|
Plagegeister aller Art und deren Bekämpfung: evtl. virus befall?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.09.2011, 01:07 | #1 | |
| evtl. virus befall? Hallo, ich habe ja seit neusten folgendes Problem. Alle virenscanner stürtzten mit fehlermeldung bei mir ab. Ich hatte die ganze zeit AVG free drauf und plötzlich abstürtze. Danach habe ich antivir und avast ausprobiert genau das selbe. Also irgendetwas stimmt ja hier nicht. Kann das mit einem virus zusammen hängen? Mein system ist Windows 7 64 Bit. Ich poste einmal die log von malwarebytes: Zitat:
|
22.09.2011, 12:19 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall? Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.
__________________Zitat:
__________________ |
22.09.2011, 13:41 | #3 | |
| evtl. virus befall? Hallo,
__________________ja sig ist schon ewig nicht mehr aktualisiert habs gerade mal nachgeholt. Habe jetzt mal geschaut unter logs sind keine weiteren vorhanden. Im moment läuft immernoch avast aber schutzkomponenten sind deaktiviert krieg die nicht mehr an. Habe gerade nochmal Malwarebytes aktualisiert und quickscan der hat auch was gefunden. Zitat:
Geändert von josy1982 (22.09.2011 um 14:05 Uhr) |
22.09.2011, 14:29 | #4 | |
| evtl. virus befall? hallo, habe noch die logs von avg rausgesucht: Zitat:
|
22.09.2011, 15:02 | #5 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall?Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
22.09.2011, 15:15 | #6 | |
| evtl. virus befall? Hab das programm entfernt: Zitat:
|
22.09.2011, 15:21 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall? Führ bitte auch ESET aus, danach sehen wir weiter: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
22.09.2011, 16:21 | #8 | |
| evtl. virus befall? So hier dann mal die log von eset: Zitat:
|
22.09.2011, 20:00 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall? CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
22.09.2011, 20:17 | #10 |
| evtl. virus befall? Hier das gewünschte log: OTL Logfile: Code:
ATTFilter OTL logfile created on: 22.09.2011 21:11:17 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\xxxxxxxxxx\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,75 Gb Total Physical Memory | 2,24 Gb Available Physical Memory | 59,85% Memory free 7,49 Gb Paging File | 5,51 Gb Available in Paging File | 73,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 451,32 Gb Total Space | 410,05 Gb Free Space | 90,86% Space Free | Partition Type: NTFS Drive D: | 14,15 Gb Total Space | 1,74 Gb Free Space | 12,31% Space Free | Partition Type: NTFS Drive E: | 609,99 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive F: | 99,02 Mb Total Space | 88,88 Mb Free Space | 89,76% Space Free | Partition Type: FAT32 Computer Name: xxxxxxxxxx-HP | User Name: xxxxxxxxxx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\xxxxxxxxxx\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company) PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS) PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS) PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS) ========== Modules (No Company Name) ========== MOD - C:\Users\xxxxxxxxxx\AppData\Local\Temp\3dcf2df1-2a83-477c-a7dd-858967792357\CliSecureRT.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\307dea1fa71faaa1c2dc0175487d9639\System.Management.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\bbc34aac73481fc04fe9b7aff9927437\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cadbfd56dbffb78f67b92027bd56862e\System.Xaml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\64d84a18bdebd88f137f11ec220748ff\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d23889e1eceadc97a6f227dbb392cb60\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\0e3eea502999efc06079a0f40a795731\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\6cf9069b4b5feb38824a79009ed9c7b4\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ea0f339fb15935f1878e115be1c04f8f\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\55b41158ada67f5b5a132e120e7de269\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2721a63758cab451543e8a58dc4ffeeb\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\6c4a0cae96fe506534d1ed4b8e905d04\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ffc825af968e2afbdd0d894b475331f3\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\93e7df09dacd5fef442cc22d28efec83\mscorlib.ni.dll () MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll () MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll () MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll () MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll () MOD - C:\Users\xxxxxxxxxx\AppData\Roaming\PictureMover\DE-DE\Presentation.dll () MOD - C:\Users\xxxxxxxxxx\AppData\Roaming\PictureMover\Bin\Core.dll () MOD - C:\Windows\SysWOW64\msjetoledb40.dll () ========== Win32 Services (SafeList) ========== SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.) SRV:64bit: - (HPClientSvc) -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) SRV:64bit: - (HPAuto) -- C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard) SRV:64bit: - (HP Wireless Assistant Service) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company) SRV:64bit: - (AMD Reservation Manager) -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Advanced Micro Devices) SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.) SRV - (CDMA Device Service) -- C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe () SRV - (avgwd) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (STacSV) -- C:\Programme\IDT\WDM\stacsv64.exe (IDT, Inc.) SRV - (HPWMISVC) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation) DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.) DRV:64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys () DRV:64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys () DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation) DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation) DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation) DRV:64bit: - (Avgtdia) -- C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.) DRV:64bit: - (AVGIDSFilter) -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. ) DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. ) DRV:64bit: - (AVGIDSEH) -- C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. ) DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.) DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.) DRV:64bit: - (StarPortLite) StarPort Storage Controller (Lite) -- C:\Windows\SysNative\drivers\StarPortLite.sys (Rocket Division