| win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast! Hallo Zusammen,
ich bin neu hier, also erstmal einen Gruß in die Runde.
Und schon muss ich Euch mit einem Problem belästigen. Bin nicht der Held in diesen Dingen, also entschuldigt meine "blöden" Fragen.
Versuche mich jetzt mal verständlich auszudrücken.
Also avast "schreit" mich heute mit drei Meldungen an.
Win32:Sirefef-AO[Rtk] in C:Windows/Installer/.../800000cb.@
Win64:Sirefef-A.[Trj] in C:Windows/Installer/.../80000000.@
Win32:Maleware.gen in C:Windows/Installer/.../00000001.@
hab versucht diese in den Container zu verschieben, was nicht viel brachte. Daher habe ich gegooglet und bei Euch im Forum gelesen. Nur habe ich mich ehrlich gesagt nicht getraut allein Hand anzulegen.
Deshalb habe ich versucht Euren Hinweisen nachzugehen und hab Logfiles erstellt.
Hoffe das es so richtig war. Ansonsten bitte nicht schlagen, sondern bescheid sagen. Danke schön .
Wenn ich das richtig verstanden habe wollt Ihr den OTL.txt im Thread haben.
Und die anderen als Anhang.
Würde mich sehr über Hilfe freuen.
Danke schön
Gruß
Lio Zitat:
OTL logfile created on: 07.08.2012 20:25:25 - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\melfluga\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 56,52% Memory free
6,70 Gb Paging File | 5,47 Gb Available in Paging File | 81,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 153,63 Gb Total Space | 83,70 Gb Free Space | 54,48% Space Free | Partition Type: NTFS
Drive D: | 303,34 Gb Total Space | 284,54 Gb Free Space | 93,80% Space Free | Partition Type: NTFS
Computer Name: MELFLUGA-PC | User Name: melfluga | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - [2012.08.07 20:24:49 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\melfluga\Downloads\OTL.exe
PRC - [2012.07.03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.06.27 13:01:14 | 000,096,768 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2011.08.01 10:28:16 | 000,124,480 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.5\ICQ.exe
PRC - [2010.12.14 16:49:23 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
PRC - [2010.09.21 14:03:14 | 001,710,464 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2010.09.21 14:03:14 | 000,193,408 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009.01.09 19:46:32 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2009.01.09 19:45:26 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2008.06.02 09:47:34 | 000,277,616 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Zlh.exe
PRC - [2008.05.30 18:12:24 | 001,502,208 | ---- | M] (Koninklijke Philips Electronics N.V.) -- C:\Programme\Philips\SA19xx\Philips Device Manager\bin\DeviceManager.exe
PRC - [2008.05.28 16:06:02 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.05.28 13:40:28 | 000,020,480 | ---- | M] ( ) -- C:\Programme\Google\Google EULA\GoogleEULALauncher.exe
PRC - [2008.05.13 10:49:00 | 000,203,896 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Njeeves.exe
PRC - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
PRC - [2008.04.24 12:04:34 | 000,429,176 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Zanda.exe
PRC - [2008.02.26 03:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Programme\Picasa2\PicasaMediaDetector.exe
PRC - [2008.02.07 11:07:04 | 000,121,912 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\nvoy.exe
PRC - [2007.12.06 16:15:44 | 000,609,384 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\Shared\Tagger\tagsrv.exe
PRC - [2007.11.27 16:38:04 | 000,695,136 | ---- | M] (National Instruments, Inc.) -- C:\Windows\System32\lkcitdl.exe
PRC - [2007.11.27 14:57:52 | 000,213,552 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2007.11.27 14:57:20 | 000,050,736 | ---- | M] (National Instruments Corporation) -- C:\Windows\System32\lktsrv.exe
PRC - [2007.11.27 14:56:48 | 000,040,488 | ---- | M] (National Instruments Corporation) -- C:\Windows\System32\lkads.exe
PRC - [2007.11.21 09:59:54 | 000,150,584 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\elogsvc.exe
PRC - [2007.10.28 16:38:32 | 000,221,184 | ---- | M] (Aladdin Knowledge Systems, Ltd.) -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\PKIMonitor.exe
PRC - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2007.09.18 11:41:18 | 000,154,680 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\nvcsched.exe
PRC - [2007.08.03 14:59:24 | 000,012,696 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\MAX\nimxs.exe
PRC - [2007.07.19 17:38:16 | 000,048,704 | ---- | M] (National Instruments Corp.) -- C:\Windows\System32\nisvcloc.exe ========== Modules (No Company Name) ==========
MOD - [2012.06.14 16:59:15 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_5e32eb55\system.drawing.dll
MOD - [2012.06.14 16:59:10 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_af72375d\system.windows.forms.dll
MOD - [2012.06.14 16:58:53 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2012.01.14 12:12:00 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_94ee0c3a\mscorlib.dll
MOD - [2012.01.14 12:11:47 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_89d7c255\system.dll
