Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Verschlüsselungstrojaner! (flirt-fever.de)

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 06.06.2012, 11:42   #1
ms_sh
 
Verschlüsselungstrojaner! (flirt-fever.de) - Standard

Verschlüsselungstrojaner! (flirt-fever.de)



Liebes Forum,

Auch ich bin auf einen Verschlüsselungstrojaner hereingefallen und nachdem ich mich erstmal kräftig in den A**** gebissen habe (Anfängerfehler!) muss ich nun den Computer wieder hinkriegen.

Also ich erhielt folgende Mail und hatte schneller auf den Anhang geklickt als ich nachdenken konnte - zu spät:

------------------------------------------------------------------

***** Buchung von Flirt-Fever AG Nummer

Date: Tuesday, 5 Jun 2012 13:25
From: santa@claussanta.com
To: "*****" <*****@******.***>
Attachments:
05.06.2012.zip (44K)

Lieber Benutzer *****,

wir mussten leider feststellen, dass unsere Rechnung NR.: 9075365759 für den Nutzer ***** immer noch nicht ausgeglichen wurde. Dies bedeutet einen rechtskräftigen Vertragsbruch von Ihnen. Nach geltendem Recht könnten wir die offenen Kosten bereits jetzt durch Gericht anmelden. Wir geben Ihnen trotzdem noch eine letzte Möglichkeit, Ihre Verpflichtung zu erfüllen, indem Sie innerhalb von 3 Tagen die ausstehende Summe in Höhe von 422.00 EURO an uns zahlen.

Die erbrachten Leistungen und die Kontodaten können Sie im zugefügten Ordner ansehen.

Bitte beachten Sie, die Folgen des Verzugs bestehen vor allem in der Regresspflicht des Schuldners sowie in einer verschärften Haftung.


Flirt-Fever DE mit Stand in Bremen

Amtsgericht: Köln
Leiter:

-----------------------------------------------------------------

Kurze Zeit später stellte ich fest dass ein Teil - nicht alle - meiner Office- und pdf-Dateien nicht mehr zu öffnen waren bzw. nur Hieroglyphen enthielten. Der Dateiname blieb der alte.
Eine Zeitlang passierte sonst nicht plötzlich startete jedoch mein PC von selbst neu und nach dem Neustart wurde nach kurzer Zeit ein Bild eingeblendet welches eine Aufforderung enthielt ein kostenpflichtiges Windowsupdate durchzuführen. Dieses Bild ließ sich weder wegklicken noch im Taskmanager beenden so dass ich den PC im abgesicherter Modus neustarten musste um diese Zeilen zu tippen. Aus diesem Grund kann ich davon auch keine Screenshot posten.

Die Mail hab ich ans Trojaner-Board gemailt (N1P-I3ohLp-fm5.eml). Gerade läuft der Malwarebytes-Scan. Wenn dieser beendet ist werde ich weitere Informationen posten.

Vielen Dank schonmal!

So der Suchlauf ist beendet, Schädlinge (hoffentlich beseitigte) und Computer läuft auch wieder.

Das ist der Inhalt der Logdatei:

--------------------------------------------------------------------
Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.06.02

Windows 7 Service Pack 1 x86 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 9.0.8112.16421
***** :: *****-PC [Administrator]

Schutz: Deaktiviert

06.06.2012 12:22:17
mbam-log-2012-06-06 (12-22-17).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 583247
Laufzeit: 3 Stunde(n), 1 Minute(n), 32 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|885497D9 (Trojan.Agent) -> Daten: C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\*****\AppData\Local\Temp\ilhhrbssnz.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\*****\Downloads\DecryptHelper-0.5.3.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

--------------------------------------------------------------------

Bin dann weiter nach dem "Vorgehen beim Verschlüsselungstrojaner" vorgegangen:

- Entschlüsselungsversuche mit "Decrypthelper" und "AviraRansom" bisher erfolglos bin zu mehr noch nicht gekommen

- Defogger ohne Fehlermeldung

otl.txt
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 06.06.2012 15:32:20 - Run 1
OTL by OldTimer - Version 3.2.46.1     Folder = C:\Users\*****\Downloads
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free
5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS
Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS
Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS
Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS
Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT
Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS
 
