gutgemeint
Posts: 15 +0
Thanks in advance for any help.
I'm also stuck in an infinite windows restart loop. Microsoft Security Essentials reports Sirefef.W and Sirefef.ab infections and apparently it's not possible to get rid of it. Operating System is Windows 7 64 Bit
After reading a couple of other threads I think a Farbar Recovery scan/search is required. This is the output:
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 14-07-2012 15:17:19
Running from G:\
Windows 7 Home Premium (X64) OS Language: German Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1825064 2009-11-11] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" [171520 2010-02-11] (Sun Microsystems, Inc.)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2314120 2009-05-28] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [16397416 2010-01-11] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11106408 2011-01-23] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [320880 2009-08-26] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [597792 2009-10-24] (Sony Corporation)
HKLM-x32\...\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2010-02-11] (Sony Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-06-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3508624 2012-02-03] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Reader Application Helper] C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [892928 2012-01-31] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Alex\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [943504 2012-02-03] (Samsung)
HKU\Alex\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-02-03] ()
Tcpip\..\Interfaces\{5CA2638F-A594-4D24-80BE-A37A7C278809}: [NameServer]62.220.18.8,89.246.64.8
Tcpip\..\Interfaces\{F080DE39-A95A-4ECD-9EF4-659C412F3AD6}: [NameServer]62.220.18.8,89.246.64.8
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-09-28] (ArcSoft Inc.)
2 IviRegMgr; "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [112152 2007-01-04] (InterVideo)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 ReflectService; C:\Programme\Macrium\Reflect\ReflectService.exe [294880 2010-01-28] ()
3 Roxio UPnP Renderer 10; "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe" [313840 2009-08-31] (Sonic Solutions)
2 Roxio Upnp Server 10; "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe" [362992 2009-08-31] (Sonic Solutions)
2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" [259192 2011-01-29] (Sony Corporation)
2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe" [74496 2010-09-27] (Sony Corporation)
========================== Drivers (Whitelisted) =============
3 ArcSoftKsUFilter; C:\Windows\System32\Drivers\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
2 regi; C:\Windows\SysWow64\Drivers\regi.sys [11032 2007-04-17] (InterVideo)
3 TVICHW64; C:\Windows\System32\Drivers\TVICHW64.sys [21200 2010-07-06] (EnTech Taiwan)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] ()
3 DFUBTUSB; C:\Windows\System32\Drivers\frmupgr.sys [x]
3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-14 14:07 - 2012-07-14 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94AD557CDA899F18
2012-07-14 14:04 - 2012-07-14 14:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27B35B8EC042082A
2012-07-14 14:02 - 2012-07-14 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA3B4D7907B0ECB8
2012-07-14 13:59 - 2012-07-14 13:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9991B66838EDC5F
2012-07-14 13:56 - 2012-07-14 13:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7C441176282CAC65
2012-07-14 13:54 - 2012-07-14 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9B2CF4DE9208FE9D
2012-07-14 13:51 - 2012-07-14 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.947441CD4D02CFDF
2012-07-14 13:48 - 2012-07-14 13:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2FBDD06C4FCCC65
2012-07-14 13:45 - 2012-07-14 13:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ED197566D56949A4
2012-07-14 13:42 - 2012-07-14 13:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B1808447A6C0A6D
2012-07-14 13:39 - 2012-07-14 13:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7F672485F41B0D2
2012-07-14 13:36 - 2012-07-14 13:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B45F29A82D905D7E
2012-07-14 13:33 - 2012-07-14 13:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.91856CEFDFCC6C8D
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDE53A09F6906DB2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A54802710E5149C1
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.25294CF489D11D18
2012-07-14 13:22 - 2012-07-14 13:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68501F60356756E3
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.550DADD415F8F503
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EA28FC0C5F92C74
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60E2C6F036828E47
2012-07-14 13:11 - 2012-07-14 13:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.474EB7FEEC67C17A
2012-07-14 13:08 - 2012-07-14 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C161B1D73DEE9FD
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93FE3E8F47268A64
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6834BF7133352570
2012-07-14 12:47 - 2012-07-14 12:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.375DDB7ABB68E83B
2012-07-14 12:44 - 2012-07-14 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.53197AC98E6A2293
2012-07-14 10:41 - 2012-07-14 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6417BF20C60D483E
2012-07-14 10:37 - 2012-07-14 10:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.98596145A0AAB09C
2012-07-14 10:23 - 2012-07-14 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B2111472CBA8CEC
2012-07-14 10:19 - 2012-07-14 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.873C633BBE819F60
2012-07-14 10:16 - 2012-07-14 10:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E237F555F4A0B1
2012-07-14 10:13 - 2012-07-14 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC2FD36AC608F16
2012-07-14 10:03 - 2012-07-14 10:03 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-14 10:03 - 2012-07-14 10:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-14 09:59 - 2012-07-14 09:59 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 09:59 - 2012-07-14 09:59 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00000000 ____D C:\Program Files (x86)\Java
