![]() |
|
Log-Analyse und Auswertung: Verschlüsselungstrojaner! (flirt-fever.de)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Verschlüsselungstrojaner! (flirt-fever.de) Liebes Forum, Auch ich bin auf einen Verschlüsselungstrojaner hereingefallen und nachdem ich mich erstmal kräftig in den A**** gebissen habe (Anfängerfehler!) muss ich nun den Computer wieder hinkriegen. Also ich erhielt folgende Mail und hatte schneller auf den Anhang geklickt als ich nachdenken konnte - zu spät: ------------------------------------------------------------------ ***** Buchung von Flirt-Fever AG Nummer Date: Tuesday, 5 Jun 2012 13:25 From: santa@claussanta.com To: "*****" <*****@******.***> Attachments: 05.06.2012.zip (44K) Lieber Benutzer *****, wir mussten leider feststellen, dass unsere Rechnung NR.: 9075365759 für den Nutzer ***** immer noch nicht ausgeglichen wurde. Dies bedeutet einen rechtskräftigen Vertragsbruch von Ihnen. Nach geltendem Recht könnten wir die offenen Kosten bereits jetzt durch Gericht anmelden. Wir geben Ihnen trotzdem noch eine letzte Möglichkeit, Ihre Verpflichtung zu erfüllen, indem Sie innerhalb von 3 Tagen die ausstehende Summe in Höhe von 422.00 EURO an uns zahlen. Die erbrachten Leistungen und die Kontodaten können Sie im zugefügten Ordner ansehen. Bitte beachten Sie, die Folgen des Verzugs bestehen vor allem in der Regresspflicht des Schuldners sowie in einer verschärften Haftung. Flirt-Fever DE mit Stand in Bremen Amtsgericht: Köln Leiter: ----------------------------------------------------------------- Kurze Zeit später stellte ich fest dass ein Teil - nicht alle - meiner Office- und pdf-Dateien nicht mehr zu öffnen waren bzw. nur Hieroglyphen enthielten. Der Dateiname blieb der alte. Eine Zeitlang passierte sonst nicht plötzlich startete jedoch mein PC von selbst neu und nach dem Neustart wurde nach kurzer Zeit ein Bild eingeblendet welches eine Aufforderung enthielt ein kostenpflichtiges Windowsupdate durchzuführen. Dieses Bild ließ sich weder wegklicken noch im Taskmanager beenden so dass ich den PC im abgesicherter Modus neustarten musste um diese Zeilen zu tippen. Aus diesem Grund kann ich davon auch keine Screenshot posten. Die Mail hab ich ans Trojaner-Board gemailt (N1P-I3ohLp-fm5.eml). Gerade läuft der Malwarebytes-Scan. Wenn dieser beendet ist werde ich weitere Informationen posten. Vielen Dank schonmal! So der Suchlauf ist beendet, Schädlinge (hoffentlich beseitigte) und Computer läuft auch wieder. Das ist der Inhalt der Logdatei: -------------------------------------------------------------------- Malwarebytes Anti-Malware (Test) 1.61.0.1400 www.malwarebytes.org Datenbank Version: v2012.06.06.02 Windows 7 Service Pack 1 x86 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 9.0.8112.16421 ***** :: *****-PC [Administrator] Schutz: Deaktiviert 06.06.2012 12:22:17 mbam-log-2012-06-06 (12-22-17).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 583247 Laufzeit: 3 Stunde(n), 1 Minute(n), 32 Sekunde(n) [Abgebrochen] Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|885497D9 (Trojan.Agent) -> Daten: C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Users\*****\AppData\Roaming\Bibzrzhnhsl\675670F2885497D915E2.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\*****\AppData\Local\Temp\ilhhrbssnz.pre (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\*****\Downloads\DecryptHelper-0.5.3.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) -------------------------------------------------------------------- Bin dann weiter nach dem "Vorgehen beim Verschlüsselungstrojaner" vorgegangen: - Entschlüsselungsversuche mit "Decrypthelper" und "AviraRansom" bisher erfolglos bin zu mehr noch nicht gekommen - Defogger ohne Fehlermeldung otl.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 06.06.2012 15:32:20 - Run 1 OTL by OldTimer - Version 3.2.46.1 Folder = C:\Users\*****\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free 5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS Computer Name: *****-PC | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.06.06 12:44:41 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe PRC - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\System Update\SUService.exe PRC - [2012.05.02 01:52:12 | 000,047,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\updrgui.exe PRC - [2012.05.02 01:48:57 | 000,613,328 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\update.exe PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.02 00:42:11 | 000,210,896 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avnotify.exe PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.04.24 02:11:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PRC - [2012.04.22 13:50:44 | 000,174,120 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PRC - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe PRC - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe PRC - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2012.03.31 04:38:14 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe PRC - [2012.03.31 04:38:12 | 000,954,256 | ---- | M] (Samsung) -- C:\Program Files\Samsung\Kies\KiesHelper.exe PRC - [2012.03.28 22:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\DeviceManager.exe PRC - [2012.03.28 22:11:58 | 000,140,800 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Program Files\Samsung\Kies\External\DeviceModules\ConnectionManager.exe PRC - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE PRC - [2012.03.15 06:07:00 | 000,128,576 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe PRC - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe PRC - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe PRC - [2011.10.20 12:09:32 | 000,363,584 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe PRC - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe PRC - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe PRC - [2011.10.20 10:58:46 | 000,101,440 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\LENOVO\VIRTSCRL\virtscrl.exe PRC - [2011.07.14 16:50:56 | 000,057,672 | ---- | M] (Authentec Inc.) -- C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe PRC - [2011.07.12 18:03:32 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe PRC - [2011.07.12 17:17:04 | 000,138,680 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Zoom\TpScrex.exe PRC - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe PRC - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe PRC - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Program Files\GNU\GnuPG\dirmngr.