Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8 (https://www.trojaner-board.de/127310-tr-crypt-epack-gen2-tr-spy-banker-gen8.html)

paddy83 20.11.2012 22:12

TR/Crypt.EPACK.Gen2 / TR/Spy.Banker.Gen8
 
Hallo zusammen,

ich mir wohl u.a. durch Anschluss einer externen HDD mit älteren Daten ein paar Plagegeister eingefangen. Da waren wohl in einigen "Jugendsünden" noch ein paar Überraschungen versteckt.

MBAM OLT und ESET habe ich durchlaufen lassen, anbei die Logs.
Ich habe eine Hand voll Pfade aus den Logs aus privaten Gründen gekürzt, falls diese benötigt werden reiche ich sie nach oder füge sie selbst in das Script ein.

Vielen Dank für eure Hilfe!

Patrick



MBAM Durchlauf 1:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.11.13.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
egal :: EGAL-PC [Administrator]

13.11.2012 19:56:47
mbam-log-2012-11-13 (19-56-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 375594
Laufzeit: 44 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


MBAM Durchlauf 2:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Datenbank Version: v2012.11.13.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
egal :: EGAL-PC [Administrator]

13.11.2012 19:56:47
mbam-log-2012-11-14 (00-03-39).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|G:\|H:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 375594
Laufzeit: 44 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Patrick\AppData\Roaming\loaupdt.jpg (Extension.Mismatch) -> Keine Aktion durchgeführt.
C:\Users\Patrick\AppData\Roaming\appConf32.exe (Backdoor.Agent) -> Keine Aktion durchgeführt.

(Ende)


OLT:

OTL logfile created on: 18.11.2012 15:11:17 - Run 2
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Users\egal\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,85 Gb Total Physical Memory | 0,95 Gb Available Physical Memory | 33,24% Memory free
5,71 Gb Paging File | 2,84 Gb Available in Paging File | 49,81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 368,10 Gb Total Space | 298,23 Gb Free Space | 81,02% Space Free | Partition Type: NTFS
Drive D: | 97,66 Gb Total Space | 96,20 Gb Free Space | 98,51% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: EGAL-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days

========== Processes (SafeList) ==========

PRC - [2012.11.13 15:16:47 | 000,384,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.10.12 19:54:49 | 000,692,152 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
PRC - [2012.10.08 09:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2012.10.03 12:40:30 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\egal\Desktop\OTL.exe
PRC - [2012.09.19 18:20:40 | 000,079,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.07.09 19:51:26 | 001,672,008 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyserver.exe
PRC - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe
PRC - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe
PRC - [2012.07.09 19:50:56 | 000,594,760 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkytray.exe
PRC - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe
PRC - [2011.06.24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 22:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll


========== Services (SafeList) ==========

SRV - [2012.10.30 14:18:00 | 000,084,256 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.10.30 14:17:51 | 000,108,320 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.10.14 18:35:23 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.12 19:54:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.08.31 15:02:03 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.07.09 19:51:02 | 000,545,608 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkyproxy.exe -- (TwonkyProxy)
SRV - [2012.07.09 19:50:58 | 000,271,176 | ---- | M] () [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkywebdav.exe -- (TwonkyWebDav)
SRV - [2012.07.09 19:50:56 | 000,549,704 | ---- | M] (PacketVideo) [Auto | Running] -- C:\Programme\Twonky\TwonkyServer\twonkystarter.exe -- (TwonkyServer)
SRV - [2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IntelCpHeciSvc.exe -- (cphs)
SRV - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.11.20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010.11.20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010.11.20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.10.19 22:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2008.12.19 05:15:52 | 000,246,808 | ---- | M] (silex technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sxuptp.sys -- (sxuptp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 78 11 9F 0F B9 B9 CD 01 [binary data]
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EB DF 65 A1 12 C4 CD 01 [binary data]
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1473542197-2113749607-4133459808-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.03 14:05:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.14 18:35:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.14 18:35:21 | 000,000,000 | ---D | M]

[2012.09.26 15:22:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2012.10.14 18:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.10.03 14:05:04 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012.10.14 18:35:23 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.08.14 16:49:30 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll

O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKU\S-1-5-21-1473542197-2113749607-4133459808-1004..\Run: [ICQ] C:\Program Files\ICQ7M\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.)
O4 - Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk = C:\Programme\silex technology\SX Virtual Link\Connect.exe (silex technology, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Programme\ICQ7M\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D64C20E-EA5D-4AEE-88CD-9A5819240691}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 360 Days ==========

