|
Plagegeister aller Art und deren Bekämpfung: Windows Firewall wird immer wieder unbemerkt deaktiviertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
29.11.2012, 23:03 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert Ich brauch den Quarantäneordner von Combofix. Bitte folgendes machen: 1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen! 2.) Ordner Quarantine in C:\Qoobox in eine Datei zippen 3.) die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! 4.) Wenns erfolgreich war Bescheid sagen 5.) Erst dann wieder den Virenscanner einschalten
__________________ Logfiles bitte immer in CODE-Tags posten |
29.11.2012, 23:18 | #17 |
| Windows Firewall wird immer wieder unbemerkt deaktiviert Bescheid
__________________geschafft hier mal ein |
30.11.2012, 09:45 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert Starte Windows neu, lösch die alte combofix.exe, lade CF neu runter und probier es bitte nochmal.
__________________
__________________ |
01.12.2012, 20:10 | #19 |
| Windows Firewall wird immer wieder unbemerkt deaktiviert So... diesmal war alles wie zuerst beschrieben und auch die Datei ist dort, wo sie hingehört. Ich musste auch neu starten, weil diese angekündigte Mail kam. Ein Problem ist auf jeden Fall nun weg: Die Onlineverbindung kam immer erst nach ca. 5 Min. nach hochfahren. Man konnte nur über Firefox ins Netz aber erst mit der Verbindung Programme öffnen. Dies scheint nun weg zu sein. [code] Combofix Logfile: Code:
ATTFilter ComboFix 12-12-01.01 - Denise 01.12.2012 18:01:12.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2037.1017 [GMT 1:00] ausgeführt von:: c:\users\Denise\Downloads\ComboFix.exe AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Internet Security 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Vorheriger Suchlauf ------- . c:\windows\pkunzip.pif c:\windows\pkzip.pif c:\windows\security\Database\tmp.edb c:\windows\system32\drivers\~GLH0014.TMP c:\windows\system32\URTTemp c:\windows\system32\URTTemp\regtlib.exe D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2012-11-01 bis 2012-12-01 )))))))))))))))))))))))))))))) . . 2012-12-01 17:17 . 2012-12-01 17:17 -------- d-----w- c:\users\Denise\AppData\Local\temp 2012-12-01 17:17 . 2012-12-01 17:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-01 17:17 . 2012-12-01 17:17 -------- d-----w- c:\users\Celine\AppData\Local\temp 2012-11-30 06:30 . 2012-11-19 00:04 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{12E6DA62-EA91-4D23-AF10-C4AEFF9C9949}\mpengine.dll 2012-11-28 14:54 . 2012-11-28 14:54 -------- d-----w- c:\programdata\Canneverbe Limited 2012-11-28 14:54 . 2012-11-28 14:54 -------- d-----w- c:\users\Denise\AppData\Roaming\Canneverbe Limited 2012-11-28 14:54 . 2012-11-28 14:54 -------- d-----w- c:\program files\CDBurnerXP 2012-11-28 14:54 . 2012-11-28 14:54 -------- d-----w- c:\users\Denise\AppData\Roaming\OpenCandy 2012-11-27 13:56 . 2012-11-27 13:56 -------- d-----w- c:\users\Denise\AppData\Roaming\Malwarebytes 2012-11-27 13:55 . 2012-11-27 13:55 -------- d-----w- c:\programdata\Malwarebytes 2012-11-27 13:55 . 2012-11-27 13:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-11-27 13:55 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-11-24 09:56 . 2012-10-08 07:48 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-11-24 09:56 . 2012-10-08 07:50 678912 ----a-w- c:\program files\Internet Explorer\iedvtool.dll 2012-11-23 16:49 . 2012-11-23 16:49 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-11-20 16:52 . 2010-05-10 11:03 21320 ----a-w- c:\windows\system32\authuitu.dll 2012-11-20 16:52 . 2010-05-10 11:03 30024 ----a-w- c:\windows\system32\uxtuneup.dll 2012-11-20 16:49 . 2010-05-10 11:09 30536 ----a-w- c:\windows\system32\TURegOpt.exe 2012-11-20 16:46 . 2012-11-20 16:52 -------- d-----w- c:\program files\TuneUp Utilities 2010 2012-11-19 17:40 . 2012-11-19 17:41 -------- d-----w- c:\programdata\Fugazo 2012-11-19 17:32 . 2012-11-19 17:32 -------- d-----w- c:\program files\astragon 2012-11-16 13:35 . 2012-10-12 14:29 2047488 ----a-w- c:\windows\system32\win32k.sys 2012-11-16 13:26 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll 2012-11-12 17:23 . 2012-11-12 17:23 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2012-11-12 17:23 . 2012-11-12 17:23 -------- d-----w- c:\program files\Symantec 2012-11-12 17:23 . 2012-11-12 17:23 -------- d-----w- c:\program files\Common Files\Symantec Shared 2012-11-12 17:23 . 2012-11-25 23:38 -------- d-----w- c:\windows\system32\drivers\NSM 2012-11-12 17:23 . 2012-11-12 17:23 -------- d-----w- c:\program files\Norton Family 2012-11-12 17:23 . 2012-11-12 17:23 -------- d-----w- c:\program files\NortonInstaller 2012-11-12 16:53 . 2012-11-12 17:23 -------- d-----w- c:\programdata\Norton 2012-11-07 14:41 . 2012-11-07 19:45 -------- d-----w- c:\users\Denise\Filme . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-11-23 16:49 . 2011-06-20 14:14 746984 ----a-w- c:\windows\system32\deployJava1.dll 2012-11-08 13:02 . 2012-09-07 20:58 26984 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2012-11-07 05:51 . 2012-04-22 18:16 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-11-07 05:51 . 2011-06-15 14:12 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-25 02:12 . 2012-10-25 02:12 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx 2012-10-25 02:12 . 2012-10-25 02:12 69632 ----a-w- c:\windows\system32\QuickTime.qts 2012-09-24 22:16 . 2012-09-17 19:17 821736 ----a-w- c:\windows\system32\npdeployJava1.dll 2012-09-13 13:28 . 2012-10-10 06:29 2048 ----a-w- c:\windows\system32\tzres.dll 2012-11-20 21:55 . 2012-04-30 13:19 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-11-08 13:02 1796552 ----a-w- c:\program files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll" [2012-11-08 1796552] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-11-08 15:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-11-08 15:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-11-08 15:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-11-08 15:58 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-10-25 02:12 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-07-03 07:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI] 2006-11-02 12:35 176128 ----a-w- c:\windows\System32\wpcumi.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Inhalt des "geplante Tasks" Ordners . 2012-11-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 05:51] . 2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-05 18:50] . 