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.06 12:44:41 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe
PRC - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\System Update\SUService.exe
PRC - [2012.05.02 01:52:12 | 000,047,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\updrgui.exe
PRC - [2012.05.02 01:48:57 | 000,613,328 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\update.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:42:11 | 000,210,896 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avnotify.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2012.04.22 13:50:44 | 000,174,120 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
PRC - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
PRC - [2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Program Files\Samsung\Kies\KiesHelper.exe
PRC - [2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\DeviceManager.exe
PRC - [2012.03.28 22:11:58 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\ConnectionManager.exe
PRC - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE
PRC - [2012.03.15 06:07:00 | 000,128,576 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
PRC - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
PRC - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2011.10.20 12:09:32 | 000,363,584 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe
PRC - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe
PRC - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe
PRC - [2011.10.20 10:58:46 | 000,101,440 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\LENOVO\VIRTSCRL\virtscrl.exe
PRC - [2011.07.14 16:50:56 | 000,057,672 | ---- | M] (Authentec Inc.) -- C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
PRC - [2011.07.12 18:03:32 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
PRC - [2011.07.12 17:17:04 | 000,138,680 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Zoom\TpScrex.exe
PRC - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
PRC - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
PRC - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files\GNU\GnuPG\dirmngr.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.24 12:35:46 | 000,804,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
PRC - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
PRC - [2010.11.20 05:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2010.04.23 01:16:46 | 000,128,296 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2009.01.26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
PRC - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.05 14:19:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll
MOD - [2012.06.05 14:16:30 | 000,762,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll
MOD - [2012.06.05 14:16:17 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
MOD - [2012.06.05 14:01:19 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\041b1bcf6ae9ab58925791d8198c37e2\PresentationFramework.ni.dll
MOD - [2012.06.05 14:00:46 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1de74c8d0dfd15e3246e5dd394013bf\PresentationCore.ni.dll
MOD - [2012.06.05 14:00:24 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\4b7adff986a085bb562222d0c5fdf5aa\WindowsBase.ni.dll
MOD - [2012.06.05 14:00:17 | 013,197,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9ee9841d9e33fe5dceba4cd7d90f2ae0\System.Windows.Forms.ni.dll
MOD - [2012.06.05 14:00:06 | 001,665,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\03b5233f1511f5fdb39eb681b04e5506\System.Drawing.ni.dll
MOD - [2012.06.05 14:00:05 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll
MOD - [2012.06.05 14:00:03 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
MOD - [2012.06.05 14:00:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012.06.05 13:59:54 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012.06.05 13:59:42 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.04.23 22:02:06 | 000,115,137 | ---- | M] () -- C:\Users\*****\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll
MOD - [2012.04.13 07:13:59 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\c2c7f68605a42caef1b7a19c51de58b4\System.ServiceProcess.ni.dll
MOD - [2012.04.13 07:13:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43e23da6683962ea1168aaf007bbc35d\PresentationFramework.ni.dll
MOD - [2012.04.13 07:12:07 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\74d980e52c1791f1b8608d767a393144\PresentationCore.ni.dll
MOD - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2012.03.30 03:23:38 | 000,079,872 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.FileService.dll
MOD - [2012.03.30 03:21:48 | 014,144,512 | ---- | M] () -- C:\Program Files\Samsung\Kies\Theme\Kies.Theme.dll
MOD - [2012.03.30 03:21:18 | 000,486,912 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.UI.dll
MOD - [2012.03.30 03:21:12 | 000,034,304 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.Interface.dll
MOD - [2012.03.29 18:44:34 | 000,022,528 | ---- | M] () -- C:\Program Files\Samsung\Kies\MVVM\Kies.MVVM.dll
MOD - [2012.03.28 22:13:12 | 000,037,376 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\ASF_cSharpAPI.dll
MOD - [2012.03.28 22:12:04 | 000,839,680 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\System.Data.SQLite.dll
MOD - [2012.03.28 22:12:00 | 000,712,704 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\SHOWDRM_UCC.dll
MOD - [2012.03.28 22:11:58 | 000,237,568 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\drmcm.dll
MOD - [2012.03.28 22:11:28 | 000,720,896 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\MediaModules\LDBCShConv.dll
MOD - [2012.03.18 13:08:34 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll
MOD - [2012.03.18 13:06:32 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll
MOD - [2012.03.18 13:05:59 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll
MOD - [2012.03.18 13:05:57 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.ni.dll
MOD - [2012.03.18 13:05:56 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9e8dfbd1334d30a08ce1f2df29ca9aff\System.Transactions.ni.dll
MOD - [2012.03.18 13:05:55 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll
MOD - [2012.03.18 13:04:32 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll
MOD - [2012.03.18 13:04:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
