![]() |
Log-Analyse und Auswertung: Verschlüsselungstrojaner! (flirt-fever.de)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Liebes Forum, Auch ich bin auf einen Verschlüsselungstrojaner hereingefallen und nachdem ich mich erstmal kräftig in den A**** gebissen habe (Anfängerfehler!) muss ich nun den Computer wieder hinkriegen. Also ich erhielt folgende Mail und hatte schneller auf den Anhang geklickt als ich nachdenken konnte - zu spät: ------------------------------------------------------------------ ***** Buchung von Flirt-Fever AG Nummer Date: Tuesday, 5 Jun 2012 13:25 From: santa@claussanta.com To: "*****" <*****@******.***> Attachments: 05.06.2012.zip (44K) Lieber Benutzer *****, wir mussten leider feststellen, dass unsere Rechnung NR.: 9075365759 für den Nutzer ***** immer noch nicht ausgeglichen wurde. Dies bedeutet einen rechtskräftigen Vertragsbruch von Ihnen. Nach geltendem Recht könnten wir die offenen Kosten bereits jetzt durch Gericht anmelden. Wir geben Ihnen trotzdem noch eine letzte Möglichkeit, Ihre Verpflichtung zu erfüllen, indem Sie innerhalb von 3 Tagen die ausstehende Summe in Höhe von 422.00 EURO an uns zahlen. Die erbrachten Leistungen und die Kontodaten können Sie im zugefügten Ordner ansehen. Bitte beachten Sie, die Folgen des Verzugs bestehen vor allem in der Regresspflicht des Schuldners sowie in einer verschärften Haftung. Flirt-Fever DE mit Stand in Bremen Amtsgericht: Köln Leiter: ----------------------------------------------------------------- Kurze Zeit später stellte ich fest dass ein Teil - nicht alle - meiner Office- und pdf-Dateien nicht mehr zu öffnen waren bzw. nur Hieroglyphen enthielten. Der Dateiname blieb der alte. Eine Zeitlang passierte sonst nicht plötzlich startete jedoch mein PC von selbst neu und nach dem Neustart wurde nach kurzer Zeit ein Bild eingeblendet welches eine Aufforderung enthielt ein kostenpflichtiges Windowsupdate durchzuführen. Dieses Bild ließ sich weder wegklicken noch im Taskmanager beenden so dass ich den PC im abgesicherter Modus neustarten musste um diese Zeilen zu tippen. Aus diesem Grund kann ich davon auch keine Screenshot posten. Die Mail hab ich ans Trojaner-Board gemailt (N1P-I3ohLp-fm5.eml). Gerade läuft der Malwarebytes-Scan. Wenn dieser beendet ist werde ich weitere Informationen posten. Vielen Dank schonmal! So der Suchlauf ist beendet, Schädlinge (hoffentlich beseitigte) und Computer läuft auch wieder. Das ist der Inhalt der Logdatei: -------------------------------------------------------------------- Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2012.06.06.02 Windows 7 Service Pack 1 x86 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 9.0.8112.16421 ***** :: *****-PC [Administrator] Schutz: Deaktiviert 06.06.2012 12:22:17 mbam-log-2012-06-06 (12-22-17).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 583247 Laufzeit: 3 Stunde(n), 1 Minute(n), 32 Sekunde(n) [Abgebrochen] Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|885497D9 (Trojan.Agent) -> Daten: C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\*****\AppData\Local\Temp\ilhhrbssnz.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\*****\Downloads\DecryptHelper-0.5.3.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) -------------------------------------------------------------------- Bin dann weiter nach dem "Vorgehen beim Verschlüsselungstrojaner" vorgegangen: - Entschlüsselungsversuche mit "Decrypthelper" und "AviraRansom" bisher erfolglos bin zu mehr noch nicht gekommen - Defogger ohne Fehlermeldung otl.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 06.06.2012 15:32:20 - Run 1 OTL by OldTimer - Version Folder = C:\Users\*****\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free 5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS Computer Name: *****-PC | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.06.06 12:44:41 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe PRC - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\System Update\SUService.exe PRC - [2012.05.02 01:52:12 | 000,047,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\updrgui.exe PRC - [2012.05.02 01:48:57 | 000,613,328 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\update.exe PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.02 00:42:11 | 000,210,896 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avnotify.exe PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PRC - [2012.04.22 13:50:44 | 000,174,120 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PRC - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe PRC - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe PRC - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe PRC - [2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Program Files\Samsung\Kies\KiesHelper.exe PRC - [2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\DeviceManager.exe PRC - [2012.03.28 22:11:58 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\ConnectionManager.exe PRC - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE PRC - [2012.03.15 06:07:00 | 000,128,576 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe PRC - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe PRC - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe PRC - [2011.10.20 12:09:32 | 000,363,584 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe PRC - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe PRC - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe PRC - [2011.10.20 10:58:46 | 000,101,440 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\LENOVO\VIRTSCRL\virtscrl.exe PRC - [2011.07.14 16:50:56 | 000,057,672 | ---- | M] (Authentec Inc.) -- C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe PRC - [2011.07.12 18:03:32 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe PRC - [2011.07.12 17:17:04 | 000,138,680 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Zoom\TpScrex.exe PRC - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe PRC - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe PRC - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files\GNU\GnuPG\dirmngr.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.24 12:35:46 | 000,804,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe PRC - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe PRC - [2010.11.20 05:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe PRC - [2010.04.23 01:16:46 | 000,128,296 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2009.01.26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE ========== Modules (No Company Name) ========== MOD - [2012.06.05 14:19:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll MOD - [2012.06.05 14:16:30 | 000,762,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll MOD - [2012.06.05 14:16:17 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll MOD - [2012.06.05 14:01:19 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\041b1bcf6ae9ab58925791d8198c37e2\PresentationFramework.ni.dll MOD - [2012.06.05 14:00:46 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1de74c8d0dfd15e3246e5dd394013bf\PresentationCore.ni.dll MOD - [2012.06.05 14:00:24 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\4b7adff986a085bb562222d0c5fdf5aa\WindowsBase.ni.dll MOD - [2012.06.05 14:00:17 | 013,197,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9ee9841d9e33fe5dceba4cd7d90f2ae0\System.Windows.Forms.ni.dll MOD - [2012.06.05 14:00:06 | 001,665,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\03b5233f1511f5fdb39eb681b04e5506\System.Drawing.ni.dll MOD - [2012.06.05 14:00:05 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll MOD - [2012.06.05 14:00:03 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll MOD - [2012.06.05 14:00:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll MOD - [2012.06.05 13:59:54 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll MOD - [2012.06.05 13:59:42 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll MOD - [2012.04.23 22:02:06 | 000,115,137 | ---- | M] () -- C:\Users\*****\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll MOD - [2012.04.13 07:13:59 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\c2c7f68605a42caef1b7a19c51de58b4\System.ServiceProcess.ni.dll MOD - [2012.04.13 07:13:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43e23da6683962ea1168aaf007bbc35d\PresentationFramework.ni.dll MOD - [2012.04.13 07:12:07 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\74d980e52c1791f1b8608d767a393144\PresentationCore.ni.dll MOD - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MOD - [2012.03.30 03:23:38 | 000,079,872 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.FileService.dll MOD - [2012.03.30 03:21:48 | 014,144,512 | ---- | M] () -- C:\Program Files\Samsung\Kies\Theme\Kies.Theme.dll MOD - [2012.03.30 03:21:18 | 000,486,912 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.UI.dll MOD - [2012.03.30 03:21:12 | 000,034,304 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.Interface.dll MOD - [2012.03.29 18:44:34 | 000,022,528 | ---- | M] () -- C:\Program Files\Samsung\Kies\MVVM\Kies.MVVM.dll MOD - [2012.03.28 22:13:12 | 000,037,376 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\ASF_cSharpAPI.dll MOD - [2012.03.28 22:12:04 | 000,839,680 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\System.Data.SQLite.dll MOD - [2012.03.28 22:12:00 | 000,712,704 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\SHOWDRM_UCC.dll MOD - [2012.03.28 22:11:58 | 000,237,568 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\drmcm.dll MOD - [2012.03.28 22:11:28 | 000,720,896 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\MediaModules\LDBCShConv.dll MOD - [2012.03.18 13:08:34 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll MOD - [2012.03.18 13:06:32 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll MOD - [2012.03.18 13:05:59 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll MOD - [2012.03.18 13:05:57 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.ni.dll MOD - [2012.03.18 13:05:56 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9e8dfbd1334d30a08ce1f2df29ca9aff\System.Transactions.ni.dll MOD - [2012.03.18 13:05:55 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll MOD - [2012.03.18 13:04:32 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll MOD - [2012.03.18 13:04:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll MOD - [2012.03.18 13:04:15 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll MOD - [2012.03.18 13:04:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll MOD - [2012.03.18 13:03:50 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll MOD - [2012.03.15 06:07:00 | 000,094,208 | ---- | M] () -- C:\PROGRA~2\ThinkPad\UTILIT~1\GR\PWMRT32V.DLL MOD - [2012.02.20 22:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.02.20 22:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf MOD - [2011.03.02 17:18:28 | 000,656,384 | ---- | M] () -- C:\Program Files\GNU\GnuPG\gpgex.dll MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll MOD - [2010.11.04 18:58:06 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\\System.Data.dll MOD - [2009.07.14 10:47:20 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\\PresentationFramework.resources.dll MOD - [2009.07.14 10:47:15 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\\System.Xml.resources.dll MOD - [2009.07.14 10:47:15 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\\System.Configuration.resources.dll MOD - [2009.07.14 10:47:11 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceProcess.resources\\System.ServiceProcess.resources.dll MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\\System.Transactions.