Software) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (clwvd) -- C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation) DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\SysNative\drivers\AtiPcie64.sys (Advanced Micro Devices Inc.) DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices) DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices) DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices) DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.) DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.) DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell) DRV:64bit: - (netw5v64) Intel(R) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (HWiNFO32) -- C:\Programme\HWiNFO64\HWiNFO64A.SYS (REALiX(tm)) DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys () DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys () DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPNOT/4 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/4 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPNOT/4 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/4 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPNOT/4 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/4 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.facebook.com" FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011.09.20 19:12:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.16 06:59:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.16 06:59:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files (x86)\AVG\AVG2012\Thunderbird\ [2011.09.16 06:14:57 | 000,000,000 | ---D | M] [2011.09.16 05:47:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxxxxxxxxx\AppData\Roaming\mozilla\Extensions [2011.09.16 06:42:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2011.09.16 06:32:28 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011.09.16 06:42:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} [2011.09.20 19:12:48 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4 [2011.09.03 08:18:05 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.09.03 02:19:44 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.09.03 02:13:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011.09.03 02:19:44 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011.09.03 02:19:44 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011.09.03 02:19:44 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011.09.03 02:19:44 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe () O4:64bit: - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB46D7C1-6D3C-42BD-BFD5-2D1E3F745F82}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.) O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.09.22 17:43:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2011.09.22 17:43:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CrystalDiskInfo [2011.09.22 02:21:34 | 000,000,000 | ---D | C] -- C:\Temp [2011.09.22 02:21:03 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Samsung [2011.09.20 23:41:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2 [2011.09.20 23:40:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metin2 [2011.09.20 19:12:20 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011.09.20 14:50:03 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\Documents\StarBurn [2011.09.20 14:50:03 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\StarBurn [2011.09.20 01:20:13 | 000,000,000 | -H-D | C] -- C:\$AVG [2011.09.20 00:45:25 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\CrashDumps [2011.09.20 00:44:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miranda Fusion 3 [2011.09.20 00:44:53 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Miranda Fusion [2011.09.20 00:44:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MirandaFusion [2011.09.19 16:03:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview [2011.09.19 16:02:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders [2011.09.16 10:52:57 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [2011.09.16 10:52:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quake 4 Demo [2011.09.16 10:52:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\id Software [2011.09.16 09:39:10 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll [2011.09.16 09:38:53 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll [2011.09.16 08:30:26 | 000,000,000 | ---D | C] -- C:\7B219B681D82F2DA0C4CD51F [2011.09.16 08:28:30 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\TV-Browser [2011.09.16 08:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2011.09.16 08:20:07 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\Documents\samsung [2011.09.16 07:58:17 | 000,000,000 | ---D | C] -- C:\BDB599930F7B32ABE33D08B1B35A [2011.09.16 07:58:15 | 000,000,000 | ---D | C] -- C:\209B54B309E467D920 [2011.09.16 07:58:13 | 000,000,000 | ---D | C] -- C:\B4E5FB7EA5E216C29241714DBB [2011.09.16 07:46:47 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.4 [2011.09.16 07:46:47 | 000,000,000 | ---D | C] -- C:\Windows\ShellNew [2011.09.16 07:45:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LibreOffice 3.4 [2011.09.16 07:42:38 | 000,177,640 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdm.sys [2011.09.16 07:42:38 | 000,157,672 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadbus.sys [2011.09.16 07:42:38 | 000,016,872 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdfl.sys [2011.09.16 07:42:38 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwhnt.sys [2011.09.16 07:42:38 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys [2011.09.16 07:42:38 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcmnt.sys [2011.09.16 07:42:38 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys [2011.09.16 07:41:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2011.09.16 07:41:28 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll [2011.09.16 07:41:15 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\SysWow64\dgderapi.dll [2011.09.16 07:41:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny [2011.09.16 07:40:54 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Samsung [2011.09.16 07:40:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung [2011.09.16 07:40:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2011.09.16 07:40:08 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Downloaded Installations [2011.09.16 07:37:32 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Malwarebytes [2011.09.16 07:37:01 | 000,000,000 | ---D | C] -- C:\PlugIns [2011.09.16 07:36:23 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Ashampoo [2011.09.16 07:35:41 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\ashampoo [2011.09.16 07:35:41 | 000,000,000 | ---D | C] -- C:\ProgramData\ashampoo [2011.09.16 07:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo [2011.09.16 07:35:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo [2011.09.16 07:33:13 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment [2011.09.16 07:33:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment [2011.09.16 07:23:15 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment [2011.09.16 07:12:27 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\TS3Client [2011.09.16 07:12:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client [2011.09.16 07:12:10 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client [2011.09.16 07:10:55 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder x64 [2011.09.16 07:09:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.09.16 07:09:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.09.16 07:09:41 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.09.16 07:09:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011.09.16 07:09:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ MALWAREBYTES ANTI-MALWARE [2011.09.16 07:08:09 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Broad Intelligence [2011.09.16 07:08:08 | 000,000,000 | ---D | C] -- C:\Program Files\MediaCoder [2011.09.16 07:05:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter [2011.09.16 07:05:50 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\FreeVideoConverter [2011.09.16 07:05:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Video Converter [2011.09.16 06:59:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared [2011.09.16 06:59:04 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll [2011.09.16 06:59:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real [2011.09.16 06:58:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Real [2011.09.16 06:58:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real [2011.09.16 06:58:42 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Real [2011.09.16 06:57:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2011.09.16 06:57:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2011.09.16 06:57:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2011.09.16 06:56:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple [2011.09.16 06:56:38 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Apple [2011.09.16 06:56:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2011.09.16 06:56:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2011.09.16 06:55:34 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\COWON [2011.09.16 06:55:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jetAudio [2011.09.16 06:55:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\COWON [2011.09.16 06:55:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JetAudio [2011.09.16 06:48:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TV-Browser [2011.09.16 06:48:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TV-Browser [2011.09.16 06:47:08 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2011.09.16 06:43:25 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2011.09.16 06:42:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2011.09.16 06:42:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2011.09.16 06:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarBurn Software [2011.09.16 06:39:04 | 000,118,888 | ---- | C] (Rocket Division Software) -- C:\Windows\SysNative\drivers\StarPortLite.sys [2011.09.16 06:39:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StarBurn Software [2011.09.16 06:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64 [2011.09.16 06:38:20 | 000,000,000 | ---D | C] -- C:\Program Files\HWiNFO64 [2011.09.16 06:38:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune [2011.09.16 06:38:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HD Tune [2011.09.16 06:37:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP [2011.09.16 06:37:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EASEUS Partition Master 9.1.0 Home Edition [2011.09.16 06:37:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EASEUS [2011.09.16 06:37:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2011.09.16 06:37:21 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.09.16 06:37:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support [2011.09.16 06:35:23 | 000,000,000 | ---D | C] -- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837} [2011.09.16 06:32:49 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\CyberLink [2011.09.16 06:32:48 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\Documents\Youcam [2011.09.16 06:32:48 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\CyberLink [2011.09.16 06:32:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2011.09.16 06:29:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc [2011.09.16 06:29:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IZArc [2011.09.16 06:26:15 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe [2011.09.16 06:25:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2011.09.16 06:24:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2011.09.16 06:24:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2011.09.16 06:17:31 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\WindowsUpdate [2011.09.16 06:15:59 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\AVG2012 [2011.09.16 06:15:38 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2011.09.16 06:15:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012 [2011.09.16 06:15:30 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG [2011.09.16 06:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2011.09.16 06:14:54 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG [2011.09.16 06:14:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG [2011.09.16 06:13:18 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2011.09.16 06:00:43 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\ZumoDrive [2011.09.16 05:58:10 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Adobe [2011.09.16 05:54:42 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Skype [2011.09.16 05:54:38 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2011.09.16 05:54:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype [2011.09.16 05:48:25 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Mozilla [2011.09.16 05:47:23 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Mozilla [2011.09.16 05:47:22 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Thunderbird [2011.09.16 05:47:22 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Thunderbird [2011.09.16 05:47:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2011.09.16 05:46:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2011.09.16 05:43:30 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Macromedia [2011.09.16 05:43:26 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Adobe [2011.09.16 05:41:53 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\AMD [2011.09.16 05:41:46 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\ATI [2011.09.16 05:41:46 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\ATI [2011.09.16 05:41:44 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\PictureMover [2011.09.16 05:40:45 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\hpqLog [2011.09.16 05:40:43 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Synaptics [2011.09.16 05:40:28 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011.09.16 05:40:28 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Searches [2011.09.16 05:40:28 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011.09.16 05:40:20 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Identities [2011.09.16 05:40:17 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Contacts [2011.09.16 05:39:57 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\RemEngine [2011.09.16 05:39:00 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Hewlett-Packard [2011.09.16 05:38:55 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Hewlett-Packard [2011.09.16 05:38:41 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Hewlett-Packard_Company [2011.09.16 05:37:38 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\VirtualStore [2011.09.16 05:37:02 | 000,000,000 | --SD | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Videos [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Saved Games [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Pictures [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Music [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Links [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Favorites [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Downloads [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Documents [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\Desktop [2011.09.16 05:37:02 | 000,000,000 | R--D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Vorlagen [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Verlauf [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Temporary Internet Files [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Startmenü [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\SendTo [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Recent [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Netzwerkumgebung [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Lokale Einstellungen [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Documents\Eigene Videos [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Documents\Eigene Musik [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Eigene Dateien [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Documents\Eigene Bilder [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Druckumgebung [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Cookies [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Anwendungsdaten [2011.09.16 05:37:02 | 000,000,000 | -HSD | C] -- C:\Users\xxxxxxxxxx\Anwendungsdaten [2011.09.16 05:37:02 | 000,000,000 | -H-D | C] -- C:\Users\xxxxxxxxxx\AppData [2011.09.16 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Temp [2011.09.16 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Local\Microsoft [2011.09.16 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Media Center Programs [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Programme [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2011.09.16 05:36:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2011.09.16 05:35:07 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2011.09.14 18:38:35 | 000,000,000 | ---D | C] -- C:\Windows\ehome [2011.09.14 09:08:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2011.09.14 09:01:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft [2011.09.14 09:00:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2011.09.14 08:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2011.09.14 08:58:47 | 000,000,000 | ---D | C] -- C:\ProgramData\PictureMover [2011.09.14 08:58:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PictureMover [2011.09.14 08:58:33 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam [2011.09.14 08:55:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Energy Star [2011.09.14 08:54:50 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling [2011.09.14 08:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LightScribe [2011.09.14 08:52:26 | 000,000,000 | ---D | C] -- C:\Windows\Hewlett-Packard [2011.09.14 08:51:18 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom [2011.09.14 08:50:50 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2011.09.14 08:50:14 | 000,349,800 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys [2011.09.14 08:50:01 | 005,900,288 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNGUI.exe [2011.09.14 08:50:01 | 004,594,176 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll [2011.09.14 08:50:01 | 003,069,952 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNHP.dll [2011.09.14 08:50:01 | 000,968,192 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNX.dll [2011.09.14 08:50:01 | 000,564,224 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idt64mp1.exe [2011.09.14 08:50:01 | 000,524,800 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe [2011.09.14 08:50:01 | 000,438,784 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl [2011.09.14 08:50:01 | 000,211,968 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNJ.exe [2011.09.14 08:50:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SRSLabs [2011.09.14 08:49:34 | 000,520,192 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys [2011.09.14 08:49:34 | 000,220,160 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll [2011.09.14 08:49:33 | 001,497,088 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll [2011.09.14 08:49:33 | 000,651,264 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll [2011.09.14 08:49:33 | 000,431,616 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll [2011.09.14 08:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\IDT [2011.09.14 