Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 14.08.2012, 06:28   #1
Ingmar
 
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt



Hallo,

ich bin kein Computer-Profie und hoffe, daß ich hier alles richtig mache.

ich habe folgendes Problem:

Plötzlich war mein Bildschirm wie eingefrohren. Es war der bekannte "BKA Hinweis" mit den dementsprechenden Zahlungsaufforderungen.
Habe dann den Rechner mit Strg und Entf und dann mit dem Taskmanager runtergefahren
.
Ich habe dann den Rechner neu gestartet und diesen mit Kaspersky-RescueDisc 2010 gescannt (vorher neuestes Kaspersky Update geladen).

Es wurde eine Bedrohung angezeigt und diese dann wie von Kaspersky empfohlen in die Quarantäne geschoben.
Danach habe ich den Rechner nochmal scannen lassen und Kaspersky hat dann nichts mehr gefunden.

Super dachte ich, Kaspersky Disk raus und den Rechner neu gestartet...
Windows startet kurz, ca 1 Sekunde und dann bekomm ich einen weissen Bildschirm. Sieht so aus wie eine leehre Firefoxseite.
Und nichts geht mehr, genau wie diese "BKA Seite". Kann den Rechner dann nur mit STRg und Entf über den Taskmanager ausmachen.

Nun habe ich mir über Euch die OTLPE geladen und auf eine DVD gebrannt. Programm lässt sich auch starten.

Nachdem ich den Button OTLPE gedrückt habe, habe ich meinen Windowsordner gesucht und angeklickt
"Windows 7 Ultimate (f" dann den Ordner "Windows" dann startet OTLPE auch.

Wenn ich direkt auf "Windows 7 Ultimate (f" gehe erscheint: "Target is not windows 2000 or later".

Der erste Text: "Do you wish to load the remote registry" erscheint nicht
Der Zweit und Dritte aber und habe beim dritten Text den Haken rausgenommen.

OTL startet und ich habe bei "Benutzerdefinierte Scans/Fixes" Euren Text rein kopiert von einem User mit dem gleichen Problem.

siehe:

http://www.trojaner-board.de/121242-...entfernen.html

Ich hoffe ich war jetzt nicht zu voreilig. Packe jetzt den OTL Text und versuche den Euch zu mailen.

Bedanke mich jetzt schon einmal für Eure Hilfe. OTL.tex folgt weiter unten.

