|
Log-Analyse und Auswertung: Probleme mit TR/ATRAPS.GENWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
01.08.2012, 15:47 | #1 |
| Probleme mit TR/ATRAPS.GEN Liebe Experten, ich hatte ein Problem mit Live security. Nachdem mein Virenscanner (antivir) 2 "Probleme" beseitigt hatte, unterblieben die Meldungen von Live security. Nun erhalte ich aber dauernd Meldungen des Virenscanners über Dateien mit Namen "TR/ATRAPS.GEN". Eure Anweisungen für Neulinge habe ich nach bestem Wissen durchgeführt. Hier sind die dort genannten Dateien (s.a. Anhang): defogger_disable: Anfang defogger_disable by jpshortstuff (23.02.10.1) Log created at 15:05 on 01/08/2012 (Hp) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- defogger_disable: Ende OTL: Anfang OTL logfile created on: 01.08.2012 15:07:07 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Dokumente und Einstellungen\Hp\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 958,73 Mb Total Physical Memory | 455,19 Mb Available Physical Memory | 47,48% Memory free 2,26 Gb Paging File | 1,52 Gb Available in Paging File | 67,39% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 19,53 Gb Total Space | 6,83 Gb Free Space | 34,98% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 23,67 Gb Free Space | 43,05% Space Free | Partition Type: NTFS Drive G: | 7,31 Gb Total Space | 3,95 Gb Free Space | 53,97% Space Free | Partition Type: FAT32 Computer Name: HPE | User Name: Hp | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.08.01 15:06:29 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe PRC - [2012.08.01 15:04:15 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe PRC - [2012.07.19 12:04:24 | 000,913,888 | ---- | M] (Mozilla Corporation) -- D:\Programme\Mozilla Firefox\firefox.exe PRC - [2012.07.19 11:41:14 | 000,400,352 | ---- | M] (Mozilla Corporation) -- D:\Programme\Mozilla Thunderbird\thunderbird.exe PRC - [2012.07.11 16:57:30 | 000,935,008 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe PRC - [2012.07.11 16:57:11 | 001,107,552 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe PRC - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2012.05.14 15:04:49 | 000,391,632 | ---- | M] (Avira Operations GmbH & Co. KG) -- c:\Programme\Avira\AntiVir Desktop\avcenter.exe PRC - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe PRC - [2012.05.14 15:04:49 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.14 15:04:49 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2011.12.14 13:23:34 | 001,212,224 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe PRC - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe PRC - [2011.11.09 21:05:42 | 002,420,616 | ---- | M] (Check Point Software Technologies LTD) -- D:\Programme\CheckPoint\CheckPoint\ZoneAlarm\vsmon.exe PRC - [2011.11.09 21:01:38 | 000,073,360 | ---- | M] (Check Point Software Technologies LTD) -- D:\Programme\CheckPoint\CheckPoint\ZoneAlarm\zatray.exe PRC - [2011.11.03 16:44:28 | 000,497,280 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe PRC - [2011.11.03 16:44:24 | 000,738,944 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ForceField.exe PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe ========== Modules (No Company Name) ========== MOD - [2012.08.01 15:04:15 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe MOD - [2012.07.19 12:04:22 | 002,003,424 | ---- | M] () -- D:\Programme\Mozilla Firefox\mozjs.dll MOD - [2012.07.19 11:41:19 | 001,936,352 | ---- | M] () -- D:\Programme\Mozilla Thunderbird\mozjs.dll MOD - [2012.07.19 11:41:19 | 000,162,784 | ---- | M] () -- D:\Programme\Mozilla Thunderbird\nsldap32v60.dll MOD - [2012.07.19 11:41:19 | 000,021,984 | ---- | M] () -- D:\Programme\Mozilla Thunderbird\nsldappr32v60.dll MOD - [2012.07.11 16:57:40 | 000,132,704 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll MOD - [2012.07.11 16:57:30 | 000,935,008 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe MOD - [2012.07.11 16:57:11 | 001,107,552 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe MOD - [2012.05.14 15:04:50 | 000,398,288 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll MOD - [2009.02.27 17:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU MOD - [2001.10.28 18:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012.07.29 13:01:47 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.19 12:04:23 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.11 16:57:30 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0) SRV - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService) SRV - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2011.11.09 21:05:42 | 002,420,616 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- D:\Programme\CheckPoint\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon) SRV - [2011.11.03 16:44:28 | 000,497,280 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc) SRV - [2011.06.24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) [Disabled | Stopped] -- C:\Programme\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010.03.29 08:53:22 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programme\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012.05.14 15:04:50 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.14 15:04:50 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.03.24 18:02:36 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.03.24 18:02:36 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011.12.12 20:31:38 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2011.11.09 21:01:38 | 000,525,840 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant) DRV - [2011.11.03 16:44:20 | 000,027,016 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - [2011.05.07 10:34:11 | 000,097,792 | ---- | M] (Protect Software GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ACEDRV05.sys -- (ACEDRV05) DRV - [2008.09.24 11:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) DRV - [2005.03.09 15:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2003.07.02 04:42:00 | 000,027,904 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1) DRV - [2000.07.24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\BRPAR.SYS -- (BrPar) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050 IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWin0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.5\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKCU\..\URLSearchHook: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\prxtbDVD2.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Programme\ZoneAlarm-Sicherheit\prxtbZone.dll (Conduit Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={758F62B8-C216-4913-9265-96C03CB09346}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=2011-12-10 14:38:33&v=10.0.0.7&sap=dsp&q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2613550 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search" FF - prefs.js..browser.startup.homepage: "hxxp://isearch.avg.com/?cid={7ECDEDD5-CF89-4DCF-A825-170331E0DA68}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=&v=&sap=hp" FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Programme\Gemeinsame Dateien\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Programme\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Programme\CheckPoint\ZAForceField\TrustChecker [2012.03.09 17:50:49 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: D:\Programme\Mozilla Firefox\components [2012.07.19 12:04:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: D:\Programme\Mozilla Firefox\plugins [2012.05.05 14:47:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: D:\Programme\Mozilla Thunderbird\components [2012.06.21 16:36:51 | 000,000,000 | ---D | M] [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.07.26 09:36:27 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions [2012.06.27 18:16:31 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012.03.30 15:52:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.06.24 13:31:50 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2012.07.15 11:47:34 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} [2011.12.10 15:38:40 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\avg@toolbar [2011.03.25 16:05:11 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\engine@conduit.com [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (FlashGot) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.03.28 19:40:35 | 000,000,000 | ---D | M] (Winload Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2008.08.09 13:46:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (IE Tab [de]) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2010.07.26 19:06:44 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] ("BugMeNot") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.04.02 14:05:04 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [2008.10.16 17:18:58 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\avg@toolbar [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Deutsches Wörterbuch) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\de-DE@dictionaries.addons.mozilla.org [2010.03.28 19:40:12 | 000,000,000 | ---D | M] (WINLOAD-Gutschein-Alarm) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\sparweltgutscheinewl@sparwelt.de [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012.04.09 14:36:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\staged O1 HOSTS File: ([2004.08.04 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWin0.dll (Conduit Ltd.) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.) O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programme\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Programme\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.5\pdfforgeToolbarIE.dll (Spigot, Inc.) O2 - BHO: (DVDVideoSoftTB Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\prxtbDVD2.dll (Conduit Ltd.) O2 - BHO: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Programme\ZoneAlarm-Sicherheit\prxtbZone.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWin0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programme\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.5\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Programme\DVDVideoSoft\prxtbDVD2.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKLM\..\Toolbar: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Programme\ZoneAlarm-Sicherheit\prxtbZone.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\ShellBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKCU\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Programme\Winload\prxtbWin0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Programme\DVDVideoSoft\prxtbDVD2.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm-Sicherheit Toolbar) - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - C:\Programme\ZoneAlarm-Sicherheit\prxtbZone.dll (Conduit Ltd.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [ISW] C:\Programme\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) O4 - HKLM..\Run: [ZoneAlarm] D:\Programme\CheckPoint\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.) O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.42.43.62 82.212.62.62 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8F73863-7C45-4B79-A886-BD0BD32B351C}: DhcpNameServer = 78.42.43.62 82.212.62.62 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Programme\Gemeinsame Dateien\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll () O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.08.09 09:32:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{b9b63eb3-d60b-11de-8507-0013d47182ab}\Shell\AutoRun\command - "" = G:\StartPortableApps.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.08.01 15:06:28 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.01 14:27:10 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Hp\Recent [2012.08.01 09:17:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Startmenü\Programme\Live Security Platinum [2012.08.01 09:16:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 13:27:02 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\WISO Steuer 2012 [2012.07.16 13:26:01 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2008.05.30 14:37:10 | 001,694,728 | ---- | C] (Microsoft Corporation) -- C:\Programme\dsetup32.dll [2008.05.30 14:35:56 | 000,097,288 | ---- | C] (Microsoft Corporation) -- C:\Programme\DSETUP.dll [2008.05.30 14:34:50 | 000,528,392 | ---- | C] (Microsoft Corporation) -- C:\Programme\DXSETUP.exe [11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.08.01 15:12:24 | 000,302,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:10:56 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.08.01 15:06:29 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:15 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.08.01 15:01:05 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012.08.01 14:20:00 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.08.01 14:07:42 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.08.01 14:07:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.08.01 09:24:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\System32\mscandc.ini [2012.07.31 16:12:08 | 000,000,424 | ---- | M] () -- C:\WINDOWS\zipgenius.xml [2012.07.31 11:12:20 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Ulead32.INI [2012.07.30 10:26:27 | 000,459,588 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2012.07.30 10:26:27 | 000,441,696 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012.07.30 10:26:27 | 000,084,960 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2012.07.30 10:26:27 | 000,071,632 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012.07.16 18:03:19 | 000,000,930 | ---- | M] () -- C:\WINDOWS\wiso.ini [2012.07.12 13:46:08 | 000,003,827 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2012.07.12 11:25:24 | 000,345,345 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.07.12 08:28:59 | 000,215,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.07.11 18:18:49 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.08.01 15:12:23 | 000,302,592 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:14 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.08.01 14:33:46 | 000,001,712 | ---- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\00000001.