57.0187 0792  nvstor - ok
21:08:57.0218 0792  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:08:57.0233 0792  nv_agp - ok
21:08:57.0296 0792  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:08:57.0311 0792  odserv - ok
21:08:57.0343 0792  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
21:08:57.0358 0792  ohci1394 - ok
21:08:57.0389 0792  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:08:57.0405 0792  ose - ok
21:08:57.0421 0792  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
21:08:57.0467 0792  p2pimsvc - ok
21:08:57.0483 0792  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
21:08:57.0499 0792  p2psvc - ok
21:08:57.0514 0792  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
21:08:57.0514 0792  Parport - ok
21:08:57.0545 0792  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
21:08:57.0561 0792  partmgr - ok
21:08:57.0561 0792  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:08:57.0592 0792  PcaSvc - ok
21:08:57.0592 0792  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
21:08:57.0608 0792  pci - ok
21:08:57.0608 0792  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
21:08:57.0623 0792  pciide - ok
21:08:57.0639 0792  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
21:08:57.0655 0792  pcmcia - ok
21:08:57.0670 0792  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
21:08:57.0670 0792  pcw - ok
21:08:57.0701 0792  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:08:57.0748 0792  PEAUTH - ok
21:08:57.0779 0792  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
21:08:57.0842 0792  PeerDistSvc - ok
21:08:57.0904 0792  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
21:08:57.0935 0792  PerfHost - ok
21:08:57.0982 0792  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
21:08:58.0029 0792  pla - ok
21:08:58.0060 0792  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:08:58.0107 0792  PlugPlay - ok
21:08:58.0123 0792  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
21:08:58.0138 0792  PNRPAutoReg - ok
21:08:58.0154 0792  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
21:08:58.0169 0792  PNRPsvc - ok
21:08:58.0216 0792  [ 9CC7182504133119BD39ED825F72F4E2 ] Polar Daemon    C:\Program Files (x86)\Polar\Daemon\polard.exe
21:08:58.0232 0792  Polar Daemon ( UnsignedFile.Multi.Generic ) - warning
21:08:58.0232 0792  Polar Daemon - detected UnsignedFile.Multi.Generic (1)
21:08:58.0263 0792  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
21:08:58.0310 0792  PolicyAgent - ok
21:08:58.0325 0792  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
21:08:58.0372 0792  Power - ok
21:08:58.0403 0792  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:08:58.0435 0792  PptpMiniport - ok
21:08:58.0435 0792  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\DRIVERS\processr.sys
21:08:58.0450 0792  Processor - ok
21:08:58.0481 0792  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
21:08:58.0513 0792  ProfSvc - ok
21:08:58.0528 0792  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:08:58.0528 0792  ProtectedStorage - ok
21:08:58.0591 0792  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
21:08:58.0622 0792  Psched - ok
21:08:58.0637 0792  [ A6BF0A9B5A30D743623CA0D3BE35DF05 ] PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
21:08:58.0669 0792  PxHlpa64 - ok
21:08:58.0715 0792  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
21:08:58.0747 0792  ql2300 - ok
21:08:58.0747 0792  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
21:08:58.0762 0792  ql40xx - ok
21:08:58.0793 0792  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
21:08:58.0809 0792  QWAVE - ok
21:08:58.0825 0792  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:08:58.0840 0792  QWAVEdrv - ok
21:08:58.0856 0792  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:08:58.0887 0792  RasAcd - ok
21:08:58.0903 0792  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
21:08:58.0918 0792  RasAgileVpn - ok
21:08:58.0934 0792  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
21:08:58.0965 0792  RasAuto - ok
21:08:58.0981 0792  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
21:08:59.0012 0792  Rasl2tp - ok
21:08:59.0027 0792  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
21:08:59.0074 0792  RasMan - ok
21:08:59.0074 0792  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:08:59.0105 0792  RasPppoe - ok
21:08:59.0121 0792  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
21:08:59.0152 0792  RasSstp - ok
21:08:59.0168 0792  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
21:08:59.0199 0792  rdbss - ok
21:08:59.0215 0792  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
21:08:59.0230 0792  rdpbus - ok
21:08:59.0246 0792  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
21:08:59.0277 0792  RDPCDD - ok
21:08:59.0293 0792  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
21:08:59.0324 0792  RDPDR - ok
21:08:59.0339 0792  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
21:08:59.0371 0792  RDPENCDD - ok
21:08:59.0371 0792  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
21:08:59.0402 0792  RDPREFMP - ok
21:08:59.0464 0792  [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:08:59.0495 0792  RdpVideoMiniport - ok
21:08:59.0527 0792  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
21:08:59.0558 0792  RDPWD - ok
21:08:59.0589 0792  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
21:08:59.0605 0792  rdyboost - ok
21:08:59.0620 0792  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:08:59.0651 0792  RemoteAccess - ok
21:08:59.0683 0792  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:08:59.0714 0792  RemoteRegistry - ok
21:08:59.0745 0792  RimUsb - ok
21:08:59.0776 0792  [ 4AAFFFA67AC4DFA3D9985D78573887E2 ] RimVSerPort    C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
21:08:59.0807 0792  RimVSerPort - ok
21:08:59.0839 0792  [ 388D3DD1A6457280F3BADBA9F3ACD6B1 ] ROOTMODEM      C:\Windows\system32\Drivers\RootMdm.sys
21:08:59.0870 0792  ROOTMODEM - ok
21:08:59.0885 0792  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
21:08:59.0917 0792  RpcEptMapper - ok
21:08:59.0932 0792  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
21:08:59.0948 0792  RpcLocator - ok
21:08:59.0979 0792  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
21:09:00.0010 0792  RpcSs - ok
21:09:00.0026 0792  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:09:00.0057 0792  rspndr - ok
21:09:00.0088 0792  [ 4B42BC58294E83A6A92EC8B88C14C4A3 ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
21:09:00.0119 0792  RTL8167 - ok
21:09:00.0135 0792  [ E60C0A09F997826C7627B244195AB581 ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
21:09:00.0166 0792  s3cap - ok
21:09:00.0166 0792  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
21:09:00.0182 0792  SamSs - ok
21:09:00.0197 0792  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:09:00.0213 0792  sbp2port - ok
21:09:00.0291 0792  [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService  C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
21:09:00.0307 0792  SBSDWSCService - ok
21:09:00.0322 0792  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:09:00.0369 0792  SCardSvr - ok
21:09:00.0385 0792  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
21:09:00.0431 0792  scfilter - ok
21:09:00.0478 0792  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
21:09:00.0509 0792  Schedule - ok
21:09:00.0541 0792  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
21:09:00.0556 0792  SCPolicySvc - ok
21:09:00.0587 0792  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
21:09:00.0619 0792  SDRSVC - ok
21:09:00.0634 0792  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:09:00.0665 0792  secdrv - ok
21:09:00.0697 0792  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
21:09:00.0743 0792  seclogon - ok
21:09:00.0759 0792  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
21:09:00.0790 0792  SENS - ok
21:09:00.0790 0792  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
21:09:00.0806 0792  SensrSvc - ok
21:09:00.0837 0792  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
21:09:00.0853 0792  Serenum - ok
21:09:00.0853 0792  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
21:09:00.0884 0792  Serial - ok
21:09:00.0915 0792  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
21:09:00.0931 0792  sermouse - ok
21:09:00.0993 0792  [ 9D38320BB32230349379DF5DDBBF7FCE ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
21:09:01.0009 0792  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