08:49:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\sda [2011.09.14 08:49:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek [2011.09.14 08:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics [2011.09.14 08:48:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies [2011.09.14 08:48:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies [2011.09.14 08:48:47 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2011.09.14 08:48:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center [2011.09.14 08:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD [2011.09.14 08:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies [2011.09.14 08:47:21 | 000,000,000 | ---D | C] -- C:\Program Files\ATI [2011.09.14 08:47:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies [2011.09.14 08:42:05 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.09.22 20:31:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.09.22 18:40:50 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.09.22 18:40:50 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.09.22 18:33:19 | 3015,888,896 | -HS- | M] () -- C:\hiberfil.sys [2011.09.22 17:43:42 | 000,001,940 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\CrystalDiskInfo.lnk [2011.09.22 14:41:36 | 104,899,240 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm [2011.09.22 02:20:31 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011.09.20 23:41:32 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\Metin2.lnk [2011.09.20 19:12:49 | 000,000,941 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.09.20 00:44:56 | 000,001,271 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\Miranda Fusion Configurator.lnk [2011.09.20 00:44:55 | 000,001,240 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\Miranda Fusion.lnk [2011.09.19 18:33:19 | 000,079,000 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm [2011.09.19 17:46:28 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.09.19 17:46:28 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.09.19 17:46:28 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.09.19 17:46:28 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.09.19 17:46:28 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.09.19 17:41:00 | 000,299,992 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011.09.16 10:52:42 | 000,002,041 | ---- | M] () -- C:\Users\Public\Desktop\Quake 4 Demo.lnk [2011.09.16 08:05:51 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf [2011.09.16 08:05:50 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf [2011.09.16 07:46:48 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\LibreOffice 3.4.lnk [2011.09.16 07:43:43 | 000,001,913 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk [2011.09.16 07:37:01 | 000,047,718 | ---- | M] () -- C:\Windows\unins000.dat [2011.09.16 07:37:01 | 000,013,156 | ---- | M] () -- C:\Windows\unins000.msg [2011.09.16 07:36:53 | 000,720,784 | ---- | M] () -- C:\Windows\unins000.exe [2011.09.16 07:35:41 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 8.lnk [2011.09.16 07:33:19 | 000,001,195 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\Perfect World International.lnk [2011.09.16 07:12:13 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2011.09.16 07:10:55 | 000,000,836 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\MediaCoder x64.lnk [2011.09.16 07:09:44 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.09.16 07:05:52 | 000,001,101 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\Free Video Converter.lnk [2011.09.16 06:59:04 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll [2011.09.16 06:55:21 | 000,001,781 | ---- | M] () -- C:\Users\Public\Desktop\jetAudio.lnk [2011.09.16 06:48:43 | 000,001,876 | ---- | M] () -- C:\Users\Public\Desktop\TV-Browser.lnk [2011.09.16 06:45:03 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForxxxxxxxxxx.job [2011.09.16 06:40:03 | 000,867,824 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys [2011.09.16 06:39:06 | 000,001,283 | ---- | M] () -- C:\Users\Public\Desktop\StarBurn.lnk [2011.09.16 06:38:38 | 000,000,830 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\HWiNFO64 Program.lnk [2011.09.16 06:38:08 | 000,000,886 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\HD Tune.lnk [2011.09.16 06:37:49 | 000,001,390 | ---- | M] () -- C:\Users\Public\Desktop\EASEUS Partition Master 9.1.0 Home Edition.lnk [2011.09.16 06:37:24 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.09.16 06:32:19 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2011.09.16 06:29:37 | 000,001,789 | ---- | M] () -- C:\Users\xxxxxxxxxx\Desktop\IZArc.lnk [2011.09.16 06:15:30 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm [2011.09.16 06:15:30 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm [2011.09.16 05:47:02 | 000,002,090 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk [2011.09.16 05:46:46 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011.09.16 05:36:15 | 000,052,870 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2011.09.16 05:36:15 | 000,052,870 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2011.09.14 08:58:47 | 000,002,029 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish PictureMover.lnk [2011.09.14 08:53:10 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin [2011.09.14 08:51:50 | 001,049,314 | ---- | M] () -- C:\Windows\SysNative\oem10.inf [2011.09.14 08:51:07 | 000,006,656 | ---- | M] () -- C:\Windows\SysNative\bcmwlrc.dll [2011.09.14 08:49:17 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf [2011.09.14 08:46:34 | 000,000,000 | RHS- | M] () -- C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion g6 Notebook PC_Y5335KV_0U_QCNF116707Q_E635093-041_4A_I1661_SHP_V20.21_BF.24_T110630_W73-0_L407_M3835_J500_7AMD_8F63_93.00_#110914_N_(LF141EA#ABD)_XMOBILE_CN10_Z_2059A100000204610000020100.MRK [2011.09.14 08:46:34 | 000,000,000 | RHS- | M] () -- C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion g6 Notebook PC_Y5335KV_0U_QCNF116707Q_E635093-041_4A_I1661_SHP_V20.21_BF.24_T110630_W73-0_L407_M3835_J500_7AMD_8F63_93.00_#110914_N_(LF141EA#ABD)_XMOBILE_CN10_Z_2059A100000204610000020100.MRK [2011.09.14 08:43:33 | 000,000,056 | -H-- | M] () -- C:\Windows\SysWow64\ezsidmv.dat [2011.09.09 18:23:34 | 002,469,760 | ---- | M] () -- C:\Windows\SysWow64\BootMan.exe [2011.09.07 17:06:40 | 003,321,728 | ---- | M] () -- C:\Windows\SysNative\BootMan.exe [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.09.22 17:43:42 | 000,001,940 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\CrystalDiskInfo.lnk [2011.09.22 14:41:36 | 104,899,240 