2012-07-10 16:45 - 2012-07-10 16:45 - 00005198 ____A C:\Users\Alex\Desktop\Käse-Dip - Verknüpfung.lnk
2012-07-10 16:36 - 2012-07-10 16:36 - 00005001 ____A C:\Users\Alex\Desktop\Avocado-Dip - Verknüpfung.lnk
2012-07-10 16:33 - 2012-07-10 16:33 - 00005707 ____A C:\Users\Alex\Desktop\Curry-Zwiebel-Soße - Verknüpfung.lnk
2012-07-10 16:28 - 2012-07-10 16:28 - 00005602 ____A C:\Users\Alex\Desktop\Whisky-Soße - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005488 ____A C:\Users\Alex\Desktop\Curry-Chili-Butter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005248 ____A C:\Users\Alex\Desktop\Limonen Kräuterbutter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005222 ____A C:\Users\Alex\Desktop\Bunte Pfefferbutter - Verknüpfung.lnk
2012-07-10 16:16 - 2012-07-10 16:16 - 00005752 ____A C:\Users\Alex\Desktop\Chili-Paprika-Chutney - Verknüpfung.lnk
2012-07-10 16:15 - 2012-07-10 16:15 - 00005662 ____A C:\Users\Alex\Desktop\Ketchup_Jamie O - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005679 ____A C:\Users\Alex\Desktop\Tacco-Salat - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005526 ____A C:\Users\Alex\Desktop\Cole Slaw_2 - Verknüpfung.lnk
2012-07-08 23:21 - 2012-07-08 23:21 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-03 19:46 - 2012-07-03 19:52 - 260253656 ____A (Avira GmbH) C:\Users\Alex\Downloads\rescue_system-common-en-020712.exe
2012-06-24 11:42 - 2012-06-02 23:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-24 11:42 - 2012-06-02 23:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-24 11:42 - 2012-06-02 23:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-24 11:42 - 2012-06-02 23:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-24 11:41 - 2012-06-02 23:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-24 11:41 - 2012-06-02 23:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-24 11:41 - 2012-06-02 23:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-24 11:41 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-24 11:41 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-15 21:22 - 2012-06-15 21:22 - 00000000 ____D C:\7dbb1aed4335ca44144be08d2d53
2012-06-14 13:29 - 2012-05-18 03:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 13:29 - 2012-05-18 03:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 13:29 - 2012-05-18 03:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 13:29 - 2012-05-18 02:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 13:29 - 2012-05-18 02:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 13:29 - 2012-05-18 02:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 13:29 - 2012-05-18 02:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 13:29 - 2012-05-18 02:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 13:29 - 2012-05-18 02:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 13:29 - 2012-05-18 02:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 13:29 - 2012-05-18 02:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 13:29 - 2012-05-18 02:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 13:29 - 2012-05-18 02:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 13:29 - 2012-05-18 02:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 13:29 - 2012-05-18 00:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 13:29 - 2012-05-17 23:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 13:29 - 2012-05-17 23:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 13:29 - 2012-05-17 23:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 13:29 - 2012-05-17 23:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 13:29 - 2012-05-17 23:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 13:29 - 2012-05-17 23:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 13:29 - 2012-05-17 23:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 13:29 - 2012-05-17 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 13:29 - 2012-05-17 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 13:29 - 2012-05-17 23:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 13:29 - 2012-05-17 23:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 13:29 - 2012-05-17 23:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 13:29 - 2012-05-17 23:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-14 11:37 - 2012-04-26 06:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-14 11:37 - 2012-04-26 06:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-14 11:37 - 2012-04-26 06:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-14 11:36 - 2012-05-15 02:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-14 11:36 - 2012-05-04 12:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-14 11:36 - 2012-05-04 11:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-14 11:36 - 2012-05-04 11:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-14 11:36 - 2012-05-01 06:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-14 11:36 - 2012-04-28 04:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-14 11:36 - 2012-04-24 06:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-14 11:36 - 2012-04-24 06:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-14 11:36 - 2012-04-24 06:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-14 11:36 - 2012-04-07 13:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-14 11:36 - 2012-04-07 12:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-07-14 14:10 - 2009-07-14 00:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-14 14:09 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 14:08 - 2010-05-02 20:38 - 00044827 ____A C:\Windows\setupact.log
2012-07-14 14:07 - 2012-07-14 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94AD557CDA899F18
2012-07-14 14:04 - 2012-07-14 14:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27B35B8EC042082A
2012-07-14 14:02 - 2012-07-14 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA3B4D7907B0ECB8
2012-07-14 13:59 - 2012-07-14 13:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9991B66838EDC5F
2012-07-14 13:56 - 2012-07-14 13:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7C441176282CAC65
2012-07-14 13:54 - 2012-07-14 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9B2CF4DE9208FE9D
2012-07-14 13:51 - 2012-07-14 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.947441CD4D02CFDF
2012-07-14 13:48 - 2012-07-14 13:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2FBDD06C4FCCC65
2012-07-14 13:45 - 2012-07-14 13:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ED197566D56949A4