[2012.11.16 03:00:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.11.16 03:00:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.11.16 03:00:45 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.11.16 03:00:44 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.11.16 03:00:44 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.11.16 03:00:44 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.11.16 03:00:44 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.11.16 03:00:43 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.11.15 03:52:10 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2012.11.15 03:52:09 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.11.13 19:55:39 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.10.26 18:49:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Avira
[2012.10.19 20:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.10.19 20:11:19 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.10.19 20:11:18 | 000,133,824 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.10.19 20:11:18 | 000,083,432 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.10.19 20:11:18 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.10.19 20:11:15 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.10.19 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\Handy
[2012.10.17 19:09:02 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TeamViewer
[2012.10.15 19:00:17 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2012.10.14 19:37:21 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\QuickPar
[2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\UseNeXT
[2012.10.14 18:39:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\UseNeXT
[2012.10.14 18:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.10.10 16:46:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.10.10 16:45:55 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.10.10 16:45:55 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.10.07 19:19:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TwonkyMedia
[2012.10.07 08:04:14 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\vlc
[2012.10.06 14:24:07 | 000,000,000 | ---D | C] -- C:\ProgramData\twonkyclient
[2012.10.03 19:28:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
[2012.10.03 19:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\Tracker Software
[2012.10.03 18:52:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Philips
[2012.10.03 18:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\Philips
[2012.10.03 18:50:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012.10.03 18:49:38 | 000,000,000 | ---D | C] -- C:\ProgramData\TwonkyServer
[2012.10.03 18:49:32 | 000,000,000 | ---D | C] -- C:\Program Files\Twonky
[2012.10.03 13:51:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes
[2012.10.03 13:49:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\GVU Logs
[2012.10.03 12:46:18 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.03 10:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.03 10:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.09.26 17:34:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7M
[2012.09.26 17:34:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\ICQ
[2012.09.26 17:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7M
[2012.09.26 15:23:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Macromedia
[2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Mozilla
[2012.09.26 15:22:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Mozilla
[2012.09.24 21:24:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\
[2012.09.24 18:21:00 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Steganos
[2012.09.24 18:15:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Adobe
[2012.09.24 18:12:38 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\TrueCrypt
[2012.09.24 18:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2012.09.24 18:12:17 | 000,231,760 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012.09.24 18:12:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2012.09.24 16:01:33 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Macromedia
[2012.09.22 22:39:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
[2012.09.22 22:28:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2012.09.22 22:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
[2012.09.22 22:22:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner
[2012.09.22 22:22:33 | 000,000,000 | ---D | C] -- C:\Program Files\Astonsoft
[2012.09.22 22:03:53 | 000,000,000 | ---D | C] -- C:\Avis
[2012.09.22 22:02:42 | 000,360,448 | ---- | C] (FLV.com) -- C:\Windows\System32\TubeFinder.exe
[2012.09.22 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLV Converter
[2012.09.22 22:02:41 | 001,081,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomctl.ocx
[2012.09.22 22:02:41 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX
[2012.09.22 22:02:41 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCFR.DLL
[2012.09.22 22:02:41 | 000,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6FR.DLL
[2012.09.22 22:02:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6STKIT.DLL
[2012.09.22 22:02:41 | 000,084,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PICCLP32.OCX
[2012.09.22 22:02:41 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGFR.DLL
[2012.09.22 22:02:41 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PCCLPFR.DLL
[2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\FreeFLVConverter
[2012.09.22 22:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Free FLV Converter
[2012.09.14 18:11:02 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012.09.14 18:11:02 | 000,187,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar
[2012.09.09 17:48:52 | 000,000,000 | ---D | C] -- C:\Program Files\QuickPar
[2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT
[2012.09.02 11:38:16 | 000,000,000 | ---D | C] -- C:\Program Files\UseNeXT
[2012.08.30 22:06:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Adobe
[2012.08.30 22:05:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012.08.30 22:05:31 | 000,198,864 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012.08.30 22:05:28 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012.08.30 22:05:28 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012.08.30 22:05:27 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012.08.30 22:05:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2012.08.30 22:05:10 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2012.08.30 22:04:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Real
[2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.08.30 21:47:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SX Virtual Link
[2012.08.30 21:01:27 | 000,000,000 | ---D | C] -- C:\Program Files\silex technology
[2012.08.30 21:01:05 | 000,246,808 | ---- | C] (silex technology, Inc.) -- C:\Windows\System32\drivers\sxuptp.sys
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\Searches
[2012.08.26 18:50:33 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.08.26 18:50:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Identities
[2012.08.26 18:50:24 | 000,000,000 | R--D | C] -- C:\Users\Admin\Contacts
[2012.08.26 18:50:22 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\VirtualStore
[2012.08.26 18:47:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics
[2012.08.26 17:48:42 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2012.08.26 17:48:42 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2012.08.26 17:48:40 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2012.08.26 17:48:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2012.08.26 17:46:32 | 000,000,000 | --SD | C] -- C:\Users\Admin\AppData\Roaming\Microsoft
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Videos
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Saved Games
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Pictures
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Music
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Links
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Favorites
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Downloads
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Documents
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\Desktop
[2012.08.26 17:46:32 | 000,000,000 | R--D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Vorlagen
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Verlauf
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Temporary Internet Files
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Startmenü
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\SendTo
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Recent
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Netzwerkumgebung
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Lokale Einstellungen
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Videos
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Musik
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Eigene Dateien
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Documents\Eigene Bilder
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Druckumgebung
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Cookies
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\AppData\Local\Anwendungsdaten
[2012.08.26 17:46:32 | 000,000,000 | -HSD | C] -- C:\Users\Admin\Anwendungsdaten
[2012.08.26 17:46:32 | 000,000,000 | -H-D | C] -- C:\Users\Admin\AppData
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Temp
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Microsoft
[2012.08.26 17:46:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Media Center Programs
[2012.08.26 17:36:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.08.26 17:36:14 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.08.26 17:36:11 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.08.26 17:36:11 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.08.26 17:36:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.08.26 17:35:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Passwort-Manager Free
[2012.08.26 17:35:25 | 000,000,000 | ---D | C] -- C:\Program Files\Steganos Password Manager Free 11
[2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012.08.26 17:33:18 | 000,000,000 | ---D | C] -- C:\Intel