21:09:01.0009 0792  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
21:09:01.0040 0792  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
21:09:01.0071 0792  SessionEnv - ok
21:09:01.0071 0792  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
21:09:01.0118 0792  sffdisk - ok
21:09:01.0133 0792  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
21:09:01.0149 0792  sffp_mmc - ok
21:09:01.0165 0792  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
21:09:01.0180 0792  sffp_sd - ok
21:09:01.0180 0792  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
21:09:01.0211 0792  sfloppy - ok
21:09:01.0227 0792  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:09:01.0258 0792  SharedAccess - ok
21:09:01.0274 0792  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:09:01.0305 0792  ShellHWDetection - ok
21:09:01.0336 0792  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:09:01.0336 0792  SiSRaid2 - ok
21:09:01.0352 0792  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
21:09:01.0352 0792  SiSRaid4 - ok
21:09:01.0383 0792  [ AAAD5499D1F967CF23FAE7B57A96722C ] SKYNET          C:\Windows\system32\DRIVERS\SkyNET_AMD64.SYS
21:09:01.0414 0792  SKYNET - ok
21:09:01.0445 0792  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
21:09:01.0477 0792  Smb - ok
21:09:01.0492 0792  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:09:01.0523 0792  SNMPTRAP - ok
21:09:01.0555 0792  [ 5F9785E7535F8F602CB294A54962C9E7 ] speedfan        C:\Windows\syswow64\speedfan.sys
21:09:01.0586 0792  speedfan - ok
21:09:01.0586 0792  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
21:09:01.0601 0792  spldr - ok
21:09:01.0617 0792  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
21:09:01.0664 0792  Spooler - ok
21:09:01.0742 0792  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
21:09:01.0804 0792  sppsvc - ok
21:09:01.0820 0792  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
21:09:01.0851 0792  sppuinotify - ok
21:09:01.0882 0792  [ D8B882C520FC83547E22014FF5EC66D7 ] Spyder3        C:\Windows\system32\DRIVERS\Spyder3.sys
21:09:01.0929 0792  Spyder3 - ok
21:09:02.0007 0792  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
21:09:02.0116 0792  srv - ok
21:09:02.0288 0792  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:09:02.0319 0792  srv2 - ok
21:09:02.0335 0792  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:09:02.0350 0792  srvnet - ok
21:09:02.0366 0792  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
21:09:02.0413 0792  SSDPSRV - ok
21:09:02.0428 0792  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
21:09:02.0444 0792  SstpSvc - ok
21:09:02.0459 0792  StarOpen - ok
21:09:02.0475 0792  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
21:09:02.0475 0792  stexstor - ok
21:09:02.0522 0792  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
21:09:02.0553 0792  stisvc - ok
21:09:02.0569 0792  [ 7785DC213270D2FC066538DAF94087E7 ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
21:09:02.0584 0792  storflt - ok
21:09:02.0600 0792  [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc        C:\Windows\system32\drivers\storvsc.sys
21:09:02.0615 0792  storvsc - ok
21:09:02.0631 0792  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
21:09:02.0647 0792  swenum - ok
21:09:02.0662 0792  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
21:09:02.0693 0792  swprv - ok
21:09:02.0709 0792  Synth3dVsc - ok
21:09:02.0740 0792  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
21:09:02.0803 0792  SysMain - ok
21:09:02.0818 0792  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:09:02.0834 0792  TabletInputService - ok
21:09:02.0849 0792  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
21:09:02.0881 0792  TapiSrv - ok
21:09:02.0896 0792  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
21:09:02.0927 0792  TBS - ok
21:09:02.0974 0792  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
21:09:03.0005 0792  Tcpip - ok
21:09:03.0037 0792  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
21:09:03.0068 0792  TCPIP6 - ok
21:09:03.0099 0792  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:09:03.0115 0792  tcpipreg - ok
21:09:03.0130 0792  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
21:09:03.0177 0792  TDPIPE - ok
21:09:03.0193 0792  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
21:09:03.0208 0792  TDTCP - ok
21:09:03.0239 0792  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
21:09:03.0255 0792  tdx - ok
21:09:03.0271 0792  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
21:09:03.0286 0792  TermDD - ok
21:09:03.0317 0792  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
21:09:03.0364 0792  TermService - ok
21:09:03.0380 0792  [ CE4B6956E4E12492715A53076E58761F ] TFsExDisk      C:\Windows\System32\Drivers\TFsExDisk.sys
21:09:03.0411 0792  TFsExDisk - ok
21:09:03.0427 0792  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
21:09:03.0442 0792  Themes - ok
21:09:03.0458 0792  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
21:09:03.0473 0792  THREADORDER - ok
21:09:03.0520 0792  [ F32E7CD2339C66760AA5178924B21E6B ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
21:09:03.0536 0792  TomTomHOMEService - ok
21:09:03.0536 0792  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
21:09:03.0567 0792  TrkWks - ok
21:09:03.0629 0792  [ C6A1A2B4E8A7B92C11CA038369BD7DBE ] truecrypt      C:\Windows\syswow64\drivers\truecrypt.sys
21:09:03.0661 0792  truecrypt - ok
21:09:03.0707 0792  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:09:03.0739 0792  TrustedInstaller - ok
21:09:03.0770 0792  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
21:09:03.0801 0792  tssecsrv - ok
21:09:03.0817 0792  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
21:09:03.0848 0792  TsUsbFlt - ok
21:09:03.0848 0792  tsusbhub - ok
21:09:03.0879 0792  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:09:03.0910 0792  tunnel - ok
21:09:03.0941 0792  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
21:09:03.0957 0792  uagp35 - ok
21:09:03.0988 0792  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:09:04.0019 0792  udfs - ok
21:09:04.0051 0792  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
21:09:04.0066 0792  UI0Detect - ok
21:09:04.0082 0792  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:09:04.0097 0792  uliagpkx - ok
21:09:04.0144 0792  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\drivers\umbus.sys
21:09:04.0160 0792  umbus - ok
21:09:04.0175 0792  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
21:09:04.0191 0792  UmPass - ok
21:09:04.0207 0792  [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService    C:\Windows\System32\umrdp.dll
21:09:04.0222 0792  UmRdpService - ok
21:09:04.0253 0792  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
21:09:04.0300 0792  upnphost - ok
21:09:04.0347 0792  [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
21:09:04.0363 0792  USBAAPL64 ( UnsignedFile.Multi.Generic ) - warning
21:09:04.0363 0792  USBAAPL64 - detected UnsignedFile.Multi.Generic (1)
21:09:04.0378 0792  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
21:09:04.0409 0792  usbccgp - ok
21:09:04.0441 0792  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
21:09:04.0441 0792  usbcir - ok
21:09:04.0472 0792  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
21:09:04.0487 0792  usbehci - ok
21:09:04.0503 0792  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
21:09:04.0534 0792  usbhub - ok
21:09:04.0534 0792  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
21:09:04.0565 0792  usbohci - ok
21:09:04.0581 0792  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
21:09:04.0597 0792  usbprint - ok
21:09:04.0628 0792  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
21:09:04.0643 0792  usbscan - ok
21:09:04.0675 0792  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:09:04.0706 0792  USBSTOR - ok
21:09:04.0706 0792  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
21:09:04.0721 0792  usbuhci - ok
21:09:04.0737 0792  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
21:09:04.0768 0792  UxSms - ok
21:09:04.0784 0792  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
21:09:04.0799 0792  VaultSvc - ok
21:09:04.0815 0792  [ B6437A7C60C817A0D7BEA1D994B01612 ] VBoxDrv        C:\Windows\system32\DRIVERS\VBoxDrv.sys
21:09:04.0846 0792  VBoxDrv - ok
21:09:04.0893 0792  [ 9E607F6240EADC4C0B3570F3E5E0358C ] VBoxNetAdp      C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
21:09:04.0924 0792  VBoxNetAdp - ok
21:09:04.0940 0792  [ 9F7BC6D33A3AA4AFF35C9DBD69C2BCA0 ] VBoxNetFlt      C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