Gruß Ingmar

OTL Text:OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 8/13/2012 9:23:58 PM - Run 
OTLPE by OldTimer - Version 3.1.48.0     Folder = X:\Programs\OTLPE
Windows 7 Ultimate  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = F: | %SystemRoot% = F:\Windows | %ProgramFiles% = F:\Program Files
Drive C: | 100.00 Mb Total Space | 65.65 Mb Free Space | 65.65% Space Free | Partition Type: NTFS
Drive D: | 7.46 Gb Total Space | 7.46 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive F: | 465.66 Gb Total Space | 170.49 Gb Free Space | 36.61% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011/09/05 10:06:01 | 000,040,960 | ---- | M] () [Auto] -- F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2011/08/11 19:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- F:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2010/11/19 11:51:48 | 001,483,072 | ---- | M] (TuneUp Software) [Auto] -- F:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/11/19 11:49:04 | 000,029,504 | ---- | M] (TuneUp Software) [Auto] -- F:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/09/07 12:01:10 | 000,079,872 | ---- | M] () [Auto] -- F:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010/07/20 13:15:34 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- F:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/07/20 13:15:17 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- F:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/03/19 11:13:40 | 000,145,680 | R--- | M] (4G Systems GmbH & Co. KG) [Auto] -- F:\Windows\service4g.exe -- (XS Stick Service)
SRV - [2010/03/18 05:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto] -- F:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/12/15 13:52:17 | 002,480,048 | ---- | M] (Acronis) [Auto] -- F:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009/12/10 06:25:00 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand] -- F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/11/12 00:42:50 | 000,661,072 | ---- | M] (Acronis) [Auto] -- F:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009/11/04 11:45:02 | 000,172,032 | ---- | M] (AMD) [Auto] -- F:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009/07/14 16:53:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) [Auto] -- F:\Program Files\RALINK\Common\RaRegistry.exe -- (RalinkRegistryWriter)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/06/22 09:21:58 | 000,304,592 | ---- | M] () [Auto] -- F:\Program Files\XSManager\WTGService.exe -- (WTGService)
SRV - [2009/05/14 11:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto] -- F:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2009/02/26 08:46:40 | 000,147,456 | ---- | M] () [Auto] -- F:\Windows\System32\ANIWConnService.exe -- (ANIWConnService)
SRV - [2008/09/08 02:59:00 | 000,575,488 | ---- | M] (Nokia.) [On_Demand] -- F:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/08/29 10:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto] -- F:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2007/06/05 08:20:32 | 000,177,704 | ---- | M] () [Auto] -- F:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/01/19 06:49:26 | 000,049,152 | ---- | M] (Wireless Service) [Auto] -- F:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService)
SRV - [2007/01/10 23:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- F:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
SRV - [2006/10/31 17:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) [Auto] -- F:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (VcommMgr)
DRV - File not found [Kernel | On_Demand] --  -- (VComm)
DRV - File not found [Kernel | On_Demand] --  -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand] --  -- (BT)
DRV - [2012/03/26 19:42:10 | 000,121,080 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/09/15 10:08:08 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] -- F:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/07/22 12:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- F:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 17:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/05/06 15:47:46 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- F:\Windows\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/10/07 07:34:32 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand] -- F:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/07/20 13:15:17 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- F:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/07/08 09:17:56 | 000,603,240 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand] -- F:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2010/06/23 05:24:56 | 000,023,040 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- F:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010/01/26 22:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto] -- F:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/12/15 13:52:18 | 000,160,288 | ---- | M] (Acronis) [File_System | On_Demand] -- F:\Windows\System32\drivers\afcdp.sys -- (afcdp)
DRV - [2009/12/15 13:52:16 | 000,911,680 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258)
DRV - [2009/12/15 13:52:12 | 000,581,984 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV - [2009/12/15 13:51:58 | 000,158,272 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV - [2009/12/11 19:53:04 | 000,271,360 | ---- | M] () [Kernel | Auto] -- F:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/12/11 19:53:00 | 000,018,048 | ---- | M] () [Kernel | Auto] -- F:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009/11/04 12:16:46 | 005,079,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/10/26 03:54:24 | 000,025,088 | ---- | M] (HTC, Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009/09/30 10:33:56 | 000,104,976 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009/09/25 05:13:12 | 000,159,232 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2009/08/17 14:17:44 | 001,077,760 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/07/29 12:18:20 | 000,553,472 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- F:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/04/15 09:32:36 | 000,715,520 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\rt2870.sys -- (rt2870)
DRV - [2009/02/13 07:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand] -- F:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2009/01/07 18:39:36 | 000,020,744 | ---- | M] (IVT Corporation.) [Kernel | Boot] -- F:\Windows\System32\drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008/12/07 07:44:54 | 000,030,088 | ---- | M] () [Kernel | On_Demand] -- F:\Windows\System32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008/10/31 10:19:38 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand] -- F:\Windows\System32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2008/09/04 00:28:22 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008/09/04 00:27:54 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008/09/04 00:27:28 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008/08/26 05:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- F:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/07/02 09:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2007/07/03 10:58:20 | 000,106,792 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2007/07/03 10:57:24 | 000,011,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2007/07/03 10:54:24 | 000,080,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2006/11/30 14:55:00 | 000,113,792 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2006/11/20 12:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2006/11/10 09:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2006/11/02 12:41:00 | 000,053,504 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2006/10/27 19:29:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006/10/10 14:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2006/10/05 11:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2005/08/01 11:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System] -- F:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/11 13:58:00 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2005/05/17 08:48:21 | 000,050,176 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/05/16 09:23:38 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005/05/16 09:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005/01/06 08:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2004/08/13 03:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand] -- F:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 3E DB 04 73 79 CA 01  [binary data]
IE - HKU\Ingmar_ON_F\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
IE - HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
 
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic Deutsch Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}:5.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: F:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/19 00:30:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/12 10:40:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\firejump@firejump.net [2011/11/24 06:17:31 | 000,000,000 | ---D | M]
 