MOD - [2012.01.14 12:11:32 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012.01.14 12:11:31 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008.10.04 13:39:19 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2008.07.29 13:55:14 | 000,969,728 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2007.03.29 15:11:10 | 000,217,088 | ---- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtXml4.dll
MOD - [2007.03.27 20:06:46 | 000,131,072 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\plugins\imageformats\qjpeg1.dll
MOD - [2007.03.27 20:04:00 | 005,529,600 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtGui4.dll
MOD - [2007.03.27 20:04:00 | 001,466,368 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtCore4.dll ========== Win32 Services (SafeList) ==========
SRV - [2012.07.14 02:13:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.27 13:01:14 | 000,096,768 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010.09.23 00:21:24 | 001,493,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2010.09.22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 14:03:14 | 001,710,464 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2008.05.13 10:49:00 | 000,203,896 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Programme\Norman\Npm\Bin\Njeeves.exe -- (Norman NJeeves)
SRV - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2008.04.24 12:04:34 | 000,429,176 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\Zanda.exe -- (Norman ZANDA)
SRV - [2008.02.07 11:07:04 | 000,121,912 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\nvoy.exe -- (NVOY)
SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.12.06 16:15:44 | 000,609,384 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService)
SRV - [2007.11.27 16:38:04 | 000,695,136 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- C:\Windows\System32\lkcitdl.exe -- (LkCitadelServer)
SRV - [2007.11.27 14:57:52 | 000,213,552 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2007.11.27 14:57:20 | 000,050,736 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Windows\System32\lktsrv.exe -- (lkTimeSync)
SRV - [2007.11.27 14:56:48 | 000,040,488 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Windows\System32\lkads.exe -- (lkClassAds)
SRV - [2007.11.21 09:59:54 | 000,150,584 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\elogsvc.exe -- (eLoggerSvc6)
SRV - [2007.10.31 09:20:36 | 001,007,616 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Programme\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager)
SRV - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2007.09.18 11:41:18 | 000,154,680 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Programme\Norman\Npm\Bin\nvcsched.exe -- (NVCScheduler)
SRV - [2007.08.03 14:59:24 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\MAX\nimxs.exe -- (mxssvr)
SRV - [2007.07.19 17:38:16 | 000,048,704 | ---- | M] (National Instruments Corp.) [Auto | Running] -- C:\Windows\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2007.05.09 16:34:34 | 000,098,304 | ---- | M] (OPC Foundation) [On_Demand | Stopped] -- C:\Windows\System32\Opcenum.exe -- (OpcEnum)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\4F76.tmp -- (MEMSWEEP2)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012.07.03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.07.03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.07.03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.07.03 18:21:53 | 000,057,656 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012.07.03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.07.03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009.06.18 12:55:41 | 000,018,816 | ---- | M] (Sophos Plc) [Kernel | System | Running] -- C:\Windows\System32\SAVRKBootTasks.sys -- (SAVRKBootTasks)
DRV - [2008.05.27 13:55:54 | 000,173,576 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s)
DRV - [2008.05.02 13:59:40 | 000,122,368 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008.04.03 14:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2008.03.19 19:30:00 | 007,438,432 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007.10.26 14:27:00 | 000,306,300 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2007.10.23 11:00:00 | 000,004,096 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2007.09.11 16:43:16 | 000,048,296 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\aksifdh.sys -- (AKSIFDH)
DRV - [2007.09.11 16:43:16 | 000,034,472 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aksup.sys -- (AKSUP)
DRV - [2007.09.11 16:43:16 | 000,012,456 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\eTSCFLT.sys -- (eTSCFLT)
DRV - [2007.07.19 12:56:44 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NiViPxiKl.sys -- (NiViPxiK)
DRV - [2007.07.19 12:56:44 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NiViPciKl.sys -- (NiViPciK)
DRV - [2007.07.19 12:48:36 | 000,011,384 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NiViFWKl.sys -- (NiViFWK)
DRV - [2007.07.18 22:12:02 | 000,011,896 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nipalusbedl.sys -- (nipalusbedl)