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService) SRV - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService) SRV - [2012.05.10 23:34:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.10 20:14:07 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) Intel(R) SRV - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R) SRV - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R) SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.03.15 06:07:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service) SRV - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) [On_Demand | Running] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc) SRV - [2012.03.15 06:07:00 | 000,165,440 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE -- (PwmEWSvc) SRV - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R) SRV - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe -- (AcSvc) SRV - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc) SRV - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC) SRV - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe -- (TPHKLOAD) SRV - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe -- (LENOVO.MICMUTE) SRV - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe -- (TPHKSVC) SRV - [2011.06.12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Program Files\GNU\GnuPG\dirmngr.exe -- (DirMngr) SRV - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2010.11.20 05:19:34 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\Mcx2Svc.dll -- (Mcx2Svc) SRV - [2010.11.04 18:52:40 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing) SRV - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess) SRV - [2009.07.14 03:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.03.15 06:07:00 | 000,025,416 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD) DRV - [2012.03.15 06:07:00 | 000,017,736 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPALP) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPAL) DRV - [2012.02.24 11:14:42 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) DRV - [2012.02.24 11:14:42 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) DRV - [2012.01.09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2012.01.09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011.12.27 03:10:35 | 000,033,080 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd) DRV - [2011.10.14 19:25:10 | 000,231,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6232.sys -- (e1express) Intel(R) DRV - [2011.05.30 18:21:24 | 000,011,976 | ---- | M] (Authentec Inc.) [Kernel | Auto | Running] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) SMI Helper Driver (smihlp) DRV - [2011.05.18 09:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB) DRV - [2011.03.29 20:14:08 | 000,122,992 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf) DRV - [2011.03.29 20:12:16 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN) DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 05:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 05:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 05:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 03:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 02:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 02:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 02:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.11.20 01:42:30 | 000,246,784 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\udfs.sys -- (udfs) DRV - [2010.10.07 04:11:38 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32) Intel(R) DRV - [2010.09.27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2010.09.07 14:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.04.08 23:11:06 | 000,045,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt) DRV - [2009.07.14 03:20:28 | 000,022,096 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk) DRV - [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009.07.14 01:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2009.07.14 01:11:15 | 000,070,656 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\cdfs.sys -- (cdfs) DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R) DRV - [2008.11.16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE) DRV - [2007.06.21 18:36:32 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2007.01.18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006.11.27 18:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 3E 0E A8 02 43 CD 01 [binary data] IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012.03.18 13:26:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.10 23:34:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.03.21 21:21:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012.03.16 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions [2012.06.02 17:08:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\q8lojr9q.default\extensions [2012.03.16 23:29:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.05.10 23:34:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.03.13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.03.16 23:36:18 | 000,441,475 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: 1001namen.com O1 - Hosts: www.1001namen.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: www.10sek.com O1 - Hosts: 10sek.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 1-2005-search.com O1 - Hosts: www.123fporn.info O1 - Hosts: 15172 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe (Lenovo) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe (Authentec Inc.) O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor File not found O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: &Citavi Picker... - C:\ProgramData\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html () O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: microsoft.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites) O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites) O15 - HKCU\..Trusted Domains: windowsupdate.com ([]* in Trusted sites) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3222A70D-BED3-44EB-9A27-3D895F894144}: DhcpNameServer = O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - Unable to obtain root file information for disk G:\ O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - J:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.06.06 12:19:53 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Malwarebytes [2012.06.06 12:19:49 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.06.06 12:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.06.06 09:49:46 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\avira [2012.06.06 08:30:28 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl [2012.06.05 13:41:03 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Avira [2012.06.05 13:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.06.05 13:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2012.06.05 13:35:18 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2012.06.05 13:35:18 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2012.06.05 13:35:18 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys [2012.06.05 13:35:18 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.06.05 12:59:18 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2 [2012.06.05 12:55:37 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\InstallShield [2012.06.05 12:54:12 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012.06.05 12:14:13 | 000,000,000 | -H-D | C] -- C:\Windows\System32\WLANProfiles [2012.06.05 12:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2012.06.05 12:11:46 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco [2012.06.05 12:06:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll [2012.06.05 12:06:32 | 000,000,000 | ---D | C] -- C:\Intel [2012.06.05 12:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab [2012.06.05 12:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2012.06.05 12:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.06.05 12:03:12 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle [2012.06.05 12:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012.06.05 11:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage [2012.06.02 17:49:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage [2012.06.02 16:58:05 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox [2012.06.02 16:57:15 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Dropbox [2012.05.29 22:27:12 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PwrMgr [2012.05.29 18:24:47 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Lenovo [2012.05.29 18:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SPBA [2012.05.29 18:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkVantage Fingerprint Software [2012.05.29 18:10:23 | 000,000,000 | ---D | C] -- C:\SWTOOLS [2012.05.29 18:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo [2012.05.21 19:41:48 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Nokia [2012.05.21 19:35:10 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\NokiaAccount [2012.05.21 19:33:59 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Nokia [2012.05.21 19:33:58 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite [2012.05.21 19:33:55 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PC Suite [2012.05.21 19:33:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia [2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Nokia [2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia [2012.05.21 19:32:19 | 000,018,816 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys [2012.05.21 19:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution [2012.05.21 19:31:44 | 000,075,264 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll [2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\ProgramData\NokiaInstallerCache [2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\Nokia [2012.05.18 22:04:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Media Player Classic [2012.05.16 09:07:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net [2012.05.11 22:04:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2012.05.11 22:03:10 | 000,000,000 | ---D | C] -- C:\Program Files\Google [2012.05.11 22:03:07 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Google [2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.06.06 15:31:53 | 000,694,430 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2012.06.06 15:31:53 | 000,693,454 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2012.06.06 15:31:53 | 000,691,192 | ---- | M] () -- C:\Windows\System32\perfh013.dat [2012.06.06 15:31:53 | 000,689,726 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012.06.06 15:31:53 | 000,689,108 | ---- | M] () -- C:\Windows\System32\perfh010.dat [2012.06.06 15:31:53 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat [2012.06.06 15:31:53 | 000,675,958 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2012.06.06 15:31:53 | 000,663,804 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2012.06.06 15:31:53 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.06.06 15:31:53 | 000,632,180 | ---- | M] () -- C:\Windows\System32\perfh00E.dat [2012.06.06 15:31:53 | 000,623,144 | ---- | M] () -- C:\Windows\System32\perfh005.dat [2012.06.06 15:31:53 | 000,617,568 | ---- | M] () -- C:\Windows\System32\perfh01D.dat [2012.06.06 15:31:53 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.06.06 15:31:53 | 000,610,202 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2012.06.06 15:31:53 | 000,551,770 | ---- | M] () -- C:\Windows\System32\perfh008.dat [2012.06.06 15:31:53 | 000,462,172 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2012.06.06 15:31:53 | 000,448,586 | ---- | M] () -- C:\Windows\System32\perfh014.dat [2012.06.06 15:31:53 | 000,434,486 | ---- | M] () -- C:\Windows\System32\perfh001.dat [2012.06.06 15:31:53 | 000,433,388 | ---- | M] () -- C:\Windows\System32\perfh00B.dat [2012.06.06 15:31:53 | 000,399,736 | ---- | M] () -- C:\Windows\System32\perfh012.dat [2012.06.06 15:31:53 | 000,388,518 | ---- | M] () -- C:\Windows\System32\perfh011.dat [2012.06.06 15:31:53 | 000,377,870 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2012.06.06 15:31:53 | 000,361,768 | ---- | M] () -- C:\Windows\System32\prfh0804.dat [2012.06.06 15:31:53 | 000,353,522 | ---- | M] () -- C:\Windows\System32\perfh00D.dat [2012.06.06 15:31:53 | 000,148,310 | ---- | M] () -- C:\Windows\System32\perfc00E.dat [2012.06.06 15:31:53 | 000,137,062 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2012.06.06 15:31:53 | 000,134,840 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012.06.06 15:31:53 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat [2012.06.06 15:31:53 | 000,132,940 | ---- | M] () -- C:\Windows\System32\perfc013.dat [2012.06.06 15:31:53 | 000,132,516 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2012.06.06 15:31:53 | 000,130,140 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2012.06.06 15:31:53 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.06.06 