2012-07-14 13:42 - 2012-07-14 13:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B1808447A6C0A6D
2012-07-14 13:39 - 2012-07-14 13:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7F672485F41B0D2
2012-07-14 13:36 - 2012-07-14 13:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B45F29A82D905D7E
2012-07-14 13:33 - 2012-07-14 13:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.91856CEFDFCC6C8D
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDE53A09F6906DB2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A54802710E5149C1
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.25294CF489D11D18
2012-07-14 13:22 - 2012-07-14 13:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68501F60356756E3
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.550DADD415F8F503
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EA28FC0C5F92C74
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60E2C6F036828E47
2012-07-14 13:11 - 2012-07-14 13:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.474EB7FEEC67C17A
2012-07-14 13:08 - 2012-07-14 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C161B1D73DEE9FD
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93FE3E8F47268A64
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6834BF7133352570
2012-07-14 12:47 - 2012-07-14 12:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.375DDB7ABB68E83B
2012-07-14 12:44 - 2012-07-14 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.53197AC98E6A2293
2012-07-14 10:41 - 2012-07-14 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6417BF20C60D483E
2012-07-14 10:37 - 2012-07-14 10:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.98596145A0AAB09C
2012-07-14 10:23 - 2012-07-14 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B2111472CBA8CEC
2012-07-14 10:19 - 2012-07-14 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.873C633BBE819F60
2012-07-14 10:16 - 2012-07-14 10:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E237F555F4A0B1
2012-07-14 10:13 - 2012-07-14 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC2FD36AC608F16
2012-07-14 10:04 - 2010-12-02 10:51 - 00001912 ____A C:\Windows\epplauncher.mif
2012-07-14 10:04 - 2010-02-11 22:00 - 01542552 ____A C:\Windows\WindowsUpdate.log
2012-07-14 10:03 - 2010-12-02 10:50 - 01527738 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-14 10:03 - 2010-02-12 06:50 - 00656528 ____A C:\Windows\System32\perfh007.dat
2012-07-14 10:03 - 2010-02-12 06:50 - 00131268 ____A C:\Windows\System32\perfc007.dat
2012-07-14 09:59 - 2012-07-14 09:59 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 09:59 - 2012-07-14 09:59 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 09:59 - 2010-05-11 19:56 - 00472880 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-07-14 09:51 - 2009-07-14 05:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-14 09:51 - 2009-07-14 05:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:24 - 2011-09-28 10:14 - 00020624 ____A C:\Users\Alex\Desktop\Gartenpflanzen_2011.ods
2012-07-10 16:45 - 2012-07-10 16:45 - 00005198 ____A C:\Users\Alex\Desktop\Käse-Dip - Verknüpfung.lnk
2012-07-10 16:36 - 2012-07-10 16:36 - 00005001 ____A C:\Users\Alex\Desktop\Avocado-Dip - Verknüpfung.lnk
2012-07-10 16:33 - 2012-07-10 16:33 - 00005707 ____A C:\Users\Alex\Desktop\Curry-Zwiebel-Soße - Verknüpfung.lnk
2012-07-10 16:28 - 2012-07-10 16:28 - 00005602 ____A C:\Users\Alex\Desktop\Whisky-Soße - Verknüpfung.lnk
2012-07-10 16:21 - 2012-05-28 23:16 - 00017824 ____A C:\Users\Alex\Desktop\Geburtstag_Alex & Volker_2012.ods
2012-07-10 16:17 - 2012-07-10 16:17 - 00005488 ____A C:\Users\Alex\Desktop\Curry-Chili-Butter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005248 ____A C:\Users\Alex\Desktop\Limonen Kräuterbutter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005222 ____A C:\Users\Alex\Desktop\Bunte Pfefferbutter - Verknüpfung.lnk
2012-07-10 16:16 - 2012-07-10 16:16 - 00005752 ____A C:\Users\Alex\Desktop\Chili-Paprika-Chutney - Verknüpfung.lnk
2012-07-10 16:15 - 2012-07-10 16:15 - 00005662 ____A C:\Users\Alex\Desktop\Ketchup_Jamie O - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005679 ____A C:\Users\Alex\Desktop\Tacco-Salat - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005526 ____A C:\Users\Alex\Desktop\Cole Slaw_2 - Verknüpfung.lnk
2012-07-03 19:52 - 2012-07-03 19:46 - 260253656 ____A (Avira GmbH) C:\Users\Alex\Downloads\rescue_system-common-en-020712.exe
2012-06-15 21:32 - 2009-07-14 06:13 - 01527382 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-15 21:25 - 2009-07-14 05:45 - 00337080 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 13:35 - 2010-03-02 20:11 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 23:19 - 2012-06-24 11:42 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-24 11:42 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-24 11:42 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-24 11:41 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-24 11:41 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:15 - 2012-06-24 11:42 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:15 - 2012-06-24 11:41 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-24 11:41 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-24 11:41 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-31 18:23 - 2009-07-14 06:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-18 03:47 - 2012-06-14 13:29 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-18 03:16 - 2012-06-14 13:29 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-18 03:06 - 2012-06-14 13:29 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-18 02:59 - 2012-06-14 13:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-18 02:59 - 2012-06-14 13:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-18 02:58 - 2012-06-14 13:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-18 02:58 - 2012-06-14 13:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-18 02:56 - 2012-06-14 13:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-18 02:55 - 2012-06-14 13:29 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-18 02:55 - 2012-06-14 13:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-18 02:54 - 2012-06-14 13:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-18 02:51 - 2012-06-14 13:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-18 02:51 - 2012-06-14 13:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-18 02:47 - 2012-06-14 13:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-18 