[2012.08.26 17:30:29 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012.08.26 17:30:28 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012.08.26 17:30:28 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012.08.26 17:30:28 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.08.26 17:30:28 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012.08.26 17:30:28 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.08.26 17:30:28 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012.08.26 17:30:28 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012.08.26 17:30:28 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012.08.26 17:30:28 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012.08.26 17:30:28 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012.08.26 17:30:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012.08.26 17:30:28 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012.08.26 17:30:28 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012.08.26 17:30:28 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.08.26 17:30:28 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012.08.26 17:30:28 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012.08.26 17:30:28 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.08.26 17:30:28 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012.08.26 17:30:28 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012.08.26 17:30:28 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.08.26 17:30:28 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.08.26 17:30:28 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012.08.26 17:30:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012.08.26 17:30:28 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.08.26 17:30:28 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012.08.26 17:30:28 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.08.26 17:30:28 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.08.26 17:30:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.08.26 17:27:41 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.08.26 17:27:40 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2012.08.26 17:27:40 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2012.08.26 17:27:40 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2012.08.26 17:27:40 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2012.08.26 17:27:40 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2012.08.26 17:27:40 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2012.08.26 17:27:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2012.08.26 17:27:31 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2012.08.26 17:27:31 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012.08.26 17:27:26 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012.08.26 17:27:25 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2012.08.26 17:27:24 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2012.08.26 17:27:24 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2012.08.26 17:27:21 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012.08.26 17:27:21 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2012.08.26 17:25:43 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2012.08.26 17:25:00 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.08.26 17:25:00 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2012.08.26 17:24:59 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2012.08.26 17:24:59 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012.08.26 17:24:55 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2012.08.26 17:24:55 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2012.08.26 17:24:44 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.08.26 17:24:43 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2012.08.26 17:24:33 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.08.26 17:24:32 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2012.08.26 17:24:30 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2012.08.26 17:24:23 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2012.08.26 17:24:23 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2012.08.26 17:24:23 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2012.08.26 17:24:22 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2012.08.26 17:24:22 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2012.08.26 17:24:20 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.08.26 17:24:16 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2012.08.26 17:24:16 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012.08.26 17:24:15 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2012.08.26 17:24:15 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012.08.26 17:24:15 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012.08.26 17:24:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012.08.26 17:24:15 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012.08.26 17:24:14 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2012.08.26 17:24:14 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2012.08.26 17:24:13 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2012.08.26 17:24:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2012.08.26 17:24:13 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.08.26 17:24:13 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2012.08.26 17:24:13 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2012.08.26 17:24:13 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2012.08.26 17:24:13 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.08.26 17:24:13 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.08.26 17:24:08 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.08.26 17:24:07 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2012.08.26 17:24:07 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2012.08.26 17:21:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2012.08.26 17:21:07 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012.08.26 17:19:48 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.08.26 17:19:48 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.08.26 17:19:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2012.08.26 17:18:19 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012.08.26 17:15:23 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.08.26 17:15:23 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.08.26 17:15:20 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.08.26 17:15:20 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.08.26 17:15:20 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.08.26 17:15:18 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.08.26 17:15:18 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012.08.26 17:14:22 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll
[2012.08.26 17:14:04 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012.08.26 17:14:02 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012.08.26 17:11:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.08.26 17:11:03 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012.08.26 17:10:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012.08.26 17:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012.08.26 17:10:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.08.26 17:09:56 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012.08.26 17:09:56 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012.08.26 17:08:11 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.08.26 13:17:53 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.08.26 13:17:39 | 000,000,000 | -HSD | C] -- C:\Boot
[2012.08.26 12:26:03 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.08.26 12:26:02 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.08.26 12:26:00 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.08.26 12:18:47 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.08.26 12:18:09 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.03.19 22:44:18 | 000,276,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe
[2012.03.19 22:44:16 | 006,215,448 | ---- | C] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2012.03.19 22:40:34 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll
[2012.03.19 22:26:56 | 006,120,960 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll
[2012.03.19 22:11:38 | 007,795,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll
[2012.03.19 21:12:30 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2012.03.19 21:12:28 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2012.03.19 21:12:28 | 000,437,248 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2012.03.19 21:12:28 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2012.03.19 21:12:28 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2012.03.19 21:12:28 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2012.03.19 21:12:26 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2012.03.19 21:12:26 | 000,430,080 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2012.03.19 21:12:26 | 000,428,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2012.03.19 21:12:24 | 000,438,272 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2012.03.19 21:12:24 | 000,437,760 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2012.03.19 21:12:24 | 000,435,200 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2012.03.19 21:12:24 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2012.03.19 21:12:22 | 000,433,664 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2012.03.19 21:12:22 | 000,427,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2012.03.19 21:12:22 | 000,426,496 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2012.03.19 21:12:08 | 000,313,344 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll
[2012.03.19 21:12:08 | 000,286,208 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2012.03.19 21:12:08 | 000,120,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2012.03.19 21:12:06 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2012.03.19 21:11:52 | 000,059,392 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll
[2012.03.19 21:11:36 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2012.03.19 21:11:30 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\Windows\System32\hccutils.dll
[2012.03.19 21:11:22 | 000,172,544 | ---- | C] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2012.03.19 21:10:56 | 009,023,488 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxress.dll
[2012.03.19 21:10:56 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc
[2012.03.19 21:09:08 | 002,321,408 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2012.03.19 21:09:08 | 000,519,680 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll
[2012.03.19 21:09:08 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2012.03.19 21:09:08 | 000,237,056 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2012.03.19 21:09:08 | 000,177,152 | ---- | C] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll

========== Files - Modified Within 360 Days ==========

[2012.11.18 14:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.18 12:37:25 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.18 12:37:25 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.18 12:37:25 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.18 12:37:25 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 10:57:04 | 000,021,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 10:49:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.18 10:49:38 | 2298,261,504 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.16 03:21:41 | 000,265,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.11.13 19:56:12 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.13 15:16:54 | 000,133,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012.11.13 15:16:54 | 000,083,432 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.11.13 15:16:54 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.10.18 18:59:05 | 002,345,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.10.17 19:20:34 | 000,000,232 | ---- | M] () -- C:\Users\Admin\Documents\Kundenliste.rtf
[2012.10.15 20:36:49 | 000,000,420 | ---- | M] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf
[2012.10.15 19:00:31 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.10.14 16:06:41 | 000,012,661 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,001,033 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,000,970 | ---- | M] () -- C:\Users\Admin\
[2012.10.12 19:54:49 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.10.12 19:54:49 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.10.08 08:56:24 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.10.08 08:47:44 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.10.08 08:46:32 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.10.08 08:45:17 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.10.08 08:44:05 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.10.08 08:42:31 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.10.08 08:40:56 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.10.08 08:37:23 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.10.07 16:27:34 | 000,539,738 | ---- | M] () -- C:\Users\Admin\Desktop\kinderkekse.xps
[2012.10.07 16:27:11 | 000,718,181 | ---- | M] () -- C:\Users\Admin\Desktop\Pizzabrot.xps
[2012.10.03 18:52:52 | 000,001,930 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk
[2012.10.03 18:52:52 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\MediaManager.lnk
[2012.10.03 12:41:28 | 001,820,575 | ---- | M] () -- C:\Users\Admin\Desktop\gvu anleitung.xps
[2012.10.03 10:16:06 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.09.26 19:16:23 | 000,217,225 | ---- | M] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf
[2012.09.25 23:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2012.09.24 21:24:42 | 000,159,468 | ---- | M] () -- C:\Users\Admin\
[2012.09.24 18:12:22 | 000,001,032 | ---- | M] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.09.24 18:12:17 | 000,231,760 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012.09.22 22:28:15 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.22 22:22:34 | 000,001,055 | ---- | M] () -- C:\Users\Admin\Desktop\DeepBurner.lnk
[2012.09.22 22:02:42 | 000,001,079 | ---- | M] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk
[2012.09.14 19:28:53 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.09.09 17:48:52 | 000,000,969 | ---- | M] () -- C:\Users\Admin\Desktop\QuickPar.lnk
[2012.09.02 11:38:16 | 000,001,807 | ---- | M] () -- C:\Users\Admin\Desktop\
[2012.08.30 22:05:31 | 000,198,864 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012.08.30 22:05:28 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012.08.30 22:05:28 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012.08.30 22:05:27 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012.08.30 21:11:25 | 000,001,234 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk
[2012.08.30 18:12:02 | 003,968,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.08.30 18:12:02 | 003,914,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.08.27 14:50:24 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.08.26 17:36:07 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012.08.26 17:36:07 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012.08.26 17:36:07 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.08.26 17:36:07 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.08.26 17:36:07 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.08.26 17:35:28 | 000,001,179 | ---- | M] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk
[2012.08.26 17:30:29 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012.08.26 17:30:28 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012.08.26 17:30:28 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012.08.26 17:30:28 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.08.26 17:30:28 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012.08.26 17:30:28 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.08.26 17:30:28 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012.08.26 17:30:28 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012.08.26 17:30:28 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012.08.26 17:30:28 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012.08.26 17:30:28 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012.08.26 17:30:28 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012.08.26 17:30:28 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012.08.26 17:30:28 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012.08.26 17:30:28 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.08.26 17:30:28 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012.08.26 17:30:28 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012.08.26 17:30:28 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.08.26 17:30:28 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012.08.26 17:30:28 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012.08.26 17:30:28 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.08.26 17:30:28 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.08.26 17:30:28 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012.08.26 17:30:28 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012.08.26 17:30:28 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012.08.26 17:30:28 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.08.26 17:30:28 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012.08.26 17:30:28 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.08.26 17:30:28 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.08.26 17:30:28 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.08.26 13:17:41 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012.08.26 12:21:31 | 000,177,271 | ---- | M] () -- C:\Windows\System32\license.rtf
[2012.08.26 12:20:09 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.08.22 18:16:46 | 000,240,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012.08.22 18:16:36 | 000,187,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012.07.04 22:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2012.06.06 06:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2012.06.02 23:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.06.02 23:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.06.02 23:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.06.02 23:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.06.02 23:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.06.02 14:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.06.02 14:12:20 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012.06.02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.05.31 11:25:14 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012.05.05 08:46:52 | 000,400,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012.04.26 05:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.04.26 05:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.04.26 05:41:16 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.03.19 22:58:28 | 000,080,208 | ---- | M] () -- C:\Windows\System32\iglhxs32.vp