MOD - [2012.03.18 13:04:15 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
MOD - [2012.03.18 13:04:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2012.03.18 13:03:50 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2012.03.15 06:07:00 | 000,094,208 | ---- | M] () -- C:\PROGRA~2\ThinkPad\UTILIT~1\GR\PWMRT32V.DLL
MOD - [2012.02.20 22:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 22:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2011.03.02 17:18:28 | 000,656,384 | ---- | M] () -- C:\Program Files\GNU\GnuPG\gpgex.dll
MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.04 18:58:06 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009.07.14 10:47:20 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2009.07.14 10:47:15 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll
MOD - [2009.07.14 10:47:15 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll
MOD - [2009.07.14 10:47:11 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2012.05.10 23:34:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.10 20:14:07 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) Intel(R)
SRV - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.15 06:07:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service)
SRV - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) [On_Demand | Running] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc)
SRV - [2012.03.15 06:07:00 | 000,165,440 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE -- (PwmEWSvc)
SRV - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R)
SRV - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
SRV - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe -- (TPHKLOAD)
SRV - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe -- (LENOVO.MICMUTE)
SRV - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2011.06.12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Program Files\GNU\GnuPG\dirmngr.exe -- (DirMngr)
SRV - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2010.11.20 05:19:34 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\Mcx2Svc.dll -- (Mcx2Svc)
SRV - [2010.11.04 18:52:40 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess)
SRV - [2009.07.14 03:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.15 06:07:00 | 000,025,416 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD)
DRV - [2012.03.15 06:07:00 | 000,017,736 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF)
DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPALP)
DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPAL)
DRV - [2012.02.24 11:14:42 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.)
DRV - [2012.02.24 11:14:42 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV - [2012.01.09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2012.01.09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.12.27 03:10:35 | 000,033,080 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd)
DRV - [2011.10.14 19:25:10 | 000,231,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6232.sys -- (e1express) Intel(R)
DRV - [2011.05.30 18:21:24 | 000,011,976 | ---- | M] (Authentec Inc.) [Kernel | Auto | Running] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) SMI Helper Driver (smihlp)
DRV - [2011.05.18 09:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV - [2011.03.29 20:14:08 | 000,122,992 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf)
DRV - [2011.03.29 20:12:16 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN)
DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 05:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 05:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 05:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 03:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 02:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 02:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 02:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.11.20 01:42:30 | 000,246,784 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\udfs.sys -- (udfs)
DRV - [2010.10.07 04:11:38 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32)     Intel(R)
DRV - [2010.09.27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2010.09.07 14:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.04.08 23:11:06 | 000,045,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2009.07.14 03:20:28 | 000,022,096 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk)
DRV - [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009.07.14 01:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2009.07.14 01:11:15 | 000,070,656 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\cdfs.sys -- (cdfs)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2008.11.16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2007.06.21 18:36:32 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007.01.18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2006.11.27 18:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 3E 0E A8 02 43 CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012.03.18 13:26:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.10 23:34:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.03.21 21:21:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2012.03.16 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions
[2012.06.02 17:08:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\q8lojr9q.default\extensions
[2012.03.16 23:29:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.05.10 23:34:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.03.13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.03.13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.03.13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.03.13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.03.13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.03.16 23:36:18 | 000,441,475 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1	www.007guard.com
O1 - Hosts: 127.0.0.1	007guard.com
O1 - Hosts: 127.0.0.1	008i.com
O1 - Hosts: 127.0.0.1	www.008k.com
O1 - Hosts: 127.0.0.1	008k.com
O1 - Hosts: 127.0.0.1	www.00hq.com
O1 - Hosts: 127.0.0.1	00hq.com
O1 - Hosts: 127.0.0.1	010402.com
O1 - Hosts: 127.0.0.1	www.032439.com
O1 - Hosts: 127.0.0.1	032439.com
O1 - Hosts: 127.0.0.1	www.0scan.com
O1 - Hosts: 127.0.0.1	0scan.com
O1 - Hosts: 127.0.0.1	www.1000gratisproben.com