@ [2012.05.19 11:49:34 | 000,044,098 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\usrlgo.bmp [2012.02.25 11:25:12 | 000,345,345 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.02.14 21:48:58 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012.01.20 19:44:14 | 000,222,089 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled3_MAS.bak [2011.12.16 20:56:31 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2011.11.29 22:13:18 | 000,000,849 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\.recently-used.xbel [2011.10.20 13:24:23 | 000,067,320 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled1_MAS.bak [2011.08.08 17:33:00 | 000,003,163 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled10_MAS.bak [2011.08.08 17:28:22 | 000,155,546 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled4_MAS.bak [2011.08.08 17:18:34 | 000,367,598 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled2_MAS.bak [2011.03.20 11:17:59 | 000,823,296 | ---- | C] () -- C:\WINDOWS\j3dcore-d3d.dll [2011.03.20 11:17:59 | 000,163,840 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl.dll [2011.03.20 11:17:59 | 000,049,152 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-chk.dll [2011.03.20 11:17:59 | 000,040,960 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-cg.dll [2010.12.25 11:21:50 | 001,456,640 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\Falk Navi-Manager.msi [2010.12.25 11:21:27 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\$_hpcst$.hpc [2010.05.05 18:06:55 | 000,499,743 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled0_MAS.bak [2009.11.20 09:28:25 | 000,005,943 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\mainhst.zgh [2009.01.03 12:32:49 | 000,003,827 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2008.09.10 17:02:04 | 000,008,810 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\gsview32.ini [2008.08.10 17:40:41 | 000,007,168 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.05.30 14:38:30 | 001,158,739 | ---- | C] () -- C:\Programme\BDANT.cab [2008.05.30 14:38:30 | 001,130,465 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x86.cab [2008.05.30 14:38:30 | 001,118,469 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x86.cab [2008.05.30 14:38:30 | 001,087,968 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x86.cab [2008.05.30 14:38:30 | 001,082,704 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x86.cab [2008.05.30 14:38:30 | 001,082,210 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x86.cab [2008.05.30 14:38:28 | 001,080,892 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x86.cab [2008.05.30 14:38:26 | 001,068,173 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x86.cab [2008.05.30 14:38:26 | 001,016,473 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x86.cab [2008.05.30 14:38:26 | 000,978,396 | ---- | C] () -- C:\Programme\BDAXP.cab [2008.05.30 14:38:26 | 000,919,678 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86.cab [2008.05.30 14:38:26 | 000,867,848 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x64.cab [2008.05.30 14:38:26 | 000,855,534 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x64.cab [2008.05.30 14:38:24 | 000,871,076 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x64.cab [2008.05.30 14:38:24 | 000,853,167 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x86.cab [2008.05.30 14:38:24 | 000,848,132 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x64.cab [2008.05.30 14:38:24 | 000,807,132 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x86.cab [2008.05.30 14:38:24 | 000,702,292 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x64.cab [2008.05.30 14:38:22 | 000,821,508 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x86.cab [2008.05.30 14:38:22 | 000,800,115 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x86.cab [2008.05.30 14:38:22 | 000,701,860 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x64.cab [2008.05.30 14:38:20 | 000,701,720 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x86.cab [2008.05.30 14:38:18 | 000,272,876 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x64.cab [2008.05.30 14:38:16 | 000,699,113 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x86.cab [2008.05.30 14:38:16 | 000,254,442 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x64.cab [2008.05.30 14:38:14 | 000,272,272 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,229,498 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,216,055 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x64.cab [2008.05.30 14:38:12 | 000,201,344 | ---- | C] () -- C:\Programme\AUG2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,370 | ---- | C] () -- C:\Programme\JUN2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,010 | ---- | C] () -- C:\Programme\NOV2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,197,923 | ---- | C] () -- C:\Programme\FEB2007_XACT_x64.cab [2008.05.30 14:38:10 | 000,186,151 | ---- | C] () -- C:\Programme\AUG2006_XACT_x64.cab [2008.05.30 14:38:10 | 000,185,609 | ---- | C] () -- C:\Programme\OCT2006_XACT_x64.cab [2008.05.30 14:38:08 | 000,199,014 | ---- | C] () -- C:\Programme\APR2007_XACT_x64.cab [2008.05.30 14:38:08 | 000,194,968 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x86.cab [2008.05.30 14:38:06 | 000,195,723 | ---- | C] () -- C:\Programme\DEC2006_XACT_x64.cab [2008.05.30 14:38:06 | 000,184,033 | ---- | C] () -- C:\Programme\JUN2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,182,381 | ---- | C] () -- C:\Programme\Apr2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,181,607 | ---- | C] () -- C:\Programme\Feb2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,156,157 | ---- | C] () -- C:\Programme\JUN2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,512 | ---- | C] () -- C:\Programme\NOV2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,231 | ---- | C] () -- C:\Programme\FEB2007_XACT_x86.cab [2008.05.30 14:38:02 | 000,156,260 | ---- | C] () -- C:\Programme\AUG2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,154,473 | ---- | C] () -- C:\Programme\APR2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,136,351 | ---- | C] () -- C:\Programme\Apr2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,148,847 | ---- | C] () -- C:\Programme\DEC2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,135,657 | ---- | C] () -- C:\Programme\Feb2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,141,265 | ---- | C] () -- C:\Programme\OCT2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,140,483 | ---- | C] () -- C:\Programme\AUG2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,136,919 | ---- | C] () -- C:\Programme\JUN2006_XACT_x86.cab [2008.05.30 14:37:54 | 000,056,550 | ---- | C] () -- C:\Programme\APR2007_xinput_x86.cab [2008.05.30 14:37:52 | 000,125,584 | ---- | C] () -- C:\Programme\Mar2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,124,302 | ---- | C] () -- C:\Programme\Jun2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,100,065 | ---- | C] () -- C:\Programme\APR2007_xinput_x64.cab [2008.05.30 14:37:52 | 000,058,402 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x64.cab [2008.05.30 14:37:52 | 000,049,306 | ---- | C] () -- C:\Programme\AUG2006_xinput_x86.cab [2008.05.30 14:37:50 | 000,058,306 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x64.cab [2008.05.30 14:37:50 | 000,025,153 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x86.cab [2008.05.30 14:37:48 | 000,097,916 | ---- | C] () -- C:\Programme\dxupdate.cab [2008.05.30 14:37:48 | 000,049,258 | ---- | C] () -- C:\Programme\Apr2006_xinput_x86.cab [2008.05.30 14:37:48 | 000,048,607 | ---- | C] () -- C:\Programme\Oct2005_xinput_x86.cab [2008.05.30 14:37:46 | 000,090,390 | ---- | C] () -- C:\Programme\AUG2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,090,349 | ---- | C] () -- C:\Programme\Apr2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,047,700 | ---- | C] () -- C:\Programme\dxdllreg_x86.cab [2008.05.30 14:37:44 | 000,049,392 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x64.cab [2008.05.30 14:37:42 | 000,096,982 | ---- | C] () -- C:\Programme\Mar2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,096,376 | ---- | C] () -- C:\Programme\Jun2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,089,285 | ---- | C] () -- C:\Programme\Oct2005_xinput_x64.cab [2008.05.30 14:37:42 | 000,025,115 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x86.cab [2008.05.30 14:37:42 | 000,021,744 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x86.cab [2008.05.30 14:36:04 | 013,267,416 | ---- | C] () -- C:\Programme\dxnt.cab [2008.05.30 14:36:02 | 004,165,878 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86_Archive.cab [2008.05.30 14:36:02 | 001,805,306 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x64.cab [2008.05.30 14:36:00 | 001,803,408 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x64.cab [2008.05.30 14:35:56 | 001,795,856 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x64.cab [2008.05.30 14:35:56 | 001,773,110 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x64.cab [2008.05.30 14:35:56 | 001,712,608 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x86.cab [2008.05.30 14:35:56 | 001,711,400 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x86.cab [2008.05.30 14:35:56 | 001,611,022 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x64.cab [2008.05.30 14:35:56 | 001,610,606 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x64.cab [2008.05.30 14:35:56 | 001,610,534 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x86.cab [2008.05.30 14:35:56 | 001,609,287 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x86.cab [2008.05.30 14:35:56 | 001,577,624 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x86.cab [2008.05.30 14:35:56 | 001,574,402 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x64.cab [2008.05.30 14:35:56 | 001,467,126 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x86.cab [2008.05.30 14:35:56 | 001,446,530 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x86.cab [2008.05.30 14:35:56 | 001,416,150 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x64.cab [2008.05.30 14:35:56 | 001,401,078 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x64.cab [2008.05.30 14:35:56 | 001,361,224 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x64.cab [2008.05.30 14:35:56 | 001,339,250 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x64.cab [2008.05.30 14:35:54 | 001,366,044 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x64.cab [2008.05.30 14:35:54 | 001,353,790 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x64.cab [2008.05.30 14:35:54 | 001,350,602 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x64.cab [2008.05.30 14:35:54 | 001,250,747 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x64.cab [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\@ [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\{170ff124-1ba0-a426-70fe-860c313d0703}\@ ========== LOP Check ========== [2012.08.01 14:19:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 13:41:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search [2012.04.09 14:36:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon [2012.07.16 14:01:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Buhl Data Service GmbH [2011.11.12 09:11:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CheckPoint [2011.12.10 15:38:17 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files [2008.12.06 20:31:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\eXPert PDF 4 [2008.08.09 10:37:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MailFrontier [2011.08.29 18:37:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Power Soft [2011.10.14 17:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2010.10.29 15:20:21 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2011.10.14 17:41:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2010.04.30 08:27:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009.01.30 14:54:34 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{55A29068-F2CE-456C-9148-C869879E2357} [2009.10.31 14:57:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009.10.30 19:26:51 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} ========== Purity Check ========== < End of report > OTL: Ende Vielen Dank für Eure Hilfe. Herzliche Grüße Hanspeter |
04.08.2012, 13:34 | #2 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GENZitat:
Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Zitat:
bitte umgehend deinstallieren und die Windows-Firewall einschalten!
__________________ |
05.08.2012, 13:30 | #3 |
| Probleme mit TR/ATRAPS.GEN Lieber Arne,