21:09:04.0971 0792  VBoxNetFlt - ok
21:09:05.0002 0792  [ 84B57B85A550476456EC5AB32FA99513 ] VBoxUSBMon      C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
21:09:05.0018 0792  VBoxUSBMon - ok
21:09:05.0033 0792  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
21:09:05.0049 0792  vdrvroot - ok
21:09:05.0080 0792  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
21:09:05.0127 0792  vds - ok
21:09:05.0143 0792  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
21:09:05.0158 0792  vga - ok
21:09:05.0158 0792  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
21:09:05.0205 0792  VgaSave - ok
21:09:05.0205 0792  VGPU - ok
21:09:05.0236 0792  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
21:09:05.0252 0792  vhdmp - ok
21:09:05.0267 0792  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
21:09:05.0283 0792  viaide - ok
21:09:05.0314 0792  [ 86EA3E79AE350FEA5331A1303054005F ] vmbus          C:\Windows\system32\drivers\vmbus.sys
21:09:05.0314 0792  vmbus - ok
21:09:05.0330 0792  [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
21:09:05.0361 0792  VMBusHID - ok
21:09:05.0361 0792  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:09:05.0377 0792  volmgr - ok
21:09:05.0392 0792  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
21:09:05.0408 0792  volmgrx - ok
21:09:05.0423 0792  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
21:09:05.0439 0792  volsnap - ok
21:09:05.0455 0792  [ B4A73CA4EF9A02B9738CEA9AD5FE5917 ] vpcbus          C:\Windows\system32\DRIVERS\vpchbus.sys
21:09:05.0470 0792  vpcbus - ok
21:09:05.0486 0792  [ E675FB2B48C54F09895482E2253B289C ] vpcnfltr        C:\Windows\system32\DRIVERS\vpcnfltr.sys
21:09:05.0517 0792  vpcnfltr - ok
21:09:05.0517 0792  [ 5FB42082B0D19A0268705F1DD343DF20 ] vpcusb          C:\Windows\system32\DRIVERS\vpcusb.sys
21:09:05.0533 0792  vpcusb - ok
21:09:05.0548 0792  [ 63F4E10873BEB4124028C6D1A66B0968 ] vpcuxd          C:\Windows\system32\drivers\vpcuxd.sys
21:09:05.0595 0792  vpcuxd - ok
21:09:05.0611 0792  [ 207B6539799CC1C112661A9B620DD233 ] vpcvmm          C:\Windows\system32\drivers\vpcvmm.sys
21:09:05.0626 0792  vpcvmm - ok
21:09:05.0657 0792  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
21:09:05.0673 0792  vsmraid - ok
21:09:05.0720 0792  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
21:09:05.0782 0792  VSS - ok
21:09:05.0798 0792  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
21:09:05.0813 0792  vwifibus - ok
21:09:05.0845 0792  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
21:09:05.0891 0792  W32Time - ok
21:09:05.0891 0792  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
21:09:05.0907 0792  WacomPen - ok
21:09:05.0938 0792  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
21:09:05.0969 0792  WANARP - ok
21:09:05.0969 0792  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:09:06.0001 0792  Wanarpv6 - ok
21:09:06.0016 0792  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
21:09:06.0047 0792  wbengine - ok
21:09:06.0063 0792  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
21:09:06.0079 0792  WbioSrvc - ok
21:09:06.0094 0792  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
21:09:06.0125 0792  wcncsvc - ok
21:09:06.0141 0792  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:09:06.0188 0792  WcsPlugInService - ok
21:09:06.0188 0792  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
21:09:06.0203 0792  Wd - ok
21:09:06.0219 0792  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:09:06.0235 0792  Wdf01000 - ok
21:09:06.0250 0792  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:09:06.0297 0792  WdiServiceHost - ok
21:09:06.0297 0792  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
21:09:06.0313 0792  WdiSystemHost - ok
21:09:06.0344 0792  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
21:09:06.0375 0792  WebClient - ok
21:09:06.0391 0792  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:09:06.0422 0792  Wecsvc - ok
21:09:06.0422 0792  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
21:09:06.0453 0792  wercplsupport - ok
21:09:06.0484 0792  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
21:09:06.0515 0792  WerSvc - ok
21:09:06.0531 0792  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
21:09:06.0562 0792  WfpLwf - ok
21:09:06.0562 0792  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
21:09:06.0578 0792  WIMMount - ok
21:09:06.0593 0792  WinDefend - ok
21:09:06.0593 0792  WinHttpAutoProxySvc - ok
21:09:06.0640 0792  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
21:09:06.0671 0792  Winmgmt - ok
21:09:06.0718 0792  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
21:09:06.0765 0792  WinRM - ok
21:09:06.0827 0792  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
21:09:06.0859 0792  WinUsb - ok
21:09:06.0890 0792  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
21:09:06.0921 0792  Wlansvc - ok
21:09:06.0968 0792  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
21:09:06.0983 0792  WmiAcpi - ok
21:09:07.0015 0792  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:09:07.0030 0792  wmiApSrv - ok
21:09:07.0030 0792  WMPNetworkSvc - ok
21:09:07.0046 0792  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:09:07.0077 0792  WPCSvc - ok
21:09:07.0108 0792  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:09:07.0139 0792  WPDBusEnum - ok
21:09:07.0155 0792  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
21:09:07.0186 0792  ws2ifsl - ok
21:09:07.0202 0792  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
21:09:07.0233 0792  wscsvc - ok
21:09:07.0233 0792  WSearch - ok
21:09:07.0280 0792  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
21:09:07.0358 0792  wuauserv - ok
21:09:07.0389 0792  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
21:09:07.0436 0792  WudfPf - ok
21:09:07.0451 0792  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
21:09:07.0498 0792  WUDFRd - ok
21:09:07.0514 0792  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
21:09:07.0545 0792  wudfsvc - ok
21:09:07.0561 0792  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
21:09:07.0639 0792  WwanSvc - ok
21:09:07.0654 0792  ================ Scan global ===============================
21:09:07.0670 0792  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
21:09:07.0701 0792  [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
21:09:07.0701 0792  [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
21:09:07.0717 0792  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
21:09:07.0732 0792  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
21:09:07.0732 0792  [Global] - ok
21:09:07.0732 0792  ================ Scan MBR ==================================
21:09:07.0732 0792  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:09:08.0200 0792  \Device\Harddisk0\DR0 - ok
21:09:08.0216 0792  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
21:09:08.0419 0792  \Device\Harddisk1\DR1 - ok
21:09:08.0419 0792  ================ Scan VBR ==================================
21:09:08.0419 0792  [ 59DAAFF37C5D074B84C79D3D12C49817 ] \Device\Harddisk0\DR0\Partition1
21:09:08.0419 0792  \Device\Harddisk0\DR0\Partition1 - ok
21:09:08.0434 0792  [ 6698D5082C2BDD71D19B424767860BCB ] \Device\Harddisk1\DR1\Partition1
21:09:08.0434 0792  \Device\Harddisk1\DR1\Partition1 - ok
21:09:08.0450 0792  [ D07BEFBF418CF03CD4AB9684A0A93FFF ] \Device\Harddisk1\DR1\Partition2
21:09:08.0450 0792  \Device\Harddisk1\DR1\Partition2 - ok
21:09:08.0450 0792  ============================================================
21:09:08.0450 0792  Scan finished
21:09:08.0450 0792  ============================================================
21:09:08.0465 3888  Detected object count: 5
21:09:08.0465 3888  Actual detected object count: 5
21:09:34.0065 3888  IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
21:09:34.0065 3888  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:09:34.0065 3888  NTIOLib_1_0_6 ( UnsignedFile.Multi.Generic ) - skipped by user
21:09:34.0065 3888  NTIOLib_1_0_6 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:09:34.0065 3888  Polar Daemon ( UnsignedFile.Multi.Generic ) - skipped by user
21:09:34.0065 3888  Polar Daemon ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:09:34.0065 3888  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
21:09:34.0065 3888  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:09:34.0065 3888  USBAAPL64 ( UnsignedFile.Multi.Generic ) - skipped by user
21:09:34.0065 3888  USBAAPL64 ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 27.10.2012 20:29