O1 - Hosts: 127.0.0.1	1000gratisproben.com
O1 - Hosts: 127.0.0.1	1001namen.com
O1 - Hosts: 127.0.0.1	www.1001namen.com
O1 - Hosts: 127.0.0.1	100888290cs.com
O1 - Hosts: 127.0.0.1	www.100888290cs.com
O1 - Hosts: 127.0.0.1	www.100sexlinks.com
O1 - Hosts: 127.0.0.1	100sexlinks.com
O1 - Hosts: 127.0.0.1	www.10sek.com
O1 - Hosts: 127.0.0.1	10sek.com
O1 - Hosts: 127.0.0.1	www.1-2005-search.com
O1 - Hosts: 127.0.0.1	1-2005-search.com
O1 - Hosts: 127.0.0.1	www.123fporn.info
O1 - Hosts: 15172 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe (Authentec Inc.)
O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor File not found
O4 - HKCU..\Run: []  File not found
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &Citavi Picker... - C:\ProgramData\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html ()
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.220.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3222A70D-BED3-44EB-9A27-3D895F894144}: DhcpNameServer = 192.168.220.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk G:\
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - J:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.06 12:19:53 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Malwarebytes
[2012.06.06 12:19:49 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.06 12:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.06.06 09:49:46 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\avira
[2012.06.06 08:30:28 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl
[2012.06.05 13:41:03 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Avira
[2012.06.05 13:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.06.05 13:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.06.05 13:35:18 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.06.05 13:35:18 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.06.05 13:35:18 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.06.05 13:35:18 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.06.05 12:59:18 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2
[2012.06.05 12:55:37 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\InstallShield
[2012.06.05 12:54:12 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.06.05 12:14:13 | 000,000,000 | -H-D | C] -- C:\Windows\System32\WLANProfiles
[2012.06.05 12:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2012.06.05 12:11:46 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
[2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco
[2012.06.05 12:06:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2012.06.05 12:06:32 | 000,000,000 | ---D | C] -- C:\Intel
[2012.06.05 12:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2012.06.05 12:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.06.05 12:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.06.05 12:03:12 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012.06.05 12:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.06.05 11:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2012.06.02 17:49:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage
[2012.06.02 16:58:05 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012.06.02 16:57:15 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Dropbox
[2012.05.29 22:27:12 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PwrMgr
[2012.05.29 18:24:47 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Lenovo
[2012.05.29 18:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SPBA
[2012.05.29 18:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkVantage Fingerprint Software
[2012.05.29 18:10:23 | 000,000,000 | ---D | C] -- C:\SWTOOLS
[2012.05.29 18:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo
[2012.05.21 19:41:48 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Nokia
[2012.05.21 19:35:10 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\NokiaAccount
[2012.05.21 19:33:59 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Nokia
[2012.05.21 19:33:58 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite
[2012.05.21 19:33:55 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PC Suite
[2012.05.21 19:33:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia
[2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Nokia
[2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia
[2012.05.21 19:32:19 | 000,018,816 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
[2012.05.21 19:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
[2012.05.21 19:31:44 | 000,075,264 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll
[2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\ProgramData\NokiaInstallerCache
[2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\Nokia
[2012.05.18 22:04:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Media Player Classic
[2012.05.16 09:07:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
[2012.05.11 22:04:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012.05.11 22:03:10 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012.05.11 22:03:07 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Google
[2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.06 15:31:53 | 000,694,430 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2012.06.06 15:31:53 | 000,693,454 | ---- | M] () -- C:\Windows\System32\perfh00A.dat
[2012.06.06 15:31:53 | 000,691,192 | ---- | M] () -- C:\Windows\System32\perfh013.dat
[2012.06.06 15:31:53 | 000,689,726 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2012.06.06 15:31:53 | 000,689,108 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2012.06.06 15:31:53 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2012.06.06 15:31:53 | 000,675,958 | ---- | M] () -- C:\Windows\System32\perfh019.dat
[2012.06.06 15:31:53 | 000,663,804 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2012.06.06 15:31:53 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.06 15:31:53 | 000,632,180 | ---- | M] () -- C:\Windows\System32\perfh00E.dat
[2012.06.06 15:31:53 | 000,623,144 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.06.06 15:31:53 | 000,617,568 | ---- | M] () -- C:\Windows\System32\perfh01D.dat
[2012.06.06 15:31:53 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.06 15:31:53 | 000,610,202 | ---- | M] () -- C:\Windows\System32\perfh01F.dat
[2012.06.06 15:31:53 | 000,551,770 | ---- | M] () -- C:\Windows\System32\perfh008.dat