00:11 - 2012-06-14 13:29 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 23:48 - 2012-06-14 13:29 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 23:45 - 2012-06-14 13:29 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 23:36 - 2012-06-14 13:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 23:35 - 2012-06-14 13:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 23:35 - 2012-06-14 13:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 23:33 - 2012-06-14 13:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 23:31 - 2012-06-14 13:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 23:29 - 2012-06-14 13:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 23:29 - 2012-06-14 13:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 23:27 - 2012-06-14 13:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 23:25 - 2012-06-14 13:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 23:24 - 2012-06-14 13:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 23:20 - 2012-06-14 13:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:32 - 2012-06-14 11:36 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 12:06 - 2012-06-14 11:36 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 11:03 - 2012-06-14 11:36 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 11:03 - 2012-06-14 11:36 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 06:40 - 2012-06-14 11:36 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-28 04:55 - 2012-06-14 11:36 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 06:41 - 2012-06-14 11:37 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 06:41 - 2012-06-14 11:37 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 06:34 - 2012-06-14 11:37 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 06:37 - 2012-06-14 11:36 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 06:37 - 2012-06-14 11:36 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 06:37 - 2012-06-14 11:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\@
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\L
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\n
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\U
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\U\00000001.@
ZeroAccess:
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\@
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\L
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 4014.09 MB
Available physical RAM: 3371.36 MB
Total Pagefile: 4012.24 MB
Available Pagefile: 3359.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:456.5 GB) (Free:325.33 GB) NTFS
2 Drive e: (Recovery) (Fixed) (Total:9.17 GB) (Free:0.82 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (RAVENNA) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Datentr„ger ### Status Gr”áe Frei Dyn GPT
--------------- ------------- ------- ------- --- ---
Datentr„ger 0 Online 465 GB 0 B
Datentr„ger 1 Online 1912 MB 0 B
Partitions of Disk 0:
===============
Partition ### Typ GrӇe Offset
------------- ---------------- ------- -------
Partition 1 Wiederherstellun 9 GB 1024 KB
Partition 2 Prim„r 100 MB 9 GB
Partition 3 Prim„r 456 GB 9 GB
==================================================================================
Disk: 0
Partition 1
Typ : 27
Versteckt: Ja
Aktiv : Nein
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recovery NTFS Partition 9 GB Fehlerfre Versteck
==================================================================================
Disk: 0
Partition 2
Typ : 07
Versteckt: Nein
Aktiv : Ja
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Fehlerfre
==================================================================================
Disk: 0
Partition 3
Typ : 07
Versteckt: Nein
Aktiv : Nein
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 456 GB Fehlerfre
==================================================================================
Partitions of Disk 1:
===============
Partition ### Typ GrӇe Offset
------------- ---------------- ------- -------
Partition 1 Prim„r 1911 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Typ : 06
Versteckt: Nein
Aktiv : Ja
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G RAVENNA FAT Wechselmed 1911 MB Fehlerfre
==================================================================================
==========================================================
Last Boot: 2012-07-09 17:53
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 2012-07-14 15:52:31
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-14 00:19] - [2012-07-14 14:10] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
I'm also stuck in an infinite windows restart loop. Microsoft Security Essentials reports Sirefef.W and Sirefef.ab infections and apparently it's not possible to get rid of it. Operating System is Windows 7 64 Bit
After reading a couple of other threads I think a Farbar Recovery scan/search is required. This is the output:
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 14-07-2012 15:17:19
Running from G:\
Windows 7 Home Premium (X64) OS Language: German Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1825064 2009-11-11] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" [171520 2010-02-11] (Sun Microsystems, Inc.)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2314120 2009-05-28] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [16397416 2010-01-11] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11106408 2011-01-23] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [320880 2009-08-26] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [597792 2009-10-24] (Sony Corporation)
HKLM-x32\...\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2010-02-11] (Sony Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-06-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3508624 2012-02-03] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Reader Application Helper] C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [892928 2012-01-31] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Alex\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [943504 2012-02-03] (Samsung)
HKU\Alex\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-02-03] ()
Tcpip\..\Interfaces\{5CA2638F-A594-4D24-80BE-A37A7C278809}: [NameServer]62.220.18.8,89.246.64.8
Tcpip\..\Interfaces\{F080DE39-A95A-4ECD-9EF4-659C412F3AD6}: [NameServer]62.220.18.8,89.246.64.8
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-09-28] (ArcSoft Inc.)