Auch unauffällig

Downloade dir bitte ESET's ServiceRepair.exe auf deinem Desktop.
Doppelklick auf die Datei und bestätige die ersten Nachricht mit Yes.

Das Tool wird einen Neustart verlangen, dies bitte zulassen.

magnus65 27.10.2012 20:48

Hat leider keine Besserung gebracht, immer noch Zugriff verweigert.

cosinus 27.10.2012 22:38

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

magnus65 28.10.2012 09:46

So, da ich mir nicht sicher war, wie ich AVG korrekt abschalte, hab ich es deinstalliert und neu gestartet.
interessanterweise sagt combofix, das es trotzdem läuft.

Hier das log :

Code:

Microsoft Windows 7 Ultimate  6.1.7601.1.1252.49.1031.18.8183.6481 [GMT 1:00]
ausgeführt von:: c:\users\Uli\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\Common Files\EXCEL.ico
c:\program files (x86)\Common Files\HHelp.ico
c:\program files (x86)\Common Files\VISIO.ico
c:\program files (x86)\Common Files\WINWORD.ico
c:\users\Uli\AppData\Roaming\Raax
c:\users\Uli\AppData\Roaming\Raax\vokudy.exe
c:\users\Uli\ia_remove.sh3001.tmp
c:\users\Uli\ia_remove.sh5329.tmp
c:\users\Uli\ia_remove.sh9180.tmp
c:\windows\msvcr71.dll
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\kWab.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-28 bis 2012-10-28  ))))))))))))))))))))))))))))))
.
.
2012-10-28 08:41 . 2012-10-28 08:41        --------        d-----w-        c:\users\Kate\AppData\Local\temp
2012-10-28 08:41 . 2012-10-28 08:41        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-28 08:41 . 2012-10-28 08:41        --------        d-----w-        c:\users\admin\AppData\Local\temp
2012-10-28 08:41 . 2012-10-28 08:41        --------        d-----w-        c:\users\uliadm\AppData\Local\temp
2012-10-27 12:23 . 2012-10-27 12:23        --------        d-----w-        c:\users\Uli\AppData\Local\Mozilla Firefox
2012-10-26 09:05 . 2012-10-17 00:31        9291768        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{11140E1C-5133-4A88-9FF3-71A21F03D02E}\mpengine.dll
2012-10-24 11:09 . 2012-10-24 11:22        --------        d-----w-        c:\users\testadm
2012-10-17 17:33 . 2012-10-17 17:33        --------        d-----w-        c:\users\Kate\AppData\Roaming\ATI
2012-10-17 17:33 . 2012-10-17 17:33        --------        d-----w-        c:\users\Kate\AppData\Local\ATI
2012-10-17 14:31 . 2012-10-17 14:31        --------        d-----w-        c:\users\Uli\AppData\Roaming\ATI
2012-10-17 14:31 . 2012-10-17 14:31        --------        d-----w-        c:\users\Uli\AppData\Local\ATI
2012-10-17 14:28 . 2006-10-13 06:18        18216        ----a-w-        c:\windows\nvoclk64.sys
2012-10-17 14:28 . 2006-10-13 06:18        6912        ----a-w-        c:\windows\nvoclock.sys
2012-10-17 14:28 . 2006-10-13 06:16        421888        ----a-w-        c:\windows\nvsulib.dll
2012-10-17 14:28 . 2006-09-05 12:59        217088        ----a-w-        c:\windows\NVGfxOgl.dll
2012-10-17 14:28 . 2006-06-01 15:22        53248        ----a-w-        c:\windows\Nvgpio.dll
2012-10-17 14:27 . 2006-10-13 06:18        380928        ----a-w-        c:\windows\ntuneoem.dll
2012-10-17 14:27 . 2006-10-13 06:13        1622016        ----a-w-        c:\windows\NVBenchMarks.dll
2012-10-17 14:27 . 2006-10-13 06:12        28672        ----a-w-        c:\windows\AutoTuneScript.dll
2012-10-17 14:27 . 2006-08-21 07:20        45056        ----a-w-        c:\windows\NTuneGpu.dll
2012-10-17 14:27 . 2005-09-23 14:33        499712        ----a-w-        c:\windows\msvcp71.dll
2012-10-17 14:27 . 2005-09-23 14:33        1060864        ----a-w-        c:\windows\MFC71.dll
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\users\admin\AppData\Roaming\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\users\admin\AppData\Local\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\programdata\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\program files\Common Files\ATI Technologies
2012-10-17 14:11 . 2009-08-23 08:02        120336        ----a-w-        c:\windows\system32\drivers\AtiHdmi.sys
2012-10-17 14:02 . 2009-05-21 04:23        4178264        ----a-w-        c:\windows\SysWow64\D3DX9_41.dll
2012-10-17 14:02 . 2009-03-18 13:00        32768        ----a-w-        c:\windows\SysWow64\Auxiliary.dll
2012-10-17 14:00 . 2012-10-17 14:11        --------        d-----w-        c:\program files (x86)\Setup Files
2012-10-17 13:56 . 2012-10-17 13:56        --------        d-----w-        c:\users\Uli\AppData\Roaming\Tracker Software
2012-10-16 20:17 . 2012-10-16 20:18        --------        d-----w-        c:\users\Uli\AppData\Roaming\Research In Motion
2012-10-16 20:17 . 2012-10-16 20:17        --------        d-----w-        c:\users\Uli\AppData\Local\Research In Motion
2012-10-16 20:15 . 2011-07-20 11:58        44032        ----a-w-        c:\windows\system32\drivers\RimSerial_AMD64.sys
2012-10-16 20:15 . 2012-10-25 10:43        --------        d-----w-        c:\program files (x86)\Common Files\XCPCSync.OEM
2012-10-15 11:48 . 2012-10-15 11:48        --------        d-----w-        c:\programdata\Gigaset QuickSync
2012-10-15 11:47 . 2012-10-15 11:47        --------        d-----w-        c:\users\Uli\AppData\Local\Gigaset_Communications_Gm
2012-10-15 11:45 . 2012-10-15 11:45        --------        d-----w-        c:\program files (x86)\Gigaset QuickSync
2012-10-15 11:37 . 2012-10-15 11:37        --------        d-----w-        c:\users\Uli\AppData\Local\Shaw Computer
2012-10-15 11:37 . 2009-06-23 03:59        313856        ----a-w-        c:\windows\SysWow64\SPort.dll
2012-10-15 11:37 . 2003-06-22 18:31        65536        ----a-w-        c:\windows\SysWow64\vbalProgBar6.ocx
2012-10-15 11:37 . 2001-05-24 09:20        544256        ----a-w-        c:\windows\SysWow64\janGraphics.dll
2012-10-15 11:37 . 1998-07-05 23:00        158208        ----a-w-        c:\windows\SysWow64\MSCMCDE.DLL
2012-10-15 11:37 . 2012-10-15 11:37        --------        d-----w-        c:\program files (x86)\gTool
2012-10-15 11:37 . 2008-10-10 12:36        656200        ----a-w-        c:\windows\SysWow64\MSCOMCT2.OCX
2012-10-15 11:37 . 2000-07-19 13:26        151552        ----a-w-        c:\windows\SysWow64\ccrpFD6.ocx
2012-10-15 11:37 . 1998-07-06 00:00        33792        ----a-w-        c:\windows\SysWow64\CMDLGDE.DLL
2012-10-15 11:37 . 1998-07-05 23:00        64512        ----a-w-        c:\windows\SysWow64\MSCC2DE.DLL
2012-10-15 11:37 . 1998-07-05 23:00        14336        ----a-w-        c:\windows\SysWow64\MSComDE.dll
2012-10-10 18:45 . 2012-08-11 00:56        715776        ----a-w-        c:\windows\system32\kerberos.dll
2012-10-10 18:45 . 2012-08-10 23:56        542208        ----a-w-        c:\windows\SysWow64\kerberos.dll
2012-10-10 18:45 . 2012-06-02 05:41        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-10 18:45 . 2012-06-02 05:41        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-10 18:45 . 2012-06-02 05:41        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-10 18:45 . 2012-06-02 04:36        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-10-10 18:45 . 2012-06-02 04:36        1159680        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-10-10 18:45 . 2012-06-02 04:36        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2012-10-10 09:56 . 2012-10-10 09:56        --------        d-----w-        c:\program files\CPUID
2012-10-08 13:22 . 2012-08-21 11:01        33240        ----a-w-        c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\program files\iTunes
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\program files (x86)\iTunes
2012-10-08 13:21 . 2012-10-08 13:21        --------        d-----w-        c:\program files\iPod
2012-10-08 11:39 . 2012-10-08 11:39        794112        ----a-w-        c:\windows\system32\Gqstsp.tsp
2012-10-08 11:26 . 2012-10-08 11:26        495616        ----a-w-        c:\windows\SysWow64\Gqstsp.tsp
2012-10-08 11:09 . 2012-10-08 11:09        54272        ----a-w-        c:\windows\system32\drivers\GigasetGenericUSB_x64.sys
2012-09-30 22:37 . 2012-09-30 22:37        --------        d-----w-        c:\users\Kate\AppData\Roaming\AVG10
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 21:57 . 2010-03-20 19:08        65309168        ----a-w-        c:\windows\system32\MRT.exe
2012-10-09 09:29 . 2012-04-26 10:18        696760        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 09:29 . 2011-06-10 06:23        73656        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-29 17:54 . 2011-08-04 20:39        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-16 18:01 . 2012-06-08 11:11        61440        ----a-r-        c:\users\admin\AppData\Roaming\Microsoft\Installer\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}\ARPPRODUCTICON.exe
2012-08-24 11:15 . 2012-09-22 09:52        17810944        ----a-w-        c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 09:52        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 09:52        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 09:52        1346048        ----a-w-        c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 09:52        1392128        ----a-w-        c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 09:52        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 09:52        237056        ----a-w-        c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 09:52        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 09:52        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 09:52        816640        ----a-w-        c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 09:52        599040        ----a-w-        c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 09:52        2144768        ----a-w-        c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 09:52        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 09:52        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 09:52        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 09:52        248320        ----a-w-        c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 09:52        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 09:52        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 09:52        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 09:52        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 09:52        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 09:52        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 09:38        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 09:38        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 09:38        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 09:38        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-26 15:06        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-08-21 11:01 . 2010-03-21 10:21        125872        ----a-w-        c:\windows\system32\GEARAspi64.dll
2012-08-21 11:01 . 2010-03-21 10:21        106928        ----a-w-        c:\windows\SysWow64\GEARAspi.dll
2012-08-20 17:38 . 2012-10-10 18:46        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2012-08-02 17:58 . 2012-09-12 09:38        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-08-02 16:57 . 2012-09-12 09:38        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-04-19 611712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2011-10-30 571392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-14 98304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start hxxp://www.avg.de/de.special-uninstallation-feedback-appf?lic=NFU3SEctWUxVVlUtRVMyRUctUUY3WEMtVkxDOVctUTRMWkc&inst=NzctNjIyNjE5MDcwLUJBUjlHKzEtRkwrOS1YTzM2KzEtRjlNN0MrNS1GOU0zKzEtRkwxMCsxLUNJUCsyLUREVCsxNzUxNS1MU0QrMi1ERDEwRisxLVNUMTBGQVBQKzE&prod=90&ver=10.0.1411" [?]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Spyder3Utility.lnk - c:\program files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe [2009-9-1 6407854]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-08-17 7390560]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Polar Daemon;Polar Daemon;c:\program files (x86)\Polar\Daemon\polard.exe [2012-08-17 413184]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-03-21 1038088]
R3 GigasetGenericUSB_x64;GigasetGenericUSB_x64;c:\windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [2012-10-08 54272]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
R3 NTIOLib_1_0_0;NTIOLib_1_0_0;c:\program files (x86)\MSI\DirectOC\NTIOLib_X64.sys [2009-06-12 14136]
R3 NTIOLib_1_0_1;NTIOLib_1_0_1;c:\program files (x86)\MSI\ControlCenter\NTIOLib_X64.sys [2009-10-05 14136]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x]
R3 NTIOLib_1_0_6;NTIOLib_1_0_6;c:\program files (x86)\Setup Files\Ms7583v1B0\NTIOLib_X64.sys [2011-01-06 11888]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 Spyder3;Datacolor Spyder3;c:\windows\system32\DRIVERS\Spyder3.sys [2008-09-08 15360]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vpcuxd;USB-Virtualisierungsstubdienst;c:\windows\system32\drivers\vpcuxd.sys [2010-11-20 16384]
R4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2010-04-19 288112]
R4 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R4 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 26704]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2011-03-16 37456]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-21 52856]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2011-01-07 304720]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-03-01 41552]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2011-04-04 377936]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-11-04 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-11-04 130864]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 202752]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-05-27 118864]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-02-10 29264]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\DRIVERS\SkyNET_AMD64.SYS [2010-03-20 615440]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-11-04 146736]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-11-04 165680]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-26 09:29]
.
2012-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001Core.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-10 17:13]
.
2012-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001UA.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-10 17:13]
.
.
--------- X64 Entries -----------
.
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: {F8FC1530-0608-11DF-2008-0800200C9A66} - hxxps://portal.computacenter.de/CACHE/sdesktop/install/binaries/instweb.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AutoStartNPSAgent - c:\program files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKLM-Run-NWEReboot - (no file)
Wow6432Node-HKLM-Run-NPSStartup - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-10-28  09:44:15
ComboFix-quarantined-files.txt  2012-10-28 08:44
.
Vor Suchlauf: 21 Verzeichnis(se), 670.199.934.976 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 670.984.093.696 Bytes frei
.
- - End Of File - - F59F44E1303E30C51EADC99CFEA4235C


cosinus 28.10.2012 12:15

Zitat:

AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
Wieso hast du zwei AVPs am laufen, das ist kontraproduktiv! :wtf:
Bitte einen der beiden umgehend deinstallieren!

magnus65 28.10.2012 14:05

Liste der Anhänge anzeigen (Anzahl: 1)
AVG hatte ich schnmal entfernt, aber offensichtlich nicht vollständig.
Mit AVG remove ists zumindest nicht mehr in der Liste der installierten Programme.

Avira habe ich auch komplett deinstalliert.

Bin etwas ratlos warum beide angeblich noch laufen, in der Prozessliste kann ich sie auch nicht finden.

cosinus 28.10.2012 15:04

Probier mal den AVG Remover => AVG Tools-Download

magnus65 28.10.2012 17:42

Liste der Anhänge anzeigen (Anzahl: 1)
Schon versucht.
Regedit und Suche nach AVG oder AVIRA bringt kaum Ergebnisse, bei Autoruns steht auch nichts.

Hab jetzt unter Programme die AVG Ordner gelöscht und in der Registry die gefundenen Einträge rausgelöscht, bei Avira deinstalliert und ich finde auch kaum noch was.

Aber Avira ist angeblich trotzdem aktiv.

cosinus 28.10.2012 17:47

Zitat:

Schon versucht.
Und weiter?! Ergebnis?

magnus65 28.10.2012 18:03

Anbei das Log mit den diversen Versuchen.

magnus65 29.10.2012 08:11

Liste der Anhänge anzeigen (Anzahl: 1)
So, Update, habe inzwischen Avast installiert , da trotz der Meldungen von Combofix kein Virenscanner aktiv ist.Anbei das Ergebnis des Scans.

cosinus 29.10.2012 08:17

Zitat:

Zitat von magnus65 (Beitrag 947371)
So, Update, habe inzwischen Avast installiert , da trotz der Meldungen von Combofix kein Virenscanner aktiv ist.Anbei das Ergebnis des Scans.

Bitte was?! :wtf:
Sind jetzt drei Virenscanner am werkeln?

magnus65 29.10.2012 09:29

Zitat:

Zitat von cosinus (Beitrag 947375)
Bitte was?! :wtf:
Sind jetzt drei Virenscanner am werkeln?

Nein, ich hatte doch oben geschrieben, das ich Avira und AVG deinstalliert habe.
Warum Combofix der Meinung ist, das Avira noch aktiv ist - keine Ahnung.
Das einzige , was ich noch finden kann, ist das TrayIcon von Avira

Durchsuchen der Registry nach Avira oder AVG bring keinen Treffer.

Habe jetzt Avast installiert um nicht ganz ohne Scanner dazustehen.

OTL weiss auch nur von Avast :

Code:

OTL logfile created on: 29.10.2012 08:47:07 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Uli\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,99 Gb Total Physical Memory | 6,43 Gb Available Physical Memory | 80,40% Memory free
15,98 Gb Paging File | 14,39 Gb Available in Paging File | 90,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 624,35 Gb Free Space | 67,03% Space Free | Partition Type: NTFS
Drive D: | 1863,01 Gb Total Space | 1032,68 Gb Free Space | 55,43% Space Free | Partition Type: NTFS
Drive K: | 14,90 Gb Total Space | 14,63 Gb Free Space | 98,22% Space Free | Partition Type: FAT32
 
Computer Name: GOLLUM | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.27 13:23:29 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Users\Uli\AppData\Local\Mozilla Firefox\firefox.exe
PRC - [2012.10.25 08:15:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Uli\Desktop\OTL.exe
PRC - [2012.10.23 12:17:40 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.23 12:17:40 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2009.09.01 21:46:56 | 006,407,854 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.27 13:23:28 | 002,295,264 | ---- | M] () -- C:\Users\Uli\AppData\Local\Mozilla Firefox\mozjs.dll
MOD - [2009.09.01 21:46:56 | 006,407,854 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe
MOD - [2009.09.01 21:40:36 | 001,167,312 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\XML.dll
MOD - [2009.09.01 21:40:36 | 000,892,928 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\RBScript.dll
MOD - [2009.09.01 21:40:36 | 000,335,872 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\CGamma.dll
MOD - [2009.09.01 21:40:36 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\RegEx.dll
MOD - [2009.09.01 21:40:36 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\Appearance Pak.dll
MOD - [2009.09.01 21:40:36 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\CSensor.dll
MOD - [2009.09.01 21:40:36 | 000,098,304 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\Shell.dll
MOD - [2009.09.01 21:40:36 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\MBSRegistrationPlugin15968.dll
MOD - [2009.09.01 21:40:36 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility Libs\MBSPluginVersionPlugin15968.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2010.03.03 05:12:12 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.10.24 18:50:38 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.23 12:17:40 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.10.09 10:29:18 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2010.06.24 15:41:38 | 000,092,008 | ---- | M] (TomTom) [Disabled | Stopped] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010.04.19 12:01:44 | 000,288,112 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2010.03.21 02:20:07 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV - [2010.03.21 02:19:11 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.09.16 12:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.10.23 12:18:31 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.10.23 12:18:31 | 000,364,096 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.10.23 12:18:31 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.10.23 12:18:30 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.10.23 12:18:30 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.10.15 18:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.10.08 12:09:34 | 000,054,272 | ---- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys -- (GigasetGenericUSB_x64)
DRV:64bit: - [2012.08.21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.04 12:37:00 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:34:02 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010.11.20 14:34:02 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:35:32 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010.11.20 12:35:24 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcuxd.sys -- (vpcuxd)
DRV:64bit: - [2010.11.20 12:35:20 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 12:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010.06.23 09:10:56 | 000,344,680 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.04.19 11:55:30 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2010.03.21 01:48:19 | 000,052,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.03.21 00:22:21 | 000,615,440 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SkyNET_AMD64.sys -- (SKYNET)
DRV:64bit: - [2010.03.03 05:23:10 | 006,402,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.03.03 05:23:10 | 006,402,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.03.03 04:07:32 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2009.12.14 08:21:44 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2009.08.23 09:02:30 | 000,120,336 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.09.08 17:26:20 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Spyder3.sys -- (Spyder3)
DRV - [2010.04.19 11:55:30 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2009.12.14 08:21:44 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 49 B5 CD 07 60 C8 CA 01  [binary data]
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 59 C7 E3 26 B5 CD 01  [binary data]
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.10.28 23:16:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.10.28 17:24:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.06.23 08:16:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.06.23 08:16:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2010.06.16 22:08:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Extensions
[2010.06.16 22:08:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\w315ohqn.default\extensions
[2012.10.28 17:24:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.10.24 18:50:58 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.04.26 11:20:44 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.10.24 18:50:17 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.24 18:50:17 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
 