DRV - [2007.07.18 22:11:38 | 000,580,184 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nipalk.sys -- (NIPALK)
DRV - [2007.07.18 22:11:02 | 000,011,904 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nipalfwedl.sys -- (nipalfwedl)
DRV - [2007.07.12 19:18:14 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nidimkl.sys -- (nidimk)
DRV - [2007.07.12 18:31:08 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\niorbkl.sys -- (niorbk)
DRV - [2007.07.10 21:08:14 | 000,015,448 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nipbcfk.sys -- (nipbcfk)
DRV - [2007.01.31 13:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2007.01.18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/br/ie9_startpage
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81fae9c9-cfbd-4cb3-8322-412e72f55f65} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{09038620-190C-402B-A92F-18864E6AB22F}: "URL" = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{40064957-18EB-412d-9146-3F57E8D92EEC}: "URL" = hxxp://go.gmx.net/br/ie9_search_pic/?su={searchTerms}
IE - HKCU\..\SearchScopes\{5A817CF6-92D5-4DE5-AC38-82DF8A73EF28}: "URL" = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC
IE - HKCU\..\SearchScopes\{6A3BAADF-623E-4EBF-AFED-45178AA1808B}: "URL" = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
IE - HKCU\..\SearchScopes\{6B1D1FB7-7233-4F7C-802C-21A1DDB12754}: "URL" = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{8D27B32E-89EE-460e-82D2-5FC354078EAD}: "URL" = hxxp://go.gmx.net/br/ie9_search_produkte/?su={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQFPC8pHI&i=26
IE - HKCU\..\SearchScopes\{DCE59F23-A446-45a5-9459-E68FDC0DE38D}: "URL" = hxxp://go.gmx.net/br/ie9_search_maps/?su={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ==========
FF - prefs.js..CT3228856.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "FreemakeVideoConverterTB Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT3228856&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3228856&SearchSource=2&q="
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\melfluga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.07.28 19:12:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.08.05 17:40:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.07 19:25:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2010.08.06 16:25:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Extensions
[2012.08.07 14:34:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions
[2011.05.14 11:50:17 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.07.06 11:59:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.08.07 14:34:07 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\ffxtlbr@incredibar.com
[2012.08.07 19:23:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions
[2010.09.22 12:26:30 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.05.19 16:05:05 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.07.25 16:33:54 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.07.28 19:12:06 | 000,000,000 | ---D | M] (FreemakeVideoConverterTB) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{81fae9c9-cfbd-4cb3-8322-412e72f55f65}
[2012.08.07 14:34:06 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\ffxtlbr@incredibar.com
[2011.05.29 20:04:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\nostmp
[2012.08.07 19:26:22 | 000,000,853 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\11-suche.xml
[2012.08.07 15:11:47 | 000,000,941 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\conduit.xml
[2012.08.07 19:26:23 | 000,002,209 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\englische-ergebnisse.xml
[2012.08.07 19:26:22 | 000,010,506 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\gmx-suche.xml
[2012.08.03 13:43:38 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-1.xml
[2011.08.27 14:49:23 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-10.xml
[2011.10.03 16:22:22 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-11.xml
[2011.11.27 16:02:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-12.xml
[2011.12.06 14:27:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-13.xml
[2012.01.08 15:16:47 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-14.xml
[2012.01.15 20:15:03 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-15.xml
[2012.07.29 12:19:26 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-16.xml
[2010.10.25 13:18:17 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-2.xml
[2010.10.30 16:59:02 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-3.xml
[2010.12.26 15:53:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-4.xml
[2010.12.29 21:21:33 | 000,000,656 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-5.xml
[2011.05.10 12:57:30 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-6.xml
[2011.05.29 20:04:49 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-7.xml
[2011.07.06 11:59:25 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-8.xml
[2011.08.21 11:30:33 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-9.xml