15:31:53 | 000,128,094 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2012.06.06 15:31:53 | 000,127,144 | ---- | M] () -- C:\Windows\System32\perfc010.dat [2012.06.06 15:31:53 | 000,123,740 | ---- | M] () -- C:\Windows\System32\perfc01D.dat [2012.06.06 15:31:53 | 000,121,788 | ---- | M] () -- C:\Windows\System32\perfc005.dat [2012.06.06 15:31:53 | 000,121,526 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc011.dat [2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.06.06 15:31:53 | 000,104,676 | ---- | M] () -- C:\Windows\System32\perfc012.dat [2012.06.06 15:31:53 | 000,104,248 | ---- | M] () -- C:\Windows\System32\prfc0804.dat [2012.06.06 15:31:53 | 000,099,334 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2012.06.06 15:31:53 | 000,089,436 | ---- | M] () -- C:\Windows\System32\perfc008.dat [2012.06.06 15:31:53 | 000,082,148 | ---- | M] () -- C:\Windows\System32\perfc00B.dat [2012.06.06 15:31:53 | 000,079,804 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2012.06.06 15:31:53 | 000,078,984 | ---- | M] () -- C:\Windows\System32\perfc001.dat [2012.06.06 15:31:53 | 000,077,096 | ---- | M] () -- C:\Windows\System32\perfc014.dat [2012.06.06 15:31:53 | 000,069,094 | ---- | M] () -- C:\Windows\System32\perfc00D.dat [2012.06.06 15:31:03 | 000,000,000 | ---- | M] () -- C:\Users\*****\defogger_reenable [2012.06.06 15:27:10 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.06.06 15:27:10 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr [2012.06.06 15:27:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.06.06 15:26:52 | 2414,682,112 | -HS- | M] () -- C:\hiberfil.sys [2012.06.06 12:19:50 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.06 12:08:23 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.06.06 10:14:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.06.05 12:14:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.04 22:07:07 | 1363,885,269 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.06.04 20:38:06 | 009,299,786 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.06.04 18:10:48 | 000,007,168 | ---- | M] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.05.29 21:32:20 | 1453,899,807 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.05.21 19:35:46 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf [2012.05.21 19:35:23 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf [2012.05.17 21:41:46 | 1453,921,921 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Der Wald steht schwarz und schweiget - Sonntag, 13.05.2012 Das Erste.flv [2012.05.10 23:05:08 | 1460,780,570 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Tatort Die Ballade von Cenk und Valerie - Sonntag, 06.05.2012 Das Erste.flv [1 C:\Windows\System32\drivers\UMDF\*.tmp files -> C:\Windows\System32\drivers\UMDF\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.06.06 15:31:03 | 000,000,000 | ---- | C] () -- C:\Users\*****\defogger_reenable [2012.06.06 15:27:10 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr [2012.06.06 12:19:50 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.05 12:14:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.05 11:52:43 | 000,002,088 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Device Experience.lnk [2012.06.05 11:52:42 | 000,002,476 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools.lnk [2012.05.21 19:35:46 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf [2012.05.21 19:35:23 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf [2012.05.11 22:03:13 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.05.11 22:03:12 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.05.10 22:27:38 | 000,007,168 | ---- | C] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.04.18 19:00:07 | 000,000,100 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc [2012.03.28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2012.03.27 17:27:16 | 000,037,046 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Kommagetrennte Werte (Windows).ADR [2012.03.18 04:58:31 | 000,617,568 | ---- | C] () -- C:\Windows\System32\perfh01D.dat [2012.03.18 04:58:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat [2012.03.18 04:58:31 | 000,123,740 | ---- | C] () -- C:\Windows\System32\perfc01D.dat [2012.03.18 04:58:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat [2012.03.18 04:58:30 | 000,691,192 | ---- | C] () -- C:\Windows\System32\perfh013.dat [2012.03.18 04:58:30 | 000,632,180 | ---- | C] () -- C:\Windows\System32\perfh00E.dat [2012.03.18 04:58:30 | 000,353,522 | ---- | C] () -- C:\Windows\System32\perfh00D.dat [2012.03.18 04:58:30 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat [2012.03.18 04:58:30 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat [2012.03.18 04:58:30 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat [2012.03.18 04:58:30 | 000,148,310 | ---- | C] () -- C:\Windows\System32\perfc00E.dat [2012.03.18 04:58:30 | 000,069,094 | ---- | C] () -- C:\Windows\System32\perfc00D.dat [2012.03.18 04:58:30 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat [2012.03.18 04:58:30 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat [2012.03.18 04:58:30 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat [2012.03.18 04:58:29 | 000,388,518 | ---- | C] () -- C:\Windows\System32\perfh011.dat [2012.03.18 04:58:29 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat [2012.03.18 04:58:29 | 000,132,940 | ---- | C] () -- C:\Windows\System32\perfc013.dat [2012.03.18 04:58:29 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc011.dat [2012.03.18 04:58:29 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat [2012.03.18 00:04:25 | 000,551,770 | ---- | C] () -- C:\Windows\System32\perfh008.dat [2012.03.18 00:04:25 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat [2012.03.18 00:04:25 | 000,089,436 | ---- | C] () -- C:\Windows\System32\perfc008.dat [2012.03.18 00:04:25 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat [2012.03.17 23:25:14 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat [2012.03.17 23:25:13 | 000,689,108 | ---- | C] () -- C:\Windows\System32\perfh010.dat [2012.03.17 23:25:13 | 000,127,144 | ---- | C] () -- C:\Windows\System32\perfc010.dat [2012.03.17 23:25:13 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat [2012.03.17 23:02:46 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat [2012.03.17 23:02:45 | 000,434,486 | ---- | C] () -- C:\Windows\System32\perfh001.dat [2012.03.17 23:02:45 | 000,078,984 | ---- | C] () -- C:\Windows\System32\perfc001.dat [2012.03.17 23:02:45 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat [2012.03.17 22:41:24 | 000,679,342 | ---- | C] () -- C:\Windows\System32\prfh0816.dat [2012.03.17 22:41:24 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat [2012.03.17 22:41:24 | 000,133,752 | ---- | C] () -- C:\Windows\System32\prfc0816.dat [2012.03.17 22:41:24 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat [2012.03.17 22:23:54 | 000,462,172 | ---- | C] () -- C:\Windows\System32\perfh006.dat [2012.03.17 22:23:54 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat [2012.03.17 22:23:54 | 000,079,804 | ---- | C] () -- C:\Windows\System32\perfc006.dat [2012.03.17 22:23:54 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat [2012.03.17 22:04:51 | 000,693,454 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2012.03.17 22:04:51 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2012.03.17 22:04:51 | 000,137,062 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2012.03.17 22:04:51 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2012.03.17 21:38:24 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2012.03.17 21:38:23 | 000,689,726 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2012.03.17 21:38:23 | 000,134,840 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2012.03.17 21:38:23 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2012.03.17 21:21:25 | 000,675,958 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2012.03.17 21:21:25 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2012.03.17 21:21:25 | 000,132,516 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2012.03.17 21:21:25 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2012.03.17 20:57:09 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2012.03.17 20:57:08 | 000,663,804 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2012.03.17 20:57:08 | 000,128,094 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2012.03.17 20:57:08 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2012.03.17 20:15:05 | 000,610,202 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2012.03.17 20:15:05 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2012.03.17 20:15:05 | 000,121,526 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2012.03.17 20:15:05 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2012.03.17 11:44:09 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2012.03.17 11:43:46 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.03.17 09:33:11 | 000,694,430 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2012.03.17 09:33:11 | 000,377,870 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2012.03.17 09:33:11 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2012.03.17 09:33:11 | 000,130,140 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2012.03.17 09:33:11 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2012.03.17 09:33:11 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat [2012.03.17 09:33:11 | 000,099,334 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2012.03.17 09:33:11 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2012.03.17 09:33:10 | 000,623,144 | ---- | C] () -- C:\Windows\System32\perfh005.dat [2012.03.17 09:33:10 | 000,433,388 | ---- | C] () -- C:\Windows\System32\perfh00B.dat [2012.03.17 09:33:10 | 000,361,768 | ---- | C] () -- C:\Windows\System32\prfh0804.dat [2012.03.17 09:33:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat [2012.03.17 09:33:10 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat [2012.03.17 09:33:10 | 000,121,788 | ---- | C] () -- C:\Windows\System32\perfc005.dat [2012.03.17 09:33:10 | 000,104,248 | ---- | C] () -- C:\Windows\System32\prfc0804.dat [2012.03.17 09:33:10 | 000,082,148 | ---- | C] () -- C:\Windows\System32\perfc00B.dat [2012.03.17 09:33:10 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat [2012.03.17 09:33:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat [2012.03.17 09:33:09 | 000,448,586 | ---- | C] () -- C:\Windows\System32\perfh014.dat [2012.03.17 09:33:09 | 000,399,736 | ---- | C] () -- C:\Windows\System32\perfh012.dat [2012.03.17 09:33:09 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat [2012.03.17 09:33:09 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat [2012.03.17 09:33:09 | 000,104,676 | ---- | C] () -- C:\Windows\System32\perfc012.dat [2012.03.17 09:33:09 | 000,077,096 | ---- | C] () -- C:\Windows\System32\perfc014.dat [2012.03.17 09:33:09 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat [2012.03.17 09:33:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat [2010.09.27 13:03:08 | 000,201,512 | ---- | C] () -- C:\Windows\System32\vpnapi.dll ========== LOP Check ========== [2012.04.27 22:46:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Amazon [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl [2012.06.05 22:57:59 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Dropbox [2012.04.03 08:46:29 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\GHISLER [2012.06.06 12:48:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\gnupg [2012.04.28 00:00:02 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\HandBrake [2012.04.18 18:59:05 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Intermedia Software [2012.03.17 10:44:31 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\IrfanView [2012.04.09 17:42:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LibreOffice [2012.03.17 00:37:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LucasArts [2012.05.21 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Nokia [2012.05.21 19:38:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PC Suite [2012.05.29 22:27:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PwrMgr [2012.04.23 22:01:49 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Samsung [2012.03.19 09:28:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Swiss Academic Software [2012.03.22 