[2012.03.19 22:44:18 | 000,276,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\IntelCpHeciSvc.exe
[2012.03.19 22:44:16 | 006,215,448 | ---- | M] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2012.03.19 22:40:34 | 000,081,920 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2696.dll
[2012.03.19 22:26:56 | 006,120,960 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll
[2012.03.19 22:26:08 | 000,145,804 | ---- | M] () -- C:\Windows\System32\igcompkrng600.bin
[2012.03.19 22:26:06 | 000,963,912 | ---- | M] () -- C:\Windows\System32\igkrng600.bin
[2012.03.19 22:26:06 | 000,261,208 | ---- | M] () -- C:\Windows\System32\igfcg600m.bin
[2012.03.19 22:25:58 | 000,058,880 | ---- | M] () -- C:\Windows\System32\igdde32.dll
[2012.03.19 22:11:38 | 007,795,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll
[2012.03.19 21:21:14 | 013,212,672 | ---- | M] () -- C:\Windows\System32\ig4icd32.dll
[2012.03.19 21:12:48 | 000,144,790 | ---- | M] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2012.03.19 21:12:46 | 000,139,901 | ---- | M] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2012.03.19 21:12:46 | 000,125,306 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-TW.resources
[2012.03.19 21:12:46 | 000,123,778 | ---- | M] () -- C:\Windows\System32\Gfxres.zh-CN.resources
[2012.03.19 21:12:44 | 000,221,877 | ---- | M] () -- C:\Windows\System32\Gfxres.th-TH.resources
[2012.03.19 21:12:44 | 000,143,564 | ---- | M] () -- C:\Windows\System32\Gfxres.tr-TR.resources
[2012.03.19 21:12:44 | 000,141,854 | ---- | M] () -- C:\Windows\System32\Gfxres.sv-SE.resources
[2012.03.19 21:12:42 | 000,192,378 | ---- | M] () -- C:\Windows\System32\Gfxres.ru-RU.resources
[2012.03.19 21:12:42 | 000,140,548 | ---- | M] () -- C:\Windows\System32\Gfxres.sk-SK.resources
[2012.03.19 21:12:42 | 000,136,850 | ---- | M] () -- C:\Windows\System32\Gfxres.sl-SI.resources
[2012.03.19 21:12:40 | 000,143,112 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-BR.resources
[2012.03.19 21:12:40 | 000,142,079 | ---- | M] () -- C:\Windows\System32\Gfxres.pt-PT.resources
[2012.03.19 21:12:40 | 000,141,421 | ---- | M] () -- C:\Windows\System32\Gfxres.pl-PL.resources
[2012.03.19 21:12:38 | 000,147,116 | ---- | M] () -- C:\Windows\System32\Gfxres.ko-KR.resources
[2012.03.19 21:12:38 | 000,142,797 | ---- | M] () -- C:\Windows\System32\Gfxres.nl-NL.resources
[2012.03.19 21:12:38 | 000,136,778 | ---- | M] () -- C:\Windows\System32\Gfxres.nb-NO.resources
[2012.03.19 21:12:36 | 000,162,150 | ---- | M] () -- C:\Windows\System32\Gfxres.ja-JP.resources
[2012.03.19 21:12:36 | 000,148,461 | ---- | M] () -- C:\Windows\System32\Gfxres.it-IT.resources
[2012.03.19 21:12:36 | 000,142,606 | ---- | M] () -- C:\Windows\System32\Gfxres.hu-HU.resources
[2012.03.19 21:12:34 | 000,157,713 | ---- | M] () -- C:\Windows\System32\Gfxres.he-IL.resources
[2012.03.19 21:12:34 | 000,144,267 | ---- | M] () -- C:\Windows\System32\Gfxres.fr-FR.resources
[2012.03.19 21:12:34 | 000,140,949 | ---- | M] () -- C:\Windows\System32\Gfxres.fi-FI.resources
[2012.03.19 21:12:32 | 000,208,522 | ---- | M] () -- C:\Windows\System32\Gfxres.el-GR.resources
[2012.03.19 21:12:32 | 000,146,125 | ---- | M] () -- C:\Windows\System32\Gfxres.es-ES.resources
[2012.03.19 21:12:32 | 000,146,008 | ---- | M] () -- C:\Windows\System32\Gfxres.de-DE.resources
[2012.03.19 21:12:30 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2012.03.19 21:12:30 | 000,164,821 | ---- | M] () -- C:\Windows\System32\Gfxres.ar-SA.resources
[2012.03.19 21:12:30 | 000,141,297 | ---- | M] () -- C:\Windows\System32\Gfxres.cs-CZ.resources
[2012.03.19 21:12:30 | 000,136,261 | ---- | M] () -- C:\Windows\System32\Gfxres.da-DK.resources
[2012.03.19 21:12:28 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2012.03.19 21:12:28 | 000,437,248 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2012.03.19 21:12:28 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2012.03.19 21:12:28 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2012.03.19 21:12:28 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2012.03.19 21:12:28 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2012.03.19 21:12:26 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2012.03.19 21:12:26 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2012.03.19 21:12:26 | 000,435,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2012.03.19 21:12:26 | 000,430,080 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2012.03.19 21:12:26 | 000,428,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2012.03.19 21:12:24 | 000,438,272 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2012.03.19 21:12:24 | 000,437,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2012.03.19 21:12:24 | 000,436,736 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2012.03.19 21:12:24 | 000,436,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2012.03.19 21:12:24 | 000,435,200 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2012.03.19 21:12:24 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2012.03.19 21:12:22 | 000,433,664 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2012.03.19 21:12:22 | 000,427,008 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2012.03.19 21:12:22 | 000,426,496 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2012.03.19 21:12:22 | 000,131,674 | ---- | M] () -- C:\Windows\System32\Gfxres.en-US.resources
[2012.03.19 21:12:08 | 000,313,344 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll
[2012.03.19 21:12:08 | 000,286,208 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2012.03.19 21:12:08 | 000,120,320 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2012.03.19 21:12:06 | 000,025,088 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2012.03.19 21:11:52 | 000,059,392 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll
[2012.03.19 21:11:36 | 000,130,048 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2012.03.19 21:11:30 | 000,096,256 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hccutils.dll
[2012.03.19 21:11:22 | 000,172,544 | ---- | M] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2012.03.19 21:11:22 | 000,009,216 | ---- | M] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.03.19 21:10:56 | 009,023,488 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxress.dll
[2012.03.19 21:10:56 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrenu.lrc
[2012.03.19 21:09:28 | 000,000,264 | ---- | M] () -- C:\Windows\System32\GfxUI.exe.config
[2012.03.19 21:09:08 | 002,321,408 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2012.03.19 21:09:08 | 001,921,265 | ---- | M] () -- C:\Windows\System32\iglhxa32.cpa
[2012.03.19 21:09:08 | 000,519,680 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhsip32.dll
[2012.03.19 21:09:08 | 000,452,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2012.03.19 21:09:08 | 000,237,056 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2012.03.19 21:09:08 | 000,177,152 | ---- | M] (Intel Corporation) -- C:\Windows\System32\iglhcp32.dll
[2012.03.19 21:09:08 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll
[2012.03.19 21:09:08 | 000,059,594 | ---- | M] () -- C:\Windows\System32\iglhxc32.vp
[2012.03.19 21:09:08 | 000,059,384 | ---- | M] () -- C:\Windows\System32\iglhxc32_dev.vp
[2012.03.19 21:09:08 | 000,059,328 | ---- | M] () -- C:\Windows\System32\iglhxg32_dev.vp
[2012.03.19 21:09:08 | 000,059,215 | ---- | M] () -- C:\Windows\System32\iglhxo32_dev.vp
[2012.03.19 21:09:08 | 000,058,781 | ---- | M] () -- C:\Windows\System32\iglhxo32.vp
[2012.03.19 21:09:08 | 000,058,684 | ---- | M] () -- C:\Windows\System32\iglhxg32.vp
[2012.03.19 21:09:08 | 000,001,074 | ---- | M] () -- C:\Windows\System32\iglhxa32.vp
[2012.03.03 06:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.02.17 06:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012.02.15 13:51:56 | 000,360,448 | ---- | M] (FLV.com) -- C:\Windows\System32\TubeFinder.exe
[2011.12.30 06:27:56 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl

========== Files Created - No Company Name ==========

[2012.11.13 19:55:41 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.17 19:20:33 | 000,000,232 | ---- | C] () -- C:\Users\Admin\Documents\Kundenliste.rtf
[2012.10.15 20:36:49 | 000,000,420 | ---- | C] () -- C:\Users\Admin\Desktop\Wohnzimmer.rtf
[2012.10.15 19:00:31 | 000,001,136 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.10.15 19:00:31 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012.10.14 16:06:41 | 000,012,661 | ---- | C] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,001,033 | ---- | C] () -- C:\Users\Admin\Desktop\
[2012.10.14 16:04:39 | 000,000,970 | ---- | C] () -- C:\Users\Admin\
[2012.10.07 16:27:34 | 000,539,738 | ---- | C] () -- C:\Users\Admin\Desktop\kinderkekse.xps
[2012.10.07 16:27:10 | 000,718,181 | ---- | C] () -- C:\Users\Admin\Desktop\Pizzabrot.xps
[2012.10.03 18:52:52 | 000,001,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MediaServer.lnk
[2012.10.03 18:52:52 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\MediaManager.lnk
[2012.10.03 12:42:14 | 001,820,575 | ---- | C] () -- C:\Users\Admin\Desktop\gvu anleitung.xps
[2012.10.03 10:05:31 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.26 19:16:22 | 000,217,225 | ---- | C] () -- C:\Users\Admin\Desktop\Anschreiben m. Anforderungsformularen.pdf
[2012.09.24 21:24:40 | 000,159,468 | ---- | C] () --
[2012.09.24 18:12:22 | 000,001,032 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.09.22 22:28:15 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.09.22 22:28:15 | 000,001,849 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.09.22 22:22:34 | 000,001,055 | ---- | C] () -- C:\Users\Admin\Desktop\DeepBurner.lnk
[2012.09.22 22:02:42 | 000,001,079 | ---- | C] () -- C:\Users\Admin\Desktop\Free FLV Converter.lnk
[2012.09.22 22:02:41 | 000,364,544 | ---- | C] () -- C:\Windows\System32\PropertyGrid.ocx
[2012.09.22 22:02:41 | 000,208,500 | ---- | C] () -- C:\Windows\System32\ReyXpBasics.tlb
[2012.09.22 22:02:41 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ControlSubX.ocx
[2012.09.09 17:48:52 | 000,000,969 | ---- | C] () -- C:\Users\Admin\Desktop\QuickPar.lnk
[2012.09.02 11:38:16 | 000,001,807 | ---- | C] () -- C:\Users\Admin\Desktop\UseNeXT.lnk
[2012.08.30 21:01:31 | 000,001,234 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk
[2012.08.26 18:50:33 | 000,001,413 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.08.26 17:35:28 | 000,001,179 | ---- | C] () -- C:\Users\Public\Desktop\Passwort-Manager.lnk
[2012.08.26 17:30:28 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012.08.26 17:19:50 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.26 17:14:22 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2012.08.26 17:10:34 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012.08.26 13:17:41 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2012.08.26 13:17:39 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012.08.26 12:21:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.08.26 12:21:15 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.08.26 12:20:09 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.08.26 12:18:10 | 2298,261,504 | -HS- | C] () -- C:\hiberfil.sys
[2012.03.19 22:58:28 | 000,080,208 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp
[2012.03.19 22:26:08 | 000,145,804 | ---- | C] () -- C:\Windows\System32\igcompkrng600.bin
[2012.03.19 22:26:06 | 000,963,912 | ---- | C] () -- C:\Windows\System32\igkrng600.bin
[2012.03.19 22:26:06 | 000,261,208 | ---- | C] () -- C:\Windows\System32\igfcg600m.bin
[2012.03.19 22:25:58 | 000,058,880 | ---- | C] () -- C:\Windows\System32\igdde32.dll
[2012.03.19 21:21:14 | 013,212,672 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2012.03.19 21:12:48 | 000,144,790 | ---- | C] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2012.03.19 21:12:46 | 000,139,901 | ---- | C] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2012.03.19 21:12:46 | 000,125,306 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-TW.resources