[2009/12/10 04:48:47 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Extensions
[2012/07/16 04:05:42 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions
[2012/05/18 14:04:31 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/07/16 04:05:42 | 000,000,000 | ---D | M] (ST Deutsch Community Toolbar) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}
[2011/12/30 07:52:36 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/12/15 08:40:47 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011/06/05 05:00:30 | 000,000,000 | ---D | M] (Conduit Engine) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com
[2011/11/24 06:17:31 | 000,000,000 | ---D | M] (FireJump) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\firejump@firejump.net
[2011/09/05 10:06:08 | 000,002,559 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\askcom.xml
[2011/09/05 10:06:08 | 000,001,110 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\conduit.xml
[2011/12/15 07:19:47 | 000,003,915 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\sweetim.xml
[2011/09/05 10:06:08 | 000,001,872 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{44A48CB3-B684-4A71-A2E8-4D0767F54B17}.xml
[2011/09/05 10:06:08 | 000,002,190 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{47620369-28C0-4261-9EF5-2369DBC3C023}.xml
[2011/09/05 10:06:08 | 000,002,079 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{4985DE69-F338-4A7D-83E2-D06AE13DA867}.xml
[2011/11/25 04:12:38 | 000,000,000 | ---D | M] (No name found) -- F:\Program Files\Mozilla Firefox\extensions
[2011/03/11 17:56:52 | 000,000,000 | ---D | M] (Skype extension) -- F:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
File not found (No name found) -- 
[2012/07/19 00:30:12 | 000,136,672 | ---- | M] (Mozilla Foundation) -- F:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 15:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- F:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/09 12:15:13 | 000,001,392 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/02/16 19:31:59 | 000,002,352 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/04/09 12:15:13 | 000,002,252 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/09 12:15:13 | 000,001,153 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/04/09 12:15:13 | 000,006,805 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/04/09 12:15:13 | 000,001,178 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/04/09 12:15:13 | 000,001,105 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010/12/02 15:20:34 | 000,000,898 | ---- | M]) - F:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1                activate.adobe.com
O1 - Hosts: 127.0.0.1       applian.securesites.com
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - F:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (Softonic Deutsch Toolbar) - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] F:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] F:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ANIWZCS2Service] F:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [Ask and Record FLV Service] F:\Program Files\Replay Media Catcher\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] F:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [D-Link D-Link Wireless N DWA-140] F:\Program Files\D-Link\DWA-140 revB\AirNCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [EEventManager] F:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] F:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [HTC Sync Loader] F:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [NBKeyScan] F:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [Ocs_SM] F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKLM..\Run: [OpwareSE4] F:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Smart File Advisor] F:\Program Files\Smart File Advisor\sfa.exe (Filefacts.net)
O4 - HKLM..\Run: [StartCCC] F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [starter4g] F:\Windows\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [TrueImageMonitor.exe] F:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [TweakUI 1.33 deutsch] F:\Windows\System32\TWEAKUI.CPL (Brummelchen@gmx.at)
O4 - HKLM..\Run: [WrtMon.exe] F:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKU\Ingmar_ON_F..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] F:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKU\Ingmar_ON_F..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\Ingmar_ON_F..\Run: [wnzhztlwwvwoahc] F:\ProgramData\wnzhztlw.exe ()