[2012.07.24 14:48:30 | 000,000,168 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.gif
[2012.07.24 14:48:30 | 000,000,618 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.src
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.xml
[2012.08.07 19:26:22 | 000,002,368 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\lastminute.xml
[2012.08.07 14:33:44 | 000,002,203 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\MyStart Search.xml
[2012.08.07 19:26:22 | 000,005,489 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\webde-suche.xml
[2012.08.07 19:25:45 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.08.05 17:40:44 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012.07.28 19:12:19 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
[2012.08.07 15:10:31 | 000,503,717 | ---- | M] () (No name found) -- C:\USERS\MELFLUGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I0Z660PH.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI
[2012.07.14 02:15:45 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.14 02:45:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ==========
CHR - homepage: hxxp://www.google.com
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: hxxp://www.google.com
CHR - Extension: No name found = C:\Users\melfluga\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: No name found = C:\Users\melfluga\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {81FAE9C9-CFBD-4CB3-8322-412E72F55F65} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [eTMonitor] C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\PKIMonitor.exe (Aladdin Knowledge Systems, Ltd.)
O4 - HKLM..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [Norman ZANDA] C:\Program Files\Norman\Npm\Bin\ZLH.EXE (Norman ASA)
O4 - HKLM..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PhilipsDM\SA1916] C:\Program Files\Philips\SA19XX\Philips Device Manager\Bin\LaunchDM.exe (Koninklijke Philips Electronics N.V.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [fsc-reg] C:\fsc-reg\fscreg.exe (Fujitsu Siemens)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [laxzyldodalp] C:\Users\melfluga\laxzyldodalp.exe File not found
O4 - HKCU..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - Startup: C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} hxxp://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9BFF10D2-C0C5-46F9-B7AE-A76B17ED3CE4}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper2_white.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper2_white.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ==========
[2012.08.07 19:25:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.08.07 19:25:46 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.08.07 19:23:45 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Talkback
[2012.08.07 19:22:41 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.08.07 19:06:40 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{C3FD24A1-70CA-43A4-B931-24BAA9D74587}
[2012.08.07 19:06:18 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{0219835C-8191-4F1C-B576-AC28498C549B}
[2012.08.07 18:54:19 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{D4D91617-CC77-48E7-BDE9-55BD21E2B671}
[2012.08.07 18:45:13 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{470EA7CE-CE90-40FA-9AC7-4381CE90692A}
[2012.08.07 18:38:57 | 000,018,816 | ---- | C] (Sophos Plc) -- C:\Windows\System32\SAVRKBootTasks.sys
[2012.08.07 17:38:09 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{A84E662F-0A30-4F2F-83DB-B8542B056F0C}
[2012.08.07 17:37:49 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{BA49D768-26AF-475A-B96A-B5E095820786}
[2012.08.07 15:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2012.08.07 15:22:54 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2012.08.07 14:35:37 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\vlc
[2012.08.07 14:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.08.07 14:35:01 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012.08.07 14:20:33 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Malwarebytes
[2012.08.07 14:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.08.07 14:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.08.07 14:20:20 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.08.07 14:20:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.08.07 13:54:07 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{CD215D49-3F62-4D9F-9627-FDF2E16EF6A9}
[2012.08.05 18:07:56 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2012.08.05 17:41:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.08.05 17:41:41 | 000,353,688 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.08.05 17:41:41 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.08.05 17:41:37 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012.08.05 17:41:36 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.08.05 17:41:34 | 000,721,000 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.08.05 17:41:32 | 000,057,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.08.05 17:40:34 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.08.05 17:40:33 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.08.05 17:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.08.05 17:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.08.03 19:22:48 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012.07.29 19:57:07 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791886270979735