2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-05 18:50] . . ------- Zusätzlicher Suchlauf ------- . uSearch Page = uStart Page = hxxp://www.msn.de/ IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 LSP: c:\windows\system32\wpclsp.dll TCP: DhcpNameServer = 192.168.2.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Denise\AppData\Roaming\Mozilla\Firefox\Profiles\xmour6lv.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - ExtSQL: 2012-11-17 12:05; {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}; c:\programdata\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.43\coFFFw FF - ExtSQL: 2012-11-22 23:14; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . . ------- Dateityp-Verknüpfung ------- . .scr=DWGTrueViewScriptFile . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2012-12-01 18:17 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NSM] "ImagePath"="\"c:\program files\Norton Family\Engine\2.6.0.52\ccSvcHst.exe\" /s \"NSM\" /m \"c:\program files\Norton Family\Engine\2.6.0.52\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Data] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking 4.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for Oracle] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for SqlServer] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NETFramework] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ACEDRV07] "ImagePath"="\??\c:\windows\system32\drivers\ACEDRV07.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ACPI] "ImagePath"="system32\drivers\acpi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeARMservice] "ImagePath"="\"c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeFlashPlayerUpdateSvc] "ImagePath"="c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adp94xx] "ImagePath"="\SystemRoot\system32\drivers\adp94xx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpahci] "ImagePath"="\SystemRoot\system32\drivers\adpahci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu160m] "ImagePath"="\SystemRoot\system32\drivers\adpu160m.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu320] "ImagePath"="\SystemRoot\system32\drivers\adpu320.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adsi] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvc] "ServiceDll"="%SystemRoot%\System32\aelupsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AFD] "ImagePath"="\SystemRoot\system32\drivers\afd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aic78xx] "ImagePath"="\SystemRoot\system32\drivers\djsvs.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ALG] "ImagePath"="%SystemRoot%\System32\alg.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aliide] "ImagePath"="\SystemRoot\system32\drivers\aliide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdagp] "ImagePath"="\SystemRoot\system32\drivers\amdagp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdide] "ImagePath"="\SystemRoot\system32\drivers\amdide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AmdK7] "ImagePath"="\SystemRoot\system32\drivers\amdk7.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AmdK8] "ImagePath"="\SystemRoot\system32\drivers\amdk8.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Appinfo] "ServiceDll"="%SystemRoot%\System32\appinfo.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt] "ServiceDll"="%SystemRoot%\System32\appmgmts.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arc] "ImagePath"="\SystemRoot\system32\drivers\arc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arcsas] "ImagePath"="\SystemRoot\system32\drivers\arcsas.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASP.NET_1.1.4322] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AsyncMac] "ImagePath"="system32\DRIVERS\asyncmac.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi] "ImagePath"="system32\drivers\atapi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioEndpointBuilder] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Audiosrv] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avg] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgfwfd] "ImagePath"="system32\DRIVERS\avgfwd6x.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgfws] "ImagePath"="\"c:\program files\AVG\AVG2012\avgfws.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSAgent] "ImagePath"="\"c:\program files\AVG\AVG2012\AVGIDSAgent.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSDriver] "ImagePath"="system32\DRIVERS\avgidsdriverx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSFilter] "ImagePath"="system32\DRIVERS\avgidsfilterx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSHX] "ImagePath"="system32\DRIVERS\avgidshx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSShim] "ImagePath"="system32\DRIVERS\avgidsshimx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgldx86] "ImagePath"="system32\DRIVERS\avgldx86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgmfx86] "ImagePath"="system32\DRIVERS\avgmfx86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgrkx86] "ImagePath"="system32\DRIVERS\avgrkx86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgtdix] "ImagePath"="system32\DRIVERS\avgtdix.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgtp] "ImagePath"="\??\c:\windows\system32\drivers\avgtpx86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgwd] "ImagePath"="\"c:\program files\AVG\AVG2012\avgwdsvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BattC] "MofImagePath"="system32\drivers\battc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Beep] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BFE] "ServiceDll"="%SystemRoot%\System32\bfe.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS] "ServiceDll"="%systemroot%\system32\qmgr.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blbdrive] "ImagePath"="\SystemRoot\system32\drivers\blbdrive.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bowser] "ImagePath"="system32\DRIVERS\bowser.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltLo] "ImagePath"="\SystemRoot\system32\drivers\brfiltlo.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltUp] "ImagePath"="\SystemRoot\system32\drivers\brfiltup.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Browser] "ServiceDll"="%SystemRoot%\System32\browser.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Brserid] "ImagePath"="\SystemRoot\system32\drivers\brserid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrSerWdm] "ImagePath"="\SystemRoot\system32\drivers\brserwdm.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbMdm] "ImagePath"="\SystemRoot\system32\drivers\brusbmdm.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbSer] "ImagePath"="\SystemRoot\system32\drivers\brusbser.