O4 - HKU\LocalService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\Ingmar_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: Free YouTube Download - F:\Users\Ingmar\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - F:\Users\Ingmar\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000048 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000050 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000051 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000052 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000053 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000054 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000055 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000056 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000057 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000058 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000059 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000060 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000061 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000062 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000063 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000064 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000065 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000066 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000067 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000068 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000069 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000070 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000071 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000072 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000073 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000074 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000075 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000076 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000077 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000078 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000079 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000080 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000081 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000082 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000083 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000084 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000085 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000086 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000087 -  File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab (Java Plug-in 1.5.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - F:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - F:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - F:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell - "" = AutoRun
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell\AutoRun\command - "" = H:\USBAutoRun.exe
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AUTORUN.exe
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell - "" = AutoRun
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AUTORUN.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: Sharedaccess -  File not found
NetSvcs: SRService -  File not found
NetSvcs: UxTuneUp - F:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp -  File not found
NetSvcs: wuauserv -  File not found
NetSvcs: BITS -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
MsConfig - State: "bootini" - 0
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/08/10 16:02:12 | 000,000,000 | ---D | C] -- F:\ProgramData\jqfnlczewmpbtxp
[2012/07/28 06:51:48 | 000,000,000 | ---D | C] -- F:\Users\Ingmar\AppData\Roaming\Malwarebytes
[2012/07/28 06:51:45 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/28 06:51:44 | 000,000,000 | ---D | C] -- F:\Program Files\Malwarebytes' Anti-Malware
[2012/07/28 06:51:44 | 000,000,000 | ---D | C] -- F:\ProgramData\Malwarebytes
[2010/11/07 17:53:42 | 002,131,336 | ---- | C] (Ask.com                                                      ) -- F:\Program Files\Common Files\AskToolbarInstaller.exe
[2010/03/11 07:55:02 | 000,047,360 | ---- | C] (VSO Software) -- F:\Users\Ingmar\AppData\Roaming\pcouffin.sys
[1 F:\Windows\System32\*.tmp files -> F:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/08/11 11:13:09 | 000,067,584 | --S- | M] () -- F:\Windows\bootstat.dat
[2012/08/11 11:12:05 | 000,000,007 | ---- | M] () -- F:\Windows\System32\ANIWZCSUSERNAME
[2012/08/11 11:11:46 | 000,001,094 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/11 11:11:29 | 2616,594,432 | -HS- | M] () -- F:\hiberfil.sys
[2012/08/11 10:34:19 | 000,016,944 | -H-- | M] () -- F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/11 10:34:19 | 000,016,944 | -H-- | M] () -- F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/10 16:02:12 | 000,000,051 | ---- | M] () -- F:\ProgramData\mijgefhjgbuamsf
[2012/08/10 16:02:06 | 000,057,344 | ---- | M] () -- F:\ProgramData\wnzhztlw.exe
[2012/08/10 15:35:00 | 000,001,098 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/10 11:22:13 | 000,657,438 | ---- | M] () -- F:\Windows\System32\perfh007.dat
[2012/08/10 11:22:13 | 000,618,714 | ---- | M] () -- F:\Windows\System32\perfh009.dat