__________________vielen Dank für die Hilfe. Ich hoffe, dass die folgenden Informationen die gewünschten sind: Code:
ATTFilter Avira Antivirus Premium 2012 Erstellungsdatum der Reportdatei: Donnerstag, 2. August 2012 15:46 Es wird nach 4044902 Virenstämmen gesucht. Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Hanspeter Eichhorn Seriennummer : 2218436276-PEPWE-0000001 Plattform : Microsoft Windows XP Windowsversion : (Service Pack 3) [5.1.2600] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : HPE Versionsinformationen: BUILD.DAT : 12.0.0.1145 42650 Bytes 23.05.2012 17:04:00 AVSCAN.EXE : 12.3.0.15 466896 Bytes 14.05.2012 13:04:49 AVSCAN.DLL : 12.3.0.15 66256 Bytes 14.05.2012 13:04:49 LUKE.DLL : 12.3.0.15 68304 Bytes 14.05.2012 13:04:50 AVSCPLR.DLL : 12.3.0.14 97032 Bytes 08.05.2012 13:02:24 AVREG.DLL : 12.3.0.17 232200 Bytes 10.05.2012 17:02:44 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 15:43:17 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 18:52:21 VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 17:45:31 VBASE003.VDF : 7.11.21.238 4472832 Bytes 01.02.2012 09:48:14 VBASE004.VDF : 7.11.26.44 4329472 Bytes 28.03.2012 10:51:56 VBASE005.VDF : 7.11.34.116 4034048 Bytes 29.06.2012 15:43:15 VBASE006.VDF : 7.11.34.117 2048 Bytes 29.06.2012 15:43:15 VBASE007.VDF : 7.11.34.118 2048 Bytes 29.06.2012 15:43:15 VBASE008.VDF : 7.11.34.119 2048 Bytes 29.06.2012 15:43:15 VBASE009.VDF : 7.11.34.120 2048 Bytes 29.06.2012 15:43:15 VBASE010.VDF : 7.11.34.121 2048 Bytes 29.06.2012 15:43:15 VBASE011.VDF : 7.11.34.122 2048 Bytes 29.06.2012 15:43:15 VBASE012.VDF : 7.11.34.123 2048 Bytes 29.06.2012 15:43:15 VBASE013.VDF : 7.11.34.124 2048 Bytes 29.06.2012 15:43:15 VBASE014.VDF : 7.11.38.18 2554880 Bytes 30.07.2012 15:47:13 VBASE015.VDF : 7.11.38.70 556032 Bytes 31.07.2012 14:06:11 VBASE016.VDF : 7.11.38.71 2048 Bytes 31.07.2012 14:06:11 VBASE017.VDF : 7.11.38.72 2048 Bytes 31.07.2012 14:06:11 VBASE018.VDF : 7.11.38.73 2048 Bytes 31.07.2012 14:06:11 VBASE019.VDF : 7.11.38.74 2048 Bytes 31.07.2012 14:06:11 VBASE020.VDF : 7.11.38.75 2048 Bytes 31.07.2012 14:06:11 VBASE021.VDF : 7.11.38.76 2048 Bytes 31.07.2012 14:06:11 VBASE022.VDF : 7.11.38.77 2048 Bytes 31.07.2012 14:06:11 VBASE023.VDF : 7.11.38.78 2048 Bytes 31.07.2012 14:06:11 VBASE024.VDF : 7.11.38.79 2048 Bytes 31.07.2012 14:06:11 VBASE025.VDF : 7.11.38.80 2048 Bytes 31.07.2012 14:06:12 VBASE026.VDF : 7.11.38.81 2048 Bytes 31.07.2012 14:06:12 VBASE027.VDF : 7.11.38.82 2048 Bytes 31.07.2012 14:06:12 VBASE028.VDF : 7.11.38.83 2048 Bytes 31.07.2012 14:06:12 VBASE029.VDF : 7.11.38.84 2048 Bytes 31.07.2012 14:06:12 VBASE030.VDF : 7.11.38.85 2048 Bytes 31.07.2012 14:06:12 VBASE031.VDF : 7.11.38.120 87040 Bytes 01.08.2012 12:35:28 Engineversion : 8.2.10.120 AEVDF.DLL : 8.1.2.10 102772 Bytes 11.07.2012 15:45:28 AESCRIPT.DLL : 8.1.4.36 459131 Bytes 27.07.2012 13:46:57 AESCN.DLL : 8.1.8.2 131444 Bytes 27.01.2012 14:00:18 AESBX.DLL : 8.2.5.12 606578 Bytes 14.06.2012 13:05:15 AERDL.DLL : 8.1.9.15 639348 Bytes 11.09.2011 10:38:08 AEPACK.DLL : 8.3.0.18 807287 Bytes 27.07.2012 13:46:56 AEOFFICE.DLL : 8.1.2.42 201083 Bytes 21.07.2012 11:47:55 AEHEUR.DLL : 8.1.4.80 5075318 Bytes 27.07.2012 13:46:55 AEHELP.DLL : 8.1.23.2 258422 Bytes 28.06.2012 11:42:52 AEGEN.DLL : 8.1.5.34 434548 Bytes 21.07.2012 11:47:44 AEEXP.DLL : 8.1.0.72 86389 Bytes 27.07.2012 13:46:57 AEEMU.DLL : 8.1.3.2 393587 Bytes 11.07.2012 15:45:27 AECORE.DLL : 8.1.27.2 201078 Bytes 11.07.2012 15:45:26 AEBB.DLL : 8.1.1.0 53618 Bytes 24.04.2010 14:57:51 AVWINLL.DLL : 12.3.0.15 27344 Bytes 14.05.2012 13:04:48 AVPREF.DLL : 12.3.0.15 51920 Bytes 14.05.2012 13:04:49 AVREP.DLL : 12.3.0.15 179208 Bytes 08.05.2012 13:02:23 AVARKT.DLL : 12.3.0.15 211408 Bytes 14.05.2012 13:04:49 AVEVTLOG.DLL : 12.3.0.15 169168 Bytes 14.05.2012 13:04:49 SQLITE3.DLL : 3.7.0.1 398288 Bytes 14.05.2012 13:04:50 AVSMTP.DLL : 12.3.0.15 63952 Bytes 14.05.2012 13:04:49 NETNT.DLL : 12.3.0.15 17104 Bytes 14.05.2012 13:04:50 RCIMAGE.DLL : 12.3.0.15 4491472 Bytes 14.05.2012 13:04:48 RCTEXT.DLL : 12.3.0.15 98512 Bytes 14.05.2012 13:04:48 Konfiguration für den aktuellen Suchlauf: Job Name..............................: AVGuardAsyncScan Konfigurationsdatei...................: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira\AntiVir Desktop\TEMP\AVGUARD_501a396d\guard_slideup.avp Protokollierung.......................: standard Primäre Aktion........................: reparieren Sekundäre Aktion......................: quarantäne Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: aus Durchsuche aktive Programme...........: ein Durchsuche Registrierung..............: aus Suche nach Rootkits...................: aus Integritätsprüfung von Systemdateien..: aus Datei Suchmodus.......................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: vollständig Beginn des Suchlaufs: Donnerstag, 2. August 2012 15:46 Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'WINWORD.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'msdtc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'dllhost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AcroRd32.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiapsrv.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TuneUpUtilitiesApp32.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'AVWEBGRD.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avmailc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ToolbarUpdater.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'TuneUpUtilitiesService32.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'jqs.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'ForceField.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'brss01a.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'brsvc01a.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'IswSvc.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'Explorer.EXE' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '1' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '1' Modul(e) wurden durchsucht Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\80000000.@' C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\80000000.@ [FUND] Ist das Trojanische Pferd TR/ATRAPS.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '52112470.qua' verschoben! Beginne mit der Suche in 'C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\800000cb.@' C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\800000cb.@ [FUND] Ist das Trojanische Pferd TR/ATRAPS.Gen2 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a860bd7.qua' verschoben! Ende des Suchlaufs: Donnerstag, 2. August 2012 15:47 Benötigte Zeit: 00:12 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 0 Verzeichnisse wurden überprüft 36 Dateien wurden geprüft 2 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 2 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 34 Dateien ohne Befall 0 Archive wurden durchsucht 0 Warnungen 2 Hinweise Wenn Sie ein bißchen Zeit haben könnten Sie vielleicht auch die Äußerung "Zonealarm ist kontraproduktiver Müll" etwas näher erläutern. Vielen Dank und herzliche Grüße HanspeterE |
05.08.2012, 15:59 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN Lies einfach mal hier, ich denke dann sollte es etwas klarer werden: Die Vertrauensbrecher c't Editorial über Internet Security Suites und warum sie idR nichts taugen Oberthal online: Personal Firewalls: Sinnvoll oder sinnfrei? personal firewalls ? Wiki ? ubuntuusers.de Dann wirst Du feststellen, dass es einfach nur unnötig ist, sich das System mit einer weiteren "Schutzkomponente" zu verhunzen... Malwarebefall vermeiden kannst Du sowieso nur, wenn Du selbst Dein verhalten in den Griff bekommst => Kompromittierung unvermeidbar?
__________________ Logfiles bitte immer in CODE-Tags posten |
05.08.2012, 17:09 | #5 |
| Probleme mit TR/ATRAPS.GEN Hallo Arne, vielen Dank für die grundsätzlichen Informationen. Könnten Sie mir bitte noch Hinweise zur Beseitigung meines aktuellen Problems TR/ATRAPS.GEN geben. Vielen Dank. Herzliche Grüße HanspeterE |
05.08.2012, 17:12 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN Deinstalliere erst ZoneAlarm Mach dann mit Malwarebytes und ESET weiter: Bitte erstmal routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen! Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ --> Probleme mit TR/ATRAPS.GEN |
06.08.2012, 07:34 | #7 |
| Probleme mit TR/ATRAPS.GEN Hallo Arne, vielen DanK! Hier die geforderten Logs: Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.05.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 6.0.2900.5512 Hp :: HPE [Administrator] Schutz: Aktiviert 05.08.2012 19:03:15 mbam-log-2012-08-05 (19-03-15).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 343586 Laufzeit: 3 Stunde(n), 16 Minute(n), 27 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCR\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32| (Trojan.Zaccess) -> Bösartig: (\\.\globalroot\systemroot\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\n.) Gut: (wbemess.dll) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 D:\Programme\ClearProg\eBay\eBayShortcuts.exe (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter 2012/08/05 19:00:14 +0200 HPE Hp MESSAGE Starting protection 2012/08/05 19:00:23 +0200 HPE Hp MESSAGE Protection started successfully 2012/08/05 19:00:26 +0200 HPE Hp MESSAGE Starting IP protection 2012/08/05 19:00:41 +0200 HPE Hp MESSAGE IP Protection started successfully 2012/08/05 19:01:24 +0200 HPE Hp MESSAGE Starting database refresh 2012/08/05 19:01:24 +0200 HPE Hp MESSAGE Stopping IP protection 2012/08/05 19:01:24 +0200 HPE Hp MESSAGE IP Protection stopped 2012/08/05 19:01:45 +0200 HPE Hp MESSAGE Database refreshed successfully 2012/08/05 19:01:45 +0200 HPE Hp MESSAGE Starting IP protection 2012/08/05 19:02:01 +0200 HPE Hp MESSAGE IP Protection started successfully 2012/08/05 22:24:06 +0200 HPE Hp MESSAGE Starting protection 2012/08/05 22:24:20 +0200 HPE Hp MESSAGE Protection started successfully 2012/08/05 22:24:23 +0200 HPE Hp MESSAGE Starting IP protection 2012/08/05 22:24:36 +0200 HPE Hp MESSAGE IP Protection started successfully 2012/08/05 22:47:56 +0200 HPE Hp MESSAGE Executing scheduled update: Daily 2012/08/05 22:48:11 +0200 HPE Hp MESSAGE Scheduled update executed successfully: database updated from version v2012.08.05.07 to version v2012.08.05.08 2012/08/05 22:48:11 +0200 HPE Hp MESSAGE Starting database refresh 2012/08/05 22:48:11 +0200 HPE Hp MESSAGE Stopping IP protection 2012/08/05 22:48:11 +0200 HPE Hp MESSAGE IP Protection stopped 2012/08/05 22:48:20 +0200 HPE Hp MESSAGE Database refreshed successfully 2012/08/05 22:48:20 +0200 HPE Hp MESSAGE Starting IP protection 2012/08/05 22:48:33 +0200 HPE Hp MESSAGE IP Protection started successfully Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=5fc3bc8b54046a4c852454b32c09a7a2 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-05 10:52:51 # local_time=2012-08-06 12:52:51 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1792 16777175 100 0 11597149 11597149 0 0 # compatibility_mode=8192 67108863 100 0 528 528 0 0 # compatibility_mode=9217 16777214 0 9 12978865 12978867 0 0 # scanned=111370 # found=12 # cleaned=0 # scan_time=8024 C:\Dokumente und Einstellungen\Gast1\Eigene Dateien\Downloads\SweetImSetup.exe a variant of Win32/SweetIM.B application (unable to clean) 00000000000000000000000000000000 I C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\24\766972d8-66ea8ae2 Java/Exploit.CVE-2012-1723.AB trojan (unable to clean) 00000000000000000000000000000000 I C:\Programme\Application Updater\ApplicationUpdater.exe probably a variant of Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Programme\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Programme\Gemeinsame Dateien\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I C:\Programme\Gemeinsame Dateien\Spigot\wtxpcom\components\WidgiToolbarFF.dll a variant of Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I C:\Programme\pdfforge Toolbar\IE\4.5\pdfforgeToolbarIE.dll a variant of Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I D:\Programme\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe Win32/Toolbar.Widgi application (unable to clean) 00000000000000000000000000000000 I HanspeterE |
06.08.2012, 15:42 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
06.08.2012, 18:40 | #9 |
| Probleme mit TR/ATRAPS.GEN Hallo Arne, weiter geht's mit AdwCleaner: Code:
ATTFilter # AdwCleaner v1.800 - Logfile created 08/06/2012 at 19:37:07 # Updated 01/08/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Hp - HPE # Running from : C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** Found : Application Updater Found : vToolbarUpdater11.2.0 ***** [Files / Folders] ***** Folder Found : C:\DVDVideoSoft Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\AVG Secure Search Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Babylon Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\BabylonToolbar Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoft Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\pdfforge Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\PriceGong Folder Found : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Search Settings Folder Found : C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\pdfforge Folder Found : C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\Search Settings Folder Found : C:\Dokumente und Einstellungen\Hp\Eigene Dateien\DVDVideoSoft Folder Found : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search Folder Found : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon Folder Found : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\DealPly Folder Found : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\DVDVideoSoft Folder Found : C:\Programme\Application Updater Folder Found : C:\Programme\AskBarDis Folder Found : C:\Programme\AskSearch Folder Found : C:\Programme\AVG Secure Search Folder Found : C:\Programme\BabylonToolbar Folder Found : C:\Programme\Conduit Folder Found : C:\Programme\DealPly Folder Found : C:\Programme\DVDVideoSoft Folder Found : C:\Programme\DVDVideoSoftTB Folder Found : C:\Programme\pdfforge Toolbar Folder Found : C:\Programme\Winload Folder Found : C:\Programme\ZoneAlarm-Sicherheit Folder Found : C:\Programme\Gemeinsame Dateien\AVG Secure Search Folder Found : C:\Programme\Gemeinsame Dateien\DVDVideoSoft Folder Found : C:\Programme\Gemeinsame Dateien\spigot Folder Found : C:\WINDOWS\Installer\{638482BC-3092-42DC-AEA1-735264911A77} File Found : C:\Programme\Mozilla FireFox\Components\AskSearch.js File Found : C:\WINDOWS\system32\conduitEngine.tmp ***** [Registry] ***** [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2269050[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2319825[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Found : HKCU\Software\AppDataLow\AskBarDis Key Found : HKCU\Software\AppDataLow\AskSA Key Found : HKCU\Software\AVG Secure Search Key Found : HKCU\Software\BabylonToolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\DealPly Key Found : HKCU\Software\DVDVideoSoft Key Found : HKCU\Software\DVDVideoSoftTB Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKCU\Software\pdfforge Key Found : HKCU\Software\PriceGong Key Found : HKCU\Software\Search Settings Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\Winload Key Found : HKCU\Software\ZoneAlarm-Sicherheit Key Found : HKCU\Toolbar Key Found : HKLM\SOFTWARE\Application Updater Key Found : HKLM\SOFTWARE\AskBarDis Key Found : HKLM\SOFTWARE\AVG Secure Search Key Found : HKLM\SOFTWARE\Babylon Key Found : HKLM\SOFTWARE\BabylonToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Found : HKLM\SOFTWARE\Classes\b Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Found : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\CB2848362903CD24EA1A37254619A177 Key Found : HKLM\SOFTWARE\Classes\Installer\Products\CB2848362903CD24EA1A37254619A177 Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\DealPly Key Found : HKLM\SOFTWARE\DVDVideoSoft Key Found : HKLM\SOFTWARE\DVDVideoSoftTB Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoft Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winload Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm-Sicherheit Toolbar Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : HKLM\SOFTWARE\pdfforge Key Found : HKLM\SOFTWARE\Search Settings Key Found : HKLM\SOFTWARE\Winload Key Found : HKLM\SOFTWARE\ZoneAlarm-Sicherheit ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0702A2B6-13AA-4090-9E01-BCDC85DD933F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2} Key Found : HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Found : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60} Key Found : HKLM\SOFTWARE\Classes\CLSID\{622FD888-4E91-4D68-84D4-7262FD0811BF} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B0DE3308-5D5A-470D-81B9-634FC078393B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C94E154B-1459-4A47-966B-4B843BEFC7DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F47FA7D6-CD65-4ADF-9DB2-674D146D4E24} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1D9723C-3216-4892-BCD5-B97E3B35BA4E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{07EF6E96-0BCA-4ECF-99AF-C23908ECE54D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BDEFD635-F125-48C2-AAEF-714FC22E365E} Key Found : HKLM\SOFTWARE\Classes\CLSID\{40C3CC16-7269-4B32-9531-17F2950FB06F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3299AD6E-F4BF-49C6-9AF6-138227D007E5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4175524-FF45-48A7-A9BE-92A377C547B4} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3654B83F-264E-4646-861E-1498BB139256} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A29413B9-7926-423A-9D8E-ADEEA0C91CD9} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Key Found : HKLM\SOFTWARE\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362} Key Found : HKLM\SOFTWARE\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA} Key Found : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Key Found : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Key Found : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Key Found : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Key Found : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Key Found : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Key Found : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Key Found : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9} Key Found : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Key Found : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Key Found : HKLM\SOFTWARE\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742} Key Found : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41B7F301-5636-4E48-A8BF-EC5BD1D8A86E} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0DE48723-5713-42D8-8CDA-5055F39A0AE6} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E3CF422-505E-457B-8BE5-E744D11098F0} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8DF2AE65-8F3F-4DB1-8DFD-91C29205CF15} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01B21C84-9A4E-4CDA-9755-366FA1273C68} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{236E3511-B836-44A7-A14F-076A43425912} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD0A88F7-FF66-4BC7-B4D2-42FC7F81DCFC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AD19E9-D736-4D7E-9AA9-AB89E88F9ADC} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C3CC16-7269-4B32-9531-17F2950FB06F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B1D9723C-3216-4892-BCD5-B97E3B35BA4E} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BDEFD635-F125-48C2-AAEF-714FC22E365E} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4175524-FF45-48A7-A9BE-92A377C547B4} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A29413B9-7926-423A-9D8E-ADEEA0C91CD9} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3041D03E-FD4B-44E0-B742-2D9B88305F98}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3041D03E-FD4B-44E0-B742-2D9B88305F98}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] ***** [Internet Browsers] ***** -\\ Internet Explorer v6.0.2900.5512 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={758F62B8-C216-4913-9265-96C03CB09346}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=2011-12-10 14:38:33&v=11.1.0.12&sap=nt [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= ************************* AdwCleaner[R1].txt - [19771 octets] - [06/08/2012 19:37:07] ########## EOF - C:\AdwCleaner[R1].txt - [19900 octets] ########## Gruß HanspeterE |
07.08.2012, 12:34 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
__________________ Logfiles bitte immer in CODE-Tags posten |
07.08.2012, 18:18 | #11 |
| Probleme mit TR/ATRAPS.GEN Hallo Arne, vielen Dank. Hier ist die geforderte Datei Code:
ATTFilter # AdwCleaner v1.800 - Logfile created 08/07/2012 at 19:11:55 # Updated 01/08/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Hp - HPE # Running from : C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : Application Updater Stopped & Deleted : vToolbarUpdater11.2.0 ***** [Files / Folders] ***** Folder Deleted : C:\DVDVideoSoft Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\AVG Secure Search Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Babylon Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\BabylonToolbar Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoft Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\pdfforge Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\PriceGong Folder Deleted : C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Search Settings Folder Deleted : C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\pdfforge Folder Deleted : C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\Search Settings Folder Deleted : C:\Dokumente und Einstellungen\Hp\Eigene Dateien\DVDVideoSoft Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon Folder Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\DealPly Folder Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\DVDVideoSoft Folder Deleted : C:\Programme\Application Updater Folder Deleted : C:\Programme\AskBarDis Folder Deleted : C:\Programme\AskSearch Folder Deleted : C:\Programme\AVG Secure Search Folder Deleted : C:\Programme\BabylonToolbar Folder Deleted : C:\Programme\Conduit Folder Deleted : C:\Programme\DealPly Folder Deleted : C:\Programme\DVDVideoSoft Folder Deleted : C:\Programme\DVDVideoSoftTB Folder Deleted : C:\Programme\pdfforge Toolbar Folder Deleted : C:\Programme\Winload Folder Deleted : C:\Programme\ZoneAlarm-Sicherheit Folder Deleted : C:\Programme\Gemeinsame Dateien\AVG Secure Search Folder Deleted : C:\Programme\Gemeinsame Dateien\DVDVideoSoft Folder Deleted : C:\Programme\Gemeinsame Dateien\spigot Folder Deleted : C:\WINDOWS\Installer\{638482BC-3092-42DC-AEA1-735264911A77} File Deleted : C:\Programme\Mozilla FireFox\Components\AskSearch.js File Deleted : C:\WINDOWS\system32\conduitEngine.tmp ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2319825[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Key Deleted : HKCU\Software\AppDataLow\AskBarDis Key Deleted : HKCU\Software\AppDataLow\AskSA Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DealPly Key Deleted : HKCU\Software\DVDVideoSoft Key Deleted : HKCU\Software\DVDVideoSoftTB Key Deleted : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKCU\Software\pdfforge Key Deleted : HKCU\Software\PriceGong Key Deleted : HKCU\Software\Search Settings Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\Winload Key Deleted : HKCU\Software\ZoneAlarm-Sicherheit Key Deleted : HKCU\Toolbar Key Deleted : HKLM\SOFTWARE\Application Updater Key Deleted : HKLM\SOFTWARE\AskBarDis Key Deleted : HKLM\SOFTWARE\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Babylon Key Deleted : HKLM\SOFTWARE\BabylonToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\b Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\CB2848362903CD24EA1A37254619A177 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\CB2848362903CD24EA1A37254619A177 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\DealPly Key Deleted : HKLM\SOFTWARE\DVDVideoSoft Key Deleted : HKLM\SOFTWARE\DVDVideoSoftTB Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{638482BC-3092-42DC-AEA1-735264911A77} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoft Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winload Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm-Sicherheit Toolbar Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\SOFTWARE\pdfforge Key Deleted : HKLM\SOFTWARE\Search Settings Key Deleted : HKLM\SOFTWARE\Winload Key Deleted : HKLM\SOFTWARE\ZoneAlarm-Sicherheit ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0702A2B6-13AA-4090-9E01-BCDC85DD933F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{622FD888-4E91-4D68-84D4-7262FD0811BF} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B0DE3308-5D5A-470D-81B9-634FC078393B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C94E154B-1459-4A47-966B-4B843BEFC7DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F47FA7D6-CD65-4ADF-9DB2-674D146D4E24} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B1D9723C-3216-4892-BCD5-B97E3B35BA4E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{07EF6E96-0BCA-4ECF-99AF-C23908ECE54D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BDEFD635-F125-48C2-AAEF-714FC22E365E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{40C3CC16-7269-4B32-9531-17F2950FB06F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3299AD6E-F4BF-49C6-9AF6-138227D007E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4175524-FF45-48A7-A9BE-92A377C547B4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3654B83F-264E-4646-861E-1498BB139256} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A29413B9-7926-423A-9D8E-ADEEA0C91CD9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41B7F301-5636-4E48-A8BF-EC5BD1D8A86E} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0DE48723-5713-42D8-8CDA-5055F39A0AE6} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E3CF422-505E-457B-8BE5-E744D11098F0} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8DF2AE65-8F3F-4DB1-8DFD-91C29205CF15} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01B21C84-9A4E-4CDA-9755-366FA1273C68} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{236E3511-B836-44A7-A14F-076A43425912} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD0A88F7-FF66-4BC7-B4D2-42FC7F81DCFC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2AD19E9-D736-4D7E-9AA9-AB89E88F9ADC} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C3CC16-7269-4B32-9531-17F2950FB06F} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B1D9723C-3216-4892-BCD5-B97E3B35BA4E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BDEFD635-F125-48C2-AAEF-714FC22E365E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4175524-FF45-48A7-A9BE-92A377C547B4} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A29413B9-7926-423A-9D8E-ADEEA0C91CD9} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3041D03E-FD4B-44E0-B742-2D9B88305F98}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3041D03E-FD4B-44E0-B742-2D9B88305F98}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}] ***** [Internet Browsers] ***** -\\ Internet Explorer v6.0.2900.5512 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050 --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={758F62B8-C216-4913-9265-96C03CB09346}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=2011-12-10 14:38:33&v=11.1.0.12&sap=nt --> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q= --> hxxp://www.google.com ************************* AdwCleaner[R1].txt - [19902 octets] - [06/08/2012 19:37:07] AdwCleaner[S1].txt - [20472 octets] - [07/08/2012 19:11:55] ########## EOF - C:\AdwCleaner[S1].txt - [20601 octets] ########## HanspeterE |
08.08.2012, 18:43 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN Hätte da mal zwei Fragen bevor es weiter geht 1.) Geht der normale Modus von Windows (wieder) uneingeschränkt? 2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
__________________ Logfiles bitte immer in CODE-Tags posten |
09.08.2012, 11:29 | #13 |
| Probleme mit TR/ATRAPS.GEN Hallo, hier sind die Antworten auf folgende Fragen: Zitat Anfang: Dies ist der Beitrag, der gerade geschrieben wurde: *************** Hätte da mal zwei Fragen bevor es weiter geht 1.) Geht der normale Modus von Windows (wieder) uneingeschränkt? 2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden? *************** Zitat Ende. Antworten: 1) Normaler Modus von Windows läuft nach meiner Einschätzung wieder uneingeschränkt. Es gab auch keine Warnmeldungen des Anti-Viren-Programmes mehr. Alles scheint normal zu funktionieren. 2) Ich vermisse keine Programme. Im Startmenü befinden sich folgende leere Ordner: Autostart und Live Security Platinum. Vielen Dank für weitere Hilfe, herzliche Grüße HanspeterE |
10.08.2012, 11:50 | #14 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Probleme mit TR/ATRAPS.GEN Hier gibt es eine Zitatsfunktion! Du musst das Rad nicht neu erfinden um Zitate zu kennzeichnen! Zitat:
Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
10.08.2012, 13:46 | #15 |
| Probleme mit TR/ATRAPS.GEN Hallo Arne, hier ist der Inhalt aus OTL.Txt: OTL Logfile: Code:
ATTFilter OTL logfile created on: 10.08.2012 14:23:34 - Run 2 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Dokumente und Einstellungen\Hp\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 958,73 Mb Total Physical Memory | 519,18 Mb Available Physical Memory | 54,15% Memory free 2,26 Gb Paging File | 1,83 Gb Available in Paging File | 80,96% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 19,53 Gb Total Space | 7,03 Gb Free Space | 35,99% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 23,65 Gb Free Space | 43,01% Space Free | Partition Type: NTFS Drive G: | 7,31 Gb Total Space | 3,37 Gb Free Space | 46,08% Space Free | Partition Type: FAT32 Computer Name: HPE | User Name: Hp | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.08.10 14:20:39 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- d:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- D:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe PRC - [2012.05.14 15:04:49 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.14 15:04:49 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2011.12.14 13:23:34 | 001,212,224 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe PRC - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe ========== Modules (No Company Name) ========== MOD - [2012.05.14 15:04:50 | 000,398,288 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll MOD - [2009.02.27 17:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU MOD - [2001.10.28 18:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\Programme\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc) SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012.08.05 20:01:32 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.19 12:04:23 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- d:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService) SRV - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010.03.29 08:53:22 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programme\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | Auto | Stopped] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.05.14 15:04:50 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.14 15:04:50 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.03.24 18:02:36 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.03.24 18:02:36 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011.12.12 20:31:38 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2011.05.07 10:34:11 | 000,097,792 | ---- | M] (Protect Software GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ACEDRV05.sys -- (ACEDRV05) DRV - [2008.09.24 11:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) DRV - [2005.03.09 15:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2003.07.02 04:42:00 | 000,027,904 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1) DRV - [2000.07.24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\BRPAR.SYS -- (BrPar) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search" FF - prefs.js..browser.startup.homepage: "hxxp://isearch.avg.com/?cid={7ECDEDD5-CF89-4DCF-A825-170331E0DA68}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=&v=&sap=hp" FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Programme\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Programme\CheckPoint\ZAForceField\TrustChecker FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: D:\Programme\Mozilla Firefox\components [2012.07.19 12:04:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: D:\Programme\Mozilla Firefox\plugins [2012.05.05 14:47:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: D:\Programme\Mozilla Thunderbird\components [2012.06.21 16:36:51 | 000,000,000 | ---D | M] [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.07.26 09:36:27 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions [2012.06.27 18:16:31 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012.03.30 15:52:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.06.24 13:31:50 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2012.07.15 11:47:34 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} [2011.12.10 15:38:40 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\avg@toolbar [2011.03.25 16:05:11 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\engine@conduit.com [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (FlashGot) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.03.28 19:40:35 | 000,000,000 | ---D | M] (Winload Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2008.08.09 13:46:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (IE Tab [de]) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2010.07.26 19:06:44 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] ("BugMeNot") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.04.02 14:05:04 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [2008.10.16 17:18:58 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\avg@toolbar [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Deutsches Wörterbuch) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\de-DE@dictionaries.addons.mozilla.org [2010.03.28 19:40:12 | 000,000,000 | ---D | M] (WINLOAD-Gutschein-Alarm) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\sparweltgutscheinewl@sparwelt.de [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012.04.09 14:36:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\staged O1 HOSTS File: ([2004.08.04 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No CLSID value found. O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] d:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.) O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.42.43.62 82.212.62.62 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8F73863-7C45-4B79-A886-BD0BD32B351C}: DhcpNameServer = 78.42.43.62 82.212.62.62 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.08.09 09:32:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{b9b63eb3-d60b-11de-8507-0013d47182ab}\Shell\AutoRun\command - "" = G:\StartPortableApps.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: 6to4 - File not found NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: Sharedaccess - File not found NetSvcs: WmdmPmSp - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: SharedAccess - File not found SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offlinebrowsingpaket ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer-Hilfe ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789) ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsererweiterungen ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - Zugang zu MSN Site ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML-Datenbindung ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer-Hauptschriftarten ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML-Hilfe ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.08.10 14:20:36 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.06 08:45:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\TroBoard [2012.08.05 22:30:27 | 000,000,000 | ---D | C] -- C:\Programme\ESET [2012.08.05 22:30:07 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\Hp\Desktop\esetsmartinstaller_enu.exe [2012.08.05 19:00:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Malwarebytes [2012.08.05 18:59:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware [2012.08.05 18:59:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes [2012.08.05 18:59:45 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012.08.05 18:58:17 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Hp\Desktop\mbam-setup-1.62.0.1300.exe [2012.08.01 16:28:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\Neuer Ordner [2012.08.01 15:19:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten-Dateien [2012.08.01 14:27:10 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Hp\Recent [2012.08.01 09:17:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Startmenü\Programme\Live Security Platinum [2012.08.01 09:16:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 13:27:02 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\WISO Steuer 2012 [2008.05.30 14:37:10 | 001,694,728 | ---- | C] (Microsoft Corporation) -- C:\Programme\dsetup32.dll [2008.05.30 14:35:56 | 000,097,288 | ---- | C] (Microsoft Corporation) -- C:\Programme\DSETUP.dll [2008.05.30 14:34:50 | 000,528,392 | ---- | C] (Microsoft Corporation) -- C:\Programme\DXSETUP.exe [10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.08.10 14:20:39 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.10 14:20:01 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.08.10 14:17:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.08.10 14:16:50 | 000,000,040 | ---- | M] () -- C:\WINDOWS\System32\mscandc.ini [2012.08.10 14:16:48 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.08.10 14:16:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.08.09 13:33:20 | 000,000,424 | ---- | M] () -- C:\WINDOWS\zipgenius.xml [2012.08.09 13:01:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012.08.06 19:36:33 | 000,614,903 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe [2012.08.05 22:30:08 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\Hp\Desktop\esetsmartinstaller_enu.exe [2012.08.05 18:59:47 | 000,000,630 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.05 18:58:35 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Hp\Desktop\mbam-setup-1.62.0.1300.exe [2012.08.03 12:42:54 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Ulead32.INI [2012.08.01 16:29:23 | 000,010,541 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Logfile.zip [2012.08.01 15:19:24 | 000,074,704 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten.html [2012.08.01 15:12:24 | 000,302,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:15 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.07.30 10:26:27 | 000,459,588 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2012.07.30 10:26:27 | 000,441,696 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012.07.30 10:26:27 | 000,084,960 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2012.07.30 10:26:27 | 000,071,632 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012.07.16 18:03:19 | 000,000,930 | ---- | M] () -- C:\WINDOWS\wiso.ini [2012.07.12 13:46:08 | 000,003,827 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2012.07.12 11:25:24 | 000,345,345 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.07.12 08:28:59 | 000,215,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.07.11 18:18:49 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.08.06 19:36:33 | 000,614,903 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe [2012.08.05 18:59:47 | 000,000,630 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.01 16:29:21 | 000,010,541 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Logfile.zip [2012.08.01 15:19:17 | 000,074,704 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten.html [2012.08.01 15:12:23 | 000,302,592 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:14 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.08.01 14:33:46 | 000,001,712 | ---- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\00000001.@ [2012.05.19 11:49:34 | 000,044,098 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\usrlgo.bmp [2012.02.25 11:25:12 | 000,345,345 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.02.14 21:48:58 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012.01.20 19:44:14 | 000,222,089 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled3_MAS.bak [2011.12.16 20:56:31 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2011.11.29 22:13:18 | 000,000,849 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\.recently-used.xbel [2011.10.20 13:24:23 | 000,067,320 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled1_MAS.bak [2011.08.08 17:33:00 | 000,003,163 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled10_MAS.bak [2011.08.08 17:28:22 | 000,155,546 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled4_MAS.bak [2011.08.08 17:18:34 | 000,367,598 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled2_MAS.bak [2011.03.20 11:17:59 | 000,823,296 | ---- | C] () -- C:\WINDOWS\j3dcore-d3d.dll [2011.03.20 11:17:59 | 000,163,840 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl.dll [2011.03.20 11:17:59 | 000,049,152 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-chk.dll [2011.03.20 11:17:59 | 000,040,960 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-cg.dll [2010.12.25 11:21:50 | 001,456,640 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\Falk Navi-Manager.msi [2010.12.25 11:21:27 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\$_hpcst$.hpc [2010.05.05 18:06:55 | 000,499,743 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled0_MAS.bak [2009.11.20 09:28:25 | 000,005,943 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\mainhst.zgh [2009.01.03 12:32:49 | 000,003,827 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2008.09.10 17:02:04 | 000,008,810 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\gsview32.ini [2008.08.10 17:40:41 | 000,007,168 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.05.30 14:38:30 | 001,158,739 | ---- | C] () -- C:\Programme\BDANT.cab [2008.05.30 14:38:30 | 001,130,465 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x86.cab [2008.05.30 14:38:30 | 001,118,469 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x86.cab [2008.05.30 14:38:30 | 001,087,968 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x86.cab [2008.05.30 14:38:30 | 001,082,704 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x86.cab [2008.05.30 14:38:30 | 001,082,210 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x86.cab [2008.05.30 14:38:28 | 001,080,892 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x86.cab [2008.05.30 14:38:26 | 001,068,173 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x86.cab [2008.05.30 14:38:26 | 001,016,473 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x86.cab [2008.05.30 14:38:26 | 000,978,396 | ---- | C] () -- C:\Programme\BDAXP.cab [2008.05.30 14:38:26 | 000,919,678 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86.cab [2008.05.30 14:38:26 | 000,867,848 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x64.cab [2008.05.30 14:38:26 | 000,855,534 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x64.cab [2008.05.30 14:38:24 | 000,871,076 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x64.cab [2008.05.30 14:38:24 | 000,853,167 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x86.cab [2008.05.30 14:38:24 | 000,848,132 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x64.cab [2008.05.30 14:38:24 | 000,807,132 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x86.cab [2008.05.30 14:38:24 | 000,702,292 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x64.cab [2008.05.30 14:38:22 | 000,821,508 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x86.cab [2008.05.30 14:38:22 | 000,800,115 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x86.cab [2008.05.30 14:38:22 | 000,701,860 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x64.cab [2008.05.30 14:38:20 | 000,701,720 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x86.cab [2008.05.30 14:38:18 | 000,272,876 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x64.cab [2008.05.30 14:38:16 | 000,699,113 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x86.cab [2008.05.30 14:38:16 | 000,254,442 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x64.cab [2008.05.30 14:38:14 | 000,272,272 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,229,498 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,216,055 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x64.cab [2008.05.30 14:38:12 | 000,201,344 | ---- | C] () -- C:\Programme\AUG2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,370 | ---- | C] () -- C:\Programme\JUN2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,010 | ---- | C] () -- C:\Programme\NOV2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,197,923 | ---- | C] () -- C:\Programme\FEB2007_XACT_x64.cab [2008.05.30 14:38:10 | 000,186,151 | ---- | C] () -- C:\Programme\AUG2006_XACT_x64.cab [2008.05.30 14:38:10 | 000,185,609 | ---- | C] () -- C:\Programme\OCT2006_XACT_x64.cab [2008.05.30 14:38:08 | 000,199,014 | ---- | C] () -- C:\Programme\APR2007_XACT_x64.cab [2008.05.30 14:38:08 | 000,194,968 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x86.cab [2008.05.30 14:38:06 | 000,195,723 | ---- | C] () -- C:\Programme\DEC2006_XACT_x64.cab [2008.05.30 14:38:06 | 000,184,033 | ---- | C] () -- C:\Programme\JUN2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,182,381 | ---- | C] () -- C:\Programme\Apr2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,181,607 | ---- | C] () -- C:\Programme\Feb2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,156,157 | ---- | C] () -- C:\Programme\JUN2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,512 | ---- | C] () -- C:\Programme\NOV2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,231 | ---- | C] () -- C:\Programme\FEB2007_XACT_x86.cab [2008.05.30 14:38:02 | 000,156,260 | ---- | C] () -- C:\Programme\AUG2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,154,473 | ---- | C] () -- C:\Programme\APR2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,136,351 | ---- | C] () -- C:\Programme\Apr2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,148,847 | ---- | C] () -- C:\Programme\DEC2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,135,657 | ---- | C] () -- C:\Programme\Feb2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,141,265 | ---- | C] () -- C:\Programme\OCT2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,140,483 | ---- | C] () -- C:\Programme\AUG2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,136,919 | ---- | C] () -- C:\Programme\JUN2006_XACT_x86.cab [2008.05.30 14:37:54 | 000,056,550 | ---- | C] () -- C:\Programme\APR2007_xinput_x86.cab [2008.05.30 14:37:52 | 000,125,584 | ---- | C] () -- C:\Programme\Mar2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,124,302 | ---- | C] () -- C:\Programme\Jun2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,100,065 | ---- | C] () -- C:\Programme\APR2007_xinput_x64.cab [2008.05.30 14:37:52 | 000,058,402 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x64.cab [2008.05.30 14:37:52 | 000,049,306 | ---- | C] () -- C:\Programme\AUG2006_xinput_x86.cab [2008.05.30 14:37:50 | 000,058,306 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x64.cab [2008.05.30 14:37:50 | 000,025,153 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x86.cab [2008.05.30 14:37:48 | 000,097,916 | ---- | C] () -- C:\Programme\dxupdate.cab [2008.05.30 14:37:48 | 000,049,258 | ---- | C] () -- C:\Programme\Apr2006_xinput_x86.cab [2008.05.30 14:37:48 | 000,048,607 | ---- | C] () -- C:\Programme\Oct2005_xinput_x86.cab [2008.05.30 14:37:46 | 000,090,390 | ---- | C] () -- C:\Programme\AUG2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,090,349 | ---- | C] () -- C:\Programme\Apr2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,047,700 | ---- | C] () -- C:\Programme\dxdllreg_x86.cab [2008.05.30 14:37:44 | 000,049,392 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x64.cab [2008.05.30 14:37:42 | 000,096,982 | ---- | C] () -- C:\Programme\Mar2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,096,376 | ---- | C] () -- C:\Programme\Jun2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,089,285 | ---- | C] () -- C:\Programme\Oct2005_xinput_x64.cab [2008.05.30 14:37:42 | 000,025,115 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x86.cab [2008.05.30 14:37:42 | 000,021,744 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x86.cab [2008.05.30 14:36:04 | 013,267,416 | ---- | C] () -- C:\Programme\dxnt.cab [2008.05.30 14:36:02 | 004,165,878 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86_Archive.cab [2008.05.30 14:36:02 | 001,805,306 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x64.cab [2008.05.30 14:36:00 | 001,803,408 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x64.cab [2008.05.30 14:35:56 | 001,795,856 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x64.cab [2008.05.30 14:35:56 | 001,773,110 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x64.cab [2008.05.30 14:35:56 | 001,712,608 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x86.cab [2008.05.30 14:35:56 | 001,711,400 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x86.cab [2008.05.30 14:35:56 | 001,611,022 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x64.cab [2008.05.30 14:35:56 | 001,610,606 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x64.cab [2008.05.30 14:35:56 | 001,610,534 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x86.cab [2008.05.30 14:35:56 | 001,609,287 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x86.cab [2008.05.30 14:35:56 | 001,577,624 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x86.cab [2008.05.30 14:35:56 | 001,574,402 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x64.cab [2008.05.30 14:35:56 | 001,467,126 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x86.cab [2008.05.30 14:35:56 | 001,446,530 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x86.cab [2008.05.30 14:35:56 | 001,416,150 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x64.cab [2008.05.30 14:35:56 | 001,401,078 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x64.cab [2008.05.30 14:35:56 | 001,361,224 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x64.cab [2008.05.30 14:35:56 | 001,339,250 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x64.cab [2008.05.30 14:35:54 | 001,366,044 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x64.cab [2008.05.30 14:35:54 | 001,353,790 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x64.cab [2008.05.30 14:35:54 | 001,350,602 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x64.cab [2008.05.30 14:35:54 | 001,250,747 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x64.cab [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\@ [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\{170ff124-1ba0-a426-70fe-860c313d0703}\@ ========== LOP Check ========== [2012.08.01 14:19:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 14:01:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Buhl Data Service GmbH [2011.11.12 09:11:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CheckPoint [2011.12.10 15:38:17 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files [2008.12.06 20:31:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\eXPert PDF 4 [2008.08.09 10:37:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MailFrontier [2011.08.29 18:37:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Power Soft [2011.10.14 17:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2010.10.29 15:20:21 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2011.10.14 17:41:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2010.04.30 08:27:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009.01.30 14:54:34 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{55A29068-F2CE-456C-9148-C869879E2357} [2009.10.31 14:57:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009.10.30 19:26:51 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} [2010.08.03 18:25:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\CheckPoint [2010.11.19 12:56:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\Thunderbird [2011.11.09 12:23:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\TuneUp Software [2011.10.22 09:24:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\TuneUp Software [2010.10.29 16:00:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\TuneUp Software ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2008.09.02 10:31:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\ABBYY [2010.12.01 20:46:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Adobe [2011.07.18 12:28:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Apple Computer [2012.03.24 18:19:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Avira [2008.12.13 21:05:26 | 000,000,000 | R--D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Brother [2010.06.03 10:28:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Buhl Data Service [2011.03.03 17:37:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\CheckPoint [2010.12.02 21:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2008.08.11 16:26:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Design Science [2012.06.03 13:44:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox [2011.09.12 16:40:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers [2009.03.27 16:32:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\eXPert PDF Editor [2008.11.30 14:31:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Google [2011.11.29 22:13:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\gtk-2.0 [2008.09.10 17:05:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Help [2008.08.09 09:44:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Identities [2008.09.04 09:47:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\InterVideo [2008.09.06 09:16:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\IrfanView [2010.12.01 20:54:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\JacquieLawsonAdventCalendar [2011.11.12 22:23:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\JLAdventCalendarLondon2011 [2011.05.07 10:34:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Klett [2009.04.14 10:25:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\KnotPlot [2010.05.02 11:10:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Macromedia [2012.08.05 19:00:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Malwarebytes [2010.12.30 13:25:52 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Microsoft [2008.08.09 12:18:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Microsoft Web Folders [2010.10.21 17:28:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla [2009.09.14 18:20:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\OpenOffice.org [2008.08.09 13:11:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Sun [2008.08.09 11:01:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Talkback [2011.01.03 14:34:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Thunderbird [2011.10.14 17:43:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\TuneUp Software [2010.03.28 19:47:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Youtube Downloader HD [2012.05.19 12:07:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\ZipGenius < %APPDATA%\*.exe /s > [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\Dropbox.exe [2012.05.24 20:39:24 | 000,872,144 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\DropboxUpdateHelper.exe [2012.05.24 20:39:30 | 000,177,280 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\Uninstall.exe [2011.11.12 22:21:02 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2011.05.19 09:02:53 | 000,188,152 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\FlashGot.exe [2010.03.29 08:53:22 | 000,029,984 | ---- | M] (NOS Microsystems Ltd.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe [2008.05.29 17:35:44 | 000,167,336 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\FlashGot.exe [2011.06.11 17:00:48 | 000,617,472 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\OpenOffice.org\3\user\uno_packages\cache\uno_packages\11.tmp_\oracle-pdfimport.oxt\xpdfimport.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys [2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll < MD5 for: IASTOR.SYS > [2004.09.26 15:24:54 | 000,477,952 | ---- | M] (Intel Corporation) MD5=DD19FDD8BB262F64A11C50CC23FC6F70 -- C:\WINDOWS\OEM\iaStor\iaStor.sys < MD5 for: NETLOGON.DLL > [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: NVATABUS.SYS > [2004.09.02 09:24:38 | 000,082,816 | ---- | M] (NVIDIA Corporation) MD5=EEABD98AA887DD923546F20D400B2907 -- C:\WINDOWS\OEM\nvatabus\nvatabus.sys < MD5 for: SCECLI.DLL > [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll < MD5 for: USER32.DLL > [2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll [2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe < MD5 for: VIAMRAID.SYS > [2004.05.18 15:55:26 | 000,074,112 | ---- | M] (VIA Technologies inc,.ltd) MD5=F199939205DCCC7836AE5AB8B5DD5E83 -- C:\WINDOWS\OEM\viapdsk\viamraid.sys [2004.05.18 15:55:26 | 000,074,112 | ---- | M] (VIA Technologies inc,.ltd) MD5=F199939205DCCC7836AE5AB8B5DD5E83 -- C:\WINDOWS\system32\drivers\viamraid.sys < MD5 for: WINLOGON.EXE > [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2008.08.09 11:19:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2008.08.09 11:19:29 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2008.08.09 11:19:29 | 000,442,368 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < > < End of report > Vielen Dank. Herzliche Grüße HanspeterE Hallo Arne, hier ist der Inhalt aus OTL.Txt: OTL Logfile: Code:
ATTFilter OTL logfile created on: 10.08.2012 14:23:34 - Run 2 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Dokumente und Einstellungen\Hp\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 958,73 Mb Total Physical Memory | 519,18 Mb Available Physical Memory | 54,15% Memory free 2,26 Gb Paging File | 1,83 Gb Available in Paging File | 80,96% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 19,53 Gb Total Space | 7,03 Gb Free Space | 35,99% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 23,65 Gb Free Space | 43,01% Space Free | Partition Type: NTFS Drive G: | 7,31 Gb Total Space | 3,37 Gb Free Space | 46,08% Space Free | Partition Type: FAT32 Computer Name: HPE | User Name: Hp | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.08.10 14:20:39 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- d:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- D:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe PRC - [2012.05.14 15:04:49 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.14 15:04:49 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2011.12.14 13:23:34 | 001,212,224 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe PRC - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe ========== Modules (No Company Name) ========== MOD - [2012.05.14 15:04:50 | 000,398,288 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll MOD - [2009.02.27 17:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU MOD - [2001.10.28 18:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\Programme\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc) SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012.08.05 20:01:32 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.19 12:04:23 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- d:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.05.14 15:04:50 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.14 15:04:49 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2012.05.14 15:04:49 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService) SRV - [2012.05.14 15:04:49 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.12.14 13:23:32 | 001,514,304 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010.03.29 08:53:22 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programme\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | Auto | Stopped] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012.05.14 15:04:50 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.14 15:04:50 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.03.24 18:02:36 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.03.24 18:02:36 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011.12.12 20:31:38 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2011.05.07 10:34:11 | 000,097,792 | ---- | M] (Protect Software GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ACEDRV05.sys -- (ACEDRV05) DRV - [2008.09.24 11:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) DRV - [2005.03.09 15:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2003.07.02 04:42:00 | 000,027,904 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1) DRV - [2000.07.24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\BRPAR.SYS -- (BrPar) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search" FF - prefs.js..browser.startup.homepage: "hxxp://isearch.avg.com/?cid={7ECDEDD5-CF89-4DCF-A825-170331E0DA68}&mid=6dcf566e154e47d1a54cd15a92956b58-6835479ae09fc5296a25f06ad21fc3ac79e5a147&lang=de&ds=tt014&pr=sa&d=&v=&sap=hp" FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Programme\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Programme\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Programme\CheckPoint\ZAForceField\TrustChecker FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: D:\Programme\Mozilla Firefox\components [2012.07.19 12:04:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: D:\Programme\Mozilla Firefox\plugins [2012.05.05 14:47:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: D:\Programme\Mozilla Thunderbird\components [2012.06.21 16:36:51 | 000,000,000 | ---D | M] [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions [2010.08.06 18:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.07.26 09:36:27 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions [2012.06.27 18:16:31 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012.03.30 15:52:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.06.24 13:31:50 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2012.07.15 11:47:34 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} [2011.12.10 15:38:40 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\avg@toolbar [2011.03.25 16:05:11 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\engine@conduit.com [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (FlashGot) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.03.28 19:40:35 | 000,000,000 | ---D | M] (Winload Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2008.08.09 13:46:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (IE Tab [de]) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2010.07.26 19:06:44 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] ("BugMeNot") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42} [2010.07.26 19:06:43 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2008.08.09 13:46:27 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.04.02 14:05:04 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [2008.10.16 17:18:58 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} [2011.12.10 15:38:42 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\avg@toolbar [2008.08.09 13:46:25 | 000,000,000 | ---D | M] (Deutsches Wörterbuch) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\de-DE@dictionaries.addons.mozilla.org [2010.03.28 19:40:12 | 000,000,000 | ---D | M] (WINLOAD-Gutschein-Alarm) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\extensions\sparweltgutscheinewl@sparwelt.de [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012.04.09 14:36:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2012.04.09 14:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\staged O1 HOSTS File: ([2004.08.04 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No CLSID value found. O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] d:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-839522115-1935655697-2147179587-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.) O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.42.43.62 82.212.62.62 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8F73863-7C45-4B79-A886-BD0BD32B351C}: DhcpNameServer = 78.42.43.62 82.212.62.62 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.08.09 09:32:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{b9b63eb3-d60b-11de-8507-0013d47182ab}\Shell\AutoRun\command - "" = G:\StartPortableApps.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: 6to4 - File not found NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: Sharedaccess - File not found NetSvcs: WmdmPmSp - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: SharedAccess - File not found SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offlinebrowsingpaket ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer-Hilfe ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789) ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsererweiterungen ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - Zugang zu MSN Site ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML-Datenbindung ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer-Hauptschriftarten ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML-Hilfe ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.08.10 14:20:36 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.06 08:45:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\TroBoard [2012.08.05 22:30:27 | 000,000,000 | ---D | C] -- C:\Programme\ESET [2012.08.05 22:30:07 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\Hp\Desktop\esetsmartinstaller_enu.exe [2012.08.05 19:00:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Malwarebytes [2012.08.05 18:59:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware [2012.08.05 18:59:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes [2012.08.05 18:59:45 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012.08.05 18:58:17 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Hp\Desktop\mbam-setup-1.62.0.1300.exe [2012.08.01 16:28:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\Neuer Ordner [2012.08.01 15:19:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten-Dateien [2012.08.01 14:27:10 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Hp\Recent [2012.08.01 09:17:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Hp\Startmenü\Programme\Live Security Platinum [2012.08.01 09:16:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 13:27:02 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\WISO Steuer 2012 [2008.05.30 14:37:10 | 001,694,728 | ---- | C] (Microsoft Corporation) -- C:\Programme\dsetup32.dll [2008.05.30 14:35:56 | 000,097,288 | ---- | C] (Microsoft Corporation) -- C:\Programme\DSETUP.dll [2008.05.30 14:34:50 | 000,528,392 | ---- | C] (Microsoft Corporation) -- C:\Programme\DXSETUP.exe [10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.08.10 14:20:39 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Hp\Desktop\OTL.exe [2012.08.10 14:20:01 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.08.10 14:17:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.08.10 14:16:50 | 000,000,040 | ---- | M] () -- C:\WINDOWS\System32\mscandc.ini [2012.08.10 14:16:48 | 000,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.08.10 14:16:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.08.09 13:33:20 | 000,000,424 | ---- | M] () -- C:\WINDOWS\zipgenius.xml [2012.08.09 13:01:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012.08.06 19:36:33 | 000,614,903 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe [2012.08.05 22:30:08 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\Hp\Desktop\esetsmartinstaller_enu.exe [2012.08.05 18:59:47 | 000,000,630 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.05 18:58:35 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Hp\Desktop\mbam-setup-1.62.0.1300.exe [2012.08.03 12:42:54 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Ulead32.INI [2012.08.01 16:29:23 | 000,010,541 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Logfile.zip [2012.08.01 15:19:24 | 000,074,704 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten.html [2012.08.01 15:12:24 | 000,302,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:15 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.07.30 10:26:27 | 000,459,588 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat [2012.07.30 10:26:27 | 000,441,696 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012.07.30 10:26:27 | 000,084,960 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat [2012.07.30 10:26:27 | 000,071,632 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012.07.16 18:03:19 | 000,000,930 | ---- | M] () -- C:\WINDOWS\wiso.ini [2012.07.12 13:46:08 | 000,003,827 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2012.07.12 11:25:24 | 000,345,345 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.07.12 08:28:59 | 000,215,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.07.11 18:18:49 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.08.06 19:36:33 | 000,614,903 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\adwcleaner.exe [2012.08.05 18:59:47 | 000,000,630 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk [2012.08.01 16:29:21 | 000,010,541 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Logfile.zip [2012.08.01 15:19:17 | 000,074,704 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\69886-alle-hilfesuchenden-eroeffnung-themas-beachten.html [2012.08.01 15:12:23 | 000,302,592 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\x0g99d80.exe [2012.08.01 15:05:28 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\defogger_reenable [2012.08.01 15:04:14 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Desktop\Defogger.exe [2012.08.01 14:33:46 | 000,001,712 | ---- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\U\00000001.@ [2012.05.19 11:49:34 | 000,044,098 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\usrlgo.bmp [2012.02.25 11:25:12 | 000,345,345 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled5_MAS.bak [2012.02.14 21:48:58 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012.01.20 19:44:14 | 000,222,089 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled3_MAS.bak [2011.12.16 20:56:31 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2011.11.29 22:13:18 | 000,000,849 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\.recently-used.xbel [2011.10.20 13:24:23 | 000,067,320 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled1_MAS.bak [2011.08.08 17:33:00 | 000,003,163 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled10_MAS.bak [2011.08.08 17:28:22 | 000,155,546 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled4_MAS.bak [2011.08.08 17:18:34 | 000,367,598 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled2_MAS.bak [2011.03.20 11:17:59 | 000,823,296 | ---- | C] () -- C:\WINDOWS\j3dcore-d3d.dll [2011.03.20 11:17:59 | 000,163,840 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl.dll [2011.03.20 11:17:59 | 000,049,152 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-chk.dll [2011.03.20 11:17:59 | 000,040,960 | ---- | C] () -- C:\WINDOWS\j3dcore-ogl-cg.dll [2010.12.25 11:21:50 | 001,456,640 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\Falk Navi-Manager.msi [2010.12.25 11:21:27 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\$_hpcst$.hpc [2010.05.05 18:06:55 | 000,499,743 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Untitled0_MAS.bak [2009.11.20 09:28:25 | 000,005,943 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\mainhst.zgh [2009.01.03 12:32:49 | 000,003,827 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Maple9.5.ini [2008.09.10 17:02:04 | 000,008,810 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\gsview32.ini [2008.08.10 17:40:41 | 000,007,168 | ---- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.05.30 14:38:30 | 001,158,739 | ---- | C] () -- C:\Programme\BDANT.cab [2008.05.30 14:38:30 | 001,130,465 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x86.cab [2008.05.30 14:38:30 | 001,118,469 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x86.cab [2008.05.30 14:38:30 | 001,087,968 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x86.cab [2008.05.30 14:38:30 | 001,082,704 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x86.cab [2008.05.30 14:38:30 | 001,082,210 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x86.cab [2008.05.30 14:38:28 | 001,080,892 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x86.cab [2008.05.30 14:38:26 | 001,068,173 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x86.cab [2008.05.30 14:38:26 | 001,016,473 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x86.cab [2008.05.30 14:38:26 | 000,978,396 | ---- | C] () -- C:\Programme\BDAXP.cab [2008.05.30 14:38:26 | 000,919,678 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86.cab [2008.05.30 14:38:26 | 000,867,848 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x64.cab [2008.05.30 14:38:26 | 000,855,534 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x64.cab [2008.05.30 14:38:24 | 000,871,076 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x64.cab [2008.05.30 14:38:24 | 000,853,167 | ---- | C] () -- C:\Programme\Jun2008_d3dx10_38_x86.cab [2008.05.30 14:38:24 | 000,848,132 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x64.cab [2008.05.30 14:38:24 | 000,807,132 | ---- | C] () -- C:\Programme\Nov2007_d3dx10_36_x86.cab [2008.05.30 14:38:24 | 000,702,292 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x64.cab [2008.05.30 14:38:22 | 000,821,508 | ---- | C] () -- C:\Programme\Mar2008_d3dx10_37_x86.cab [2008.05.30 14:38:22 | 000,800,115 | ---- | C] () -- C:\Programme\AUG2007_d3dx10_35_x86.cab [2008.05.30 14:38:22 | 000,701,860 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x64.cab [2008.05.30 14:38:20 | 000,701,720 | ---- | C] () -- C:\Programme\JUN2007_d3dx10_34_x86.cab [2008.05.30 