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHMODEM] "ImagePath"="\SystemRoot\system32\drivers\bthmodem.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\catchme] "ImagePath"="\??\c:\users\Denise\AppData\Local\Temp\catchme.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ccSet_NSM] "ImagePath"="\SystemRoot\system32\drivers\NSM\0206000.034\ccSetx86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdfs] "ImagePath"="system32\DRIVERS\cdfs.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdrom] "ImagePath"="system32\DRIVERS\cdrom.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CertPropSvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\circlass] "ImagePath"="\SystemRoot\system32\drivers\circlass.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CLFS] "ImagePath"="System32\CLFS.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ClipInc001] "ImagePath"="c:\program files\Tobit ClipInc\Server\ClipInc-Server.exe 001" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32] "ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_32] "ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CmBatt] "ImagePath"="system32\DRIVERS\CmBatt.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdide] "ImagePath"="\SystemRoot\system32\drivers\cmdide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Compbatt] "ImagePath"="system32\DRIVERS\compbatt.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\COMSysApp] "ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crcdisk] "ImagePath"="system32\drivers\crcdisk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Crusoe] "ImagePath"="\SystemRoot\system32\drivers\crusoe.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CryptSvc] "ServiceDll"="%SystemRoot%\system32\cryptsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DCLocator] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DcomLaunch] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DfsC] "ImagePath"="System32\Drivers\dfsc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DFSR] "ImagePath"="%SystemRoot%\system32\DFSR.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dhcp] "ServiceDll"="%SystemRoot%\system32\dhcpcsvc.dll" -- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk] "ImagePath"="system32\drivers\disk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache] "ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dot3svc] "ServiceDll"="%SystemRoot%\System32\dot3svc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPS] "ServiceDll"="%SystemRoot%\system32\dps.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drmkaud] "ImagePath"="system32\drivers\drmkaud.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DXGKrnl] "ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\E1G60] "ImagePath"="system32\DRIVERS\E1G60I32.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EapHost] "ServiceDll"="%SystemRoot%\System32\eapsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ecache] "ImagePath"="System32\drivers\ecache.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehRecvr] "ImagePath"="%systemroot%\ehome\ehRecvr.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehSched] "ImagePath"="%systemroot%\ehome\ehsched.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehstart] "ServiceDll"="%SystemRoot%\ehome\ehstart.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\elxstor] "ImagePath"="\SystemRoot\system32\drivers\elxstor.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EmdCache] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EMDMgmt] "ServiceDll"="%systemroot%\system32\emdmgmt.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ESENT] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog] "ServiceDll"="%SystemRoot%\System32\wevtsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystem] "ServiceDll"="%systemroot%\system32\es.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\exfat] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fastfat] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdc] "ImagePath"="system32\DRIVERS\fdc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdPHost] "ServiceDll"="%SystemRoot%\system32\fdPHost.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FDResPub] "ServiceDll"="%SystemRoot%\system32\fdrespub.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FETNDIS] "ImagePath"="system32\DRIVERS\fetnd5.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FileInfo] "ImagePath"="system32\drivers\fileinfo.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Filetrace] "ImagePath"="system32\drivers\filetrace.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\flpydisk] "ImagePath"="system32\DRIVERS\flpydisk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FltMgr] "ImagePath"="system32\drivers\fltmgr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache] "ServiceDll"="%SystemRoot%\system32\FntCache.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache3.0.0.0] "ImagePath"="%systemroot%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fssfltr] "ImagePath"="system32\DRIVERS\fssfltr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fsssvc] "ImagePath"="\"c:\program files\Windows Live\Family Safety\fsssvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fs_Rec] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gagp30kx] "ImagePath"="\SystemRoot\system32\drivers\gagp30kx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GnabService] "ImagePath"="c:\program files\common files\gnab\service\servicecontroller.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gpsvc] "ServiceDll"="%SystemRoot%\System32\gpsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdate] "ImagePath"="\"c:\program files\Google\Update\GoogleUpdate.exe\" /svc" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdatem] "ImagePath"="\"c:\program files\Google\Update\GoogleUpdate.exe\" /medsvc" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HdAudAddService] "ImagePath"="system32\drivers\HdAudio.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HDAudBus] "ImagePath"="system32\DRIVERS\HDAudBus.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidBth] "ImagePath"="\SystemRoot\system32\drivers\hidbth.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidIr] "ImagePath"="\SystemRoot\system32\drivers\hidir.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hidserv] "ServiceDll"="%SystemRoot%\System32\hidserv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidUsb] "ImagePath"="system32\DRIVERS\hidusb.