2 IviRegMgr; "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [112152 2007-01-04] (InterVideo)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 ReflectService; C:\Programme\Macrium\Reflect\ReflectService.exe [294880 2010-01-28] ()
3 Roxio UPnP Renderer 10; "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe" [313840 2009-08-31] (Sonic Solutions)
2 Roxio Upnp Server 10; "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe" [362992 2009-08-31] (Sonic Solutions)
2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" [259192 2011-01-29] (Sony Corporation)
2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe" [74496 2010-09-27] (Sony Corporation)
========================== Drivers (Whitelisted) =============
3 ArcSoftKsUFilter; C:\Windows\System32\Drivers\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
2 regi; C:\Windows\SysWow64\Drivers\regi.sys [11032 2007-04-17] (InterVideo)
3 TVICHW64; C:\Windows\System32\Drivers\TVICHW64.sys [21200 2010-07-06] (EnTech Taiwan)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-11-12] ()
3 DFUBTUSB; C:\Windows\System32\Drivers\frmupgr.sys [x]
3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-14 14:07 - 2012-07-14 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94AD557CDA899F18
2012-07-14 14:04 - 2012-07-14 14:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27B35B8EC042082A
2012-07-14 14:02 - 2012-07-14 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA3B4D7907B0ECB8
2012-07-14 13:59 - 2012-07-14 13:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9991B66838EDC5F
2012-07-14 13:56 - 2012-07-14 13:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7C441176282CAC65
2012-07-14 13:54 - 2012-07-14 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9B2CF4DE9208FE9D
2012-07-14 13:51 - 2012-07-14 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.947441CD4D02CFDF
2012-07-14 13:48 - 2012-07-14 13:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2FBDD06C4FCCC65
2012-07-14 13:45 - 2012-07-14 13:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ED197566D56949A4
2012-07-14 13:42 - 2012-07-14 13:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B1808447A6C0A6D
2012-07-14 13:39 - 2012-07-14 13:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7F672485F41B0D2
2012-07-14 13:36 - 2012-07-14 13:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B45F29A82D905D7E
2012-07-14 13:33 - 2012-07-14 13:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.91856CEFDFCC6C8D
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDE53A09F6906DB2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A54802710E5149C1
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.25294CF489D11D18
2012-07-14 13:22 - 2012-07-14 13:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68501F60356756E3
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.550DADD415F8F503
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EA28FC0C5F92C74
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60E2C6F036828E47
2012-07-14 13:11 - 2012-07-14 13:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.474EB7FEEC67C17A
2012-07-14 13:08 - 2012-07-14 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C161B1D73DEE9FD
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93FE3E8F47268A64
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6834BF7133352570
2012-07-14 12:47 - 2012-07-14 12:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.375DDB7ABB68E83B
2012-07-14 12:44 - 2012-07-14 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.53197AC98E6A2293
2012-07-14 10:41 - 2012-07-14 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6417BF20C60D483E
2012-07-14 10:37 - 2012-07-14 10:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.98596145A0AAB09C
2012-07-14 10:23 - 2012-07-14 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B2111472CBA8CEC
2012-07-14 10:19 - 2012-07-14 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.873C633BBE819F60
2012-07-14 10:16 - 2012-07-14 10:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E237F555F4A0B1
2012-07-14 10:13 - 2012-07-14 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC2FD36AC608F16
2012-07-14 10:03 - 2012-07-14 10:03 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-14 10:03 - 2012-07-14 10:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-14 09:59 - 2012-07-14 09:59 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 09:59 - 2012-07-14 09:59 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00000000 ____D C:\Program Files (x86)\Java
2012-07-10 16:45 - 2012-07-10 16:45 - 00005198 ____A C:\Users\Alex\Desktop\Käse-Dip - Verknüpfung.lnk
2012-07-10 16:36 - 2012-07-10 16:36 - 00005001 ____A C:\Users\Alex\Desktop\Avocado-Dip - Verknüpfung.lnk
2012-07-10 16:33 - 2012-07-10 16:33 - 00005707 ____A C:\Users\Alex\Desktop\Curry-Zwiebel-Soße - Verknüpfung.lnk
2012-07-10 16:28 - 2012-07-10 16:28 - 00005602 ____A C:\Users\Alex\Desktop\Whisky-Soße - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005488 ____A C:\Users\Alex\Desktop\Curry-Chili-Butter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005248 ____A C:\Users\Alex\Desktop\Limonen Kräuterbutter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005222 ____A C:\Users\Alex\Desktop\Bunte Pfefferbutter - Verknüpfung.lnk
2012-07-10 16:16 - 2012-07-10 16:16 - 00005752 ____A C:\Users\Alex\Desktop\Chili-Paprika-Chutney - Verknüpfung.lnk
2012-07-10 16:15 - 2012-07-10 16:15 - 00005662 ____A C:\Users\Alex\Desktop\Ketchup_Jamie O - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005679 ____A C:\Users\Alex\Desktop\Tacco-Salat - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005526 ____A C:\Users\Alex\Desktop\Cole Slaw_2 - Verknüpfung.lnk