[2012.03.19 21:12:46 | 000,123,778 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-CN.resources
[2012.03.19 21:12:44 | 000,221,877 | ---- | C] () -- C:\Windows\System32\Gfxres.th-TH.resources
[2012.03.19 21:12:44 | 000,143,564 | ---- | C] () -- C:\Windows\System32\Gfxres.tr-TR.resources
[2012.03.19 21:12:44 | 000,141,854 | ---- | C] () -- C:\Windows\System32\Gfxres.sv-SE.resources
[2012.03.19 21:12:42 | 000,192,378 | ---- | C] () -- C:\Windows\System32\Gfxres.ru-RU.resources
[2012.03.19 21:12:42 | 000,140,548 | ---- | C] () -- C:\Windows\System32\Gfxres.sk-SK.resources
[2012.03.19 21:12:42 | 000,136,850 | ---- | C] () -- C:\Windows\System32\Gfxres.sl-SI.resources
[2012.03.19 21:12:40 | 000,143,112 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-BR.resources
[2012.03.19 21:12:40 | 000,142,079 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-PT.resources
[2012.03.19 21:12:40 | 000,141,421 | ---- | C] () -- C:\Windows\System32\Gfxres.pl-PL.resources
[2012.03.19 21:12:38 | 000,147,116 | ---- | C] () -- C:\Windows\System32\Gfxres.ko-KR.resources
[2012.03.19 21:12:38 | 000,142,797 | ---- | C] () -- C:\Windows\System32\Gfxres.nl-NL.resources
[2012.03.19 21:12:38 | 000,136,778 | ---- | C] () -- C:\Windows\System32\Gfxres.nb-NO.resources
[2012.03.19 21:12:36 | 000,162,150 | ---- | C] () -- C:\Windows\System32\Gfxres.ja-JP.resources
[2012.03.19 21:12:36 | 000,148,461 | ---- | C] () -- C:\Windows\System32\Gfxres.it-IT.resources
[2012.03.19 21:12:36 | 000,142,606 | ---- | C] () -- C:\Windows\System32\Gfxres.hu-HU.resources
[2012.03.19 21:12:34 | 000,157,713 | ---- | C] () -- C:\Windows\System32\Gfxres.he-IL.resources
[2012.03.19 21:12:34 | 000,144,267 | ---- | C] () -- C:\Windows\System32\Gfxres.fr-FR.resources
[2012.03.19 21:12:34 | 000,140,949 | ---- | C] () -- C:\Windows\System32\Gfxres.fi-FI.resources
[2012.03.19 21:12:32 | 000,208,522 | ---- | C] () -- C:\Windows\System32\Gfxres.el-GR.resources
[2012.03.19 21:12:32 | 000,146,125 | ---- | C] () -- C:\Windows\System32\Gfxres.es-ES.resources
[2012.03.19 21:12:32 | 000,146,008 | ---- | C] () -- C:\Windows\System32\Gfxres.de-DE.resources
[2012.03.19 21:12:30 | 000,164,821 | ---- | C] () -- C:\Windows\System32\Gfxres.ar-SA.resources
[2012.03.19 21:12:30 | 000,141,297 | ---- | C] () -- C:\Windows\System32\Gfxres.cs-CZ.resources
[2012.03.19 21:12:30 | 000,136,261 | ---- | C] () -- C:\Windows\System32\Gfxres.da-DK.resources
[2012.03.19 21:12:22 | 000,131,674 | ---- | C] () -- C:\Windows\System32\Gfxres.en-US.resources
[2012.03.19 21:11:22 | 000,009,216 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.03.19 21:09:28 | 000,000,264 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2012.03.19 21:09:08 | 001,921,265 | ---- | C] () -- C:\Windows\System32\iglhxa32.cpa
[2012.03.19 21:09:08 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
[2012.03.19 21:09:08 | 000,059,594 | ---- | C] () -- C:\Windows\System32\iglhxc32.vp
[2012.03.19 21:09:08 | 000,059,384 | ---- | C] () -- C:\Windows\System32\iglhxc32_dev.vp
[2012.03.19 21:09:08 | 000,059,328 | ---- | C] () -- C:\Windows\System32\iglhxg32_dev.vp
[2012.03.19 21:09:08 | 000,059,215 | ---- | C] () -- C:\Windows\System32\iglhxo32_dev.vp
[2012.03.19 21:09:08 | 000,058,781 | ---- | C] () -- C:\Windows\System32\iglhxo32.vp
[2012.03.19 21:09:08 | 000,058,684 | ---- | C] () -- C:\Windows\System32\iglhxg32.vp
[2012.03.19 21:09:08 | 000,001,074 | ---- | C] () -- C:\Windows\System32\iglhxa32.vp
[2010.11.21 01:46:14 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2010.11.21 01:46:14 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2010.11.21 01:46:14 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2010.11.21 01:46:14 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2010.11.20 22:29:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe

========== ZeroAccess Check ==========

[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >



ESET Log:

ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=12
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=97206b8cac1e69449988079e3006b1e2
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-11-18 09:52:51
# local_time=2012-11-18 10:52:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 2597649 2597649 0 0
# compatibility_mode=5893 16776573 100 94 42720 104902715 0 0
# compatibility_mode=8192 67108863 100 0 4647 4647 0 0
# scanned=142556
# found=6
# cleaned=0
# scan_time=4068
C:\Users\Patrick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\738cd4bb-675ba20a a variant of Win32/Kryptik.AOPO trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Patrick\AppData\Roaming\AcroIEHelpe231.dll Win32/Spy.Banker.YRG trojan (unable to clean) 00000000000000000000000000000000 I
F:\Filme\Filmchen\arkanum\Magma swingt im Lustschloss Arkanum.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I
F:\Filme\Filmchen\gr\Magma swingt im Lustschloss Arkanum gr.exe a variant of MSIL/Injector.ANA trojan (unable to clean) 00000000000000000000000000000000 I
F:\Wichtige Dokumente\p\Software\Babylon_Uebersetzer\Babylon8_setup.exe a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I
F:\Wichtige Dokumente\p\Software\pdf\PDF-Creator\PDFCreator-1_2_1_setup.exe Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I

cosinus 21.11.2012 19:43

Hallo und :hallo:

Zitat:

Ich habe eine Hand voll Pfade aus den Logs aus privaten Gründen gekürzt,
Was hast du da gekürzt? Nur Namen unkenntlich gemacht? Bitte beschreiben

paddy83 21.11.2012 20:26

Hallo,

ich habe aus dem OLT-Log, im Abschnitt " Files/Folders - Created Within 360 Days" und im Abschnitt " Files - Modified Within 360 Days" ein paar Pfade gekürzt.
Beispiel:
[2012.09.24 21:24:40 | 000,159,468 | ---- | C] () -- !!!Hier fehlt der Pfad zu einer persönlichen Datei !!!


Gruß

Patrick

cosinus 21.11.2012 21:14

Derartige Zensuraktionen sind kontraproduktiv, du solltest nur private Infos wie komplette Vor- und Nachnamen unkenntlich machen

paddy83 21.11.2012 21:23

Ok, das nächste mal werde ich anders vorgehen.
Im Endeffekt macht es an der Stelle ja keinen Unterschied ob ich einen Pfad aus xxxe oder ihn Lösche, ungültig ist er in jedem Fall. Egal, ich werde das zukünftig beachten:daumenhoc

cosinus 22.11.2012 12:05

Bitte nun Logs mit GMER (<<< klick für Anleitung) und aswMBR (Anleitung etwas weiter unten) erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim zweiten Mal nicht will, lass es einfach weg und führ nur aswMBR aus.

aswMBR-Download => aswMBR.exe - speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.


Alle Zeitangaben in WEZ +1. Es ist jetzt 08:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131