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hkmsvc] "ServiceDLL"="%SystemRoot%\system32\kmsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Hotkey] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HpCISSs] "ImagePath"="\SystemRoot\system32\drivers\hpcisss.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HTTP] "ImagePath"="system32\drivers\HTTP.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omp] "ImagePath"="\SystemRoot\system32\drivers\i2omp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i8042prt] "ImagePath"="system32\DRIVERS\i8042prt.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IAANTMON] "ImagePath"="c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ialm] "ImagePath"="system32\DRIVERS\igdkmd32.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iaStor] "ImagePath"="system32\DRIVERS\iaStor.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iaStorV] "ImagePath"="\SystemRoot\system32\drivers\iastorv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\idsvc] "ImagePath"="\"%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\igfx] "ImagePath"="system32\DRIVERS\igdkmd32.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iirsp] "ImagePath"="\SystemRoot\system32\drivers\iirsp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IKEEXT] "ServiceDll"="%SystemRoot%\System32\ikeext.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\inetaccs] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IntcAzAudAddService] "ImagePath"="system32\drivers\RTKVHDA.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelide] "ImagePath"="system32\drivers\intelide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelppm] "ImagePath"="system32\DRIVERS\intelppm.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPBusEnum] "ServiceDll"="%SystemRoot%\system32\ipbusenum.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpFilterDriver] "ImagePath"="system32\DRIVERS\ipfltdrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvc] "ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpInIp] "ImagePath"="system32\DRIVERS\ipinip.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPMIDRV] "ImagePath"="\SystemRoot\system32\drivers\ipmidrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPNAT] "ImagePath"="system32\DRIVERS\ipnat.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRENUM] "ImagePath"="system32\drivers\irenum.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\isapnp] "ImagePath"="\SystemRoot\system32\drivers\isapnp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iScsiPrt] "ImagePath"="system32\DRIVERS\msiscsi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteatapi] "ImagePath"="\SystemRoot\system32\drivers\iteatapi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteraid] "ImagePath"="\SystemRoot\system32\drivers\iteraid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Iviaspi] "ImagePath"="system32\drivers\iviaspi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IviRegMgr] "ImagePath"="c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdclass] "ImagePath"="system32\DRIVERS\kbdclass.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdhid] "ImagePath"="\SystemRoot\system32\drivers\kbdhid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KeyIso] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KSecDD] "ImagePath"="System32\Drivers\ksecdd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRm] "ServiceDll"="%systemroot%\system32\msdtckrm.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServer] "ServiceDll"="%SystemRoot%\System32\srvsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation] "ServiceDll"="%SystemRoot%\System32\wkssvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LightScribeService] "ImagePath"="\"c:\program files\Common Files\LightScribe\LSSrvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdio] "ImagePath"="system32\DRIVERS\lltdio.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvc] "ServiceDll"="%SystemRoot%\System32\lltdsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lmhosts] "ServiceDll"="%SystemRoot%\System32\lmhsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Lsa] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_FC] "ImagePath"="\SystemRoot\system32\drivers\lsi_fc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SAS] "ImagePath"="\SystemRoot\system32\drivers\lsi_sas.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SCSI] "ImagePath"="\SystemRoot\system32\drivers\lsi_scsi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\luafv] "ImagePath"="\SystemRoot\system32\drivers\luafv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mailKmd] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMProtector] "ImagePath"="\??\c:\windows\system32\drivers\mbam.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMScheduler] "ImagePath"="\"c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMService] "ImagePath"="\"c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mcx2Svc] "ServiceDll"="%SystemRoot%\system32\Mcx2Svc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\megasas] "ImagePath"="\SystemRoot\system32\drivers\megasas.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSS] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Modem] "ImagePath"="system32\drivers\modem.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\monitor] "ImagePath"="system32\DRIVERS\monitor.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouclass] "ImagePath"="system32\DRIVERS\mouclass.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouhid] "ImagePath"="system32\DRIVERS\mouhid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MountMgr] "ImagePath"="System32\drivers\mountmgr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpio] "ImagePath"="\SystemRoot\system32\drivers\mpio.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpsdrv] "ImagePath"="System32\drivers\mpsdrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvc] "ServiceDll"="%SystemRoot%\system32\mpssvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mraid35x] "ImagePath"="\SystemRoot\system32\drivers\mraid35x.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxDAV] "ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb] "ImagePath"="system32\DRIVERS\mrxsmb.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb10] "ImagePath"="system32\DRIVERS\mrxsmb10.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb20] "ImagePath"="system32\DRIVERS\mrxsmb20.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msahci] "ImagePath"="\SystemRoot\system32\drivers\msahci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdsm] "ImagePath"="\SystemRoot\system32\drivers\msdsm.