2012-07-08 23:21 - 2012-07-08 23:21 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-03 19:46 - 2012-07-03 19:52 - 260253656 ____A (Avira GmbH) C:\Users\Alex\Downloads\rescue_system-common-en-020712.exe
2012-06-24 11:42 - 2012-06-02 23:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-24 11:42 - 2012-06-02 23:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-24 11:42 - 2012-06-02 23:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-24 11:42 - 2012-06-02 23:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-24 11:41 - 2012-06-02 23:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-24 11:41 - 2012-06-02 23:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-24 11:41 - 2012-06-02 23:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-24 11:41 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-24 11:41 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-15 21:22 - 2012-06-15 21:22 - 00000000 ____D C:\7dbb1aed4335ca44144be08d2d53
2012-06-14 13:29 - 2012-05-18 03:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 13:29 - 2012-05-18 03:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 13:29 - 2012-05-18 03:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 13:29 - 2012-05-18 02:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 13:29 - 2012-05-18 02:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 13:29 - 2012-05-18 02:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 13:29 - 2012-05-18 02:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 13:29 - 2012-05-18 02:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 13:29 - 2012-05-18 02:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 13:29 - 2012-05-18 02:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 13:29 - 2012-05-18 02:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 13:29 - 2012-05-18 02:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 13:29 - 2012-05-18 02:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 13:29 - 2012-05-18 02:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 13:29 - 2012-05-18 00:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 13:29 - 2012-05-17 23:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 13:29 - 2012-05-17 23:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 13:29 - 2012-05-17 23:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 13:29 - 2012-05-17 23:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 13:29 - 2012-05-17 23:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 13:29 - 2012-05-17 23:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 13:29 - 2012-05-17 23:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 13:29 - 2012-05-17 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 13:29 - 2012-05-17 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 13:29 - 2012-05-17 23:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 13:29 - 2012-05-17 23:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 13:29 - 2012-05-17 23:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 13:29 - 2012-05-17 23:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-14 11:37 - 2012-04-26 06:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-14 11:37 - 2012-04-26 06:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-14 11:37 - 2012-04-26 06:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-14 11:36 - 2012-05-15 02:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-14 11:36 - 2012-05-04 12:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-14 11:36 - 2012-05-04 11:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-14 11:36 - 2012-05-04 11:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-14 11:36 - 2012-05-01 06:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-14 11:36 - 2012-04-28 04:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-14 11:36 - 2012-04-24 06:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-14 11:36 - 2012-04-24 06:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-14 11:36 - 2012-04-24 06:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-14 11:36 - 2012-04-24 05:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-14 11:36 - 2012-04-07 13:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-14 11:36 - 2012-04-07 12:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-07-14 14:10 - 2009-07-14 00:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-14 14:09 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 14:08 - 2010-05-02 20:38 - 00044827 ____A C:\Windows\setupact.log
2012-07-14 14:07 - 2012-07-14 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94AD557CDA899F18
2012-07-14 14:04 - 2012-07-14 14:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27B35B8EC042082A
2012-07-14 14:02 - 2012-07-14 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EA3B4D7907B0ECB8
2012-07-14 13:59 - 2012-07-14 13:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9991B66838EDC5F
2012-07-14 13:56 - 2012-07-14 13:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7C441176282CAC65
2012-07-14 13:54 - 2012-07-14 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9B2CF4DE9208FE9D
2012-07-14 13:51 - 2012-07-14 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.947441CD4D02CFDF
2012-07-14 13:48 - 2012-07-14 13:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2FBDD06C4FCCC65
2012-07-14 13:45 - 2012-07-14 13:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ED197566D56949A4
2012-07-14 13:42 - 2012-07-14 13:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B1808447A6C0A6D
2012-07-14 13:39 - 2012-07-14 13:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7F672485F41B0D2