[2012/08/10 11:22:13 | 000,130,810 | ---- | M] () -- F:\Windows\System32\perfc007.dat
[2012/08/10 11:22:13 | 000,107,034 | ---- | M] () -- F:\Windows\System32\perfc009.dat
[2012/08/10 11:00:29 | 103,525,852 | ---- | M] () -- F:\Windows\System32\drivers\Avg\incavi.avm
[2012/08/09 02:17:11 | 000,000,040 | -HS- | M] () -- F:\ProgramData\.zreglib
[2012/08/09 02:14:36 | 000,000,000 | R--D | M] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/07 04:13:03 | 000,000,102 | ---- | M] () -- F:\Users\Ingmar\AppData\default.pls
[2012/07/28 11:47:15 | 000,000,000 | ---D | M] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/28 10:48:14 | 267,563,210 | ---- | M] () -- F:\Windows\MEMORY.DMP
[2012/07/19 00:30:16 | 000,002,047 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[1 F:\Windows\System32\*.tmp files -> F:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/08/10 16:02:12 | 000,057,344 | ---- | C] () -- F:\ProgramData\wnzhztlw.exe
[2012/08/10 16:02:07 | 000,000,051 | ---- | C] () -- F:\ProgramData\mijgefhjgbuamsf
[2012/08/09 02:17:11 | 000,000,040 | -HS- | C] () -- F:\ProgramData\.zreglib
[2012/08/09 02:14:36 | 000,002,122 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HD Writer.lnk
[2012/08/09 02:14:36 | 000,001,379 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
[2012/08/09 02:14:36 | 000,000,914 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
[2012/06/20 10:58:21 | 004,503,728 | ---- | C] () -- F:\ProgramData\0tbpw.pad
[2012/05/11 10:18:27 | 000,065,793 | ---- | C] () -- F:\Windows\System32\esfwad.bin
[2012/01/22 07:02:43 | 000,085,504 | ---- | C] () -- F:\Windows\System32\ff_vfw.dll
[2011/11/25 16:55:36 | 000,000,029 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\default.rss
[2011/11/25 16:55:35 | 000,000,000 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\downloads.m3u
[2011/04/29 05:49:52 | 000,045,115 | ---- | C] () -- F:\Windows\System32\ANICtl.dll
[2011/02/12 09:51:37 | 000,000,000 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\chrtmp
[2010/12/23 15:25:31 | 000,000,056 | -H-- | C] () -- F:\Windows\System32\ezsidmv.dat
[2010/12/02 15:21:12 | 000,237,568 | ---- | C] () -- F:\Windows\System32\rmc_rtspdl.dll
[2010/11/12 11:52:21 | 000,000,060 | ---- | C] () -- F:\Windows\dcmvwr.INI
[2010/11/10 13:56:16 | 000,000,000 | ---- | C] () -- F:\Windows\iPlayer.INI
[2010/11/04 09:47:40 | 000,003,284 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\ANIWZCS{B44F8B5D-A5B3-441F-9F39-49F0C4B7E99B}
[2010/11/04 09:46:47 | 000,147,456 | ---- | C] () -- F:\Windows\System32\ANIWConnService.exe
[2010/11/04 09:46:42 | 000,315,392 | ---- | C] () -- F:\Windows\System32\ANIOApi.dll
[2010/11/04 09:46:32 | 000,258,048 | ---- | C] () -- F:\Windows\System32\wlanapp.dll
[2010/11/04 09:46:32 | 000,204,800 | ---- | C] () -- F:\Windows\System32\aIPH.dll
[2010/11/04 09:46:32 | 000,049,152 | ---- | C] () -- F:\Windows\System32\JJAKEn.dll
[2010/11/04 09:46:32 | 000,049,152 | ---- | C] () -- F:\Windows\System32\AQCKGen.dll
[2010/11/04 09:46:18 | 000,724,992 | ---- | C] () -- F:\Windows\System32\ANIOWPS.dll
[2010/11/04 09:46:18 | 000,237,568 | ---- | C] () -- F:\Windows\System32\ANIWPS.exe
[2010/11/04 09:45:06 | 000,013,931 | ---- | C] () -- F:\Windows\System32\RaCoInst.dat
[2010/07/15 02:39:00 | 000,000,173 | ---- | C] () -- F:\Windows\SOFTPEG.INI
[2010/06/02 13:36:25 | 000,000,848 | -HS- | C] () -- F:\Windows\System32\KGyGaAvL.sys
[2010/03/17 08:18:02 | 000,000,071 | ---- | C] () -- F:\Windows\EPSONCD.INI
[2010/03/15 06:07:16 | 000,040,960 | ---- | C] () -- F:\Windows\System32\IPPCPUID.DLL
[2010/03/15 06:06:21 | 000,011,776 | ---- | C] () -- F:\Windows\System32\pmsbfn32.dll
[2010/03/15 06:04:09 | 000,000,416 | ---- | C] () -- F:\Windows\MAXLINK.INI
[2010/03/15 05:53:17 | 000,000,029 | ---- | C] () -- F:\Windows\DEBUGSM.INI
[2010/03/15 05:37:40 | 000,094,486 | ---- | C] () -- F:\Windows\System32\EPPICPrinterDB.dat
[2010/03/15 05:37:40 | 000,001,146 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_DU.dat
[2010/03/15 05:37:40 | 000,001,136 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_ES.dat
[2010/03/15 05:37:40 | 000,001,120 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_IT.dat
[2010/03/15 05:37:40 | 000,001,107 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_GE.dat
[2010/03/15 05:37:40 | 000,001,104 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_EN.dat
[2010/03/15 05:37:40 | 000,000,099 | ---- | C] () -- F:\Windows\System32\PICSDK.ini
[2010/03/15 05:37:39 | 000,026,154 | ---- | C] () -- F:\Windows\System32\EPPICPattern1.dat
[2010/03/15 05:37:39 | 000,024,903 | ---- | C] () -- F:\Windows\System32\EPPICPattern3.dat
[2010/03/15 05:37:39 | 000,021,390 | ---- | C] () -- F:\Windows\System32\EPPICPattern5.dat
[2010/03/15 05:37:39 | 000,020,148 | ---- | C] () -- F:\Windows\System32\EPPICPattern2.dat
[2010/03/15 05:37:39 | 000,011,811 | ---- | C] () -- F:\Windows\System32\EPPICPattern4.dat