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC] "ImagePath"="%SystemRoot%\System32\msdtc.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 4.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Msfs] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msisadrv] "ImagePath"="system32\drivers\msisadrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSiSCSI] "ServiceDll"="%systemroot%\system32\iscsiexe.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSKSSRV] "ImagePath"="system32\drivers\MSKSSRV.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPCLOCK] "ImagePath"="system32\drivers\MSPCLOCK.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPQM] "ImagePath"="system32\drivers\MSPQM.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MsRPC] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSSCNTRS] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mssmbios] "ImagePath"="system32\DRIVERS\mssmbios.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSTEE] "ImagePath"="system32\drivers\MSTEE.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mup] "ImagePath"="System32\Drivers\mup.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\napagent] "ServiceDLL"="%SystemRoot%\system32\qagentRT.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NativeWifiP] "ImagePath"="system32\DRIVERS\nwifi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NBService] "ImagePath"="c:\program files\Nero\Nero 7\Nero BackItUp\NBService.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDIS] "ImagePath"="system32\drivers\ndis.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisTapi] "ImagePath"="system32\DRIVERS\ndistapi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio] "ImagePath"="system32\DRIVERS\ndisuio.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisWan] "ImagePath"="system32\DRIVERS\ndiswan.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDProxy] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetBIOS] "ImagePath"="system32\DRIVERS\netbios.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netbt] "ImagePath"="System32\DRIVERS\netbt.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netlogon] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netman] "ServiceDll"="%SystemRoot%\System32\netman.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netprofm] "ServiceDll"="%SystemRoot%\System32\netprofm.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharing] "ImagePath"="\"%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nfrd960] "ImagePath"="\SystemRoot\system32\drivers\nfrd960.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NlaSvc] "ServiceDll"="%SystemRoot%\System32\nlasvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NMIndexingService] "ImagePath"="\"c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NMSAccess] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NMSAccessU] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsi] "ServiceDll"="%systemroot%\system32\nsisvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsiproxy] "ImagePath"="system32\drivers\nsiproxy.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NSM] "ImagePath"="\"c:\program files\Norton Family\Engine\2.6.0.52\ccSvcHst.exe\" /s \"NSM\" /m \"c:\program files\Norton Family\Engine\2.6.0.52\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTDS] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfs] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ntrigdigi] "ImagePath"="\SystemRoot\system32\drivers\ntrigdigi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Null] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvraid] "ImagePath"="\SystemRoot\system32\drivers\nvraid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvstor] "ImagePath"="\SystemRoot\system32\drivers\nvstor.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nv_agp] "ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFlt] "ImagePath"="system32\DRIVERS\nwlnkflt.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFwd] "ImagePath"="system32\DRIVERS\nwlnkfwd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\odserv] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ohci1394] "ImagePath"="system32\DRIVERS\ohci1394.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ose] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Outlook] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2pimsvc] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2psvc] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Parport] "ImagePath"="system32\DRIVERS\parport.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partmgr] "ImagePath"="System32\drivers\partmgr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Parvdm] "ImagePath"="system32\DRIVERS\parvdm.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PcaSvc] "ServiceDll"="%SystemRoot%\System32\pcasvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pci] "ImagePath"="system32\drivers\pci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pciide] "ImagePath"="\SystemRoot\system32\drivers\pciide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pcmcia] "ImagePath"="\SystemRoot\system32\drivers\pcmcia.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PEAUTH] "ImagePath"="system32\drivers\peauth.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pla] "ServiceDll"="%systemroot%\system32\pla.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PLFlash DeviceIoControl Service] "ImagePath"="c:\windows\system32\IoctlSvc.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay] "ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPAutoReg] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPsvc] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent] "ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PortProxy] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PptpMiniport] "ImagePath"="system32\DRIVERS\raspptp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Processor] "ImagePath"="\SystemRoot\system32\drivers\processr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProfSvc] "ServiceDll"="%systemroot%\system32\profsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PSched] "ImagePath"="system32\DRIVERS\pacer.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql2300] "ImagePath"="\SystemRoot\system32\drivers\ql2300.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql40xx] "ImagePath"="\SystemRoot\system32\drivers\ql40xx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVE] "ServiceDll"="%windir%\system32\qwave.