2012-07-14 13:36 - 2012-07-14 13:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B45F29A82D905D7E
2012-07-14 13:33 - 2012-07-14 13:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.91856CEFDFCC6C8D
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDE53A09F6906DB2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A54802710E5149C1
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.25294CF489D11D18
2012-07-14 13:22 - 2012-07-14 13:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68501F60356756E3
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.550DADD415F8F503
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EA28FC0C5F92C74
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60E2C6F036828E47
2012-07-14 13:11 - 2012-07-14 13:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.474EB7FEEC67C17A
2012-07-14 13:08 - 2012-07-14 13:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C161B1D73DEE9FD
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93FE3E8F47268A64
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6834BF7133352570
2012-07-14 12:47 - 2012-07-14 12:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.375DDB7ABB68E83B
2012-07-14 12:44 - 2012-07-14 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.53197AC98E6A2293
2012-07-14 10:41 - 2012-07-14 10:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6417BF20C60D483E
2012-07-14 10:37 - 2012-07-14 10:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.98596145A0AAB09C
2012-07-14 10:23 - 2012-07-14 10:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B2111472CBA8CEC
2012-07-14 10:19 - 2012-07-14 10:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.873C633BBE819F60
2012-07-14 10:16 - 2012-07-14 10:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E237F555F4A0B1
2012-07-14 10:13 - 2012-07-14 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC2FD36AC608F16
2012-07-14 10:04 - 2010-12-02 10:51 - 00001912 ____A C:\Windows\epplauncher.mif
2012-07-14 10:04 - 2010-02-11 22:00 - 01542552 ____A C:\Windows\WindowsUpdate.log
2012-07-14 10:03 - 2010-12-02 10:50 - 01527738 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-14 10:03 - 2010-02-12 06:50 - 00656528 ____A C:\Windows\System32\perfh007.dat
2012-07-14 10:03 - 2010-02-12 06:50 - 00131268 ____A C:\Windows\System32\perfc007.dat
2012-07-14 09:59 - 2012-07-14 09:59 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 09:59 - 2012-07-14 09:59 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 09:59 - 2012-07-14 09:59 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 09:59 - 2010-05-11 19:56 - 00472880 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-07-14 09:51 - 2009-07-14 05:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-14 09:51 - 2009-07-14 05:45 - 00013936 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:24 - 2011-09-28 10:14 - 00020624 ____A C:\Users\Alex\Desktop\Gartenpflanzen_2011.ods
2012-07-10 16:45 - 2012-07-10 16:45 - 00005198 ____A C:\Users\Alex\Desktop\Käse-Dip - Verknüpfung.lnk
2012-07-10 16:36 - 2012-07-10 16:36 - 00005001 ____A C:\Users\Alex\Desktop\Avocado-Dip - Verknüpfung.lnk
2012-07-10 16:33 - 2012-07-10 16:33 - 00005707 ____A C:\Users\Alex\Desktop\Curry-Zwiebel-Soße - Verknüpfung.lnk
2012-07-10 16:28 - 2012-07-10 16:28 - 00005602 ____A C:\Users\Alex\Desktop\Whisky-Soße - Verknüpfung.lnk
2012-07-10 16:21 - 2012-05-28 23:16 - 00017824 ____A C:\Users\Alex\Desktop\Geburtstag_Alex & Volker_2012.ods
2012-07-10 16:17 - 2012-07-10 16:17 - 00005488 ____A C:\Users\Alex\Desktop\Curry-Chili-Butter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005248 ____A C:\Users\Alex\Desktop\Limonen Kräuterbutter - Verknüpfung.lnk
2012-07-10 16:17 - 2012-07-10 16:17 - 00005222 ____A C:\Users\Alex\Desktop\Bunte Pfefferbutter - Verknüpfung.lnk
2012-07-10 16:16 - 2012-07-10 16:16 - 00005752 ____A C:\Users\Alex\Desktop\Chili-Paprika-Chutney - Verknüpfung.lnk
2012-07-10 16:15 - 2012-07-10 16:15 - 00005662 ____A C:\Users\Alex\Desktop\Ketchup_Jamie O - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005679 ____A C:\Users\Alex\Desktop\Tacco-Salat - Verknüpfung.lnk
2012-07-10 16:14 - 2012-07-10 16:14 - 00005526 ____A C:\Users\Alex\Desktop\Cole Slaw_2 - Verknüpfung.lnk
2012-07-03 19:52 - 2012-07-03 19:46 - 260253656 ____A (Avira GmbH) C:\Users\Alex\Downloads\rescue_system-common-en-020712.exe
2012-06-15 21:32 - 2009-07-14 06:13 - 01527382 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-15 21:25 - 2009-07-14 05:45 - 00337080 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 13:35 - 2010-03-02 20:11 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 23:19 - 2012-06-24 11:42 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-24 11:42 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-24 11:42 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-24 11:41 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-24 11:41 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:15 - 2012-06-24 11:42 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:15 - 2012-06-24 11:41 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-24 11:41 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-24 11:41 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-31 18:23 - 2009-07-14 06:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-18 03:47 - 2012-06-14 13:29 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-18 03:16 - 2012-06-14 13:29 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-18 03:06 - 2012-06-14 13:29 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-18 02:59 - 2012-06-14 13:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-18 02:59 - 2012-06-14 13:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-18 02:58 - 2012-06-14 13:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-18 02:58 - 2012-06-14 13:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-18 02:56 - 2012-06-14 13:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-18 02:55 - 2012-06-14 13:29 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-18 02:55 - 2012-06-14 13:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-18 02:54 - 2012-06-14 13:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-18 02:51 - 2012-06-14 13:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-18 02:51 - 2012-06-14 13:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-18 02:47 - 2012-06-14 13:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-18 00:11 - 2012-06-14 13:29 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 23:48 - 2012-06-14 13:29 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 23:45 - 2012-06-14 13:29 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 23:36 - 2012-06-14 13:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 23:35 - 2012-06-14 13:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 23:35 - 2012-06-14 13:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 23:33 - 2012-06-14 13:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 23:31 - 2012-06-14 13:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 23:29 - 2012-06-14 13:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 23:29 - 2012-06-14 13:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 23:27 - 2012-06-14 13:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 23:25 - 2012-06-14 13:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 23:24 - 2012-06-14 13:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 23:20 - 2012-06-14 13:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:32 - 2012-06-14 11:36 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 12:06 - 2012-06-14 11:36 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 11:03 - 2012-06-14 11:36 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 11:03 - 2012-06-14 11:36 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 06:40 - 2012-06-14 11:36 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-28 04:55 - 2012-06-14 11:36 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 06:41 - 2012-06-14 11:37 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 06:41 - 2012-06-14 11:37 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 06:34 - 2012-06-14 11:37 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 06:37 - 2012-06-14 11:36 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 06:37 - 2012-06-14 11:36 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 06:37 - 2012-06-14 11:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-24 05:36 - 2012-06-14 11:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\@
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\L
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\n
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\U
C:\Windows\Installer\{2365e920-423f-e779-4f9d-0324858bbbcc}\U\00000001.@
ZeroAccess:
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\@
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\L
C:\Users\Alex\AppData\Local\{2365e920-423f-e779-4f9d-0324858bbbcc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 4014.09 MB
Available physical RAM: 3371.36 MB
Total Pagefile: 4012.24 MB
Available Pagefile: 3359.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:456.5 GB) (Free:325.33 GB) NTFS
2 Drive e: (Recovery) (Fixed) (Total:9.17 GB) (Free:0.82 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (RAVENNA) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Datentr„ger ### Status Gr”áe Frei Dyn GPT
--------------- ------------- ------- ------- --- ---
Datentr„ger 0 Online 465 GB 0 B
Datentr„ger 1 Online 1912 MB 0 B
Partitions of Disk 0:
===============
Partition ### Typ GrӇe Offset
------------- ---------------- ------- -------
Partition 1 Wiederherstellun 9 GB 1024 KB
Partition 2 Prim„r 100 MB 9 GB
Partition 3 Prim„r 456 GB 9 GB
==================================================================================
Disk: 0
Partition 1
Typ : 27
Versteckt: Ja
Aktiv : Nein
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recovery NTFS Partition 9 GB Fehlerfre Versteck
==================================================================================
Disk: 0
Partition 2
Typ : 07
Versteckt: Nein
Aktiv : Ja
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Fehlerfre
==================================================================================
Disk: 0
Partition 3
Typ : 07
Versteckt: Nein
Aktiv : Nein
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 456 GB Fehlerfre
==================================================================================
Partitions of Disk 1:
===============
Partition ### Typ GrӇe Offset
------------- ---------------- ------- -------
Partition 1 Prim„r 1911 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Typ : 06
Versteckt: Nein
Aktiv : Ja
Volume ### Bst Bezeichnung DS Typ GrӇe Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G RAVENNA FAT Wechselmed 1911 MB Fehlerfre
==================================================================================
==========================================================
Last Boot: 2012-07-09 17:53
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 2012-07-14 15:52:31
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-14 00:19] - [2012-07-14 14:10] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======