[2012.06.06 15:31:53 | 000,462,172 | ---- | M] () -- C:\Windows\System32\perfh006.dat
[2012.06.06 15:31:53 | 000,448,586 | ---- | M] () -- C:\Windows\System32\perfh014.dat
[2012.06.06 15:31:53 | 000,434,486 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2012.06.06 15:31:53 | 000,433,388 | ---- | M] () -- C:\Windows\System32\perfh00B.dat
[2012.06.06 15:31:53 | 000,399,736 | ---- | M] () -- C:\Windows\System32\perfh012.dat
[2012.06.06 15:31:53 | 000,388,518 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2012.06.06 15:31:53 | 000,377,870 | ---- | M] () -- C:\Windows\System32\prfh0404.dat
[2012.06.06 15:31:53 | 000,361,768 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2012.06.06 15:31:53 | 000,353,522 | ---- | M] () -- C:\Windows\System32\perfh00D.dat
[2012.06.06 15:31:53 | 000,148,310 | ---- | M] () -- C:\Windows\System32\perfc00E.dat
[2012.06.06 15:31:53 | 000,137,062 | ---- | M] () -- C:\Windows\System32\perfc00A.dat
[2012.06.06 15:31:53 | 000,134,840 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2012.06.06 15:31:53 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2012.06.06 15:31:53 | 000,132,940 | ---- | M] () -- C:\Windows\System32\perfc013.dat
[2012.06.06 15:31:53 | 000,132,516 | ---- | M] () -- C:\Windows\System32\perfc019.dat
[2012.06.06 15:31:53 | 000,130,140 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2012.06.06 15:31:53 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.06 15:31:53 | 000,128,094 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2012.06.06 15:31:53 | 000,127,144 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2012.06.06 15:31:53 | 000,123,740 | ---- | M] () -- C:\Windows\System32\perfc01D.dat
[2012.06.06 15:31:53 | 000,121,788 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.06.06 15:31:53 | 000,121,526 | ---- | M] () -- C:\Windows\System32\perfc01F.dat
[2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.06 15:31:53 | 000,104,676 | ---- | M] () -- C:\Windows\System32\perfc012.dat
[2012.06.06 15:31:53 | 000,104,248 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2012.06.06 15:31:53 | 000,099,334 | ---- | M] () -- C:\Windows\System32\prfc0404.dat
[2012.06.06 15:31:53 | 000,089,436 | ---- | M] () -- C:\Windows\System32\perfc008.dat
[2012.06.06 15:31:53 | 000,082,148 | ---- | M] () -- C:\Windows\System32\perfc00B.dat
[2012.06.06 15:31:53 | 000,079,804 | ---- | M] () -- C:\Windows\System32\perfc006.dat
[2012.06.06 15:31:53 | 000,078,984 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2012.06.06 15:31:53 | 000,077,096 | ---- | M] () -- C:\Windows\System32\perfc014.dat
[2012.06.06 15:31:53 | 000,069,094 | ---- | M] () -- C:\Windows\System32\perfc00D.dat
[2012.06.06 15:31:03 | 000,000,000 | ---- | M] () -- C:\Users\*****\defogger_reenable
[2012.06.06 15:27:10 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.06 15:27:10 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr
[2012.06.06 15:27:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.06 15:26:52 | 2414,682,112 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.06 12:19:50 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.06.06 12:08:23 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.06 10:14:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.05 12:14:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf
[2012.06.04 22:07:07 | 1363,885,269 | ---- | M] () -- C:\Users\*****\Documents\*****.flv
[2012.06.04 20:38:06 | 009,299,786 | ---- | M] () -- C:\Users\*****\Documents\*****.flv
[2012.06.04 18:10:48 | 000,007,168 | ---- | M] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.05.29 21:32:20 | 1453,899,807 | ---- | M] () -- C:\Users\*****\Documents\*****.flv
[2012.05.21 19:35:46 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2012.05.21 19:35:23 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2012.05.17 21:41:46 | 1453,921,921 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Der Wald steht schwarz und schweiget - Sonntag, 13.05.2012  Das Erste.flv
[2012.05.10 23:05:08 | 1460,780,570 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Tatort Die Ballade von Cenk und Valerie - Sonntag, 06.05.2012  Das Erste.flv
[1 C:\Windows\System32\drivers\UMDF\*.tmp files -> C:\Windows\System32\drivers\UMDF\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.06 15:31:03 | 000,000,000 | ---- | C] () -- C:\Users\*****\defogger_reenable
[2012.06.06 15:27:10 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr
[2012.06.06 12:19:50 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.06.05 12:14:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf
[2012.06.05 11:52:43 | 000,002,088 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Device Experience.lnk
[2012.06.05 11:52:42 | 000,002,476 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools.lnk
[2012.05.21 19:35:46 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2012.05.21 19:35:23 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2012.05.11 22:03:13 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.05.11 22:03:12 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.05.10 22:27:38 | 000,007,168 | ---- | C] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.04.18 19:00:07 | 000,000,100 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012.03.28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2012.03.27 17:27:16 | 000,037,046 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Kommagetrennte Werte (Windows).ADR
[2012.03.18 04:58:31 | 000,617,568 | ---- | C] () -- C:\Windows\System32\perfh01D.dat
[2012.03.18 04:58:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat
[2012.03.18 04:58:31 | 000,123,740 | ---- | C] () -- C:\Windows\System32\perfc01D.dat
[2012.03.18 04:58:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat
[2012.03.18 04:58:30 | 000,691,192 | ---- | C] () -- C:\Windows\System32\perfh013.dat
[2012.03.18 04:58:30 | 000,632,180 | ---- | C] () -- C:\Windows\System32\perfh00E.dat
[2012.03.18 04:58:30 | 000,353,522 | ---- | C] () -- C:\Windows\System32\perfh00D.dat
[2012.03.18 04:58:30 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat
[2012.03.18 04:58:30 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat
[2012.03.18 04:58:30 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat
[2012.03.18 04:58:30 | 000,148,310 | ---- | C] () -- C:\Windows\System32\perfc00E.dat