O1 HOSTS File: ([2012.10.28 09:41:27 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001..\Run: [AdobeBridge]  File not found
O4 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [aswAhAScr.dll] C:\Program Files\AVAST Software\Avast\aswRegSvr.exe (AVAST Software)
O4 - HKLM..\RunOnce: [aswasOutExt.dll] C:\Program Files\AVAST Software\Avast\aswRegSvr.exe (AVAST Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: An Mindjet MindManager senden - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..Trusted Domains: computacenter.de ([ccportal] https in Trusted sites)
O15 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..Trusted Domains: computacenter.de ([ccwebapps1] https in Trusted sites)
O15 - HKU\S-1-5-21-1394765569-1510172786-3570238692-1001\..Trusted Domains: mycomputacenter.de ([www] https in Trusted sites)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://computacenter-meeting.webex.com/client/T27LC/webex/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {F8FC1530-0608-11DF-2008-0800200C9A66} https://portal.computacenter.de/CACHE/sdesktop/install/binaries/instweb.cab (CSD ActiveX Installer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1D7A73-1D65-4711-8628-94DE26AF4F1A}: DhcpNameServer = 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F054716-A4DB-4871-91AD-482C9EC79FF2}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.28 22:52:07 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.10.28 22:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.10.28 22:52:06 | 000,364,096 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.10.28 22:52:00 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.10.28 22:52:00 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.10.28 22:51:56 | 000,984,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.10.28 22:51:51 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.10.28 22:51:51 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.10.28 22:51:36 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.10.28 22:51:36 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.10.28 22:51:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.10.28 22:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.10.28 18:14:32 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\Macromedia
[2012.10.28 17:59:00 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.10.28 17:45:40 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\IrfanView
[2012.10.28 17:45:16 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012.10.28 17:37:46 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.10.28 17:26:10 | 004,989,309 | R--- | C] (Swearware) -- C:\Users\admin\Desktop\ComboFix.exe
[2012.10.28 17:24:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.10.28 16:56:39 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\temp
[2012.10.28 14:33:49 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\IObit
[2012.10.28 09:13:35 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.10.28 09:13:35 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.10.28 09:13:35 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.10.28 09:11:30 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.28 09:11:20 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.10.27 20:38:39 | 000,000,000 | ---D | C] -- C:\Users\Public\Desktop\CC Support
[2012.10.17 17:34:19 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012.10.17 15:14:46 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\ATI
[2012.10.17 15:14:46 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\ATI
[2012.10.17 15:14:46 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.10.17 15:14:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012.10.17 15:14:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012.10.17 15:00:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Setup Files
[2012.10.16 21:15:51 | 000,044,032 | ---- | C] (Research in Motion Ltd) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys
[2012.10.16 21:15:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\XCPCSync.OEM
[2012.10.15 12:48:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Gigaset QuickSync
[2012.10.15 12:45:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigaset QuickSync
[2012.10.15 12:45:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gigaset QuickSync
[2012.10.15 12:37:41 | 000,313,856 | ---- | C] (ELTIMA Software) -- C:\Windows\SysWow64\SPort.dll
[2012.10.15 12:37:41 | 000,065,536 | ---- | C] (vbAccelerator) -- C:\Windows\SysWow64\vbalProgBar6.ocx
[2012.10.15 12:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gTool
[2012.10.15 12:37:40 | 000,151,552 | ---- | C] (Domenico Statuto - CCRP) -- C:\Windows\SysWow64\ccrpFD6.ocx
[2012.10.15 12:37:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gTool
[2012.10.10 10:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2012.10.10 10:56:37 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2012.10.08 14:22:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.10.08 14:21:43 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.10.08 14:21:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012.10.08 14:21:43 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.10.08 14:21:43 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012.10.08 12:39:08 | 000,794,112 | ---- | C] (Gigaset Communications GmbH) -- C:\Windows\SysNative\Gqstsp.tsp
[2012.10.08 12:26:52 | 000,495,616 | ---- | C] (Gigaset Communications GmbH) -- C:\Windows\SysWow64\Gqstsp.tsp
[2012.10.08 12:09:34 | 000,054,272 | ---- | C] (Siemens Home and Office Communication Devices GmbH & Co. KG) -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.29 08:34:54 | 000,014,928 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 08:34:54 | 000,014,928 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.29 08:31:55 | 001,621,940 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.29 08:31:55 | 000,702,236 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.29 08:31:55 | 000,655,612 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.29 08:31:55 | 000,149,792 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.29 08:31:55 | 000,122,484 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.29 08:29:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.29 08:27:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.29 08:27:25 | 2140,495,871 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.29 08:22:13 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLet.DAT
[2012.10.29 08:20:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001UA.job
[2012.10.28 23:16:30 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.10.28 22:52:07 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.10.28 20:20:00 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001Core.job
[2012.10.28 17:26:38 | 004,989,309 | R--- | M] (Swearware) -- C:\Users\admin\Desktop\ComboFix.exe
[2012.10.28 17:24:02 | 000,001,151 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.10.28 15:58:49 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLev.DAT
[2012.10.28 09:41:27 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.10.25 20:14:58 | 000,000,512 | ---- | M] () -- C:\Users\admin\Desktop\MBR.dat
[2012.10.25 08:13:58 | 000,000,000 | ---- | M] () -- C:\Users\admin\defogger_reenable
[2012.10.24 19:47:28 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.23 12:18:31 | 000,984,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.10.23 12:18:31 | 000,364,096 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.10.23 12:18:31 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.10.23 12:18:30 | 000,071,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.10.23 12:18:30 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.10.23 12:17:48 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.10.23 12:17:38 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.10.23 12:17:13 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.10.22 22:04:34 | 000,007,604 | ---- | M] () -- C:\Users\admin\AppData\Local\Resmon.ResmonCfg
[2012.10.17 20:03:23 | 515,215,215 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.10.17 15:01:35 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\DirectOC.lnk
[2012.10.16 21:16:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
[2012.10.16 21:15:57 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
[2012.10.15 18:59:28 | 000,054,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.10.15 12:45:34 | 000,001,992 | ---- | M] () -- C:\Users\Public\Desktop\Gigaset QuickSync.exe.lnk
[2012.10.10 10:56:37 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2012.10.09 13:47:46 | 000,002,055 | ---- | M] () -- C:\Users\Public\Desktop\Lightroom 4.2 64-Bit.lnk
[2012.10.08 14:22:40 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.10.08 12:39:08 | 000,794,112 | ---- | M] (Gigaset Communications GmbH) -- C:\Windows\SysNative\Gqstsp.tsp
[2012.10.08 12:26:52 | 000,495,616 | ---- | M] (Gigaset Communications GmbH) -- C:\Windows\SysWow64\Gqstsp.tsp
[2012.10.08 12:09:34 | 000,054,272 | ---- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys
[2012.09.29 18:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.10.28 22:52:07 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.10.28 22:51:51 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012.10.28 17:24:02 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.10.28 17:24:02 | 000,001,151 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.10.28 09:13:35 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.10.28 09:13:35 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.10.28 09:13:35 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.10.28 09:13:35 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.10.28 09:13:35 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.10.25 20:13:38 | 000,000,512 | ---- | C] () -- C:\Users\admin\Desktop\MBR.dat
[2012.10.25 08:13:58 | 000,000,000 | ---- | C] () -- C:\Users\admin\defogger_reenable
[2012.10.17 17:34:10 | 515,215,215 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.10.17 15:02:10 | 000,032,768 | ---- | C] () -- C:\Windows\SysWow64\Auxiliary.dll
[2012.10.17 15:01:35 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\DirectOC.lnk
[2012.10.16 21:16:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
[2012.10.16 21:15:57 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
[2012.10.15 12:45:34 | 000,001,992 | ---- | C] () -- C:\Users\Public\Desktop\Gigaset QuickSync.exe.lnk
[2012.10.15 12:37:41 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2012.10.10 10:56:37 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2012.10.09 13:47:46 | 000,002,075 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4.2 64-bit.lnk
[2012.10.09 13:47:46 | 000,002,055 | ---- | C] () -- C:\Users\Public\Desktop\Lightroom 4.2 64-Bit.lnk
[2012.10.08 14:22:40 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.10.07 20:32:02 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.16 18:59:52 | 000,000,268 | RH-- | C] () -- C:\Users\admin\AppData\Roaming\Digital Light
[2012.09.16 18:59:52 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Folder Actions Handlers
[2012.09.16 18:59:51 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLeo.DAT
[2012.07.22 21:04:01 | 000,007,604 | ---- | C] () -- C:\Users\admin\AppData\Local\Resmon.ResmonCfg
[2012.06.09 20:46:58 | 000,000,000 | ---- | C] () -- C:\ProgramData\Cocoa
[2012.06.08 12:10:09 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Distortion
[2012.06.08 12:10:09 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Definition Bundle
[2012.06.08 12:10:09 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Dance Kit
[2012.06.08 12:10:09 | 000,000,268 | RH-- | C] () -- C:\Users\admin\AppData\Roaming\CustomDataViews
[2012.06.08 12:10:09 | 000,000,268 | RH-- | C] () -- C:\Users\admin\AppData\Roaming\Contextual Menu Items
[2012.06.08 12:10:09 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Drums
[2012.06.08 12:03:50 | 000,000,000 | ---- | C] () -- C:\ProgramData\Core Data Application
[2012.06.08 12:03:38 | 000,000,000 | ---- | C] () -- C:\ProgramData\Database
[2012.06.08 12:03:25 | 000,000,000 | ---- | C] () -- C:\ProgramData\Contents
[2011.01.28 12:25:00 | 000,000,154 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.01.07 11:51:24 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.08.17 09:02:59 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLev.DAT
[2010.08.17 09:02:59 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLet.DAT
[2010.08.17 09:02:59 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLes.DAT
[2010.06.16 22:11:58 | 000,002,528 | ---- | C] () -- C:\Users\admin\AppData\Roaming\$_hpcst$.hpc
[2010.06.15 20:47:53 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2010.06.14 17:54:46 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Icons
[2010.06.14 17:54:46 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLck.DAT
[2010.06.14 17:54:46 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Rock Kit
[2010.06.14 17:54:44 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Image Capture
[2010.06.14 17:54:44 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Sample Delay
[2010.06.14 17:37:13 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLbx.DAT
[2010.03.29 12:01:19 | 000,000,000 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2010.03.22 09:36:12 | 000,000,000 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.10.28 14:33:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\IObit
[2012.10.28 17:45:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\IrfanView
[2012.04.10 16:41:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Notepad++
[2010.06.16 22:13:31 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\PC Suite
[2010.06.16 22:11:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Samsung
[2012.09.30 23:37:51 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\AVG10
[2010.10.28 20:01:48 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\Canon
[2010.05.11 21:20:32 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\HdO Adventure
[2010.06.15 12:10:21 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\IrfanView
[2012.03.18 11:51:08 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\Klok2.DD7F2188B985C2439837C76B42A187050457E61B.1
[2012.09.17 21:30:13 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\Manifesto Games
[2011.12.31 10:40:55 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\Memeo
[2010.06.16 22:16:20 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\PC Suite
[2010.06.16 22:16:26 | 000,000,000 | ---D | M] -- C:\Users\Kate\AppData\Roaming\Samsung
[2010.10.04 14:00:12 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Canneverbe Limited
[2011.01.11 10:25:29 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Canon
[2011.10.17 10:21:58 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.03.02 19:46:06 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\com.mcgraphix.KlokworkTeamConsole
[2011.02.01 20:54:22 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\DBDesigner4
[2010.04.04 13:29:21 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\DeepBurner
[2011.08.11 12:17:08 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\EAC
[2012.09.25 21:50:20 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\FileZilla
[2012.06.14 22:53:50 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\foobar2000
[2012.10.24 12:21:05 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\IrfanView
[2010.11.19 10:48:55 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\jpg-Illuminator
[2011.02.04 21:21:31 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Klok2.DD7F2188B985C2439837C76B42A187050457E61B.1
[2012.09.13 20:03:18 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Manifesto Games
[2011.12.03 21:04:49 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Nik Software
[2010.08.18 09:20:56 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Nikon
[2012.04.10 17:21:42 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Notepad++
[2012.03.02 15:55:57 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Opwibah
[2010.06.16 22:24:57 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\PC Suite
[2011.05.28 08:05:32 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\PhotoLine
[2012.10.16 21:18:01 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Research In Motion
[2010.06.16 18:48:23 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Samsung
[2010.03.20 22:36:59 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Thunderbird
[2010.06.29 12:54:04 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\TomTom
[2012.10.17 14:56:06 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\Tracker Software
[2010.11.03 16:10:33 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\TrueCrypt
[2012.08.30 09:16:56 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\webex
[2011.08.13 14:51:14 | 000,000,000 | ---D | M] -- C:\Users\Uli\AppData\Roaming\WindSolutions
[2012.08.16 12:34:49 | 000,000,000 | ---D | M] -- C:\Users\uliadm\AppData\Roaming\IrfanView
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0908F1AC