09:14:06 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Thunderbird [2012.06.03 11:57:16 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > extra.txtOTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 06.06.2012 15:32:20 - Run 1 OTL by OldTimer - Version Folder = C:\Users\*****\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free 5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS Computer Name: *****-PC | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{11C140D1-C8CA-480E-8C22-6FB108AC5B9B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1B695C61-DED9-412B-9F95-749966962621}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{2E6F1837-74C5-4816-983B-524C69680091}" = lport=137 | protocol=17 | dir=in | app=system | "{36E1979F-0A03-4220-A284-89B8265DCAE9}" = lport=445 | protocol=6 | dir=in | app=system | "{4586B191-EB75-4CD3-A6A8-73102F4D7A8E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4BD76F22-1306-4362-81DD-B1C21B0A1879}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4CD5AA15-FC9F-41F8-A0CF-97C686ECDC83}" = lport=10243 | protocol=6 | dir=in | app=system | "{79B401E3-7F75-4A19-BAB9-4345C95DFBF3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7A2C2210-0657-4A0A-AD54-3ADA7772DC71}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{81454568-B251-494F-B0DB-E09375187CB6}" = rport=10243 | protocol=6 | dir=out | app=system | "{83CBC572-FF34-4D54-B01F-D4D55B50DF29}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{89F356D0-65B6-49EC-8371-625A9BA23B6A}" = lport=139 | protocol=6 | dir=in | app=system | "{8CC84360-489A-4F1F-A1F5-5AC475480875}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{99B63B6D-E64E-425B-B240-2CE97D0ED178}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A13B6A0E-21E3-42B5-97BF-AAD958E766C1}" = lport=138 | protocol=17 | dir=in | app=system | "{A7FD2748-8BDB-424D-85E6-5693CE1C5515}" = lport=2869 | protocol=6 | dir=in | app=system | "{AD473898-7C8A-4FBA-B5EF-33CBC72590C9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B75CF7C7-DB43-49EB-97D7-0216E5A19722}" = rport=138 | protocol=17 | dir=out | app=system | "{CDA34F23-BD6D-4B2C-AAC3-E2467F7333C3}" = rport=139 | protocol=6 | dir=out | app=system | "{D0CFF402-CEB5-44FE-A417-8AF8D944F413}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D65552B0-8F3B-4B2D-88FB-0CE505539F7C}" = rport=445 | protocol=6 | dir=out | app=system | "{E40DF8EE-0878-44DC-B4D1-8933AE5CD172}" = rport=137 | protocol=17 | dir=out | app=system | "{F4527DDC-7A77-4B4B-B51F-DE54574C5599}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F6D1E7E5-5AD3-4135-BDC7-23F05D7B4444}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{154615E7-398E-46D4-AB52-B8F82E32A662}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{190E9810-D7C4-4D2F-8E3F-C046F13A2E95}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{28D924FD-E511-49CA-80CD-5EDA3FD031D4}" = protocol=6 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | "{2D0603D6-D2B9-4878-89BA-8F047EDEA786}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{30847B64-D196-42CD-90D9-3D962C86DB4E}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "{3983EBC6-99D0-49C5-BB67-240C2242D2F4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{44D3D234-9BBC-4B01-BB00-D6466CC2CB8C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4AFEA250-9F4E-42A7-8D44-F9CCF4A6AD03}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{4EE4D181-E01B-40F0-8543-C8BCD7A5C43F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{5E4295EF-424F-4A80-9E0D-79B38BFD8F3C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | "{605371DF-B588-4FB4-B1FD-B06E6AE4BCA5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{63EA84F6-CCF0-4973-A453-ECFE9AAB23C2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{66751421-723E-4CCF-804F-4321622D0E31}" = protocol=17 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | "{713FFEAA-5865-45DB-B6D8-9C2EF9989329}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{71FB772D-FE3C-4B4D-8BF3-809C6C3103BA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{7EF1447F-FECB-47A5-8810-73A1D209598B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7F29A31B-5977-4945-98BC-79053C8C43B1}" = protocol=6 | dir=out | app=system | "{8AC62D2F-DA7F-4422-8ADE-5E4F1C98C766}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{999FBBAC-37A5-4C7B-9992-8B1BDEA3FD2B}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe | "{A1591105-6B07-456D-B8CA-260FA1C09A12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AC64A7C5-410F-435E-A114-0617CE9F0073}" = protocol=17 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | "{B424D08A-C3FF-4F3E-8EAE-54C913AE6706}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{B4BE2661-4E69-4462-B1CC-981559F6089C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{BC4BB849-FF8F-48B3-900F-B5E42A3521A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BC7ACAF4-EF07-4EC6-81D7-D7BC696AC81D}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe | "{C6C32619-9A88-45C5-A8AB-685EC5D35EC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C6F2EB79-2A7A-4DDB-9029-C14E2F63FDE8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{C9F41199-FAC6-48E6-BC31-4D952F1DEA22}" = dir=in | app=c:\program files\itunes\itunes.exe | "{CD3B3755-12DB-4BD5-9B50-7BD9EF5ED7C9}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe | "{D43A31F6-B972-414E-AFBB-2D6DF9A01D8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D66A39EF-0619-4686-9193-0BA51D4845C4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{DE4BDEC8-2C9A-43FF-819C-696D8747CCD5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | "{EC0B430D-A5AB-420E-AA99-68EEF19A9D24}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{EC3D1D9D-3EB0-43D6-8A9D-DA6D4B3471FB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{FDE172B7-7D0D-463A-B4C5-C5B77A9DC13B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FE010E17-D333-48A7-BD2B-F6D575155F2F}" = protocol=6 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0E8E4718-0702-4D33-B007-5E95849BAB3C}" = LibreOffice 3.5 "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{17CBC505-D1AE-459D-B445-3D2000A85842}" = Dienstprogramm "ThinkPad UltraNav" "{1CE60928-8325-49A8-8B06-633E48DD2B67}" = Cisco Systems VPN Client "{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes "{24E92E7A-6848-4747-A3EA-3AAC0576BE52}" = Lenovo Patch Utility "{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{705EE775-5776-48FD-B704-C3C9CF535420}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7964AE02-9127-42C0-A917-2CE4CD4EFE3B}" = Nokia Suite "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software "{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver "{A7BB9BBD-DFE4-4276-820A-7CD141FC09E6}" = Lenovo Patch Utility "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{BA722179-62EA-4090-923D-D324CE1A691D}}_is1" = Helium Music Manager 8 (build 10470) "{BAA0BE9B-9E6D-4802-91CB-FB7ED5CD4BEF}" = Intel® PROSet/Wireless WiFi-Software "{C2938C94-239C-4156-B245-C5406A4F3E93}" = ThinkVantage Fingerprint Software "{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel "{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}" = Steuer-Spar-Erklärung 2012 "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution "{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = Energie-Manager "{E12C6653-1FF0-4686-ADB8-589C13AE761F}" = Citavi "{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86 "{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support "{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: "2004BB9EB6CEA02846881BEF1F51C11F7A90C9D6" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 "504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 "Avira AntiVir Desktop" = Avira Free Antivirus "BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 "Clementine" = Clementine "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588" = ThinkPad Modem "GPG4Win" = Gpg4win (2.1.0) "HandBrake" = HandBrake 0.9.6 "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "IrfanView" = IrfanView (remove only) "LENOVO.SMIIF" = Lenovo System Interface Driver "LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility "Loeffelfamilie" = Loeffelfamilie Screen Saver "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2 "MISEC" = Monkey Island™ Special Edition Collection "Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de) "Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nokia Suite" = Nokia Suite "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "OnScreenDisplay" = Anzeige am Bildschirm "Power Management Driver" = ThinkPad Power Management Driver "ProInst" = Intel PROSet Wireless "SnowFox Total Video Converter_is1" = SnowFox Total Video Converter "SynTPDeinstKey" = ThinkPad UltraNav Driver "ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier "Totalcmd" = Total Commander (Remove or Repair) "VLC media player" = VLC media player 2.0.1 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 9000 Description = Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 1006 Description = Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. [ System Events ] Error - 06.06.2012 09:28:19 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 4 Mal passiert. Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet: %%-1906441657 Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 5 Mal passiert. < End of report > Der Gmer-Scan hat dann sehr lange gedauert weshalb ich ihn nicht permanent verfolgen konnte. Aber er scheint aus irgendeinem Grund den PC zum Absturz gebracht zu haben, weswegen ich ihn nochmal neu starte! Geändert von ms_sh (06.06.2012 um 11:59 Uhr) |
![]() | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Führ bitte auch ESET aus, danach sehen wir weiter:
__________________ESET Online Scanner
Hinweise bzgl. der verschlüsselten Dateien: Wann genau deine Daten entschlüsselt werden können wird dir niemand genau sagen können außer vllt einer ![]() Einfach hier nochmal reinsehen in regelmäßigen Abständen, obige Hinweise beachten. 8 Tools mitsamt hunderten Diskussionsbeiträgen stehen da schon Entschlüsselungsversuche der verschlüsselten Dateien sind nur auf zusätzliche Kopien der verschlüsselten Dateien anzuwenden, sonst zerhackt man sich die noch weiter ohne die "original" verschlüsselte Datei mehr zu haben. Das willst du sicher nicht! Man darf sich aber keine falschen Hoffnungen machen. Mittlerweile sieht es finster aus => Delphi-PRAXiS - Einzelnen Beitrag anzeigen - Verschlüsselungs-Trojaner, Hilfe benötigt Und in Zukunft willst du sicher mal an ein besseres Backupkonzept denken. Hier ein Denkanstoß => http://www.trojaner-board.de/115678-...r-backups.html
__________________ |
![]() | #3 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) ESET-Log im Anhang:
__________________ |
![]() | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de)Code:
ATTFilter J:\Users\***\Downloads\SoftonicDownloader67308.exe ![]() Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen Hätte da mal zwei Fragen bevor es weiter geht 1.) Geht der normale Modus von Windows (wieder) uneingeschränkt? 2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Vielen Dank für die Antworten. Leider habe ich im Moment sehr wenig Zeit, brauche aber zum Glück den Computer beruflich nur sehr wenig und hatte ein Backup vor nicht allzu langer Zeit erstellt. Ein paar wichtige Dateien sind trotzden flöten gegangen. Um das Thema Entschlüsselung bzw. Datenherstellung will ich mich am Wochenende jetzt mal verstärkt kümmern. Zu deinen Fragen: - Windows geht wieder ganz normal - Alle Programme scheinen da zu sein, im Startmenü alles wie gehabt. Gruß und Danke, S. |
![]() | #6 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) So habe mich ein wenig mit den Entschlüsselungstools auseinander gesetzt, leider bisher ohne Erfolg. So konnte ich zwar mit ScareUncrypt einen Schlüssel erstellen, irgendwie passiert aber bei der Entschlüsselung nichts... auch die Versuche der Datenrettung waren erfolglos. Ich probier's erstmal weiter... |
![]() | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #8 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) OTL Logfile: Code:
ATTFilter OTL logfile created on: 25.06.2012 09:24:05 - Run 2 OTL by OldTimer - Version Folder = C:\Users\***\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 68,08% Memory free 5,99 Gb Paging File | 4,74 Gb Available in Paging File | 79,13% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,78 Gb Total Space | 163,36 Gb Free Space | 73,00% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 31,92 Gb Free Space | 16,34% Space Free | Partition Type: NTFS Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS Drive G: | 931,51 Gb Total Space | 139,98 Gb Free Space | 15,03% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.06.25 09:22:19 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\***\Downloads\OTL(1).exe PRC - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\System Update\SUService.exe PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PRC - [2012.04.22 13:50:44 | 000,174,120 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PRC - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe PRC - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe PRC - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe PRC - [2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Program Files\Samsung\Kies\KiesHelper.exe PRC - [2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\DeviceManager.exe PRC - [2012.03.28 22:11:58 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\ConnectionManager.exe PRC - [2012.03.15 06:07:00 | 000,128,576 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe PRC - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe PRC - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe PRC - [2011.10.20 12:09:32 | 000,363,584 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe PRC - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe PRC - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe PRC - [2011.10.20 10:58:46 | 000,101,440 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\LENOVO\VIRTSCRL\virtscrl.exe PRC - [2011.07.14 16:50:56 | 000,057,672 | ---- | M] (Authentec Inc.) -- C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe PRC - [2011.07.12 18:03:32 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe PRC - [2011.07.12 17:17:04 | 000,138,680 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Zoom\TpScrex.exe PRC - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe PRC - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe PRC - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.03.02 17:26:12 | 000,264,704 | ---- | M] () -- C:\Program Files\GNU\GnuPG\gpg-agent.exe PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files\GNU\GnuPG\dirmngr.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.24 12:35:46 | 000,804,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe PRC - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe PRC - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) -- C:\Program Files\ShadowExplorer\sesvc.exe PRC - [2010.11.20 05:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe PRC - [2010.04.23 01:16:46 | 000,128,296 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2009.01.26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2009.01.12 07:15:52 | 000,071,096 | ---- | M] () -- C:\Windows\System32\NMSAccess32.exe PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE ========== Modules (No Company Name) ========== MOD - [2012.06.05 14:19:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll MOD - [2012.06.05 14:16:30 | 000,762,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll MOD - [2012.06.05 14:16:17 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll MOD - [2012.06.05 14:01:19 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\041b1bcf6ae9ab58925791d8198c37e2\PresentationFramework.ni.dll MOD - [2012.06.05 14:00:46 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1de74c8d0dfd15e3246e5dd394013bf\PresentationCore.ni.dll MOD - [2012.06.05 14:00:24 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\4b7adff986a085bb562222d0c5fdf5aa\WindowsBase.ni.dll MOD - [2012.06.05 14:00:17 | 013,197,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9ee9841d9e33fe5dceba4cd7d90f2ae0\System.Windows.Forms.ni.dll MOD - [2012.06.05 14:00:06 | 001,665,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\03b5233f1511f5fdb39eb681b04e5506\System.Drawing.ni.dll MOD - [2012.06.05 14:00:05 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll MOD - [2012.06.05 14:00:03 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll MOD - [2012.06.05 14:00:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll MOD - [2012.06.05 13:59:54 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll MOD - [2012.06.05 13:59:42 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll MOD - [2012.04.23 22:02:06 | 000,115,137 | ---- | M] () -- C:\Users\***\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll MOD - [2012.04.13 07:13:59 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\c2c7f68605a42caef1b7a19c51de58b4\System.ServiceProcess.ni.dll MOD - [2012.04.13 07:13:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43e23da6683962ea1168aaf007bbc35d\PresentationFramework.ni.dll MOD - [2012.04.13 07:12:07 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\74d980e52c1791f1b8608d767a393144\PresentationCore.ni.dll MOD - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MOD - [2012.03.30 03:23:38 | 000,079,872 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.FileService.dll MOD - [2012.03.30 03:21:48 | 014,144,512 | ---- | M] () -- C:\Program Files\Samsung\Kies\Theme\Kies.Theme.dll MOD - [2012.03.30 03:21:18 | 000,486,912 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.UI.dll MOD - [2012.03.30 03:21:12 | 000,034,304 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.Interface.dll MOD - [2012.03.29 18:44:34 | 000,022,528 | ---- | M] () -- C:\Program Files\Samsung\Kies\MVVM\Kies.MVVM.dll MOD - [2012.03.28 22:13:12 | 000,037,376 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\ASF_cSharpAPI.dll MOD - [2012.03.28 22:12:04 | 000,839,680 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\System.Data.SQLite.dll MOD - [2012.03.28 22:12:00 | 000,712,704 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\SHOWDRM_UCC.dll MOD - [2012.03.28 22:11:58 | 000,237,568 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\drmcm.dll MOD - [2012.03.28 22:11:28 | 000,720,896 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\MediaModules\LDBCShConv.dll MOD - [2012.03.18 13:08:34 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll MOD - [2012.03.18 13:06:32 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll MOD - [2012.03.18 13:05:59 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll MOD - [2012.03.18 13:05:57 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.ni.dll MOD - [2012.03.18 13:05:56 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9e8dfbd1334d30a08ce1f2df29ca9aff\System.Transactions.ni.dll MOD - [2012.03.18 13:05:55 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll MOD - [2012.03.18 13:04:32 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll MOD - [2012.03.18 13:04:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll MOD - [2012.03.18 13:04:15 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll MOD - [2012.03.18 13:04:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll MOD - [2012.03.18 13:03:50 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll MOD - [2012.03.15 06:07:00 | 000,094,208 | ---- | M] () -- C:\PROGRA~2\ThinkPad\UTILIT~1\GR\PWMRT32V.DLL MOD - [2012.02.20 22:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.02.20 22:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf MOD - [2011.03.02 17:26:12 | 000,264,704 | ---- | M] () -- C:\Program Files\GNU\GnuPG\gpg-agent.exe MOD - [2011.03.02 17:17:18 | 000,603,136 | ---- | M] () -- C:\Program Files\GNU\GnuPG\libgcrypt-11.dll MOD - [2011.03.02 17:16:08 | 000,073,216 | ---- | M] () -- C:\Program Files\GNU\GnuPG\libassuan-0.dll MOD - [2011.03.02 17:13:52 | 000,048,640 | ---- | M] () -- C:\Program Files\GNU\GnuPG\libgpg-error-0.dll MOD - [2011.03.02 17:11:52 | 000,038,400 | ---- | M] () -- C:\Program Files\GNU\GnuPG\libw32pth-0.dll MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll MOD - [2010.11.04 18:58:06 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\\System.Data.dll MOD - [2009.07.14 10:47:20 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\\PresentationFramework.resources.dll MOD - [2009.07.14 10:47:15 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\\System.Xml.resources.dll MOD - [2009.07.14 10:47:15 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\\System.Configuration.resources.dll MOD - [2009.07.14 10:47:11 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceProcess.resources\\System.ServiceProcess.resources.dll MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\\System.Transactions.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService) SRV - [2012.06.23 08:14:15 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService) SRV - [2012.05.10 23:34:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) Intel(R) SRV - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R) SRV - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R) SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.03.15 06:07:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service) SRV - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc) SRV - [2012.03.15 06:07:00 | 000,165,440 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE -- (PwmEWSvc) SRV - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R) SRV - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe -- (AcSvc) SRV - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc) SRV - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC) SRV - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe -- (TPHKLOAD) SRV - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe -- (LENOVO.MICMUTE) SRV - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe -- (TPHKSVC) SRV - [2011.06.12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Program Files\GNU\GnuPG\dirmngr.exe -- (DirMngr) SRV - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2011.01.02 21:29:50 | 000,009,216 | ---- | M] (www.shadowexplorer.com) [Auto | Running] -- C:\Program Files\ShadowExplorer\sesvc.exe -- (sesvc) SRV - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2009.01.12 07:15:52 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Windows\System32\NMSAccess32.exe -- (NMSAccess32) SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.03.15 06:07:00 | 000,025,416 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD) DRV - [2012.03.15 06:07:00 | 000,017,736 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPALP) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPAL) DRV - [2012.02.24 11:14:42 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) DRV - [2012.02.24 11:14:42 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) DRV - [2012.01.09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2012.01.09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011.12.27 03:10:35 | 000,033,080 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd) DRV - [2011.10.14 19:25:10 | 000,231,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6232.sys -- (e1express) Intel(R) DRV - [2011.05.30 18:21:24 | 000,011,976 | ---- | M] (Authentec Inc.) [Kernel | Auto | Running] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) SMI Helper Driver (smihlp) DRV - [2011.05.18 09:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB) DRV - [2011.03.29 20:14:08 | 000,122,992 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf) DRV - [2011.03.29 20:12:16 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN) DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 05:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 05:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 05:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 03:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 02:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 02:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 02:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.10.07 04:11:38 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32) Intel(R) DRV - [2010.09.27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2010.09.07 14:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.04.08 23:11:06 | 000,045,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt) DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009.07.14 01:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R) DRV - [2008.11.16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE) DRV - [2007.06.21 18:36:32 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2007.01.18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006.11.27 18:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 3E 0E A8 02 43 CD 01 [binary data] IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012.03.18 13:26:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.10 23:34:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.06.16 21:38:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012.03.16 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2012.06.02 17:08:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q8lojr9q.default\extensions [2012.03.16 23:29:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.05.10 23:34:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.03.13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.03.16 23:36:18 | 000,441,475 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: 1001namen.com O1 - Hosts: www.1001namen.