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.24 12:35:46 | 000,804,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe PRC - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe PRC - [2010.11.20 05:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe PRC - [2010.04.23 01:16:46 | 000,128,296 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2009.01.26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE ========== Modules (No Company Name) ========== MOD - [2012.06.05 14:19:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll MOD - [2012.06.05 14:16:30 | 000,762,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll MOD - [2012.06.05 14:16:17 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll MOD - [2012.06.05 14:01:19 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\041b1bcf6ae9ab58925791d8198c37e2\PresentationFramework.ni.dll MOD - [2012.06.05 14:00:46 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1de74c8d0dfd15e3246e5dd394013bf\PresentationCore.ni.dll MOD - [2012.06.05 14:00:24 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\4b7adff986a085bb562222d0c5fdf5aa\WindowsBase.ni.dll MOD - [2012.06.05 14:00:17 | 013,197,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9ee9841d9e33fe5dceba4cd7d90f2ae0\System.Windows.Forms.ni.dll MOD - [2012.06.05 14:00:06 | 001,665,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\03b5233f1511f5fdb39eb681b04e5506\System.Drawing.ni.dll MOD - [2012.06.05 14:00:05 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll MOD - [2012.06.05 14:00:03 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll MOD - [2012.06.05 14:00:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll MOD - [2012.06.05 13:59:54 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll MOD - [2012.06.05 13:59:42 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll MOD - [2012.04.23 22:02:06 | 000,115,137 | ---- | M] () -- C:\Users\*****\AppData\Local\Temp\bd7c47bb-f5c0-417c-a180-ec348d87718a\CliSecureRT.dll MOD - [2012.04.13 07:13:59 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\c2c7f68605a42caef1b7a19c51de58b4\System.ServiceProcess.ni.dll MOD - [2012.04.13 07:13:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43e23da6683962ea1168aaf007bbc35d\PresentationFramework.ni.dll MOD - [2012.04.13 07:12:07 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\74d980e52c1791f1b8608d767a393144\PresentationCore.ni.dll MOD - [2012.03.31 04:38:26 | 000,021,392 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MOD - [2012.03.30 03:23:38 | 000,079,872 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.FileService.dll MOD - [2012.03.30 03:21:48 | 014,144,512 | ---- | M] () -- C:\Program Files\Samsung\Kies\Theme\Kies.Theme.dll MOD - [2012.03.30 03:21:18 | 000,486,912 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.UI.dll MOD - [2012.03.30 03:21:12 | 000,034,304 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.Interface.dll MOD - [2012.03.29 18:44:34 | 000,022,528 | ---- | M] () -- C:\Program Files\Samsung\Kies\MVVM\Kies.MVVM.dll MOD - [2012.03.28 22:13:12 | 000,037,376 | ---- | M] () -- C:\Program Files\Samsung\Kies\Common\ASF_cSharpAPI.dll MOD - [2012.03.28 22:12:04 | 000,839,680 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\System.Data.SQLite.dll MOD - [2012.03.28 22:12:00 | 000,712,704 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\SHOWDRM_UCC.dll MOD - [2012.03.28 22:11:58 | 000,237,568 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\DeviceModules\drmcm.dll MOD - [2012.03.28 22:11:28 | 000,720,896 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\MediaModules\LDBCShConv.dll MOD - [2012.03.18 13:08:34 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll MOD - [2012.03.18 13:06:32 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll MOD - [2012.03.18 13:05:59 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll MOD - [2012.03.18 13:05:57 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.ni.dll MOD - [2012.03.18 13:05:56 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9e8dfbd1334d30a08ce1f2df29ca9aff\System.Transactions.ni.dll MOD - [2012.03.18 13:05:55 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll MOD - [2012.03.18 13:04:32 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll MOD - [2012.03.18 13:04:22 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll MOD - [2012.03.18 13:04:15 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll MOD - [2012.03.18 13:04:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll MOD - [2012.03.18 13:03:50 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll MOD - [2012.03.15 06:07:00 | 000,094,208 | ---- | M] () -- C:\PROGRA~2\ThinkPad\UTILIT~1\GR\PWMRT32V.DLL MOD - [2012.02.20 22:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.02.20 22:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf MOD - [2011.03.02 17:18:28 | 000,656,384 | ---- | M] () -- C:\Program Files\GNU\GnuPG\gpgex.dll MOD - [2010.11.13 01:19:04 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2010.11.04 18:58:06 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2009.07.14 10:47:20 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll MOD - [2009.07.14 10:47:15 | 000,167,936 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll MOD - [2009.07.14 10:47:15 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll MOD - [2009.07.14 10:47:11 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService) SRV - [2012.05.11 17:02:38 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService) SRV - [2012.05.10 23:34:41 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.10 20:14:07 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.04.22 13:51:04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012.04.17 19:20:54 | 002,326,288 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) Intel(R) SRV - [2012.04.17 19:20:36 | 000,498,960 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R) SRV - [2012.04.17 19:20:32 | 000,107,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R) SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.03.15 