< End of report >


cosinus 29.10.2012 13:20

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Seccenter::
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

magnus65 29.10.2012 13:46

Anbei das Ergebnis, Combofix hat allerdings nicht nach einem neustart verlangt.

Code:

ComboFix 12-10-29.01 - admin 29.10.2012  13:35:03.6.4 - x64
Microsoft Windows 7 Ultimate  6.1.7601.1.1252.49.1031.18.8183.5923 [GMT 1:00]
ausgeführt von:: c:\users\Uli\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Uli\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-28 bis 2012-10-29  ))))))))))))))))))))))))))))))
.
.
2012-10-29 12:42 . 2012-10-29 12:42        --------        d-----w-        c:\users\uliadm\AppData\Local\temp
2012-10-29 12:42 . 2012-10-29 12:42        --------        d-----w-        c:\users\Kate\AppData\Local\temp
2012-10-29 12:42 . 2012-10-29 12:42        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-29 12:42 . 2012-10-29 12:42        --------        d-----w-        c:\users\admin\AppData\Local\temp
2012-10-28 21:52 . 2012-10-23 11:18        25232        ----a-w-        c:\windows\system32\drivers\aswFsBlk.sys
2012-10-28 21:52 . 2012-10-23 11:18        364096        ----a-w-        c:\windows\system32\drivers\aswSP.sys
2012-10-28 21:52 . 2012-10-23 11:18        59728        ----a-w-        c:\windows\system32\drivers\aswTdi.sys
2012-10-28 21:52 . 2012-10-15 17:59        54072        ----a-w-        c:\windows\system32\drivers\aswRdr2.sys
2012-10-28 21:51 . 2012-10-23 11:18        984144        ----a-w-        c:\windows\system32\drivers\aswSnx.sys
2012-10-28 21:51 . 2012-10-23 11:18        71600        ----a-w-        c:\windows\system32\drivers\aswMonFlt.sys
2012-10-28 21:51 . 2012-10-23 11:17        285328        ----a-w-        c:\windows\system32\aswBoot.exe
2012-10-28 21:51 . 2012-10-23 11:17        41224        ----a-w-        c:\windows\avastSS.scr
2012-10-28 21:51 . 2012-10-23 11:17        227648        ----a-w-        c:\windows\SysWow64\aswBoot.exe
2012-10-28 21:51 . 2012-10-28 21:51        --------        d-----w-        c:\programdata\AVAST Software
2012-10-28 21:51 . 2012-10-28 21:51        --------        d-----w-        c:\program files\AVAST Software
2012-10-28 17:14 . 2012-10-28 17:14        --------        d-----w-        c:\users\admin\AppData\Local\Macromedia
2012-10-28 16:45 . 2012-10-28 16:45        --------        d-----w-        c:\users\admin\AppData\Roaming\IrfanView
2012-10-28 16:37 . 2012-10-29 12:42        --------        d-----w-        c:\users\Uli\AppData\Local\temp
2012-10-28 13:33 . 2012-10-28 13:33        --------        d-----w-        c:\users\admin\AppData\Roaming\IObit
2012-10-27 12:23 . 2012-10-27 12:23        --------        d-----w-        c:\users\Uli\AppData\Local\Mozilla Firefox
2012-10-26 09:05 . 2012-10-17 00:31        9291768        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{11140E1C-5133-4A88-9FF3-71A21F03D02E}\mpengine.dll
2012-10-24 11:09 . 2012-10-24 11:22        --------        d-----w-        c:\users\testadm
2012-10-17 17:33 . 2012-10-17 17:33        --------        d-----w-        c:\users\Kate\AppData\Roaming\ATI
2012-10-17 17:33 . 2012-10-17 17:33        --------        d-----w-        c:\users\Kate\AppData\Local\ATI
2012-10-17 14:31 . 2012-10-17 14:31        --------        d-----w-        c:\users\Uli\AppData\Roaming\ATI
2012-10-17 14:31 . 2012-10-17 14:31        --------        d-----w-        c:\users\Uli\AppData\Local\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\users\admin\AppData\Roaming\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\users\admin\AppData\Local\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\programdata\ATI
2012-10-17 14:14 . 2012-10-17 14:14        --------        d-----w-        c:\program files\Common Files\ATI Technologies
2012-10-17 14:11 . 2009-08-23 08:02        120336        ----a-w-        c:\windows\system32\drivers\AtiHdmi.sys
2012-10-17 14:02 . 2009-05-21 04:23        4178264        ----a-w-        c:\windows\SysWow64\D3DX9_41.dll
2012-10-17 14:02 . 2009-03-18 13:00        32768        ----a-w-        c:\windows\SysWow64\Auxiliary.dll
2012-10-17 14:00 . 2012-10-17 14:11        --------        d-----w-        c:\program files (x86)\Setup Files
2012-10-17 13:56 . 2012-10-17 13:56        --------        d-----w-        c:\users\Uli\AppData\Roaming\Tracker Software
2012-10-16 20:17 . 2012-10-16 20:18        --------        d-----w-        c:\users\Uli\AppData\Roaming\Research In Motion
2012-10-16 20:17 . 2012-10-16 20:17        --------        d-----w-        c:\users\Uli\AppData\Local\Research In Motion
2012-10-16 20:15 . 2011-07-20 11:58        44032        ----a-w-        c:\windows\system32\drivers\RimSerial_AMD64.sys
2012-10-16 20:15 . 2012-10-25 10:43        --------        d-----w-        c:\program files (x86)\Common Files\XCPCSync.OEM
2012-10-15 11:48 . 2012-10-15 11:48        --------        d-----w-        c:\programdata\Gigaset QuickSync
2012-10-15 11:47 . 2012-10-15 11:47        --------        d-----w-        c:\users\Uli\AppData\Local\Gigaset_Communications_Gm
2012-10-15 11:45 . 2012-10-15 11:45        --------        d-----w-        c:\program files (x86)\Gigaset QuickSync
2012-10-15 11:37 . 2012-10-15 11:37        --------        d-----w-        c:\users\Uli\AppData\Local\Shaw Computer
2012-10-15 11:37 . 2009-06-23 03:59        313856        ----a-w-        c:\windows\SysWow64\SPort.dll
2012-10-15 11:37 . 2003-06-22 18:31        65536        ----a-w-        c:\windows\SysWow64\vbalProgBar6.ocx
2012-10-15 11:37 . 2001-05-24 09:20        544256        ----a-w-        c:\windows\SysWow64\janGraphics.dll
2012-10-15 11:37 . 1998-07-05 23:00        158208        ----a-w-        c:\windows\SysWow64\MSCMCDE.DLL
2012-10-15 11:37 . 2012-10-15 11:37        --------        d-----w-        c:\program files (x86)\gTool
2012-10-15 11:37 . 2008-10-10 12:36        656200        ----a-w-        c:\windows\SysWow64\MSCOMCT2.OCX
2012-10-15 11:37 . 2000-07-19 13:26        151552        ----a-w-        c:\windows\SysWow64\ccrpFD6.ocx
2012-10-15 11:37 . 1998-07-06 00:00        33792        ----a-w-        c:\windows\SysWow64\CMDLGDE.DLL
2012-10-15 11:37 . 1998-07-05 23:00        64512        ----a-w-        c:\windows\SysWow64\MSCC2DE.DLL
2012-10-15 11:37 . 1998-07-05 23:00        14336        ----a-w-        c:\windows\SysWow64\MSComDE.dll
2012-10-10 18:45 . 2012-08-11 00:56        715776        ----a-w-        c:\windows\system32\kerberos.dll
2012-10-10 18:45 . 2012-08-10 23:56        542208        ----a-w-        c:\windows\SysWow64\kerberos.dll
2012-10-10 18:45 . 2012-06-02 05:41        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-10 18:45 . 2012-06-02 05:41        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-10 18:45 . 2012-06-02 05:41        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-10 18:45 . 2012-06-02 04:36        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-10-10 18:45 . 2012-06-02 04:36        1159680        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-10-10 18:45 . 2012-06-02 04:36        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2012-10-10 09:56 . 2012-10-10 09:56        --------        d-----w-        c:\program files\CPUID
2012-10-08 13:22 . 2012-08-21 11:01        33240        ----a-w-        c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\program files\iTunes
2012-10-08 13:21 . 2012-10-08 13:22        --------        d-----w-        c:\program files (x86)\iTunes
2012-10-08 13:21 . 2012-10-08 13:21        --------        d-----w-        c:\program files\iPod
2012-10-08 11:39 . 2012-10-08 11:39        794112        ----a-w-        c:\windows\system32\Gqstsp.tsp
2012-10-08 11:26 . 2012-10-08 11:26        495616        ----a-w-        c:\windows\SysWow64\Gqstsp.tsp
2012-10-08 11:09 . 2012-10-08 11:09        54272        ----a-w-        c:\windows\system32\drivers\GigasetGenericUSB_x64.sys
2012-09-30 22:37 . 2012-09-30 22:37        --------        d-----w-        c:\users\Kate\AppData\Roaming\AVG10
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 21:57 . 2010-03-20 19:08        65309168        ----a-w-        c:\windows\system32\MRT.exe
2012-10-09 09:29 . 2012-04-26 10:18        696760        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 09:29 . 2011-06-10 06:23        73656        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-29 17:54 . 2011-08-04 20:39        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-16 18:01 . 2012-06-08 11:11        61440        ----a-r-        c:\users\admin\AppData\Roaming\Microsoft\Installer\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}\ARPPRODUCTICON.exe
2012-08-24 11:15 . 2012-09-22 09:52        17810944        ----a-w-        c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 09:52        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 09:52        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 09:52        1346048        ----a-w-        c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 09:52        1392128        ----a-w-        c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 09:52        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 09:52        237056        ----a-w-        c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 09:52        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 09:52        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 09:52        816640        ----a-w-        c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 09:52        599040        ----a-w-        c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 09:52        2144768        ----a-w-        c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 09:52        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 09:52        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 09:52        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 09:52        248320        ----a-w-        c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 09:52        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 09:52        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 09:52        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 09:52        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 09:52        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 09:52        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 09:38        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 09:38        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 09:38        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 09:38        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-26 15:06        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-08-21 11:01 . 2010-03-21 10:21        125872        ----a-w-        c:\windows\system32\GEARAspi64.dll
2012-08-21 11:01 . 2010-03-21 10:21        106928        ----a-w-        c:\windows\SysWow64\GEARAspi.dll
2012-08-20 17:38 . 2012-10-10 18:46        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2012-08-02 17:58 . 2012-09-12 09:38        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-08-02 16:57 . 2012-09-12 09:38        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-04-19 611712]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Spyder3Utility.lnk - c:\program files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe [2009-9-1 6407854]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-03-21 1038088]
R3 GigasetGenericUSB_x64;GigasetGenericUSB_x64;c:\windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [2012-10-08 54272]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-24 115168]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 Spyder3;Datacolor Spyder3;c:\windows\system32\DRIVERS\Spyder3.sys [2008-09-08 15360]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-12-14 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 vpcuxd;USB-Virtualisierungsstubdienst;c:\windows\system32\drivers\vpcuxd.sys [2010-11-20 16384]
R4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2010-04-19 288112]
R4 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R4 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
R4 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R4 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-21 52856]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-11-04 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-11-04 130864]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 202752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-23 71600]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\DRIVERS\SkyNET_AMD64.SYS [2010-03-20 615440]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-11-04 146736]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-11-04 165680]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-26 09:29]
.
2012-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001Core.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-10 17:13]
.
2012-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1394765569-1510172786-3570238692-1001UA.job
- c:\users\Uli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-10 17:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 11:17        133400        ----a-w-        c:\program files\AVAST Software\Avast\ashShA64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: {F8FC1530-0608-11DF-2008-0800200C9A66} - hxxps://portal.computacenter.de/CACHE/sdesktop/install/binaries/instweb.cab
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\w315ohqn.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-10-29  13:44:13
ComboFix-quarantined-files.txt  2012-10-29 12:44
ComboFix2.txt  2012-10-28 16:37
ComboFix3.txt  2012-10-28 15:56
ComboFix4.txt  2012-10-28 12:23
ComboFix5.txt  2012-10-29 08:19
.
Vor Suchlauf: 25 Verzeichnis(se), 670.080.602.112 Bytes frei
Nach Suchlauf: 26 Verzeichnis(se), 669.881.483.264 Bytes frei
.
- - End Of File - - 8F0CFBAC1F53312EBE1AD665C1758D83