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVEdrv] "ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\R300] "ImagePath"="system32\DRIVERS\atikmdag.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAcd] "ImagePath"="System32\DRIVERS\rasacd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAuto] "ServiceDll"="%SystemRoot%\System32\rasauto.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rasl2tp] "ImagePath"="system32\DRIVERS\rasl2tp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasMan] "ServiceDll"="%SystemRoot%\System32\rasmans.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasPppoe] "ImagePath"="system32\DRIVERS\raspppoe.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasSstp] "ImagePath"="system32\DRIVERS\rassstp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdbss] "ImagePath"="system32\DRIVERS\rdbss.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPCDD] "ImagePath"="System32\DRIVERS\RDPCDD.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPDD] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdpdr] "ImagePath"="\SystemRoot\system32\drivers\rdpdr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPENCDD] "ImagePath"="system32\drivers\rdpencdd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPNP] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPWD] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess] "ServiceDLL"="%SystemRoot%\System32\mprdim.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry] "ServiceDll"="%SystemRoot%\system32\regsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rimmptsk] "ImagePath"="system32\DRIVERS\rimmptsk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rimsptsk] "ImagePath"="system32\DRIVERS\rimsptsk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rismxdp] "ImagePath"="system32\DRIVERS\rixdptsk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcLocator] "ImagePath"="%SystemRoot%\system32\locator.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rspndr] "ImagePath"="system32\DRIVERS\rspndr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RTL8169] "ImagePath"="system32\DRIVERS\Rtlh86.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RTL8187B] "ImagePath"="system32\DRIVERS\RTL8187B.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SamSs] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sbp2port] "ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SBSDWSCService] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCardSvr] "ServiceDll"="%SystemRoot%\System32\SCardSvr.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule] "ServiceDll"="%systemroot%\system32\schedsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPolicySvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sdbus] "ImagePath"="system32\DRIVERS\sdbus.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SDRSVC] "ServiceDll"="%Systemroot%\System32\SDRSVC.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\secdrv] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\seclogon] "ServiceDll"="%windir%\system32\seclogon.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENS] "ServiceDll"="%SystemRoot%\system32\sens.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serenum] "ImagePath"="system32\DRIVERS\serenum.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serial] "ImagePath"="system32\DRIVERS\serial.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sermouse] "ImagePath"="\SystemRoot\system32\drivers\sermouse.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelEndpoint 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelOperation 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelService 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SessionEnv] "ServiceDLL"="%SystemRoot%\system32\sessenv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffdisk] "ImagePath"="system32\DRIVERS\sffdisk.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_mmc] "ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_sd] "ImagePath"="system32\DRIVERS\sffp_sd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sfloppy] "ImagePath"="\SystemRoot\system32\drivers\sfloppy.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess] "ServiceDll"="%SystemRoot%\System32\ipnathlp.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetection] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid2] "ImagePath"="\SystemRoot\system32\drivers\sisraid2.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid4] "ImagePath"="\SystemRoot\system32\drivers\sisraid4.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Skype C2C Service] "ImagePath"="\"c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SkypeUpdate] "ImagePath"="\"c:\program files\Skype\Updater\Updater.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\slsvc] "ImagePath"="%SystemRoot%\system32\SLsvc.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SLUINotify] "ServiceDll"="%SystemRoot%\system32\SLUINotify.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Smb] "ImagePath"="system32\DRIVERS\smb.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smserial] "ImagePath"="system32\DRIVERS\smserial.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 4.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMPTRAP] "ImagePath"="%SystemRoot%\System32\snmptrap.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNP2UVC] "ImagePath"="system32\DRIVERS\snp2uvc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\spldr] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Spooler] "ImagePath"="%SystemRoot%\System32\spoolsv.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv] "ImagePath"="System32\DRIVERS\srv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv2] "ImagePath"="System32\DRIVERS\srv2.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srvnet] "ImagePath"="System32\DRIVERS\srvnet.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRV] "ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ssmdrv] "ImagePath"="system32\DRIVERS\ssmdrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvc] "ServiceDll"="%SystemRoot%\system32\sstpsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\stisvc] "ServiceDll"="%SystemRoot%\System32\wiaservc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swenum] "ImagePath"="system32\DRIVERS\swenum.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swprv] "ServiceDll"="%Systemroot%\System32\swprv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Symc8xx] "ImagePath"="\SystemRoot\system32\drivers\symc8xx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SymEvent] "ImagePath"="\??