[2010/03/15 05:37:39 | 000,004,943 | ---- | C] () -- F:\Windows\System32\EPPICPattern6.dat
[2010/03/15 05:37:39 | 000,001,139 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_PT.dat
[2010/03/15 05:37:39 | 000,001,139 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_BP.dat
[2010/03/15 05:37:39 | 000,001,129 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_FR.dat
[2010/03/15 05:37:39 | 000,001,129 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_CF.dat
[2010/03/15 05:25:39 | 000,000,025 | ---- | C] () -- F:\Windows\CDER220.ini
[2010/03/13 11:08:24 | 000,000,485 | ---- | C] () -- F:\Windows\DVDFabGold.INI
[2010/03/11 07:55:56 | 000,001,189 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\vso_ts_preview.xml
[2010/03/11 07:55:02 | 000,087,608 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\inst.exe
[2010/03/11 07:55:02 | 000,007,887 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\pcouffin.cat
[2010/03/11 07:55:02 | 000,001,144 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\pcouffin.inf
[2010/02/19 18:02:21 | 000,046,592 | ---- | C] () -- F:\Users\Ingmar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/04 16:24:53 | 000,303,104 | ---- | C] () -- F:\Windows\System32\CmiInstallResAll.dll
[2010/02/02 03:23:49 | 000,000,096 | ---- | C] () -- F:\Windows\WirelessFTP.INI
[2010/01/31 16:36:49 | 000,004,940 | ---- | C] () -- F:\ProgramData\mtbjfghn.xbe
[2010/01/31 03:15:24 | 000,000,000 | ---- | C] () -- F:\Windows\tosOBEX.INI
[2010/01/26 22:09:02 | 000,053,299 | ---- | C] () -- F:\Windows\System32\pthreadVC.dll
[2010/01/15 07:21:40 | 000,094,208 | ---- | C] () -- F:\Windows\VMix.dll
[2010/01/15 07:21:40 | 000,000,294 | ---- | C] () -- F:\Windows\cmudax3.ini
[2009/12/11 19:53:04 | 000,271,360 | ---- | C] () -- F:\Windows\System32\drivers\atksgt.sys
[2009/12/11 19:53:00 | 000,018,048 | ---- | C] () -- F:\Windows\System32\drivers\lirsgt.sys
[2009/12/11 08:50:37 | 000,000,102 | ---- | C] () -- F:\Users\Ingmar\AppData\default.pls
[2009/12/11 08:50:31 | 000,000,069 | ---- | C] () -- F:\Windows\NeroDigital.ini
[2009/12/10 16:53:09 | 000,007,618 | ---- | C] () -- F:\Users\Ingmar\AppData\Local\Resmon.ResmonCfg
[2009/12/10 08:07:24 | 000,000,000 | ---- | C] () -- F:\Windows\ativpsrm.bin
[2009/12/10 06:55:31 | 000,004,757 | ---- | C] () -- F:\Windows\Irremote.ini
[2009/12/10 04:48:42 | 000,000,000 | ---- | C] () -- F:\Windows\nsreg.dat
[2009/12/10 04:28:57 | 000,000,020 | ---- | C] () -- F:\Windows\RaUI.INI
[2009/12/10 04:28:04 | 000,315,392 | ---- | C] () -- F:\Windows\System32\AegisI5.exe
[2009/12/10 04:28:04 | 000,303,234 | ---- | C] () -- F:\Windows\System32\Install7x.dll
[2009/12/10 04:28:04 | 000,002,048 | ---- | C] () -- F:\Windows\System32\drivers\rt73.bin
[2009/12/03 03:27:28 | 000,080,416 | ---- | C] () -- F:\Windows\System32\RtNicProp32.dll
[2009/09/01 16:55:54 | 000,195,855 | ---- | C] () -- F:\Windows\System32\atiicdxx.dat
[2009/07/14 04:47:43 | 000,657,438 | ---- | C] () -- F:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- F:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,130,810 | ---- | C] () -- F:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- F:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- F:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 002,442,112 | ---- | C] () -- F:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,618,714 | ---- | C] () -- F:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- F:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,107,034 | ---- | C] () -- F:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- F:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- F:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- F:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- F:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- F:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- F:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- F:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- F:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- F:\Windows\System32\mlang.dat
[2009/02/18 13:55:20 | 000,294,912 | ---- | C] () -- F:\Windows\System32\ATIODE.exe
[2009/02/03 16:52:02 | 000,045,056 | ---- | C] () -- F:\Windows\System32\ATIODCLI.exe
[2008/12/07 07:44:54 | 000,030,088 | ---- | C] () -- F:\Windows\System32\drivers\btnetBus.sys
[2007/06/05 08:20:32 | 000,177,704 | ---- | C] () -- F:\Windows\System32\PSIService.exe
[2007/04/27 04:43:58 | 000,120,200 | ---- | C] () -- F:\Windows\System32\DLLDEV32i.dll
[2006/12/05 08:05:06 | 000,114,688 | ---- | C] () -- F:\Windows\System32\TosBtAcc.dll
[2005/07/22 16:30:20 | 000,065,536 | ---- | C] () -- F:\Windows\System32\TosCommAPI.dll
[2005/02/25 01:15:00 | 000,159,744 | ---- | C] () -- F:\Windows\System32\EPSPTDV.DLL
[2004/08/13 03:56:20 | 000,005,810 | ---- | C] () -- F:\Windows\System32\drivers\ASACPI.sys
[2000/07/22 11:49:46 | 000,431,104 | ---- | C] () -- F:\Windows\System32\VFCodec.dll
 