cosinus 29.10.2012 14:26

Jetzt steht aber kein Avast bei dir im Kopf vom CF-Log :D

magnus65 29.10.2012 14:45

Liste der Anhänge anzeigen (Anzahl: 1)
Stimmt ;-)

Verstehen muss ich das ja nicht unbedingt, siehe Prozessliste

cosinus 29.10.2012 15:20

Läuft das Sicherheitscenter jetzt eigenlich wieder?

magnus65 29.10.2012 15:27

Zitat:

Zitat von cosinus (Beitrag 947614)
Läuft das Sicherheitscenter jetzt eigenlich wieder?

leider nicht, das hätte ich schon freudigt erregt kundgetan.

cosinus 29.10.2012 15:31

Downloade dir bitte Farbar's Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center / Action Center
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.
Poste bitte den Inhalt hier.

magnus65 29.10.2012 15:54

Das wäre dann das hier

Code:

Farbar Service Scanner Version: 27-10-2012
Ran by admin (administrator) on 29-10-2012 at 15:49:23
Running from "C:\Temp\Test"
Microsoft Windows 7 Ultimate  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


cosinus 29.10.2012 16:16

Zitat:

Die Anmeldeinformationen waren ursprünglich leer. Slao dieses Konto, aber dann war kein Kontoname hinterlegt.

Hab jetzt wieder Lokaler Service mit dem Admin Kenwort eingegeben , bin mir aber nicht sicher, ob das ADmin kennwort da rein muss oder was anderes.
So kann das auch nicht hinhauen!
Versuch mal den Dienst Sicherheitscenter im Kontext des lokalen Systemkontos laufen zu lassen

magnus65 29.10.2012 20:14

Liste der Anhänge anzeigen (Anzahl: 1)
Zitat:

Zitat von cosinus (Beitrag 947654)
So kann das auch nicht hinhauen!
Versuch mal den Dienst Sicherheitscenter im Kontext des lokalen Systemkontos laufen zu lassen

Doch das ist schon richtig so, habs auf einem anderen Rechner verglichen.
Wenn ich es so einstelle, wie Du sagst, kommt angehängte Meldung.

Angeblich reicht es , das Ganze als lokaler Dienst ohne Kennwort anzulegen

siehe hier :

hxxp://technet.microsoft.com/de-de/library/cc755249.aspx

Hab ich gemacht geht aber auch nicht

magnus65 31.10.2012 16:06

Hi,
noch Ideen, was ich tun könnte ?
in jedem Fall vielen Dank für die Hilfe bisher.

Gruß

Magnus

cosinus 31.10.2012 19:09

ich vermute, das Problem ist, dass du versucht hast die Anmeldeinfos zu verändern. Ich hab das mal in meiner VM durchgetestet, es ging danach nicht mehr, aber zum Glück hab ich den für diesen Dienst verantwortlichen Registrybereich exportiert und danach wieder importiert, es ging dann wieder.

Vllt klappt es bei dir ja auch. Siehe Datei im Anhang. Runterladen auf den Desktop, entpacken und die wscsvc.reg per Doppelklick in die Reg importieren!


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:46 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55