\c:\windows\system32\Drivers\SYMEVENT.SYS" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}] "ImagePath"="\SystemRoot\System32\Drivers\NSM\0206000.034\SymRdr.SYS" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_hi] "ImagePath"="\SystemRoot\system32\drivers\sym_hi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_u3] "ImagePath"="\SystemRoot\system32\drivers\sym_u3.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SynTP] "ImagePath"="system32\DRIVERS\SynTP.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysMain] "ServiceDll"="%systemroot%\system32\sysmain.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TabletInputService] "ServiceDll"="%SystemRoot%\System32\TabSvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv] "ServiceDll"="%SystemRoot%\System32\tapisrv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tbhsd] "ImagePath"="system32\drivers\tbhsd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TBS] "ServiceDll"="%SystemRoot%\System32\tbssvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip] "ImagePath"="System32\drivers\tcpip.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6] "ImagePath"="system32\DRIVERS\tcpip.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tcpipreg] "ImagePath"="System32\drivers\tcpipreg.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDPIPE] "ImagePath"="system32\drivers\tdpipe.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDTCP] "ImagePath"="system32\drivers\tdtcp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdx] "ImagePath"="system32\DRIVERS\tdx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TeamViewer7] "ImagePath"="c:\program files\TeamViewer\Version7\TeamViewer_Service.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermDD] "ImagePath"="system32\DRIVERS\termdd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService] "ServiceDll"="%SystemRoot%\System32\termsrv.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Themes] "ServiceDll"="%SystemRoot%\system32\shsvcs.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\THREADORDER] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks] "ServiceDll"="%SystemRoot%\System32\trkwks.dll" -- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustedInstaller] "ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TSDDD] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tssecsrv] "ImagePath"="System32\DRIVERS\tssecsrv.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TuneUp.Defrag] "ImagePath"="c:\program files\TuneUp Utilities 2010\TuneUpDefragService.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TuneUp.UtilitiesSvc] "ImagePath"="\"c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TuneUpUtilitiesDrv] "ImagePath"="\??\c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunmp] "ImagePath"="system32\DRIVERS\tunmp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunnel] "ImagePath"="system32\DRIVERS\tunnel.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uagp35] "ImagePath"="system32\DRIVERS\uagp35.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\udfs] "ImagePath"="system32\DRIVERS\udfs.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGatherer] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGTHRSVC] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UI0Detect] "ImagePath"="%SystemRoot%\system32\UI0Detect.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UleadBurningHelper] "ImagePath"="c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliagpkx] "ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliahci] "ImagePath"="\SystemRoot\system32\drivers\uliahci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UlSata] "ImagePath"="\SystemRoot\system32\drivers\ulsata.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ulsata2] "ImagePath"="\SystemRoot\system32\drivers\ulsata2.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\umbus] "ImagePath"="system32\DRIVERS\umbus.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\upnphost] "ServiceDll"="%SystemRoot%\System32\upnphost.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usb] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbccgp] "ImagePath"="system32\DRIVERS\usbccgp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbcir] "ImagePath"="\SystemRoot\system32\drivers\usbcir.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbehci] "ImagePath"="system32\DRIVERS\usbehci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbhub] "ImagePath"="system32\DRIVERS\usbhub.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbohci] "ImagePath"="\SystemRoot\system32\drivers\usbohci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbprint] "ImagePath"="system32\DRIVERS\usbprint.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbscan] "ImagePath"="system32\DRIVERS\usbscan.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR] "ImagePath"="system32\DRIVERS\USBSTOR.SYS" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbuhci] "ImagePath"="system32\DRIVERS\usbuhci.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbvideo] "ImagePath"="System32\Drivers\usbvideo.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UxSms] "ServiceDll"="%SystemRoot%\System32\uxsms.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UxTuneUp] "ServiceDll"="%SystemRoot%\System32\uxtuneup.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vds] "ImagePath"="%SystemRoot%\System32\vds.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vga] "ImagePath"="system32\DRIVERS\vgapnp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VgaSave] "ImagePath"="\SystemRoot\System32\drivers\vga.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\viaagp] "ImagePath"="\SystemRoot\system32\drivers\viaagp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ViaC7] "ImagePath"="\SystemRoot\system32\drivers\viac7.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\viaide] "ImagePath"="\SystemRoot\system32\drivers\viaide.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgr] "ImagePath"="system32\drivers\volmgr.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgrx] "ImagePath"="System32\drivers\volmgrx.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volsnap] "ImagePath"="system32\drivers\volsnap.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsmraid] "ImagePath"="\SystemRoot\system32\drivers\vsmraid.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS] "ImagePath"="%systemroot%\system32\vssvc.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vToolbarUpdater13.2.0] "ImagePath"="c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time] "ServiceDll"="%systemroot%\system32\w32time.