[2012.07.29 19:49:54 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791881947009735
[2012.07.29 19:36:12 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791873723459735
[2012.07.28 23:11:43 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder
[2012.07.28 19:12:37 | 000,000,000 | ---D | C] -- C:\Users\melfluga\Documents\Freemake
[2012.07.28 19:12:20 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.07.28 19:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.07.28 19:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2012.07.28 19:12:06 | 000,000,000 | ---D | C] -- C:\Program Files\Freemake
[2012.07.28 19:11:51 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2012.07.28 19:11:47 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\Conduit
[2012.07.15 14:12:42 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{8EBB47B6-7D46-488A-85AF-D4CCC1B94684}
[2012.07.09 21:13:40 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{F8668D41-5714-42E7-B781-AE2B3760ABCC}
[2012.07.09 21:12:58 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{FCFC65F7-4953-4E8A-B0CD-3698DF1290D6}
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2012.08.07 20:20:57 | 000,000,000 | ---- | M] () -- C:\Users\melfluga\defogger_reenable
[2012.08.07 19:25:48 | 000,000,852 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.08.07 18:48:42 | 000,634,440 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.08.07 18:48:41 | 000,674,582 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.08.07 18:48:41 | 000,146,266 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.08.07 18:48:41 | 000,120,004 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.08.07 18:43:24 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 18:43:24 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 18:43:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.07 18:42:07 | 3488,866,304 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.07 14:35:27 | 000,000,865 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.08.07 14:34:07 | 000,000,454 | ---- | M] () -- C:\user.js
[2012.08.07 14:20:22 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.08.05 17:41:42 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.08.05 17:41:32 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.07.28 19:23:23 | 000,005,632 | ---- | M] () -- C:\Users\melfluga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.28 19:12:19 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012.07.28 19:12:09 | 000,000,009 | ---- | M] () -- C:\END
[2012.07.28 18:15:48 | 000,000,085 | -HS- | M] () -- C:\ProgramData\.zreglib
[2012.07.25 10:21:09 | 000,316,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ==========
[2012.08.07 20:20:57 | 000,000,000 | ---- | C] () -- C:\Users\melfluga\defogger_reenable
[2012.08.07 19:25:48 | 000,000,864 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.08.07 19:22:43 | 000,000,852 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.08.07 14:35:27 | 000,000,865 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.08.07 14:34:06 | 000,000,454 | ---- | C] () -- C:\user.js
[2012.08.07 14:20:22 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.08.05 17:41:42 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.07.28 19:12:19 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012.07.28 19:12:08 | 000,000,009 | ---- | C] () -- C:\END
[2012.06.24 13:26:33 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012.01.14 12:00:37 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{7cdd0fcc-31ef-f3c4-073f-a1dbf674cc1d}\@
[2012.01.14 12:00:37 | 000,002,048 | -HS- | C] () -- C:\Users\melfluga\AppData\Local\{7cdd0fcc-31ef-f3c4-073f-a1dbf674cc1d}\@
[2010.12.21 13:03:16 | 000,000,680 | ---- | C] () -- C:\Users\melfluga\AppData\Local\d3d9caps.dat
[2008.10.20 12:04:18 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008.10.04 13:39:27 | 000,000,096 | ---- | C] () -- C:\Users\melfluga\AppData\Local\fusioncache.dat
[2008.09.28 13:19:59 | 000,005,632 | ---- | C] () -- C:\Users\melfluga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== LOP Check ==========
[2012.02.27 15:50:17 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\1&1 Mail & Media GmbH
[2012.05.29 13:10:38 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\elsterformular
[2009.05.24 13:07:45 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\EPSON
[2010.12.31 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\FileZilla
[2012.08.07 18:45:26 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\ICQ
[2009.04.13 12:56:05 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\OpenOffice.org
[2008.10.04 13:35:43 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\T-Online
[2012.08.07 18:39:24 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ==========
< End of report >
| |