[2012.03.18 04:58:30 | 000,069,094 | ---- | C] () -- C:\Windows\System32\perfc00D.dat
[2012.03.18 04:58:30 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat
[2012.03.18 04:58:30 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat
[2012.03.18 04:58:30 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat
[2012.03.18 04:58:29 | 000,388,518 | ---- | C] () -- C:\Windows\System32\perfh011.dat
[2012.03.18 04:58:29 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat
[2012.03.18 04:58:29 | 000,132,940 | ---- | C] () -- C:\Windows\System32\perfc013.dat
[2012.03.18 04:58:29 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc011.dat
[2012.03.18 04:58:29 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat
[2012.03.18 00:04:25 | 000,551,770 | ---- | C] () -- C:\Windows\System32\perfh008.dat
[2012.03.18 00:04:25 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat
[2012.03.18 00:04:25 | 000,089,436 | ---- | C] () -- C:\Windows\System32\perfc008.dat
[2012.03.18 00:04:25 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat
[2012.03.17 23:25:14 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat
[2012.03.17 23:25:13 | 000,689,108 | ---- | C] () -- C:\Windows\System32\perfh010.dat
[2012.03.17 23:25:13 | 000,127,144 | ---- | C] () -- C:\Windows\System32\perfc010.dat
[2012.03.17 23:25:13 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat
[2012.03.17 23:02:46 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat
[2012.03.17 23:02:45 | 000,434,486 | ---- | C] () -- C:\Windows\System32\perfh001.dat
[2012.03.17 23:02:45 | 000,078,984 | ---- | C] () -- C:\Windows\System32\perfc001.dat
[2012.03.17 23:02:45 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat
[2012.03.17 22:41:24 | 000,679,342 | ---- | C] () -- C:\Windows\System32\prfh0816.dat
[2012.03.17 22:41:24 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat
[2012.03.17 22:41:24 | 000,133,752 | ---- | C] () -- C:\Windows\System32\prfc0816.dat
[2012.03.17 22:41:24 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat
[2012.03.17 22:23:54 | 000,462,172 | ---- | C] () -- C:\Windows\System32\perfh006.dat
[2012.03.17 22:23:54 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat
[2012.03.17 22:23:54 | 000,079,804 | ---- | C] () -- C:\Windows\System32\perfc006.dat
[2012.03.17 22:23:54 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat
[2012.03.17 22:04:51 | 000,693,454 | ---- | C] () -- C:\Windows\System32\perfh00A.dat
[2012.03.17 22:04:51 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat
[2012.03.17 22:04:51 | 000,137,062 | ---- | C] () -- C:\Windows\System32\perfc00A.dat
[2012.03.17 22:04:51 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat
[2012.03.17 21:38:24 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat
[2012.03.17 21:38:23 | 000,689,726 | ---- | C] () -- C:\Windows\System32\perfh015.dat
[2012.03.17 21:38:23 | 000,134,840 | ---- | C] () -- C:\Windows\System32\perfc015.dat
[2012.03.17 21:38:23 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat
[2012.03.17 21:21:25 | 000,675,958 | ---- | C] () -- C:\Windows\System32\perfh019.dat
[2012.03.17 21:21:25 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat
[2012.03.17 21:21:25 | 000,132,516 | ---- | C] () -- C:\Windows\System32\perfc019.dat
[2012.03.17 21:21:25 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat
[2012.03.17 20:57:09 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat
[2012.03.17 20:57:08 | 000,663,804 | ---- | C] () -- C:\Windows\System32\prfh0416.dat
[2012.03.17 20:57:08 | 000,128,094 | ---- | C] () -- C:\Windows\System32\prfc0416.dat
[2012.03.17 20:57:08 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat
[2012.03.17 20:15:05 | 000,610,202 | ---- | C] () -- C:\Windows\System32\perfh01F.dat
[2012.03.17 20:15:05 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat
[2012.03.17 20:15:05 | 000,121,526 | ---- | C] () -- C:\Windows\System32\perfc01F.dat
[2012.03.17 20:15:05 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat
[2012.03.17 11:44:09 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012.03.17 11:43:46 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012.03.17 09:33:11 | 000,694,430 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2012.03.17 09:33:11 | 000,377,870 | ---- | C] () -- C:\Windows\System32\prfh0404.dat
[2012.03.17 09:33:11 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2012.03.17 09:33:11 | 000,130,140 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2012.03.17 09:33:11 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat
[2012.03.17 09:33:11 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat
[2012.03.17 09:33:11 | 000,099,334 | ---- | C] () -- C:\Windows\System32\prfc0404.dat
[2012.03.17 09:33:11 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat
[2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat
[2012.03.17 09:33:10 | 000,623,144 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2012.03.17 09:33:10 | 000,433,388 | ---- | C] () -- C:\Windows\System32\perfh00B.dat
[2012.03.17 09:33:10 | 000,361,768 | ---- | C] () -- C:\Windows\System32\prfh0804.dat
[2012.03.17 09:33:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2012.03.17 09:33:10 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat
[2012.03.17 09:33:10 | 000,121,788 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2012.03.17 09:33:10 | 000,104,248 | ---- | C] () -- C:\Windows\System32\prfc0804.dat
[2012.03.17 09:33:10 | 000,082,148 | ---- | C] () -- C:\Windows\System32\perfc00B.dat
[2012.03.17 09:33:10 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat
[2012.03.17 09:33:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2012.03.17 09:33:09 | 000,448,586 | ---- | C] () -- C:\Windows\System32\perfh014.dat
[2012.03.17 09:33:09 | 000,399,736 | ---- | C] () -- C:\Windows\System32\perfh012.dat
[2012.03.17 09:33:09 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat
[2012.03.17 09:33:09 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat
[2012.03.17 09:33:09 | 000,104,676 | ---- | C] () -- C:\Windows\System32\perfc012.dat
[2012.03.17 09:33:09 | 000,077,096 | ---- | C] () -- C:\Windows\System32\perfc014.dat
[2012.03.17 09:33:09 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat
[2012.03.17 09:33:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat
[2010.09.27 13:03:08 | 000,201,512 | ---- | C] () -- C:\Windows\System32\vpnapi.dll
 