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm [2011.09.22 02:20:31 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011.09.20 23:41:32 | 000,000,939 | ---- | C] () -- C:\Users\Public\Desktop\Metin2.lnk [2011.09.20 00:44:56 | 000,001,271 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\Miranda Fusion Configurator.lnk [2011.09.20 00:44:55 | 000,001,240 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\Miranda Fusion.lnk [2011.09.19 18:33:19 | 000,079,000 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm [2011.09.16 10:52:42 | 000,002,041 | ---- | C] () -- C:\Users\Public\Desktop\Quake 4 Demo.lnk [2011.09.16 09:39:59 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd [2011.09.16 09:38:34 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml [2011.09.16 09:38:22 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml [2011.09.16 09:38:22 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml [2011.09.16 09:38:07 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml [2011.09.16 08:05:51 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf [2011.09.16 08:05:50 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf [2011.09.16 07:46:48 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\LibreOffice 3.4.lnk [2011.09.16 07:43:43 | 000,001,913 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk [2011.09.16 07:37:01 | 000,013,156 | ---- | C] () -- C:\Windows\unins000.msg [2011.09.16 07:37:00 | 000,720,784 | ---- | C] () -- C:\Windows\unins000.exe [2011.09.16 07:37:00 | 000,047,718 | ---- | C] () -- C:\Windows\unins000.dat [2011.09.16 07:35:41 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Photo Commander 8.lnk [2011.09.16 07:33:19 | 000,001,195 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\Perfect World International.lnk [2011.09.16 07:12:13 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2011.09.16 07:10:55 | 000,000,836 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\MediaCoder x64.lnk [2011.09.16 07:09:44 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.09.16 07:05:52 | 000,001,101 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\Free Video Converter.lnk [2011.09.16 06:56:36 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2011.09.16 06:55:21 | 000,001,781 | ---- | C] () -- C:\Users\Public\Desktop\jetAudio.lnk [2011.09.16 06:48:43 | 000,001,876 | ---- | C] () -- C:\Users\Public\Desktop\TV-Browser.lnk [2011.09.16 06:41:02 | 000,000,344 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForxxxxxxxxxx.job [2011.09.16 06:40:03 | 000,867,824 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys [2011.09.16 06:39:06 | 000,001,283 | ---- | C] () -- C:\Users\Public\Desktop\StarBurn.lnk [2011.09.16 06:38:38 | 000,000,830 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\HWiNFO64 Program.lnk [2011.09.16 06:38:08 | 000,000,886 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\HD Tune.lnk [2011.09.16 06:37:49 | 000,001,390 | ---- | C] () -- C:\Users\Public\Desktop\EASEUS Partition Master 9.1.0 Home Edition.lnk [2011.09.16 06:37:47 | 003,321,728 | ---- | C] () -- C:\Windows\SysNative\BootMan.exe [2011.09.16 06:37:47 | 002,469,760 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe [2011.09.16 06:37:47 | 000,100,232 | ---- | C] () -- C:\Windows\SysNative\setupempdrvx64.exe [2011.09.16 06:37:47 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe [2011.09.16 06:37:47 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll [2011.09.16 06:37:47 | 000,016,776 | ---- | C] () -- C:\Windows\SysNative\epmntdrv.sys [2011.09.16 06:37:47 | 000,016,256 | ---- | C] () -- C:\Windows\SysNative\EuEpmGdi.dll [2011.09.16 06:37:47 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys [2011.09.16 06:37:47 | 000,009,096 | ---- | C] () -- C:\Windows\SysNative\EuGdiDrv.sys [2011.09.16 06:37:47 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys [2011.09.16 06:37:24 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.09.16 06:29:37 | 000,001,789 | ---- | C] () -- C:\Users\xxxxxxxxxx\Desktop\IZArc.lnk [2011.09.16 06:24:49 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2011.09.16 06:15:33 | 000,000,941 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.09.16 06:15:30 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm [2011.09.16 06:15:30 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm [2011.09.16 05:47:02 | 000,002,090 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk [2011.09.16 05:47:01 | 000,002,102 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk [2011.09.16 05:46:45 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011.09.16 05:46:44 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011.09.16 05:40:36 | 000,001,405 | ---- | C] () -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2011.09.16 05:40:29 | 000,001,399 | ---- | C] () -- C:\Users\xxxxxxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011.09.16 05:38:45 | 000,002,209 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicStation.lnk [2011.09.16 05:38:45 | 000,002,204 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk [2011.09.16 05:38:45 | 000,002,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish.lnk [2011.09.16 05:35:01 | 3015,888,896 | -HS- | C] () -- C:\hiberfil.sys [2011.09.14 18:39:11 | 000,048,265 | ---- | C] () -- C:\Windows\HomePremium.xml [2011.09.14 08:58:47 | 000,002,043 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish PictureMover.lnk [2011.09.14 08:58:47 | 000,002,029 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish PictureMover.lnk [2011.09.14 08:53:10 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011.09.14 08:51:56 | 001,049,314 | ---- | C] () -- C:\Windows\SysNative\oem10.inf [2011.09.14 08:51:19 | 000,006,656 | ---- | C] () -- C:\Windows\SysNative\bcmwlrc.dll [2011.09.14 08:50:14 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll [2011.09.14 08:49:17 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf [2011.09.14 08:46:34 | 000,000,000 | RHS- | C] () -- C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion g6 Notebook PC_Y5335KV_0U_QCNF116707Q_E635093-041_4A_I1661_SHP_V20.21_BF.24_T110630_W73-0_L407_M3835_J500_7AMD_8F63_93.00_#110914_N_(LF141EA#ABD)_XMOBILE_CN10_Z_2059A100000204610000020100.MRK [2011.09.14 08:46:34 | 000,000,000 | RHS- | C] () -- C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion g6 Notebook PC_Y5335KV_0U_QCNF116707Q_E635093-041_4A_I1661_SHP_V20.21_BF.24_T110630_W73-0_L407_M3835_J500_7AMD_8F63_93.00_#110914_N_(LF141EA#ABD)_XMOBILE_CN10_Z_2059A100000204610000020100.MRK [2011.09.14 08:44:19 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2011.09.14 08:44:14 