06:07:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service) SRV - [2012.03.15 06:07:00 | 000,280,640 | ---- | M] (Lenovo.) [On_Demand | Running] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc) SRV - [2012.03.15 06:07:00 | 000,165,440 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE -- (PwmEWSvc) SRV - [2012.03.08 12:19:40 | 000,104,208 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R) SRV - [2012.03.01 11:35:18 | 000,509,448 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.10.20 12:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe -- (AcSvc) SRV - [2011.10.20 12:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc) SRV - [2011.07.12 16:54:02 | 000,127,336 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC) SRV - [2011.07.12 16:53:48 | 000,131,432 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe -- (TPHKLOAD) SRV - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe -- (LENOVO.MICMUTE) SRV - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe -- (TPHKSVC) SRV - [2011.06.12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Program Files\GNU\GnuPG\dirmngr.exe -- (DirMngr) SRV - [2011.01.24 12:35:46 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2010.11.20 05:19:34 | 000,068,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\Mcx2Svc.dll -- (Mcx2Svc) SRV - [2010.11.04 18:52:40 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing) SRV - [2010.09.27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2009.07.14 03:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\mprdim.dll -- (RemoteAccess) SRV - [2009.07.14 03:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008.07.15 18:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.03.15 06:07:00 | 000,025,416 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD) DRV - [2012.03.15 06:07:00 | 000,017,736 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPALP) DRV - [2012.03.01 10:55:22 | 000,141,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmpPal.sys -- (AMPPAL) DRV - [2012.02.24 11:14:42 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) DRV - [2012.02.24 11:14:42 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) DRV - [2012.01.09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2012.01.09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011.12.27 03:10:35 | 000,033,080 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd) DRV - [2011.10.14 19:25:10 | 000,231,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6232.sys -- (e1express) Intel(R) DRV - [2011.05.30 18:21:24 | 000,011,976 | ---- | M] (Authentec Inc.) [Kernel | Auto | Running] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) SMI Helper Driver (smihlp) DRV - [2011.05.18 09:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB) DRV - [2011.03.29 20:14:08 | 000,122,992 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf) DRV - [2011.03.29 20:12:16 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN) DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 05:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 05:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 05:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 03:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 02:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 02:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 02:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.11.20 01:42:30 | 000,246,784 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\udfs.sys -- (udfs) DRV - [2010.10.07 04:11:38 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32) Intel(R) DRV - [2010.09.27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2010.09.07 14:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.04.08 23:11:06 | 000,045,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt) DRV - [2009.07.14 03:20:28 | 000,022,096 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk) DRV - [2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009.07.14 01:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2009.07.14 01:11:15 | 000,070,656 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\cdfs.sys -- (cdfs) DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R) DRV - [2008.11.16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE) DRV - [2007.06.21 18:36:32 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2007.01.18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006.11.27 18:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 3E 0E A8 02 43 CD 01 [binary data] IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012.03.18 13:26:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.10 23:34:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.03.21 21:21:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012.03.16 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions [2012.06.02 17:08:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\q8lojr9q.default\extensions [2012.03.16 23:29:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.05.10 23:34:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.03.13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.03.16 23:36:18 | 000,441,475 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.123fporn.info O1 - Hosts: 15172 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe (Lenovo) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe (Authentec Inc.) O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor File not found O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: &Citavi Picker... - C:\ProgramData\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html () O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: microsoft.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites) O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites) O15 - HKCU\..Trusted Domains: windowsupdate.com ([]* in Trusted sites) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.220.