========== LOP Check ==========
 
[2009/12/15 13:54:31 | 000,000,000 | ---D | M] -- F:\ProgramData\Acronis
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Application Data
[2012/07/28 11:47:04 | 000,000,000 | ---D | M] -- F:\ProgramData\avg9
[2009/12/10 05:45:57 | 000,000,000 | ---D | M] -- F:\ProgramData\Azureus
[2012/02/16 19:31:55 | 000,000,000 | ---D | M] -- F:\ProgramData\Babylon
[2011/03/15 04:59:11 | 000,000,000 | -H-D | M] -- F:\ProgramData\Common Files
[2012/01/22 06:39:37 | 000,000,000 | ---D | M] -- F:\ProgramData\Cypheros
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Documents
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Dokumente
[2012/05/11 12:34:46 | 000,000,000 | ---D | M] -- F:\ProgramData\EPSON
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Favorites
[2010/02/02 02:44:33 | 000,000,000 | ---D | M] -- F:\ProgramData\Installations
[2012/08/10 19:11:37 | 000,000,000 | ---D | M] -- F:\ProgramData\jqfnlczewmpbtxp
[2011/06/24 09:29:59 | 000,000,000 | ---D | M] -- F:\ProgramData\MAGIX
[2012/06/20 11:40:52 | 000,000,000 | ---D | M] -- F:\ProgramData\MFAData
[2012/03/11 17:13:15 | 000,000,000 | ---D | M] -- F:\ProgramData\Panasonic
[2010/07/21 06:19:52 | 000,000,000 | ---D | M] -- F:\ProgramData\PC Suite
[2009/12/10 09:20:27 | 000,000,000 | ---D | M] -- F:\ProgramData\Ralink
[2009/12/10 09:19:51 | 000,000,000 | ---D | M] -- F:\ProgramData\Ralink Driver
[2010/03/15 06:03:58 | 000,000,000 | ---D | M] -- F:\ProgramData\ScanSoft
[2012/04/18 17:00:28 | 000,000,000 | ---D | M] -- F:\ProgramData\SlySoft
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Start Menu
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Startmenü
[2012/06/20 11:35:12 | 000,000,000 | ---D | M] -- F:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Templates
[2011/02/17 15:42:24 | 000,000,000 | ---D | M] -- F:\ProgramData\TuneUp Software
[2010/03/15 08:38:13 | 000,000,000 | ---D | M] -- F:\ProgramData\UDL
[2009/12/10 05:30:26 | 000,000,000 | ---D | M] -- F:\ProgramData\Ulead Systems
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Vorlagen
[2011/02/17 15:40:39 | 000,000,000 | -HSD | M] -- F:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/01/30 16:50:26 | 000,000,000 | ---D | M] -- F:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/03 01:49:23 | 000,032,640 | ---- | M] () -- F:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2010/01/15 07:23:20 | 000,000,000 | -H-D | M] -- F:\$AVG
[2010/09/08 11:24:02 | 000,000,000 | -HSD | M] -- F:\$Recycle.Bin
[2012/07/11 22:35:02 | 000,000,000 | -HSD | M] -- F:\Config.Msi
[2010/12/24 08:59:59 | 000,000,000 | ---D | M] -- F:\Die Ultimative Chart - Show - Die Beliebtesten Weihnachts Hits Aller Zeiten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\Documents and Settings
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\Dokumente und Einstellungen
[2011/02/12 08:54:26 | 000,000,000 | ---D | M] -- F:\DVDFabPlatinum_Temp
[2010/02/19 17:01:09 | 000,000,000 | ---D | M] -- F:\Games
[2012/07/28 13:03:14 | 000,000,000 | ---D | M] -- F:\Kaspersky Rescue Disk 10.0
[2009/12/10 05:20:50 | 000,000,000 | RH-D | M] -- F:\MSOCache
[2011/09/18 13:51:15 | 000,000,000 | ---D | M] -- F:\Musik Michi
[2009/07/13 22:37:05 | 000,000,000 | ---D | M] -- F:\PerfLogs
[2012/07/28 11:47:03 | 000,000,000 | R--D | M] -- F:\Program Files
[2012/08/10 16:02:12 | 000,000,000 | -H-D | M] -- F:\ProgramData
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\Programme
[2009/12/09 07:21:49 | 000,000,000 | -HSD | M] -- F:\Recovery
[2012/06/22 14:24:29 | 000,000,000 | -HSD | M] -- F:\RECYCLER
[2012/08/07 09:14:38 | 000,000,000 | ---D | M] -- F:\Ripp
[2012/07/15 17:39:39 | 000,000,000 | ---D | M] -- F:\Serien noch sehen
[2012/02/02 15:06:00 | 000,000,000 | ---D | M] -- F:\Sicherungen von FP 1TB - noch kopieren auf andere FP
[2010/10/30 13:18:42 | 000,000,000 | ---D | M] -- F:\Sounds
[2012/08/08 12:29:30 | 000,000,000 | -HSD | M] -- F:\System Volume Information
[2009/12/10 08:28:09 | 000,000,000 | ---D | M] -- F:\totalcmd
[2012/06/24 04:48:24 | 000,000,000 | ---D | M] -- F:\TV Aufnahmen Receiver
[2009/12/09 07:21:55 | 000,000,000 | R--D | M] -- F:\Users
[2012/08/09 02:13:14 | 000,000,000 | ---D | M] -- F:\Windows
 
< %PROGRAMFILES%\*.exe >
 
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- F:\Windows\System32\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- F:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2010/12/14 15:35:28 | 000,036,352 | ---- | M] (Panasonic Corporation) MD5=79FF6641458DDBDDB69A6261D46E7E71 -- F:\Program Files\Panasonic\HD Writer AE 3.0\Core\EventLog\EventLog.dll
[2010/12/14 15:35:28 | 000,036,352 | ---- | M] (Panasonic Corporation) MD5=79FF6641458DDBDDB69A6261D46E7E71 -- F:\Program Files\Panasonic\HD Writer AE 3.0\Core\Spec\AVCHD\BDCore\EventLog.dll
 
< MD5 for: EXPLORER.EXE  >
[2009/07/13 21:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- F:\Windows\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
 