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2011.09.14 08:43:33 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat [2011.07.26 17:26:48 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2011.07.26 17:26:46 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll [2011.07.26 17:26:46 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll [2011.07.26 17:26:46 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll [2011.07.26 17:26:46 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll [2011.01.11 05:05:09 | 000,000,202 | ---- | C] () -- C:\Windows\SysWow64\HPWA.ini [2011.01.11 04:58:13 | 000,009,988 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat [2010.12.17 04:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [2010.09.24 15:41:34 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL [2010.09.18 00:17:02 | 000,002,888 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2011.09.16 07:36:23 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Ashampoo [2011.09.16 06:15:59 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\AVG2012 [2011.09.16 07:08:09 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Broad Intelligence [2011.09.20 17:52:58 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\COWON [2011.09.16 07:05:50 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\FreeVideoConverter [2011.09.20 00:44:53 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Miranda Fusion [2011.09.16 05:41:46 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\PictureMover [2011.09.16 07:40:54 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Samsung [2011.09.20 14:50:03 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\StarBurn [2011.09.16 05:40:43 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Synaptics [2011.09.16 05:47:22 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\Thunderbird [2011.09.20 01:15:29 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\TS3Client [2011.09.22 18:44:11 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\TV-Browser [2011.09.16 06:00:49 | 000,000,000 | ---D | M] -- C:\Users\xxxxxxxxxx\AppData\Roaming\ZumoDrive [2009.07.14 07:08:49 | 000,007,174 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
22.09.2011, 20:53 | #11 |
| evtl. virus befall? Hier noch die andere log; OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 22.09.2011 21:11:17 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\xxxxxx\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,75 Gb Total Physical Memory | 2,24 Gb Available Physical Memory | 59,85% Memory free 7,49 Gb Paging File | 5,51 Gb Available in Paging File | 73,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 451,32 Gb Total Space | 410,05 Gb Free Space | 90,86% Space Free | Partition Type: NTFS Drive D: | 14,15 Gb Total Space | 1,74 Gb Free Space | 12,31% Space Free | Partition Type: NTFS Drive E: | 609,99 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive F: | 99,02 Mb Total Space | 88,88 Mb Free Space | 89,76% Space Free | Partition Type: FAT32 Computer Name: xxxxxx-HP | User Name: xxxxxx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0D0AD116-BE74-4ADD-9E80-83199F53370F}" = AVG 2012 "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1B6E46D9-BD48-F831-D337-64397E7EA1DB}" = ccc-utility64 "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{224EC8DF-BC76-4CE4-32B8-4D174318F7ED}" = WMV9/VC-1 Video Playback "{26A24AE4-039D-4CA4-87B4-2F86416027FF}" = Java(TM) 6 Update 27 (64-bit) "{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services "{44C05FED-4BA8-4C65-A39D-FA83451E6ACB}" = AVG 2012 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9EA86AD9-FB32-4B9E-BD56-3068F9B8031F}" = HP Wireless Assistant "{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{E18E155E-73A9-0CCA-B796-05B09A1B5D97}" = ATI Catalyst Install Manager "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FE87BA4F-9866-8332-0A4F-59864BE2196A}" = AMD Fuel "AVG" = AVG 2012 "Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter "CCleaner" = CCleaner "HWiNFO64_is1" = HWiNFO64 Version 3.86 "MediaCoder x64" = MediaCoder x64 2011 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamSpeak 3 Client" = TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0A9A553D-A324-4C3C-B6E9-2464480BAE50}" = Catalyst Control Center - Branding "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0F7254A8-4D75-979A-4445-EBC2EE90B6D2}" = CCC Help English "{124DB96E-CBF5-44FB-AB59-7D2444DEC777}" = HP On Screen Display "{14D9E133-37C6-B9CB-36C5-EB76DBE80F5C}" = Catalyst Control Center Graphics Previews Common "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{264FE20A-757B-492a-B0C3-4009E2997D8A}" = PictureMover "{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java(TM) 6 Update 27 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7 "{431D963B-16AA-FAB8-3E72-82CDB466FDD8}" = CCC Help Swedish "{49F633C6-1247-3052-F1F1-C3DC271A6E92}" = CCC Help Danish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{53CD60C7-12F9-420D-A9BF-EC8D815475A9}" = HP Documentation "{54C024E2-4761-EB23-88C5-77EE8977B854}" = CCC Help Polish "{5A018BC8-CEC4-C0E2-5EB1-4DFF3CD5E052}" = CCC Help Japanese "{5FE4D5BB-0B56-DC7D-E5A4-49DB989983CC}" = CCC Help French "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.1.0 "{6F388ED3-8C2B-222D-9CA6-38C44A3F4569}" = CCC Help Italian "{70E09E33-5C83-F272-17D5-93858F2063F2}" = CCC Help Dutch "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{7821C7B2-7E21-4CF3-925B-58B6A8BC6311}" = LibreOffice 3.4 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7D12AB72-6A28-A280-0637-485760AFDBDC}" = ccc-core-static "{802C068E-0576-4F25-8137-D54B7DB0FC5E}" = HP Setup "{81BAE41F-EF43-4902-773E-64B105245EE0}" = CCC Help Chinese Standard "{825C4BE0-5C73-4B05-A0BC-CB16F0C100D3}" = HP Software Framework "{82F6A47B-6651-0044-F871-AF99C15E4871}" = CCC Help German "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1.6 "{98218567-28F7-0D1F-BD48-3041677E5CD4}" = CCC Help Hungarian "{994406A3-EA5C-B7C9-B0C0-E9019ADD3521}" = CCC Help Korean "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A671E7CA-23EA-A86E-A61F-E518143670C0}" = CCC Help Thai "{A9AED85D-2194-F13C-EE99-F013DB2BD44F}" = CCC Help Russian "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AB32E35A-3CBE-6747-06A9-453469EF9CD2}" = CCC Help Chinese Traditional "{ABAF4569-6EDD-EA43-1574-EBA8911859BE}" = CCC Help Greek "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch "{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager "{AF306BD8-F9D1-4627-89B9-246E59074A05}" = HP Power Manager "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype "{B949352B-D05B-5670-836E-430CCAAE28FA}" = CCC Help Spanish "{BAB004F0-F04C-49DD-8118-AE4A7697C469}" = Quake 4(TM) Demo "{BC08BEE3-1503-0173-B7A5-8765AA20C08A}" = CCC Help Portuguese "{BCB2219D-A452-80E9-5C27-F497128DE10A}" = CCC Help Norwegian "{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo "{BD302920-E48F-EE44-4DBF-F58994C8BDF3}" = CCC Help Finnish "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C7231F7C-6530-4E65-ADA6-5B392CF5BEB1}" = Recovery Manager "{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime "{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}" = HP Support Assistant "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D2AC41BC-CA8B-846C-A711-42A2C8BC05BB}" = Catalyst Control Center InstallProxy "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D902BADB-499C-EF9E-B5D3-48B36566C3A6}" = Catalyst Control Center Localization All "{DA7B4F2B-0099-EEB6-6FB8-8F794248E982}" = CCC Help Czech "{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio Basic VX "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{EB58480C-0721-483C-B354-9D35A147999F}" = HP Quick Launch "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}" = LightScribe System Software "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Ashampoo Photo Commander 8_is1" = Ashampoo Photo Commander 8 v.8.4.0 "Ashampoo Photo Commander Plugin Pack_is1" = Ashampoo Photo Commander Plugin Pack "CrystalDiskInfo_is1" = CrystalDiskInfo 4.0.2 "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.0 Home Edition "Free Video Converter_is1" = Free Video Converter V 3.0 "HD Tune_is1" = HD Tune 2.55 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "InstallShield_{BAB004F0-F04C-49DD-8118-AE4A7697C469}" = Quake 4(TM) Demo "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300 "Metin2_is1" = Metin2 "MirandaFusion" = Miranda Fusion 3.0.22 "Mozilla Firefox 6.0.2 (x86 de)" = Mozilla Firefox 6.0.2 (x86 de) "Mozilla Thunderbird (6.0.2)" = Mozilla Thunderbird (6.0.2) "RealPlayer 12.0" = RealPlayer "StarBurn_is1" = StarBurn Version 13 (Build 0x20110818) "tvbrowser" = TV-Browser 3.0.2 "WinLiveSuite" = Windows Live Essentials ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 16.09.2011 00:05:15 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:05:15 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:07:02 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:07:02 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:07:42 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:07:42 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:08:07 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Iron Driver. System Error: Das System kann die angegebene Datei nicht finden. . Error - 16.09.2011 00:08:07 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Network Security WFP Driver. System Error: Das System kann die angegebene Datei nicht finden. . [ HP Wireless Assistant Events ] Error - 15.09.2011 23:59:46 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:00:54 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:02:02 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:03:11 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:04:19 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:05:28 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:06:36 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:07:43 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:08:52 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() Error - 16.09.2011 00:10:00 | Computer Name = xxxxxx-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Der RPC-Server ist nicht verfügbar. (Ausnahme von HRESULT: 0x800706BA) bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) bei System.Management.ManagementScope.InitializeGuts(Object o) bei System.Management.ManagementScope.Initialize() bei System.Management.ManagementObject.Initialize(Boolean getObject) bei System.Management.ManagementBaseObject.get_Properties() bei System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) bei HPPA_Service.CurrentConfiguration.<ReloadRadioList>b__c() [ System Events ] Error - 16.09.2011 00:10:00 | Computer Name = xxxxxx-HP | Source = DCOM | ID = 10009 Description = Error - 16.09.2011 01:43:25 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7030 Description = Der Dienst "CDMA Device Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 16.09.2011 02:13:12 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%32 Error - 16.09.2011 02:19:01 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%16405 Error - 16.09.2011 02:21:55 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80242016 fehlgeschlagen: Update für die Kompatibilitätsansichtsliste für Internet Explorer*8 für Windows 7 für x64-basierte Systeme (KB2447568) Error - 16.09.2011 02:21:55 | Computer Name = xxxxxx-HP | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80242016 fehlgeschlagen: Sicherheitsupdate für Internet Explorer 8 unter Windows 7 für x64-basierte Systeme (KB2544521) Error - 16.09.2011 03:47:26 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7043 Description = Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error - 16.09.2011 04:23:35 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7043 Description = Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error - 16.09.2011 04:51:25 | Computer Name = xxxxxx-HP | Source = DCOM | ID = 10001 Description = Error - 19.09.2011 16:55:49 | Computer Name = xxxxxx-HP | Source = Service Control Manager | ID = 7011 Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. < End of report > |
22.09.2011, 21:04 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall? Ziemlich unauffällig. Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________ Logfiles bitte immer in CODE-Tags posten |
28.09.2011, 12:43 | #13 | |
| evtl. virus befall? So hier noch das andere log : Zitat:
|
28.09.2011, 13:55 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | evtl. virus befall? Nur SPTD. Ist der Treiber für emulierte (virtuelle) DVD/CD Laufwerke. Wollen wir noch tiefer buddeln?
__________________ Logfiles bitte immer in CODE-Tags posten |
28.09.2011, 14:40 | #15 |
| evtl. virus befall? SPTD stimmt ist für virtuelles laufwerk das ist schon ok. Ja weiss ich nicht ob man noch gründlicher schauen muss wenn du der meinung bist das wir noch tiefgründiger schauen sollten dann machen wir das. |
Themen zu evtl. virus befall? |
anti-malware, antivir, avast, avg, befall, dateien, explorer, fehlermeldung, folge, folgendes, free, hängen, log, malwarebytes, minute, neuste, plötzlich, scan, scanner, service, version, virenscan, virenscanner, virus, virus befall, zusammen |