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3222A70D-BED3-44EB-9A27-3D895F894144}: DhcpNameServer = 192.168.220.1 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - Unable to obtain root file information for disk G:\ O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - J:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.06.06 12:19:53 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Malwarebytes [2012.06.06 12:19:49 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.06.06 12:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.06.06 12:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.06.06 09:49:46 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\avira [2012.06.06 08:30:28 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl [2012.06.05 13:41:03 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Avira [2012.06.05 13:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.06.05 13:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2012.06.05 13:35:18 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2012.06.05 13:35:18 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2012.06.05 13:35:18 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys [2012.06.05 13:35:18 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.06.05 13:35:17 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.06.05 12:59:18 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2 [2012.06.05 12:55:37 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\InstallShield [2012.06.05 12:54:12 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012.06.05 12:14:13 | 000,000,000 | -H-D | C] -- C:\Windows\System32\WLANProfiles [2012.06.05 12:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2012.06.05 12:11:46 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel [2012.06.05 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco [2012.06.05 12:06:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll [2012.06.05 12:06:32 | 000,000,000 | ---D | C] -- C:\Intel [2012.06.05 12:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab [2012.06.05 12:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2012.06.05 12:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012.06.05 12:03:12 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle [2012.06.05 12:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012.06.05 11:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage [2012.06.02 17:49:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage [2012.06.02 16:58:05 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox [2012.06.02 16:57:15 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Dropbox [2012.05.29 22:27:12 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PwrMgr [2012.05.29 18:24:47 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Lenovo [2012.05.29 18:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SPBA [2012.05.29 18:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\ThinkVantage Fingerprint Software [2012.05.29 18:10:23 | 000,000,000 | ---D | C] -- C:\SWTOOLS [2012.05.29 18:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lenovo [2012.05.21 19:41:48 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Nokia [2012.05.21 19:35:10 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\NokiaAccount [2012.05.21 19:33:59 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Nokia [2012.05.21 19:33:58 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite [2012.05.21 19:33:55 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\PC Suite [2012.05.21 19:33:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia [2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Nokia [2012.05.21 19:33:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia [2012.05.21 19:32:19 | 000,018,816 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys [2012.05.21 19:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution [2012.05.21 19:31:44 | 000,075,264 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll [2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\ProgramData\NokiaInstallerCache [2012.05.21 19:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\Nokia [2012.05.18 22:04:36 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Media Player Classic [2012.05.16 09:07:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net [2012.05.11 22:04:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2012.05.11 22:03:10 | 000,000,000 | ---D | C] -- C:\Program Files\Google [2012.05.11 22:03:07 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Google [2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2012.05.10 23:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.06.06 15:34:37 | 000,020,592 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.06.06 15:31:53 | 000,694,430 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2012.06.06 15:31:53 | 000,693,454 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2012.06.06 15:31:53 | 000,691,192 | ---- | M] () -- C:\Windows\System32\perfh013.dat [2012.06.06 15:31:53 | 000,689,726 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012.06.06 15:31:53 | 000,689,108 | ---- | M] () -- C:\Windows\System32\perfh010.dat [2012.06.06 15:31:53 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat [2012.06.06 15:31:53 | 000,675,958 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2012.06.06 15:31:53 | 000,663,804 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2012.06.06 15:31:53 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.06.06 15:31:53 | 000,632,180 | ---- | M] () -- C:\Windows\System32\perfh00E.dat [2012.06.06 15:31:53 | 000,623,144 | ---- | M] () -- C:\Windows\System32\perfh005.dat [2012.06.06 15:31:53 | 000,617,568 | ---- | M] () -- C:\Windows\System32\perfh01D.dat [2012.06.06 15:31:53 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.06.06 15:31:53 | 000,610,202 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2012.06.06 15:31:53 | 000,551,770 | ---- | M] () -- C:\Windows\System32\perfh008.dat [2012.06.06 15:31:53 | 000,462,172 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2012.06.06 15:31:53 | 000,448,586 | ---- | M] () -- C:\Windows\System32\perfh014.dat [2012.06.06 15:31:53 | 000,434,486 | ---- | M] () -- C:\Windows\System32\perfh001.dat [2012.06.06 15:31:53 | 000,433,388 | ---- | M] () -- C:\Windows\System32\perfh00B.dat [2012.06.06 15:31:53 | 000,399,736 | ---- | M] () -- C:\Windows\System32\perfh012.dat [2012.06.06 15:31:53 | 000,388,518 | ---- | M] () -- C:\Windows\System32\perfh011.dat [2012.06.06 15:31:53 | 000,377,870 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2012.06.06 15:31:53 | 000,361,768 | ---- | M] () -- C:\Windows\System32\prfh0804.dat [2012.06.06 15:31:53 | 000,353,522 | ---- | M] () -- C:\Windows\System32\perfh00D.dat [2012.06.06 15:31:53 | 000,148,310 | ---- | M] () -- C:\Windows\System32\perfc00E.dat [2012.06.06 15:31:53 | 000,137,062 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2012.06.06 15:31:53 | 000,134,840 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012.06.06 15:31:53 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat [2012.06.06 15:31:53 | 000,132,940 | ---- | M] () -- C:\Windows\System32\perfc013.dat [2012.06.06 15:31:53 | 000,132,516 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2012.06.06 15:31:53 | 000,130,140 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2012.06.06 15:31:53 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.06.06 15:31:53 | 000,128,094 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2012.06.06 15:31:53 | 000,127,144 | ---- | M] () -- C:\Windows\System32\perfc010.dat [2012.06.06 15:31:53 | 000,123,740 | ---- | M] () -- C:\Windows\System32\perfc01D.dat [2012.06.06 15:31:53 | 000,121,788 | ---- | M] () -- C:\Windows\System32\perfc005.dat [2012.06.06 15:31:53 | 000,121,526 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc011.dat [2012.06.06 15:31:53 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.06.06 15:31:53 | 000,104,676 | ---- | M] () -- C:\Windows\System32\perfc012.dat [2012.06.06 15:31:53 | 000,104,248 | ---- | M] () -- C:\Windows\System32\prfc0804.dat [2012.06.06 15:31:53 | 000,099,334 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2012.06.06 15:31:53 | 000,089,436 | ---- | M] () -- C:\Windows\System32\perfc008.dat [2012.06.06 15:31:53 | 000,082,148 | ---- | M] () -- C:\Windows\System32\perfc00B.dat [2012.06.06 15:31:53 | 000,079,804 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2012.06.06 15:31:53 | 000,078,984 | ---- | M] () -- C:\Windows\System32\perfc001.dat [2012.06.06 15:31:53 | 000,077,096 | ---- | M] () -- C:\Windows\System32\perfc014.dat [2012.06.06 15:31:53 | 000,069,094 | ---- | M] () -- C:\Windows\System32\perfc00D.dat [2012.06.06 15:31:03 | 000,000,000 | ---- | M] () -- C:\Users\*****\defogger_reenable [2012.06.06 15:27:10 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.06.06 15:27:10 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr [2012.06.06 15:27:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.06.06 15:26:52 | 2414,682,112 | -HS- | M] () -- C:\hiberfil.sys [2012.06.06 12:19:50 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.06 12:08:23 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.06.06 10:14:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.06.05 12:14:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.04 22:07:07 | 1363,885,269 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.06.04 20:38:06 | 009,299,786 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.06.04 18:10:48 | 000,007,168 | ---- | M] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.05.29 21:32:20 | 1453,899,807 | ---- | M] () -- C:\Users\*****\Documents\*****.flv [2012.05.21 19:35:46 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf [2012.05.21 19:35:23 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf [2012.05.17 21:41:46 | 1453,921,921 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Der Wald steht schwarz und schweiget - Sonntag, 13.05.2012 Das Erste.flv [2012.05.10 23:05:08 | 1460,780,570 | ---- | M] () -- C:\Users\*****\Documents\ARD Mediathek Tatort - Tatort Die Ballade von Cenk und Valerie - Sonntag, 06.05.2012 Das Erste.flv [1 C:\Windows\System32\drivers\UMDF\*.tmp files -> C:\Windows\System32\drivers\UMDF\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.06.06 15:31:03 | 000,000,000 | ---- | C] () -- C:\Users\*****\defogger_reenable [2012.06.06 15:27:10 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr [2012.06.06 12:19:50 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.06.05 12:14:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_AMPPAL_01009.Wdf [2012.06.05 11:52:43 | 000,002,088 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Device Experience.lnk [2012.06.05 11:52:42 | 000,002,476 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools.lnk [2012.05.21 19:35:46 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf [2012.05.21 19:35:23 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf [2012.05.11 22:03:13 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.05.11 22:03:12 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.05.10 22:27:38 | 000,007,168 | ---- | C] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.04.18 19:00:07 | 000,000,100 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc [2012.03.28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012.03.28 22:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.03.28 22:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.03.28 22:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.03.28 22:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2012.03.27 17:27:16 | 000,037,046 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Kommagetrennte Werte (Windows).ADR [2012.03.18 04:58:31 | 000,617,568 | ---- | C] () -- C:\Windows\System32\perfh01D.dat [2012.03.18 04:58:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat [2012.03.18 04:58:31 | 000,123,740 | ---- | C] () -- C:\Windows\System32\perfc01D.dat [2012.03.18 04:58:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat [2012.03.18 04:58:30 | 000,691,192 | ---- | C] () -- C:\Windows\System32\perfh013.dat [2012.03.18 04:58:30 | 000,632,180 | ---- | C] () -- C:\Windows\System32\perfh00E.dat [2012.03.18 04:58:30 | 000,353,522 | ---- | C] () -- C:\Windows\System32\perfh00D.dat [2012.03.18 04:58:30 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat [2012.03.18 04:58:30 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat [2012.03.18 04:58:30 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat [2012.03.18 04:58:30 | 000,148,310 | ---- | C] () -- C:\Windows\System32\perfc00E.dat [2012.03.18 04:58:30 | 000,069,094 | ---- | C] () -- C:\Windows\System32\perfc00D.dat [2012.03.18 04:58:30 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat [2012.03.18 04:58:30 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat [2012.03.18 04:58:30 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat [2012.03.18 04:58:29 | 000,388,518 | ---- | C] () -- C:\Windows\System32\perfh011.dat [2012.03.18 04:58:29 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat [2012.03.18 04:58:29 | 000,132,940 | ---- | C] () -- C:\Windows\System32\perfc013.dat [2012.03.18 04:58:29 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc011.dat [2012.03.18 04:58:29 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat [2012.03.18 00:04:25 | 000,551,770 | ---- | C] () -- C:\Windows\System32\perfh008.dat [2012.03.18 00:04:25 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat [2012.03.18 00:04:25 | 000,089,436 | ---- | C] () -- C:\Windows\System32\perfc008.dat [2012.03.18 00:04:25 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat [2012.03.17 23:25:14 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat [2012.03.17 23:25:13 | 000,689,108 | ---- | C] () -- C:\Windows\System32\perfh010.dat [2012.03.17 23:25:13 | 000,127,144 | ---- | C] () -- C:\Windows\System32\perfc010.dat [2012.03.17 23:25:13 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat [2012.03.17 23:02:46 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat [2012.03.17 23:02:45 | 000,434,486 | ---- | C] () -- C:\Windows\System32\perfh001.dat [2012.03.17 23:02:45 | 000,078,984 | ---- | C] () -- C:\Windows\System32\perfc001.dat [2012.03.17 23:02:45 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat [2012.03.17 22:41:24 | 000,679,342 | ---- | C] () -- C:\Windows\System32\prfh0816.dat [2012.03.17 22:41:24 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat [2012.03.17 22:41:24 | 000,133,752 | ---- | C] () -- C:\Windows\System32\prfc0816.dat [2012.03.17 22:41:24 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat [2012.03.17 22:23:54 | 000,462,172 | ---- | C] () -- C:\Windows\System32\perfh006.dat [2012.03.17 22:23:54 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat [2012.03.17 22:23:54 | 000,079,804 | ---- | C] () -- C:\Windows\System32\perfc006.dat [2012.03.17 22:23:54 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat [2012.03.17 22:04:51 | 000,693,454 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2012.03.17 22:04:51 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2012.03.17 22:04:51 | 000,137,062 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2012.03.17 22:04:51 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2012.03.17 21:38:24 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2012.03.17 21:38:23 | 000,689,726 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2012.03.17 21:38:23 | 000,134,840 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2012.03.17 21:38:23 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2012.03.17 21:21:25 | 000,675,958 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2012.03.17 21:21:25 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2012.03.17 21:21:25 | 000,132,516 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2012.03.17 21:21:25 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2012.03.17 20:57:09 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2012.03.17 20:57:08 | 000,663,804 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2012.03.17 20:57:08 | 000,128,094 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2012.03.17 20:57:08 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2012.03.17 20:15:05 | 000,610,202 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2012.03.17 20:15:05 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2012.03.17 20:15:05 | 000,121,526 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2012.03.17 20:15:05 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2012.03.17 11:44:09 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2012.03.17 11:43:46 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2012.03.17 09:33:11 | 000,694,430 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2012.03.17 09:33:11 | 000,377,870 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2012.03.17 09:33:11 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2012.03.17 09:33:11 | 000,130,140 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2012.03.17 09:33:11 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2012.03.17 09:33:11 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat [2012.03.17 09:33:11 | 000,099,334 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2012.03.17 09:33:11 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat [2012.03.17 09:33:11 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2012.03.17 09:33:10 | 000,623,144 | ---- | C] () -- C:\Windows\System32\perfh005.dat [2012.03.17 09:33:10 | 000,433,388 | ---- | C] () -- C:\Windows\System32\perfh00B.dat [2012.03.17 09:33:10 | 000,361,768 | ---- | C] () -- C:\Windows\System32\prfh0804.dat [2012.03.17 09:33:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat [2012.03.17 09:33:10 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat [2012.03.17 09:33:10 | 000,121,788 | ---- | C] () -- C:\Windows\System32\perfc005.dat [2012.03.17 09:33:10 | 000,104,248 | ---- | C] () -- C:\Windows\System32\prfc0804.dat [2012.03.17 09:33:10 | 000,082,148 | ---- | C] () -- C:\Windows\System32\perfc00B.dat [2012.03.17 09:33:10 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat [2012.03.17 09:33:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat [2012.03.17 09:33:09 | 000,448,586 | ---- | C] () -- C:\Windows\System32\perfh014.dat [2012.03.17 09:33:09 | 000,399,736 | ---- | C] () -- C:\Windows\System32\perfh012.dat [2012.03.17 09:33:09 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat [2012.03.17 09:33:09 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat [2012.03.17 09:33:09 | 000,104,676 | ---- | C] () -- C:\Windows\System32\perfc012.dat [2012.03.17 09:33:09 | 000,077,096 | ---- | C] () -- C:\Windows\System32\perfc014.dat [2012.03.17 09:33:09 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat [2012.03.17 09:33:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat [2010.09.27 13:03:08 | 000,201,512 | ---- | C] () -- C:\Windows\System32\vpnapi.dll ========== LOP Check ========== [2012.04.27 22:46:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Amazon [2012.06.06 15:25:09 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Bibzrzhnhsl [2012.06.05 22:57:59 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Dropbox [2012.04.03 08:46:29 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\GHISLER [2012.06.06 12:48:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\gnupg [2012.04.28 00:00:02 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\HandBrake [2012.04.18 18:59:05 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Intermedia Software [2012.03.17 10:44:31 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\IrfanView [2012.04.09 17:42:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LibreOffice [2012.03.17 00:37:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LucasArts [2012.05.21 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Nokia [2012.05.21 19:38:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PC Suite [2012.05.29 22:27:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PwrMgr [2012.04.23 22:01:49 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Samsung [2012.03.19 09:28:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Swiss Academic Software [2012.03.22 09:14:06 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Thunderbird [2012.06.03 11:57:16 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > extra.txtOTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 06.06.2012 15:32:20 - Run 1 OTL by OldTimer - Version 3.2.46.1 Folder = C:\Users\*****\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 52,74% Memory free 5,99 Gb Paging File | 4,40 Gb Available in Paging File | 73,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,78 Gb Total Space | 165,83 Gb Free Space | 74,10% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 34,46 Gb Free Space | 17,64% Space Free | Partition Type: NTFS Drive F: | 97,65 Gb Total Space | 79,19 Gb Free Space | 81,09% Space Free | Partition Type: NTFS Drive G: | 931,51 Gb Total Space | 328,35 Gb Free Space | 35,25% Space Free | Partition Type: NTFS Drive I: | 1,87 Gb Total Space | 1,86 Gb Free Space | 99,86% Space Free | Partition Type: FAT Drive J: | 93,16 Gb Total Space | 1,21 Gb Free Space | 1,30% Space Free | Partition Type: NTFS Computer Name: *****-PC | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{11C140D1-C8CA-480E-8C22-6FB108AC5B9B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1B695C61-DED9-412B-9F95-749966962621}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{2E6F1837-74C5-4816-983B-524C69680091}" = lport=137 | protocol=17 | dir=in | app=system | "{36E1979F-0A03-4220-A284-89B8265DCAE9}" = lport=445 | protocol=6 | dir=in | app=system | "{4586B191-EB75-4CD3-A6A8-73102F4D7A8E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4BD76F22-1306-4362-81DD-B1C21B0A1879}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4CD5AA15-FC9F-41F8-A0CF-97C686ECDC83}" = lport=10243 | protocol=6 | dir=in | app=system | "{79B401E3-7F75-4A19-BAB9-4345C95DFBF3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7A2C2210-0657-4A0A-AD54-3ADA7772DC71}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{81454568-B251-494F-B0DB-E09375187CB6}" = rport=10243 | protocol=6 | dir=out | app=system | "{83CBC572-FF34-4D54-B01F-D4D55B50DF29}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{89F356D0-65B6-49EC-8371-625A9BA23B6A}" = lport=139 | protocol=6 | dir=in | app=system | "{8CC84360-489A-4F1F-A1F5-5AC475480875}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{99B63B6D-E64E-425B-B240-2CE97D0ED178}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A13B6A0E-21E3-42B5-97BF-AAD958E766C1}" = lport=138 | protocol=17 | dir=in | app=system | "{A7FD2748-8BDB-424D-85E6-5693CE1C5515}" = lport=2869 | protocol=6 | dir=in | app=system | "{AD473898-7C8A-4FBA-B5EF-33CBC72590C9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B75CF7C7-DB43-49EB-97D7-0216E5A19722}" = rport=138 | protocol=17 | dir=out | app=system | "{CDA34F23-BD6D-4B2C-AAC3-E2467F7333C3}" = rport=139 | protocol=6 | dir=out | app=system | "{D0CFF402-CEB5-44FE-A417-8AF8D944F413}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D65552B0-8F3B-4B2D-88FB-0CE505539F7C}" = rport=445 | protocol=6 | dir=out | app=system | "{E40DF8EE-0878-44DC-B4D1-8933AE5CD172}" = rport=137 | protocol=17 | dir=out | app=system | "{F4527DDC-7A77-4B4B-B51F-DE54574C5599}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F6D1E7E5-5AD3-4135-BDC7-23F05D7B4444}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{154615E7-398E-46D4-AB52-B8F82E32A662}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{190E9810-D7C4-4D2F-8E3F-C046F13A2E95}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{28D924FD-E511-49CA-80CD-5EDA3FD031D4}" = protocol=6 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | "{2D0603D6-D2B9-4878-89BA-8F047EDEA786}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{30847B64-D196-42CD-90D9-3D962C86DB4E}" = dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "{3983EBC6-99D0-49C5-BB67-240C2242D2F4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{44D3D234-9BBC-4B01-BB00-D6466CC2CB8C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4AFEA250-9F4E-42A7-8D44-F9CCF4A6AD03}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{4EE4D181-E01B-40F0-8543-C8BCD7A5C43F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{5E4295EF-424F-4A80-9E0D-79B38BFD8F3C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | "{605371DF-B588-4FB4-B1FD-B06E6AE4BCA5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{63EA84F6-CCF0-4973-A453-ECFE9AAB23C2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{66751421-723E-4CCF-804F-4321622D0E31}" = protocol=17 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | "{713FFEAA-5865-45DB-B6D8-9C2EF9989329}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{71FB772D-FE3C-4B4D-8BF3-809C6C3103BA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{7EF1447F-FECB-47A5-8810-73A1D209598B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7F29A31B-5977-4945-98BC-79053C8C43B1}" = protocol=6 | dir=out | app=system | "{8AC62D2F-DA7F-4422-8ADE-5E4F1C98C766}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{999FBBAC-37A5-4C7B-9992-8B1BDEA3FD2B}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe | "{A1591105-6B07-456D-B8CA-260FA1C09A12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AC64A7C5-410F-435E-A114-0617CE9F0073}" = protocol=17 | dir=in | app=c:\program files\lenovo\system update\uncserver.exe | "{B424D08A-C3FF-4F3E-8EAE-54C913AE6706}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{B4BE2661-4E69-4462-B1CC-981559F6089C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{BC4BB849-FF8F-48B3-900F-B5E42A3521A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BC7ACAF4-EF07-4EC6-81D7-D7BC696AC81D}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe | "{C6C32619-9A88-45C5-A8AB-685EC5D35EC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C6F2EB79-2A7A-4DDB-9029-C14E2F63FDE8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{C9F41199-FAC6-48E6-BC31-4D952F1DEA22}" = dir=in | app=c:\program files\itunes\itunes.exe | "{CD3B3755-12DB-4BD5-9B50-7BD9EF5ED7C9}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe | "{D43A31F6-B972-414E-AFBB-2D6DF9A01D8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D66A39EF-0619-4686-9193-0BA51D4845C4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{DE4BDEC8-2C9A-43FF-819C-696D8747CCD5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.649\agent.exe | "{EC0B430D-A5AB-420E-AA99-68EEF19A9D24}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{EC3D1D9D-3EB0-43D6-8A9D-DA6D4B3471FB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{FDE172B7-7D0D-463A-B4C5-C5B77A9DC13B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FE010E17-D333-48A7-BD2B-F6D575155F2F}" = protocol=6 | dir=in | app=c:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0E8E4718-0702-4D33-B007-5E95849BAB3C}" = LibreOffice 3.5 "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{17CBC505-D1AE-459D-B445-3D2000A85842}" = Dienstprogramm "ThinkPad UltraNav" "{1CE60928-8325-49A8-8B06-633E48DD2B67}" = Cisco Systems VPN Client 5.0.07.0410 "{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes "{24E92E7A-6848-4747-A3EA-3AAC0576BE52}" = Lenovo Patch Utility "{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{705EE775-5776-48FD-B704-C3C9CF535420}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7964AE02-9127-42C0-A917-2CE4CD4EFE3B}" = Nokia Suite "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software "{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver "{A7BB9BBD-DFE4-4276-820A-7CD141FC09E6}" = Lenovo Patch Utility "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{BA722179-62EA-4090-923D-D324CE1A691D}}_is1" = Helium Music Manager 8 (build 10470) "{BAA0BE9B-9E6D-4802-91CB-FB7ED5CD4BEF}" = Intel® PROSet/Wireless WiFi-Software "{C2938C94-239C-4156-B245-C5406A4F3E93}" = ThinkVantage Fingerprint Software "{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel "{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}" = Steuer-Spar-Erklärung 2012 "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution "{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = Energie-Manager "{E12C6653-1FF0-4686-ADB8-589C13AE761F}" = Citavi "{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86 "{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support "{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171 "2004BB9EB6CEA02846881BEF1F51C11F7A90C9D6" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430) "504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 "Avira AntiVir Desktop" = Avira Free Antivirus "BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) "Clementine" = Clementine "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588" = ThinkPad Modem "GPG4Win" = Gpg4win (2.1.0) "HandBrake" = HandBrake 0.9.6 "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "IrfanView" = IrfanView (remove only) "LENOVO.SMIIF" = Lenovo System Interface Driver "LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility "Loeffelfamilie" = Loeffelfamilie Screen Saver "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2 "MISEC" = Monkey Island™ Special Edition Collection "Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de) "Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nokia Suite" = Nokia Suite "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "OnScreenDisplay" = Anzeige am Bildschirm "Power Management Driver" = ThinkPad Power Management Driver "ProInst" = Intel PROSet Wireless "SnowFox Total Video Converter_is1" = SnowFox Total Video Converter 3.0.1.0 "SynTPDeinstKey" = ThinkPad UltraNav Driver "ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier "Totalcmd" = Total Commander (Remove or Repair) "VLC media player" = VLC media player 2.0.1 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:49 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:30:56 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 9000 Description = Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Windows Search Service | ID = 1006 Description = Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. Error - 06.06.2012 09:32:08 | Computer Name = *****-PC | Source = Microsoft-Windows-CAPI2 | ID = 257 Description = Vom Kryptografiedienst konnte die Katalogdatenbank nicht initialisiert werden. "ESENT"-Fehler: -583. [ System Events ] Error - 06.06.2012 09:28:19 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:28:26 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:28:55 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:29:03 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 4 Mal passiert. Error - 06.06.2012 09:29:47 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet: %%-1906441657 Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147217025. Error - 06.06.2012 09:31:13 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7034 Description = Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 5 Mal passiert. < End of report > Der Gmer-Scan hat dann sehr lange gedauert weshalb ich ihn nicht permanent verfolgen konnte. Aber er scheint aus irgendeinem Grund den PC zum Absturz gebracht zu haben, weswegen ich ihn nochmal neu starte! Geändert von ms_sh (06.06.2012 um 11:59 Uhr) |
Themen zu Verschlüsselungstrojaner! (flirt-fever.de) |
anhang, beenden, beendet, benutzer, bild, computer, dateisystem, device driver, document, eingeblendet, euro, folge, folgende, forum, gemail, gmer-scan, google earth, heuristiks/extra, heuristiks/shuriken, install.exe, kosten, langs, lenovo, mail, microsoft office word, modus, neu, neustart, neustarten, nicht mehr, offene, ordner, plug-in, plötzlich, rechnung, safer networking, searchscopes, taskmanager, total commander, trojaner-board, version=1.0, öffnen |