========== LOP Check ==========
 
[2012.04.27 22:46:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Amazon
[2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl
[2012.06.05 22:57:59 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Dropbox
[2012.04.03 08:46:29 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\GHISLER
[2012.06.06 12:48:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\gnupg
[2012.04.28 00:00:02 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\HandBrake
[2012.04.18 18:59:05 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Intermedia Software
[2012.03.17 10:44:31 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\IrfanView
[2012.04.09 17:42:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LibreOffice
[2012.03.17 00:37:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LucasArts
[2012.05.21 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Nokia
[2012.05.21 19:38:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PC Suite
[2012.05.29 22:27:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PwrMgr
[2012.04.23 22:01:49 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Samsung
[2012.03.19 09:28:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Swiss Academic Software
[2012.03.22 09:14:06 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Thunderbird
[2012.06.03 11:57:16 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >
         

extra.txtOTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 06.06.2012 15:32:20 - Run 1
OTL by OldTimer - Version 3.2.46.1     Folder = C:\Users\*****\Downloads
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free
5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS
Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS
Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS
Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS
Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT
Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS
 
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11C140D1-C8CA-480E-8C22-6FB108AC5B9B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{1B695C61-DED9-412B-9F95-749966962621}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | 
"{2E6F1837-74C5-4816-983B-524C69680091}" = lport=137 | protocol=17 | dir=in | app=system | 
"{36E1979F-0A03-4220-A284-89B8265DCAE9}" = lport=445 | protocol=6 | dir=in | app=system | 
"{4586B191-EB75-4CD3-A6A8-73102F4D7A8E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{4BD76F22-1306-4362-81DD-B1C21B0A1879}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{4CD5AA15-FC9F-41F8-A0CF-97C686ECDC83}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{79B401E3-7F75-4A19-BAB9-4345C95DFBF3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{7A2C2210-0657-4A0A-AD54-3ADA7772DC71}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{81454568-B251-494F-B0DB-E09375187CB6}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{83CBC572-FF34-4D54-B01F-D4D55B50DF29}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{89F356D0-65B6-49EC-8371-625A9BA23B6A}" = lport=139 | protocol=6 | dir=in | app=system | 
"{8CC84360-489A-4F1F-A1F5-5AC475480875}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{99B63B6D-E64E-425B-B240-2CE97D0ED178}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A13B6A0E-21E3-42B5-97BF-AAD958E766C1}" = lport=138 | protocol=17 | dir=in | app=system | 
"{A7FD2748-8BDB-424D-85E6-5693CE1C5515}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{AD473898-7C8A-4FBA-B5EF-33CBC72590C9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{B75CF7C7-DB43-49EB-97D7-0216E5A19722}" = rport=138 | protocol=17 | dir=out | app=system | 
"{CDA34F23-BD6D-4B2C-AAC3-E2467F7333C3}" = rport=139 | protocol=6 | dir=out | app=system | 
"{D0CFF402-CEB5-44FE-A417-8AF8D944F413}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D65552B0-8F3B-4B2D-88FB-0CE505539F7C}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E40DF8EE-0878-44DC-B4D1-8933AE5CD172}" = rport=137 | protocol=17 | dir=out | app=system | 
"{F4527DDC-7A77-4B4B-B51F-DE54574C5599}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{F6D1E7E5-5AD3-4135-BDC7-23F05D7B4444}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{154615E7-398E-46D4-AB52-B8F82E32A662}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{190E9810-D7C4-4D2F-8E3F-C046F13A2E95}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{28D924FD-E511-49CA-80CD-5EDA3FD031D4}" = protocol=6 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | 
"{2D0603D6-D2B9-4878-89BA-8F047EDEA786}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | 
"{30847B64-D196-42CD-90D9-3D962C86DB4E}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | 
"{3983EBC6-99D0-49C5-BB67-240C2242D2F4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{44D3D234-9BBC-4B01-BB00-D6466CC2CB8C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{4AFEA250-9F4E-42A7-8D44-F9CCF4A6AD03}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{4EE4D181-E01B-40F0-8543-C8BCD7A5C43F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5E4295EF-424F-4A80-9E0D-79B38BFD8F3C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | 
"{605371DF-B588-4FB4-B1FD-B06E6AE4BCA5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{63EA84F6-CCF0-4973-A453-ECFE9AAB23C2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{66751421-723E-4CCF-804F-4321622D0E31}" = protocol=17 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | 
"{713FFEAA-5865-45DB-B6D8-9C2EF9989329}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{71FB772D-FE3C-4B4D-8BF3-809C6C3103BA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{7EF1447F-FECB-47A5-8810-73A1D209598B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{7F29A31B-5977-4945-98BC-79053C8C43B1}" = protocol=6 | dir=out | app=system | 
"{8AC62D2F-DA7F-4422-8ADE-5E4F1C98C766}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{999FBBAC-37A5-4C7B-9992-8B1BDEA3FD2B}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe | 
"{A1591105-6B07-456D-B8CA-260FA1C09A12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{AC64A7C5-410F-435E-A114-0617CE9F0073}" = protocol=17 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | 
"{B424D08A-C3FF-4F3E-8EAE-54C913AE6706}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{B4BE2661-4E69-4462-B1CC-981559F6089C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{BC4BB849-FF8F-48B3-900F-B5E42A3521A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BC7ACAF4-EF07-4EC6-81D7-D7BC696AC81D}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe | 
"{C6C32619-9A88-45C5-A8AB-685EC5D35EC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C6F2EB79-2A7A-4DDB-9029-C14E2F63FDE8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{C9F41199-FAC6-48E6-BC31-4D952F1DEA22}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{CD3B3755-12DB-4BD5-9B50-7BD9EF5ED7C9}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe | 
"{D43A31F6-B972-414E-AFBB-2D6DF9A01D8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{D66A39EF-0619-4686-9193-0BA51D4845C4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{DE4BDEC8-2C9A-43FF-819C-696D8747CCD5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | 
"{EC0B430D-A5AB-420E-AA99-68EEF19A9D24}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | 
"{EC3D1D9D-3EB0-43D6-8A9D-DA6D4B3471FB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{FDE172B7-7D0D-463A-B4C5-C5B77A9DC13B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{FE010E17-D333-48A7-BD2B-F6D575155F2F}" = protocol=6 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E8E4718-0702-4D33-B007-5E95849BAB3C}" = LibreOffice 3.5
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = Dienstprogramm "ThinkPad UltraNav"
"{1CE60928-8325-49A8-8B06-633E48DD2B67}" = Cisco Systems VPN Client 5.0.07.0410
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{24E92E7A-6848-4747-A3EA-3AAC0576BE52}" = Lenovo Patch Utility
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{705EE775-5776-48FD-B704-C3C9CF535420}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7964AE02-9127-42C0-A917-2CE4CD4EFE3B}" = Nokia Suite
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A7BB9BBD-DFE4-4276-820A-7CD141FC09E6}" = Lenovo Patch Utility
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BA722179-62EA-4090-923D-D324CE1A691D}}_is1" = Helium Music Manager 8 (build 10470)
"{BAA0BE9B-9E6D-4802-91CB-FB7ED5CD4BEF}" = Intel® PROSet/Wireless WiFi-Software
"{C2938C94-239C-4156-B245-C5406A4F3E93}" = ThinkVantage Fingerprint Software
"{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel
"{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}" = Steuer-Spar-Erklärung 2012
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = Energie-Manager
"{E12C6653-1FF0-4686-ADB8-589C13AE761F}" = Citavi
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171
"2004BB9EB6CEA02846881BEF1F51C11F7A90C9D6" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth  (04/08/2010 6.3.5.430)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Avira AntiVir Desktop" = Avira Free Antivirus
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)
"Clementine" = Clementine
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588" = ThinkPad Modem
"GPG4Win" = Gpg4win (2.1.0)
"HandBrake" = HandBrake 0.9.6
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"IrfanView" = IrfanView (remove only)
"LENOVO.SMIIF" = Lenovo System Interface Driver
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility
"Loeffelfamilie" = Loeffelfamilie Screen Saver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"MISEC" = Monkey Island™ Special Edition Collection
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Nokia Suite" = Nokia Suite
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"OnScreenDisplay" = Anzeige am Bildschirm
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SnowFox Total Video Converter_is1" = SnowFox Total Video Converter 3.0.1.0
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VLC media player 2.0.1
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 9000
Description = 
 
Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 1006
Description = 
 
Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257
Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert
 werden. "ESENT"-Fehler: -583.
 
[ System Events ]
Error - 06.06.2012 09:28:19 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits
 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt:
 Neustart des Diensts.
 
Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024
Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem
 Fehler beendet: %%-2147217025.
 
Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits
 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt:
 Neustart des Diensts.
 
Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024
Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem
 Fehler beendet: %%-2147217025.
 
Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits
 3 Mal passiert.
 
Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024
Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem
 Fehler beendet: %%-2147217025.
 
Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits
 4 Mal passiert.
 
Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet: 
  %%-1906441657
 
Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024
Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem
 Fehler beendet: %%-2147217025.
 
Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits
 5 Mal passiert.
 
 
< End of report >
         
-------------------------------------------
Der Gmer-Scan hat dann sehr lange gedauert weshalb ich ihn nicht permanent verfolgen konnte. Aber er scheint aus irgendeinem Grund den PC zum Absturz gebracht zu haben, weswegen ich ihn nochmal neu starte!

Geändert von ms_sh (06.06.2012 um 11:59 Uhr)

 

Themen zu Verschlüsselungstrojaner! (flirt-fever.de)
anhang, beenden, beendet, benutzer, bild, computer, dateisystem, device driver, document, eingeblendet, euro, folge, folgende, forum, gemail, gmer-scan, google earth, heuristiks/extra, heuristiks/shuriken, install.exe, kosten, langs, lenovo, mail, microsoft office word, modus, neu, neustart, neustarten, nicht mehr, offene, ordner, plug-in, plötzlich, rechnung, safer networking, searchscopes, taskmanager, total commander, trojaner-board, version=1.0, öffnen




Ähnliche Themen: Verschlüsselungstrojaner! (flirt-fever.de)


  1. Flirt-Fever Trojaner_abgesicherter Modus funktioniert nicht
    Log-Analyse und Auswertung - 12.09.2012 (5)
  2. (2x) Flirt-Fever Trojaner/Virus hat PC verseucht
    Mülltonne - 14.06.2012 (1)
  3. flirt-fever Verschlüsselungstrojaner ohne original dateien
    Plagegeister aller Art und deren Bekämpfung - 12.06.2012 (1)
  4. Verschlüsselungstrojaner von Schreiben.zip -Flirt Fever
    Plagegeister aller Art und deren Bekämpfung - 12.06.2012 (2)
  5. Windows Verschlüsselungs Trojaner (flirt-fever)
    Log-Analyse und Auswertung - 11.06.2012 (1)
  6. Entschlüsselungstrojaner von Flirt-fever
    Plagegeister aller Art und deren Bekämpfung - 08.06.2012 (2)
  7. flirt-fever trjoaner! befallen!
    Plagegeister aller Art und deren Bekämpfung - 08.06.2012 (3)
  8. Verschlüsselungstrojaner (E-Mail Flirt Fever)
    Plagegeister aller Art und deren Bekämpfung - 07.06.2012 (6)
  9. Trojaner über Flirt Fever
    Plagegeister aller Art und deren Bekämpfung - 07.06.2012 (3)
  10. Flirt-Fever Trojaner-Befall
    Plagegeister aller Art und deren Bekämpfung - 07.06.2012 (3)
  11. Verschlüsselungstrojaner nach Flirt-Fever Mail
    Plagegeister aller Art und deren Bekämpfung - 06.06.2012 (5)
  12. (2x) verschlüsselungs Trojaner nach flirt fever mail
    Mülltonne - 05.06.2012 (1)
  13. Verschlüsselungstrojaner Flirt Fever "Mahnbescheid"
    Mülltonne - 05.06.2012 (1)
  14. Flirt Fever - Verschlüsselungstrojaner
    Log-Analyse und Auswertung - 04.06.2012 (5)
  15. Flirt Fever Trojaner
    Plagegeister aller Art und deren Bekämpfung - 03.06.2012 (1)
  16. Flirt Fever Trojaner einfach nur loswerden
    Plagegeister aller Art und deren Bekämpfung - 03.06.2012 (1)
  17. flirt-fever malware
    Plagegeister aller Art und deren Bekämpfung - 31.05.2012 (2)

Zum Thema Verschlüsselungstrojaner! (flirt-fever.de) - Liebes Forum, Auch ich bin auf einen Verschlüsselungstrojaner hereingefallen und nachdem ich mich erstmal kräftig in den A**** gebissen habe (Anfängerfehler!) muss ich nun den Computer wieder hinkriegen. Also ich - Verschlüsselungstrojaner! (flirt-fever.de)...
Archiv
Du betrachtest: Verschlüsselungstrojaner! (flirt-fever.de) auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.