< MD5 for: IASTORV.SYS  >
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\System32\drivers\iaStorV.sys
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- F:\Windows\System32\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- F:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\System32\drivers\nvstor.sys
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- F:\Windows\System32\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- F:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009/07/13 21:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- F:\Windows\System32\user32.dll
[2009/07/13 21:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- F:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- F:\Windows\System32\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- F:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009/10/28 02:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- F:\Windows\System32\winlogon.exe
[2009/10/28 02:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- F:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- F:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 21:15:21 | 000,828,928 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- F:\Windows\system32\fontext.dll
[2010/07/27 10:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- F:\Windows\system32\shell32.dll
[1 F:\Windows\system32\*.tmp files -> F:\Windows\system32\*.tmp -> ]
 
Invalid Environment Variable: %USERPROFILE%\*.*
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
 
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
 
< End of report >
         
--- --- ---

 

Themen zu BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt
avg, bho, bildschirm, bonjour, conduit, converter, device driver, download, explorer, format, langs, launch, logfile, mp3, musik, neu, nvidia, object, plug-in, problem, programm, realtek, registry, rundll, softonic, softonic deutsch toolbar, software, stick, sweetim, taskmanager, trojaner, vdeck.exe, winlogon.exe, yahoo




Ähnliche Themen: BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


  1. Windows 7, Firefox-Browser: Spyware/Trojaner/Hijacker können trotz Anti-Malware und Adwcleaner nicht entfernt werden
    Plagegeister aller Art und deren Bekämpfung - 27.02.2014 (13)
  2. versteckter Trojaner trotz Kaspersky?
    Plagegeister aller Art und deren Bekämpfung - 08.02.2014 (10)
  3. do-search kann nicht entfernt werden trotz Malware Bites und Avira, Programm nicht mehr sichtbar - do-search trotzdem noch da
    Log-Analyse und Auswertung - 08.12.2013 (21)
  4. Rechner wird unendlich langsam, Kaspersky meldet Trojaner, Fierfox Startseite lässt nich nicht mehr ändern.
    Plagegeister aller Art und deren Bekämpfung - 23.10.2013 (15)
  5. Trojaner trotz Windows neuinstallation NICHT vom PC entfernt
    Plagegeister aller Art und deren Bekämpfung - 14.08.2013 (2)
  6. GVU Trojaner mit Kaspersky Rescue Disk 10 evtl nicht richtig entfernt?
    Plagegeister aller Art und deren Bekämpfung - 24.11.2012 (12)
  7. BKA Trojaner der Version 1.13 kann mit der Kaspersky-Rescue-Disc nicht entfernt werden
    Log-Analyse und Auswertung - 13.10.2012 (6)
  8. GVU Trojaner 2.07 trotz Kaspersky Rescue Disc etc. nach Internetverbindung wieder aktiv.
    Plagegeister aller Art und deren Bekämpfung - 10.10.2012 (14)
  9. BKA Trojaner trotz Kaspersky Rescue, sowie Windows-Startprobleme
    Log-Analyse und Auswertung - 14.09.2012 (13)
  10. GVU Trojaner (sperrt Computer) und ist trotz Kaspersky Rescue noch aktiv
    Log-Analyse und Auswertung - 14.08.2012 (9)
  11. GVU-Trojaner lässt sich trotz Kaspersky-RescueDisc 2010 und WindowsUnlocker nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 08.08.2012 (12)
  12. BKA-Trojaner... Kaspersky Rescuedisc scannt nicht, wie weiter mit OTL?
    Plagegeister aller Art und deren Bekämpfung - 05.04.2012 (1)
  13. GEMA Trojaner entfernt, Verknüpfungen leider auch...
    Plagegeister aller Art und deren Bekämpfung - 03.01.2012 (10)
  14. bka virus: kaspersky rescue-cd wird nicht gebootet und OTLPENet.exe kann nicht gedownloaded werden
    Plagegeister aller Art und deren Bekämpfung - 14.06.2011 (30)
  15. Facebook-Virus trotz Scan nicht entfernt
    Diskussionsforum - 12.01.2011 (1)
  16. Antivirus 2010 entfernt (?), Antivir und andere Programme laufen nicht
    Log-Analyse und Auswertung - 03.02.2010 (18)
  17. Trojaner-Befall trotz Kaspersky.
    Mülltonne - 08.10.2008 (0)

Zum Thema BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Hallo, ich bin kein Computer-Profie und hoffe, daß ich hier alles richtig mache. ich habe folgendes Problem: Plötzlich war mein Bildschirm wie eingefrohren. Es war der bekannte "BKA Hinweis" mit - BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt...
Archiv
Du betrachtest: BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.