14:38:18 | 000,272,876 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x64.cab [2008.05.30 14:38:16 | 000,699,113 | ---- | C] () -- C:\Programme\APR2007_d3dx10_33_x86.cab [2008.05.30 14:38:16 | 000,254,442 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x64.cab [2008.05.30 14:38:14 | 000,272,272 | ---- | C] () -- C:\Programme\Jun2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,229,498 | ---- | C] () -- C:\Programme\Mar2008_XAudio_x86.cab [2008.05.30 14:38:14 | 000,216,055 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x64.cab [2008.05.30 14:38:12 | 000,201,344 | ---- | C] () -- C:\Programme\AUG2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,370 | ---- | C] () -- C:\Programme\JUN2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,200,010 | ---- | C] () -- C:\Programme\NOV2007_XACT_x64.cab [2008.05.30 14:38:12 | 000,197,923 | ---- | C] () -- C:\Programme\FEB2007_XACT_x64.cab [2008.05.30 14:38:10 | 000,186,151 | ---- | C] () -- C:\Programme\AUG2006_XACT_x64.cab [2008.05.30 14:38:10 | 000,185,609 | ---- | C] () -- C:\Programme\OCT2006_XACT_x64.cab [2008.05.30 14:38:08 | 000,199,014 | ---- | C] () -- C:\Programme\APR2007_XACT_x64.cab [2008.05.30 14:38:08 | 000,194,968 | ---- | C] () -- C:\Programme\DEC2006_d3dx10_00_x86.cab [2008.05.30 14:38:06 | 000,195,723 | ---- | C] () -- C:\Programme\DEC2006_XACT_x64.cab [2008.05.30 14:38:06 | 000,184,033 | ---- | C] () -- C:\Programme\JUN2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,182,381 | ---- | C] () -- C:\Programme\Apr2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,181,607 | ---- | C] () -- C:\Programme\Feb2006_XACT_x64.cab [2008.05.30 14:38:04 | 000,156,157 | ---- | C] () -- C:\Programme\JUN2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,512 | ---- | C] () -- C:\Programme\NOV2007_XACT_x86.cab [2008.05.30 14:38:04 | 000,151,231 | ---- | C] () -- C:\Programme\FEB2007_XACT_x86.cab [2008.05.30 14:38:02 | 000,156,260 | ---- | C] () -- C:\Programme\AUG2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,154,473 | ---- | C] () -- C:\Programme\APR2007_XACT_x86.cab [2008.05.30 14:38:00 | 000,136,351 | ---- | C] () -- C:\Programme\Apr2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,148,847 | ---- | C] () -- C:\Programme\DEC2006_XACT_x86.cab [2008.05.30 14:37:58 | 000,135,657 | ---- | C] () -- C:\Programme\Feb2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,141,265 | ---- | C] () -- C:\Programme\OCT2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,140,483 | ---- | C] () -- C:\Programme\AUG2006_XACT_x86.cab [2008.05.30 14:37:56 | 000,136,919 | ---- | C] () -- C:\Programme\JUN2006_XACT_x86.cab [2008.05.30 14:37:54 | 000,056,550 | ---- | C] () -- C:\Programme\APR2007_xinput_x86.cab [2008.05.30 14:37:52 | 000,125,584 | ---- | C] () -- C:\Programme\Mar2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,124,302 | ---- | C] () -- C:\Programme\Jun2008_XACT_x64.cab [2008.05.30 14:37:52 | 000,100,065 | ---- | C] () -- C:\Programme\APR2007_xinput_x64.cab [2008.05.30 14:37:52 | 000,058,402 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x64.cab [2008.05.30 14:37:52 | 000,049,306 | ---- | C] () -- C:\Programme\AUG2006_xinput_x86.cab [2008.05.30 14:37:50 | 000,058,306 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x64.cab [2008.05.30 14:37:50 | 000,025,153 | ---- | C] () -- C:\Programme\Jun2008_X3DAudio_x86.cab [2008.05.30 14:37:48 | 000,097,916 | ---- | C] () -- C:\Programme\dxupdate.cab [2008.05.30 14:37:48 | 000,049,258 | ---- | C] () -- C:\Programme\Apr2006_xinput_x86.cab [2008.05.30 14:37:48 | 000,048,607 | ---- | C] () -- C:\Programme\Oct2005_xinput_x86.cab [2008.05.30 14:37:46 | 000,090,390 | ---- | C] () -- C:\Programme\AUG2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,090,349 | ---- | C] () -- C:\Programme\Apr2006_xinput_x64.cab [2008.05.30 14:37:46 | 000,047,700 | ---- | C] () -- C:\Programme\dxdllreg_x86.cab [2008.05.30 14:37:44 | 000,049,392 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x64.cab [2008.05.30 14:37:42 | 000,096,982 | ---- | C] () -- C:\Programme\Mar2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,096,376 | ---- | C] () -- C:\Programme\Jun2008_XACT_x86.cab [2008.05.30 14:37:42 | 000,089,285 | ---- | C] () -- C:\Programme\Oct2005_xinput_x64.cab [2008.05.30 14:37:42 | 000,025,115 | ---- | C] () -- C:\Programme\Mar2008_X3DAudio_x86.cab [2008.05.30 14:37:42 | 000,021,744 | ---- | C] () -- C:\Programme\NOV2007_X3DAudio_x86.cab [2008.05.30 14:36:04 | 013,267,416 | ---- | C] () -- C:\Programme\dxnt.cab [2008.05.30 14:36:02 | 004,165,878 | ---- | C] () -- C:\Programme\Apr2006_MDX1_x86_Archive.cab [2008.05.30 14:36:02 | 001,805,306 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x64.cab [2008.05.30 14:36:00 | 001,803,408 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x64.cab [2008.05.30 14:35:56 | 001,795,856 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x64.cab [2008.05.30 14:35:56 | 001,773,110 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x64.cab [2008.05.30 14:35:56 | 001,712,608 | ---- | C] () -- C:\Programme\Nov2007_d3dx9_36_x86.cab [2008.05.30 14:35:56 | 001,711,400 | ---- | C] () -- C:\Programme\AUG2007_d3dx9_35_x86.cab [2008.05.30 14:35:56 | 001,611,022 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x64.cab [2008.05.30 14:35:56 | 001,610,606 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x64.cab [2008.05.30 14:35:56 | 001,610,534 | ---- | C] () -- C:\Programme\JUN2007_d3dx9_34_x86.cab [2008.05.30 14:35:56 | 001,609,287 | ---- | C] () -- C:\Programme\APR2007_d3dx9_33_x86.cab [2008.05.30 14:35:56 | 001,577,624 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x86.cab [2008.05.30 14:35:56 | 001,574,402 | ---- | C] () -- C:\Programme\DEC2006_d3dx9_32_x64.cab [2008.05.30 14:35:56 | 001,467,126 | ---- | C] () -- C:\Programme\Jun2008_d3dx9_38_x86.cab [2008.05.30 14:35:56 | 001,446,530 | ---- | C] () -- C:\Programme\Mar2008_d3dx9_37_x86.cab [2008.05.30 14:35:56 | 001,416,150 | ---- | C] () -- C:\Programme\OCT2006_d3dx9_31_x64.cab [2008.05.30 14:35:56 | 001,401,078 | ---- | C] () -- C:\Programme\Apr2006_d3dx9_30_x64.cab [2008.05.30 14:35:56 | 001,361,224 | ---- | C] () -- C:\Programme\Dec2005_d3dx9_28_x64.cab [2008.05.30 14:35:56 | 001,339,250 | ---- | C] () -- C:\Programme\Jun2005_d3dx9_26_x64.cab [2008.05.30 14:35:54 | 001,366,044 | ---- | C] () -- C:\Programme\Feb2006_d3dx9_29_x64.cab [2008.05.30 14:35:54 | 001,353,790 | ---- | C] () -- C:\Programme\Aug2005_d3dx9_27_x64.cab [2008.05.30 14:35:54 | 001,350,602 | ---- | C] () -- C:\Programme\Apr2005_d3dx9_25_x64.cab [2008.05.30 14:35:54 | 001,250,747 | ---- | C] () -- C:\Programme\Feb2005_d3dx9_24_x64.cab [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{170ff124-1ba0-a426-70fe-860c313d0703}\@ [2004.08.04 14:00:00 | 000,002,048 | -HS- | C] () -- C:\Dokumente und Einstellungen\Hp\Lokale Einstellungen\Anwendungsdaten\{170ff124-1ba0-a426-70fe-860c313d0703}\@ ========== LOP Check ========== [2012.08.01 14:19:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\6F63A56600001AB8000019DD7B07D287 [2012.07.16 14:01:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Buhl Data Service GmbH [2011.11.12 09:11:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CheckPoint [2011.12.10 15:38:17 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files [2008.12.06 20:31:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\eXPert PDF 4 [2008.08.09 10:37:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MailFrontier [2011.08.29 18:37:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Power Soft [2011.10.14 17:43:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2010.10.29 15:20:21 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2011.10.14 17:41:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2010.04.30 08:27:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009.01.30 14:54:34 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{55A29068-F2CE-456C-9148-C869879E2357} [2009.10.31 14:57:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009.10.30 19:26:51 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} [2010.08.03 18:25:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\CheckPoint [2010.11.19 12:56:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\Thunderbird [2011.11.09 12:23:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast1\Anwendungsdaten\TuneUp Software [2011.10.22 09:24:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\TuneUp Software [2010.10.29 16:00:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\TuneUp Software ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2008.09.02 10:31:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\ABBYY [2010.12.01 20:46:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Adobe [2011.07.18 12:28:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Apple Computer [2012.03.24 18:19:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Avira [2008.12.13 21:05:26 | 000,000,000 | R--D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Brother [2010.06.03 10:28:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Buhl Data Service [2011.03.03 17:37:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\CheckPoint [2010.12.02 21:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2008.08.11 16:26:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Design Science [2012.06.03 13:44:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox [2011.09.12 16:40:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\DVDVideoSoftIEHelpers [2009.03.27 16:32:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\eXPert PDF Editor [2008.11.30 14:31:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Google [2011.11.29 22:13:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\gtk-2.0 [2008.09.10 17:05:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Help [2008.08.09 09:44:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Identities [2008.09.04 09:47:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\InterVideo [2008.09.06 09:16:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\IrfanView [2010.12.01 20:54:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\JacquieLawsonAdventCalendar [2011.11.12 22:23:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\JLAdventCalendarLondon2011 [2011.05.07 10:34:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Klett [2009.04.14 10:25:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\KnotPlot [2010.05.02 11:10:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Macromedia [2012.08.05 19:00:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Malwarebytes [2010.12.30 13:25:52 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Microsoft [2008.08.09 12:18:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Microsoft Web Folders [2010.10.21 17:28:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla [2009.09.14 18:20:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\OpenOffice.org [2008.08.09 13:11:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Sun [2008.08.09 11:01:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Talkback [2011.01.03 14:34:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Thunderbird [2011.10.14 17:43:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\TuneUp Software [2010.03.28 19:47:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Youtube Downloader HD [2012.05.19 12:07:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\ZipGenius < %APPDATA%\*.exe /s > [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\Dropbox.exe [2012.05.24 20:39:24 | 000,872,144 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\DropboxUpdateHelper.exe [2012.05.24 20:39:30 | 000,177,280 | ---- | M] (Dropbox, Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Dropbox\bin\Uninstall.exe [2011.11.12 22:21:02 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2011.05.19 09:02:53 | 000,188,152 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\FlashGot.exe [2010.03.29 08:53:22 | 000,029,984 | ---- | M] (NOS Microsystems Ltd.) -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\32rujttl.profil2\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe [2008.05.29 17:35:44 | 000,167,336 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\Mozilla\Firefox\Profiles\pc8e0u8i.default\FlashGot.exe [2011.06.11 17:00:48 | 000,617,472 | ---- | M] () -- C:\Dokumente und Einstellungen\Hp\Anwendungsdaten\OpenOffice.org\3\user\uno_packages\cache\uno_packages\11.tmp_\oracle-pdfimport.oxt\xpdfimport.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys [2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2004.08.04 01:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys [2008.10.15 22:18:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll < MD5 for: IASTOR.SYS > [2004.09.26 15:24:54 | 000,477,952 | ---- | M] (Intel Corporation) MD5=DD19FDD8BB262F64A11C50CC23FC6F70 -- C:\WINDOWS\OEM\iaStor\iaStor.sys < MD5 for: NETLOGON.DLL > [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: NVATABUS.SYS > [2004.09.02 09:24:38 | 000,082,816 | ---- | M] (NVIDIA Corporation) MD5=EEABD98AA887DD923546F20D400B2907 -- C:\WINDOWS\OEM\nvatabus\nvatabus.sys < MD5 for: SCECLI.DLL > [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll < MD5 for: USER32.DLL > [2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll [2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe < MD5 for: VIAMRAID.SYS > [2004.05.18 15:55:26 | 000,074,112 | ---- | M] (VIA Technologies inc,.ltd) MD5=F199939205DCCC7836AE5AB8B5DD5E83 -- C:\WINDOWS\OEM\viapdsk\viamraid.sys [2004.05.18 15:55:26 | 000,074,112 | ---- | M] (VIA Technologies inc,.ltd) MD5=F199939205DCCC7836AE5AB8B5DD5E83 -- C:\WINDOWS\system32\drivers\viamraid.sys < MD5 for: WINLOGON.EXE > [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2008.08.09 11:19:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2008.08.09 11:19:29 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2008.08.09 11:19:29 | 000,442,368 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < > < End of report > [/code] Vielen Dank. Herzliche Grüße HanspeterE |
Themen zu Probleme mit TR/ATRAPS.GEN |
78.42.43.62, acedrv05.sys, adobe, adobe flash player, antivir, askbar, avg, avg secure search, avg security toolbar, avira, babylon toolbar, babylontoolbar, bho, bonjour, converter, dealply, einstellungen, error, expert pdf, explorer, firefox, flash player, format, google earth, logfile, mozilla, mp3, object, opera, pdfforge toolbar, plug-in, problem, realtek, registry, scan, secure search, software, vtoolbarupdater, winload toolbar, wiso |