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: www.10sek.com O1 - Hosts: 10sek.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 1-2005-search.com O1 - Hosts: www.123fporn.info O1 - Hosts: 15172 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe (Lenovo) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe (Authentec Inc.) O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor File not found O4 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001..\Run: [] File not found O4 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: &Citavi Picker... - C:\ProgramData\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html () O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..Trusted Domains: microsoft.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites) O15 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites) O15 - HKU\S-1-5-21-1513476003-3093081758-2276433434-1001\..Trusted Domains: windowsupdate.com ([]* in Trusted sites) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1A88D420-BE4A-41B5-89C6-05A7BCCE7591}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3222A70D-BED3-44EB-9A27-3D895F894144}: DhcpNameServer = O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - Unable to obtain root file information for disk G:\ O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {47B3BDBB-F2AE-4B55-95C8-921C25DB3B76} - .NET Framework ActiveX: {49C187D7-91E1-459E-9759-2925384BD397} - .NET Framework ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5A604D2C-E968-429B-8327-62B5CE52126D} - .NET Framework ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9793EDE2-499E-4A14-8220-523691D8F91B} - .NET Framework ActiveX: {A59B76D1-5E3B-4893-BB7F-AF69B2570A73} - .NET Framework ActiveX: {BFA2E378-31D9-4595-AFA9-CA19E610DC0F} - .NET Framework ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CE4BC71D-A88B-4943-BB3D-AF9C0E7D4387} - .NET Framework ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {FE600E50-2C69-46D5-ACAA-2B617006245C} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.06.24 15:01:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator [2012.06.24 15:01:13 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\pdfforge [2012.06.24 15:01:11 | 000,081,408 | ---- | C] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll [2012.06.24 15:01:09 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator [2012.06.24 10:06:04 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\www.shadowexplorer.com [2012.06.24 10:05:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer [2012.06.24 10:05:55 | 000,000,000 | ---D | C] -- C:\Program Files\ShadowExplorer [2012.06.23 16:39:05 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JPEG Recovery Pro [2012.06.23 16:39:04 | 000,000,000 | ---D | C] -- C:\Program Files\JPEG Recovery Pro [2012.06.23 16:34:24 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\JPEGsnoop [2012.06.23 08:54:35 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\PandaUnRansom [2012.06.23 08:37:22 | 000,000,000 | ---D | C] -- C:\Users\***\Scareuncrypt [2012.06.19 19:39:12 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.06.19 18:55:52 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle [2012.06.18 19:23:17 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\Mis Proyectos [2012.06.18 19:23:17 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\FotoPrix [2012.06.18 19:22:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FotoPrix [2012.06.18 19:11:53 | 000,000,000 | ---D | C] -- C:\Program Files\Fotoprix [2012.06.18 19:09:00 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\fontconfig [2012.06.18 19:08:58 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\gegl-0.2 [2012.06.18 19:08:58 | 000,000,000 | ---D | C] -- C:\Users\***\.gimp-2.8 [2012.06.18 19:04:47 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2 [2012.06.17 18:17:28 | 001,208,367 | ---- | C] (Atalasoft, Inc.) -- C:\Windows\System32\ImgX61.dll [2012.06.17 18:17:28 | 001,179,648 | ---- | C] (Atalasoft, Inc.) -- C:\Windows\System32\AtalaImaging.dll [2012.06.17 18:17:28 | 000,431,864 | ---- | C] (Atalasoft, Inc.) -- C:\Windows\System32\ImgX61.ocx [2012.06.17 18:17:28 | 000,173,136 | ---- | C] (Atalasoft) -- C:\Windows\System32\ImgXDialog61.dll [2012.06.17 18:17:28 | 000,145,152 | ---- | C] (Atalasoft, Inc.) -- C:\Windows\System32\ImgXTwain61.dll [2012.06.17 18:17:28 | 000,139,264 | ---- | C] (VOLTO.COM) -- C:\Windows\System32\voltoCDX.dll [2012.06.17 18:17:28 | 000,132,232 | ---- | C] (Atalasoft) -- C:\Windows\System32\ImgXPrint61.dll [2012.06.17 18:17:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cover Me [2012.06.17 18:17:27 | 000,212,024 | ---- | C] (Innovasys) -- C:\Windows\System32\BtnPlus1.ocx [2012.06.17 18:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\Cover Me [2012.06.17 18:14:57 | 000,000,000 | ---D | C] -- C:\Program Files\CIPP [2012.06.12 08:00:35 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Macromedia [2012.06.11 19:27:38 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\EurekaLog [2012.06.11 09:31:35 | 002,557,952 | ---- | C] (Nokia Corporation and/or its subsidiary(-ies)) -- C:\Windows\System32\QtCore4.dll [2012.06.11 09:31:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2012.06.11 09:31:24 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft [2012.06.11 09:31:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft [2012.06.11 09:30:52 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\DVDVideoSoft [2012.06.07 08:11:56 | 000,100,864 | ---- | C] (GMER) -- C:\agloypog.sys [2012.06.07 08:04:31 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2012.06.06 12:19:53 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2012.06.06 12:19:49 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.06.06 12:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.06.06 09:49:46 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\avira [2012.06.06 08:30:28 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Bibzrzhnhsl [2012.06.05 13:41:03 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira [2012.06.05 13:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.06.05 13:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2012.06.05 13:35:18 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2012.06.05 13:35:18 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2012.06.05 13:35:18 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys [2012.06.05 13:35:18 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.06.05 12:59:18 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2 [2012.06.05 12:55:37 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\InstallShield [2012.06.05 12:54:12 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012.06.05 12:14:13 | 000,000,000 | -H-D | C] -- C:\Windows\System32\WLANProfiles [2012.06.05 12:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2012.06.05 12:11:46 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco [2012.06.05 12:06:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll [2012.06.05 12:06:32 | 000,000,000 | ---D | C] -- C:\Intel [2012.06.05 12:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab [2012.06.05 12:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2012.06.05 12:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.06.05 12:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012.06.05 11:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage [2012.06.02 17:49:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage [2012.06.02 16:58:05 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox [2012.06.02 16:57:15 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Dropbox [2012.05.29 22:27:12 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\PwrMgr [2012.05.29 18:24:47 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Lenovo [2012.05.29 18:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SPBA [2012.05.29 18:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkVantage Fingerprint Software [2012.05.29 18:10:23 | 000,000,000 | ---D | C] -- C:\SWTOOLS [2012.05.29 18:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.06.25 09:14:29 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.06.25 09:14:29 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.06.25 09:14:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.06.25 09:08:05 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.06.25 09:06:58 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.06.25 09:06:56 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr [2012.06.25 09:06:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.06.25 09:06:38 | 2414,682,112 | -HS- | M] () -- C:\hiberfil.sys [2012.06.24 08:29:18 | 000,694,430 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2012.06.24 08:29:18 | 000,693,454 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2012.06.24 08:29:18 | 000,691,192 | ---- | M] () -- C:\Windows\System32\perfh013.dat [2012.06.24 08:29:18 | 000,689,726 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012.06.24 08:29:18 | 000,689,108 | ---- | M] () -- C:\Windows\System32\perfh010.dat [2012.06.24 08:29:18 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat [2012.06.24 08:29:18 | 000,675,958 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2012.06.24 08:29:18 | 000,663,804 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2012.06.24 08:29:18 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.06.24 08:29:18 | 000,632,180 | ---- | M] () -- C:\Windows\System32\perfh00E.dat [2012.06.24 08:29:18 | 000,623,144 | ---- | M] () -- C:\Windows\System32\perfh005.dat [2012.06.24 08:29:18 | 000,617,568 | ---- | M] () -- C:\Windows\System32\perfh01D.dat [2012.06.24 08:29:18 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.06.24 08:29:18 | 000,610,202 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2012.06.24 08:29:18 | 000,551,770 | ---- | M] () -- C:\Windows\System32\perfh008.dat [2012.06.24 08:29:18 | 000,462,172 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2012.06.24 08:29:18 | 000,448,586 | ---- | M] () -- C:\Windows\System32\perfh014.dat [2012.06.24 08:29:18 | 000,434,486 | ---- | M] () -- C:\Windows\System32\perfh001.dat [2012.06.24 08:29:18 | 000,433,388 | ---- | M] () -- C:\Windows\System32\perfh00B.dat [2012.06.24 08:29:18 | 000,399,736 | ---- | M] () -- C:\Windows\System32\perfh012.dat [2012.06.24 08:29:18 | 000,388,518 | ---- | M] () -- C:\Windows\System32\perfh011.dat [2012.06.24 08:29:18 | 000,377,870 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2012.06.24 08:29:18 | 000,361,768 | ---- | M] () -- C:\Windows\System32\prfh0804.dat [2012.06.24 08:29:18 | 000,353,522 | ---- | M] () -- C:\Windows\System32\perfh00D.dat [2012.06.24 08:29:18 | 000,148,310 | ---- | M] () -- C:\Windows\System32\perfc00E.dat [2012.06.24 08:29:18 | 000,137,062 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2012.06.24 08:29:18 | 000,134,840 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012.06.24 08:29:18 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat [2012.06.24 08:29:18 | 000,132,940 | ---- | M] () -- C:\Windows\System32\perfc013.dat [2012.06.24 08:29:18 | 000,132,516 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2012.06.24 08:29:18 | 000,130,140 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2012.06.24 08:29:18 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.06.24 08:29:18 | 000,128,094 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2012.06.24 08:29:18 | 000,127,144 | ---- | M] () -- C:\Windows\System32\perfc010.dat [2012.06.24 08:29:18 | 000,123,740 | ---- | M] () -- C:\Windows\System32\perfc01D.dat [2012.06.24 08:29:18 | 000,121,788 | ---- | M] () -- C:\Windows\System32\perfc005.dat [2012.06.24 08:29:18 | 000,121,526 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2012.06.24 08:29:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc011.dat [2012.06.24 08:29:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.06.24 08:29:18 | 000,104,676 | ---- | M] () -- C:\Windows\System32\perfc012.dat [2012.06.24 08:29:18 | 000,104,248 | ---- | M] () -- C:\Windows\System32\prfc0804.dat [2012.06.24 08:29:18 | 000,099,334 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2012.06.24 08:29:18 | 000,089,436 | ---- | M] () -- C:\Windows\System32\perfc008.dat [2012.06.24 08:29:18 | 000,082,148 | ---- | M] () -- C:\Windows\System32\perfc00B.dat [2012.06.24 08:29:18 | 000,079,804 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2012.06.24 08:29:18 | 000,078,984 | ---- | M] () -- C:\Windows\System32\perfc001.dat [2012.06.24 08:29:18 | 000,077,096 | ---- | M] () -- C:\Windows\System32\perfc014.dat [2012.06.24 08:29:18 | 000,069,094 | ---- | M] () -- C:\Windows\System32\perfc00D.dat [2012.06.19 22:20:33 | 237,649,923 | ---- | M] () -- C:\Users\***\Documents\***.flv [2012.06.19 18:42:59 | 000,751,128 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.06.18 19:11:28 | 000,000,828 | ---- | M] () -- C:\Users\***\AppData\Local\recently-used.xbel [2012.06.18 15:33:08 | 001,135,381 | ---- | M] () -- C:\Users\***\Desktop\20120617_175418.jpg [2012.06.15 06:51:42 | 000,081,408 | ---- | M] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll [2012.06.07 10:17:00 | 526,082,919 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.06.07 08:11:56 | 000,100,864 | ---- | M] (GMER) -- C:\agloypog.sys [2012.06.06 15:31:03 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable [2012.06.06 12:19:50 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.05 12:14:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.04 22:07:07 | 1363,885,269 | ---- | M] () -- C:\Users\***\Documents\***.flv [2012.06.04 18:10:48 | 000,007,168 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.05.29 21:32:20 | 1453,899,807 | ---- | M] () -- C:\Users\***\Documents\***.flv [1 C:\Windows\System32\drivers\UMDF\*.tmp files -> C:\Windows\System32\drivers\UMDF\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.06.25 09:06:56 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr [2012.06.19 22:05:08 | 237,649,923 | ---- | C] () -- C:\Users\***\Documents\***.flv [2012.06.18 19:11:28 | 000,000,828 | ---- | C] () -- C:\Users\***\AppData\Local\recently-used.xbel [2012.06.18 19:07:32 | 000,001,049 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk [2012.06.18 15:33:05 | 001,135,381 | ---- | C] () -- C:\Users\***\Desktop\20120617_175418.jpg [2012.06.17 18:17:28 | 000,000,689 | ---- | C] () -- C:\Windows\System32\volto_CR5BAQ.lic [2012.06.17 18:12:48 | 001,908,736 | ---- | C] ( ) -- C:\Users\***\CIPP.exe [2012.06.17 18:12:48 | 001,155,034 | ---- | C] () -- C:\Users\***\Latigo.pdf [2012.06.17 18:12:48 | 000,001,815 | ---- | C] () -- C:\Users\***\DVDSettings.imp [2012.06.17 18:12:47 | 001,622,747 | ---- | C] () -- C:\Users\***\CIPP.pdf [2012.06.07 08:04:25 | 526,082,919 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012.06.06 15:31:03 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable [2012.06.06 12:19:50 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.05 12:14:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.05 11:52:43 | 000,002,088 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Device Experience.lnk [2012.06.05 11:52:42 | 000,002,476 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools.lnk [2012.05.10 22:27:38 | 000,007,168 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.04.18 19:00:07 | 000,000,100 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc [2012.03.28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2012.03.27 17:27:16 | 000,037,046 | ---- | C] () -- C:\Users\***\AppData\Roaming\Kommagetrennte Werte (Windows).ADR [2012.03.18 04:58:31 | 000,617,568 | ---- | C] () -- C:\Windows\System32\perfh01D.dat [2012.03.18 04:58:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat [2012.03.18 04:58:31 | 000,123,740 | ---- | C] () -- C:\Windows\System32\perfc01D.dat [2012.03.18 04:58:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat [2012.03.18 04:58:30 | 000,691,192 | ---- | C] () -- C:\Windows\System32\perfh013.dat [2012.03.18 04:58:30 | 000,632,180 | ---- | C] () -- C:\Windows\System32\perfh00E.dat [2012.03.18 04:58:30 | 000,353,522 | ---- | C] () -- C:\Windows\System32\perfh00D.dat [2012.03.18 04:58:30 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat [2012.03.18 04:58:30 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat [2012.03.18 04:58:30 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat [2012.03.18 04:58:30 | 000,148,310 | ---- | C] () -- C:\Windows\System32\perfc00E.dat [2012.03.18 04:58:30 | 000,069,094 | ---- | C] () -- C:\Windows\System32\perfc00D.dat [2012.03.18 04:58:30 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat [2012.03.18 04:58:30 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat [2012.03.18 04:58:30 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat [2012.03.18 04:58:29 | 000,388,518 | ---- | C] () -- C:\Windows\System32\perfh011.dat [2012.03.18 04:58:29 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat [2012.03.18 04:58:29 | 000,132,940 | ---- | C] () -- C:\Windows\System32\perfc013.dat [2012.03.18 04:58:29 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc011.dat [2012.03.18 04:58:29 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat [2012.03.18 00:04:25 | 000,551,770 | ---- | C] () -- C:\Windows\System32\perfh008.dat [2012.03.18 00:04:25 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat [2012.03.18 00:04:25 | 000,089,436 | ---- | C] () -- C:\Windows\System32\perfc008.dat [2012.03.18 00:04:25 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat [2012.03.17 23:25:14 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat [2012.03.17 23:25:13 | 000,689,108 | ---- | C] () -- C:\Windows\System32\perfh010.dat [2012.03.17 23:25:13 | 000,127,144 | ---- | C] () -- C:\Windows\System32\perfc010.dat [2012.03.17 23:25:13 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat [2012.03.17 23:02:46 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat [2012.03.17 23:02:45 | 000,434,486 | ---- | C] () -- C:\Windows\System32\perfh001.dat [2012.03.17 23:02:45 | 000,078,984 | ---- | C] () -- C:\Windows\System32\perfc001.dat [2012.03.17 23:02:45 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat [2012.03.17 22:41:24 | 000,679,342 | ---- | C] () -- C:\Windows\System32\prfh0816.dat [2012.03.17 22:41:24 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat [2012.03.17 22:41:24 | 000,133,752 | ---- | C] () -- C:\Windows\System32\prfc0816.dat [2012.03.17 22:41:24 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat [2012.03.17 22:23:54 | 000,462,172 | ---- | C] () -- C:\Windows\System32\perfh006.dat [2012.03.17 22:23:54 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat [2012.03.17 22:23:54 | 000,079,804 | ---- | C] () -- C:\Windows\System32\perfc006.dat [2012.03.17 22:23:54 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat [2012.03.17 22:04:51 | 000,693,454 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2012.03.17 22:04:51 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2012.03.17 22:04:51 | 000,137,062 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2012.03.17 22:04:51 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2012.03.17 21:38:24 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2012.03.17 21:38:23 | 000,689,726 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2012.03.17 21:38:23 | 000,134,840 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2012.03.17 21:38:23 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2012.03.17 21:21:25 | 000,675,958 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2012.03.17 21:21:25 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2012.03.17 21:21:25 | 000,132,516 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2012.03.17 21:21:25 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2012.03.17 20:57:09 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2012.03.17 20:57:08 | 000,663,804 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2012.03.17 20:57:08 | 000,128,094 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2012.03.17 20:57:08 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2012.03.17 20:15:05 | 000,610,202 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2012.03.17 20:15:05 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2012.03.17 20:15:05 | 000,121,526 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2012.03.17 20:15:05 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2012.03.17 11:44:09 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2012.03.17 11:43:46 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.03.17 09:33:11 | 000,694,430 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2012.03.17 09:33:11 | 000,377,870 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2012.03.17 09:33:11 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2012.03.17 09:33:11 | 000,130,140 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2012.03.17 09:33:11 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2012.03.17 09:33:11 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat [2012.03.17 09:33:11 | 000,099,334 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2012.03.17 09:33:11 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2012.03.17 09:33:10 | 000,623,144 | ---- | C] () -- C:\Windows\System32\perfh005.dat [2012.03.17 09:33:10 | 000,433,388 | ---- | C] () -- C:\Windows\System32\perfh00B.dat [2012.03.17 09:33:10 | 000,361,768 | ---- | C] () -- C:\Windows\System32\prfh0804.dat [2012.03.17 09:33:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat [2012.03.17 09:33:10 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat [2012.03.17 09:33:10 | 000,121,788 | ---- | C] () -- C:\Windows\System32\perfc005.dat [2012.03.17 09:33:10 | 000,104,248 | ---- | C] () -- C:\Windows\System32\prfc0804.dat [2012.03.17 09:33:10 | 000,082,148 | ---- | C] () -- C:\Windows\System32\perfc00B.dat [2012.03.17 09:33:10 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat [2012.03.17 09:33:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat [2012.03.17 09:33:09 | 000,448,586 | ---- | C] () -- C:\Windows\System32\perfh014.dat [2012.03.17 09:33:09 | 000,399,736 | ---- | C] () -- C:\Windows\System32\perfh012.dat [2012.03.17 09:33:09 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat [2012.03.17 09:33:09 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat [2012.03.17 09:33:09 | 000,104,676 | ---- | C] () -- C:\Windows\System32\perfc012.dat [2012.03.17 09:33:09 | 000,077,096 | ---- | C] () -- C:\Windows\System32\perfc014.dat [2012.03.17 09:33:09 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat [2012.03.17 09:33:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat [2010.09.27 13:03:08 | 000,201,512 | ---- | C] () -- C:\Windows\System32\vpnapi.dll [1601.02.13 10:28:18 | 000,037,382 | ---- | C] () -- C:\Users\***\AppData\Roaming\Kommagetrennte Werte (DOS).ADR ========== LOP Check ========== [2012.04.27 22:46:34 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Amazon [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Bibzrzhnhsl [2012.06.17 17:57:54 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Dropbox [2012.06.11 09:31:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoft [2012.06.11 19:27:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\EurekaLog [2012.06.18 19:23:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\FotoPrix [2012.04.03 08:46:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\GHISLER [2012.06.25 09:08:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\gnupg [2012.04.28 00:00:02 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\HandBrake [2012.04.18 18:59:05 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Intermedia Software [2012.03.17 10:44:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\IrfanView [2012.06.23 16:34:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\JPEGsnoop [2012.04.09 17:42:57 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\LibreOffice [2012.03.17 00:37:57 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\LucasArts [2012.05.21 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Nokia [2012.05.21 19:38:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PC Suite [2012.06.24 15:02:10 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\pdfforge [2012.05.29 22:27:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PwrMgr [2012.04.23 22:01:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Samsung [2012.03.19 09:28:03 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Swiss Academic Software [2012.03.22 09:14:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Thunderbird [2012.06.24 10:06:04 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\www.shadowexplorer.com [2012.06.03 11:57:16 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2012.06.18 19:11:54 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Adobe [2012.04.27 22:46:34 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Amazon [2012.04.28 09:30:50 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Apple Computer [2012.06.05 13:41:03 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Avira [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Bibzrzhnhsl [2012.06.17 17:57:54 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Dropbox [2012.06.11 09:31:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoft [2012.06.11 19:27:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\EurekaLog [2012.06.18 19:23:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\FotoPrix [2012.04.03 08:46:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\GHISLER [2012.06.25 09:08:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\gnupg [2012.04.28 00:00:02 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\HandBrake [2012.03.16 23:23:01 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Identities [2012.06.05 12:55:37 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\InstallShield [2012.03.17 16:43:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Intel [2012.04.18 18:59:05 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Intermedia Software [2012.03.17 10:44:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\IrfanView [2012.06.23 16:34:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\JPEGsnoop [2012.04.09 17:42:57 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\LibreOffice [2012.03.17 00:37:57 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\LucasArts [2012.03.17 00:04:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Macromedia [2012.06.06 12:19:53 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Malwarebytes [2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Media Center Programs [2012.05.18 22:05:05 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Media Player Classic [2012.06.24 11:49:31 | 000,000,000 | --SD | M] -- C:\Users\***\AppData\Roaming\Microsoft [2012.03.16 23:30:15 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Mozilla [2012.05.21 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Nokia [2012.05.21 19:38:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PC Suite [2012.06.24 15:02:10 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\pdfforge [2012.05.29 22:27:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PwrMgr [2012.04.23 22:01:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Samsung [2012.03.19 09:28:03 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Swiss Academic Software [2012.03.22 09:14:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Thunderbird [2012.06.20 21:30:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\vlc [2012.06.24 10:06:04 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\www.shadowexplorer.com < %APPDATA%\*.exe /s > [2012.06.07 04:02:30 | 027,502,520 | ---- | M] (Dropbox, Inc.) -- C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012.06.07 04:02:32 | 000,874,384 | ---- | M] (Dropbox, Inc.) -- C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe [2012.06.07 04:02:38 | 000,181,776 | ---- | M] (Dropbox, Inc.) -- C:\Users\***\AppData\Roaming\Dropbox\bin\Uninstall.exe [2012.03.31 15:13:23 | 000,010,134 | ---- | M] () -- C:\Users\***\AppData\Roaming\Microsoft\Installer\{24E92E7A-6848-4747-A3EA-3AAC0576BE52}\ARPPRODUCTICON.exe [2012.05.29 18:15:16 | 000,010,134 | ---- | M] () -- C:\Users\***\AppData\Roaming\Microsoft\Installer\{A7BB9BBD-DFE4-4276-820A-7CD141FC09E6}\ARPPRODUCTICON.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys [2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys < MD5 for: ATAPI.SYS > [2002.08.29 04:52:58 | 010,180,476 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp1.cab:atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys [2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys [2002.08.29 02:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\Windows.old\Windows\system32\drivers\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll < MD5 for: EVENTLOG.DLL > [2002.08.29 04:43:22 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\Windows.old\Windows\system32\dllcache\eventlog.dll [2002.08.29 04:43:22 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\Windows.old\Windows\system32\eventlog.dll < MD5 for: IASTOR.SYS > [2009.08.07 05:17:26 | 000,330,264 | ---- | M] (Intel Corporation) MD5=01446278D4563B3013C92830AE6CBB26 -- C:\Program Files\Lenovo\System Update\session\6iim10ww\IaStor.sys [2009.08.07 05:17:26 | 000,330,264 | ---- | M] (Intel Corporation) MD5=01446278D4563B3013C92830AE6CBB26 -- C:\Windows\System32\drivers\iaStor.sys [2009.08.07 05:17:26 | 000,330,264 | ---- | M] (Intel Corporation) MD5=01446278D4563B3013C92830AE6CBB26 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_c1e7c6170b79c26b\iaStor.sys < MD5 for: IASTORV.SYS > [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 07:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys [2011.03.11 07:43:55 | 000,332,160 | ---- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys [2011.03.11 07:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys [2010.11.20 05:29:56 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys [2010.11.20 05:29:56 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys [2011.03.11 07:52:21 | 000,332,160 | ---- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2002.08.29 04:43:26 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\Windows.old\Windows\system32\dllcache\netlogon.dll [2002.08.29 04:43:26 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\Windows.old\Windows\system32\netlogon.dll [2010.11.20 05:20:30 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll [2010.11.20 05:20:30 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 07:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys [2011.03.11 07:44:01 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys [2011.03.11 07:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys [2011.03.11 07:52:25 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys [2010.11.20 05:30:08 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys [2010.11.20 05:30:08 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll [2010.11.20 05:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll [2010.11.20 05:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll [2002.08.29 04:43:30 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\Windows.old\Windows\system32\dllcache\scecli.dll [2002.08.29 04:43:30 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\Windows.old\Windows\system32\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll [2002.08.29 04:43:32 | 000,561,664 | ---- | M] (Microsoft Corporation) MD5=E3DAFFDB1C86C1AEAC1B205F6CF67009 -- C:\Windows.old\Windows\system32\dllcache\user32.dll [2002.08.29 04:43:32 | 000,561,664 | ---- | M] (Microsoft Corporation) MD5=E3DAFFDB1C86C1AEAC1B205F6CF67009 -- C:\Windows.old\Windows\system32\user32.dll [2010.11.20 05:21:34 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll [2010.11.20 05:21:34 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll < MD5 for: USERINIT.EXE > [2010.11.20 05:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010.11.20 05:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe [2002.08.29 04:43:42 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\Windows.old\Windows\system32\dllcache\userinit.exe [2002.08.29 04:43:42 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\Windows.old\Windows\system32\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2002.08.29 04:43:42 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\Windows.old\Windows\system32\dllcache\winlogon.exe [2002.08.29 04:43:42 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\Windows.old\Windows\system32\winlogon.exe [2010.11.20 05:17:56 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010.11.20 05:17:56 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < MD5 for: WS2IFSL.SYS > [2001.08.18 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\Windows.old\Windows\system32\dllcache\ws2ifsl.sys [2001.08.18 12:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\Windows.old\Windows\system32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < End of report > |
![]() | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Sagmal ist das rein zufällig ein gewerblich genutzter (Büro-)PC? ![]()
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #10 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Nee.... wieso? |
![]() | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Kann ich nicht begründen, war eher ein Bauchgefühl ![]() Code:
ATTFilter [2012.06.25 09:06:56 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr [2012.06.17 18:17:28 | 000,000,689 | ---- | C] () -- C:\Windows\System32\volto_CR5BAQ.lic [2012.06.17 18:12:48 | 001,908,736 | ---- | C] ( ) -- C:\Users\***\CIPP.exe [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Bibzrzhnhsl
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #12 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) - die ersten beiden Dateien sagen mir nichts - CIPP.exe ist ein Programm zum Erstellen von CD-Covern... - der Ordner sagt mir nichts, ist aber auch leer (auch keine versteckten Dateien) |
![]() | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!! Code:
ATTFilter :OTL [2012.06.25 09:06:56 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr [2012.06.17 18:17:28 | 000,000,689 | ---- | C] () -- C:\Windows\System32\volto_CR5BAQ.lic [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Bibzrzhnhsl :Commands [purity] [emptytemp] [emptyflash] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #14 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de)Code:
ATTFilter All processes killed ========== OTL ========== C:\Windows\S.dirmngr moved successfully. C:\Windows\System32\volto_CR5BAQ.lic moved successfully. C:\Users\***\AppData\Roaming\Bibzrzhnhsl folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: *** ->Temp folder emptied: 66150382 bytes ->Temporary Internet Files folder emptied: 285661963 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 54877149 bytes ->Flash cache emptied: 816 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1533399 bytes %systemroot%\System32 .tmp files removed: 18400 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 120956749 bytes RecycleBin emptied: 18457542795 bytes Total Files Cleaned = 18.107,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Public User: *** ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version log created on 06262012_142409 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... |
![]() | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C ![]() Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten! ![]()
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() |
Themen zu Verschlüsselungstrojaner! (flirt-fever.de) |
anhang, beenden, beendet, benutzer, bild, computer, dateisystem, device driver, document, eingeblendet, euro, folge, folgende, forum, gemail, gmer-scan, google earth, heuristiks/extra, heuristiks/shuriken, install.exe, kosten, langs, lenovo, mail, microsoft office word, modus, neu, neustart, neustarten, nicht mehr, offene, ordner, plug-in, plötzlich, rechnung, safer networking, searchscopes, taskmanager, total commander, trojaner-board, version=1.0, öffnen |