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W3SVC] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen] "ImagePath"="\SystemRoot\system32\drivers\wacompen.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarp] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarpv6] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wcncsvc] "ServiceDll"="%SystemRoot%\System32\wcncsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WcsPlugInService] "ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wd] "ImagePath"="\SystemRoot\system32\drivers\wd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wdf01000] "ImagePath"="system32\drivers\Wdf01000.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiServiceHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiSystemHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClient] "ServiceDll"="%SystemRoot%\System32\webclnt.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wecsvc] "ServiceDll"="%SystemRoot%\system32\wecsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wercplsupport] "ServiceDll"="%SystemRoot%\System32\wercplsupport.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WerSvc] "ServiceDll"="%SystemRoot%\System32\WerSvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefend] "ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc] "ServiceDll"="winhttp.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winmgmt] "ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM] "ServiceDll"="%SystemRoot%\system32\WsmSvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WisLMSvc] "ImagePath"="\"c:\program files\Launch Manager\WisLMSvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wlansvc] "ServiceDll"="%SystemRoot%\System32\wlansvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wlcrasvc] "ImagePath"="\"c:\program files\Windows Live\Mesh\wlcrasvc.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wlidsvc] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiAcpi] "ImagePath"="system32\DRIVERS\wmiacpi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wmiApSrv] "ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WMPNetworkSvc] "ImagePath"="\"%ProgramFiles%\Windows Media Player\wmpnetwk.exe\"" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPCSvc] "ServiceDll"="%SystemRoot%\System32\wpcsvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPDBusEnum] "ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPFFontCache_v0400] "ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ws2ifsl] "ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearch] "ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearchIdxPi] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv] "ServiceDll"="%systemroot%\system32\wuaueng.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WUDFRd] "ImagePath"="system32\DRIVERS\WUDFRd.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wudfsvc] "ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{310825A3-322D-4107-AFC5-1E187FC18390}] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{CCD213F1-878A-492A-B886-CEF093D5CD23}] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{F09A332F-460E-4CA7-B718-E09E66C1B581}] . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Zeit der Fertigstellung: 2012-12-01 18:20:34 ComboFix-quarantined-files.txt 2012-12-01 17:20 . Vor Suchlauf: 13 Verzeichnis(se), 38.036.365.312 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 37.949.468.672 Bytes frei . - - End Of File - - F7B1836CF61D99384B70EB4A4011387A liebe Grüße und noch einen schönen Abend |
03.12.2012, 11:44 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop. Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
__________________ Logfiles bitte immer in CODE-Tags posten |
03.12.2012, 13:34 | #21 |
| Windows Firewall wird immer wieder unbemerkt deaktiviertCode:
ATTFilter # AdwCleaner v2.011 - Datei am 03/12/2012 um 13:32:34 erstellt # Aktualisiert am 02/12/2012 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : Denise - DENISE-JÜRGENPC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Denise\Downloads\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml Ordner Gefunden : C:\Program Files\AVG Secure Search Ordner Gefunden : C:\Program Files\Common Files\AVG Secure Search Ordner Gefunden : C:\Program Files\Conduit Ordner Gefunden : C:\Program Files\SweetIM Ordner Gefunden : C:\Program Files\Viewpoint Ordner Gefunden : C:\ProgramData\AVG Secure Search Ordner Gefunden : C:\ProgramData\boost_interprocess Ordner Gefunden : C:\ProgramData\Viewpoint Ordner Gefunden : C:\Users\Celine\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Celine\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Celine\AppData\Roaming\Mozilla\Firefox\Profiles\s3dw46u8.default\extensions\staged Ordner Gefunden : C:\Users\Denise\AppData\Local\AVG Secure Search Ordner Gefunden : C:\Users\Denise\AppData\Local\Conduit Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\AVG Secure Search Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Denise\AppData\Roaming\OpenCandy ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{08ED8855-4C2E-429B-A878-F129E1F624FA} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A6CC2CA2-2779-4F10-88BF-A3C9EB874C24} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1 Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : HKLM\Software\AVG Secure Search Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\Software\MetaStream Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Schlüssel Gefunden : HKLM\Software\Viewpoint Schlüssel Gefunden : HKU\S-1-5-21-3489115444-3111152892-1366146225-1003\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKU\S-1-5-21-3489115444-3111152892-1366146225-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16455 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={42DBA148-8D55-4D91-A7C5-A4F49F5CF8C2}&mid=1ba64ddc0bec47d1b6c5d15f9567fafc-91b532326ad25d70d2501b7f6309cd58319b5e48&lang=de&ds=AVG&pr=fr&d=2011-11-23 21:02:12&v=8.0.0.40&sap=nt -\\ Mozilla Firefox v17.0 (de) Profilname : default Datei : C:\Users\Denise\AppData\Roaming\Mozilla\Firefox\Profiles\xmour6lv.default\prefs.js Gefunden : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Profilname : default Datei : C:\Users\Celine\AppData\Roaming\Mozilla\Firefox\Profiles\s3dw46u8.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v23.0.1271.95 Datei : C:\Users\Denise\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [9028 octets] - [03/12/2012 13:32:34] ########## EOF - C:\AdwCleaner[R1].txt - [9088 octets] ########## |
03.12.2012, 14:55 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
Danach eine Kontrolle mit OTL bitte:
__________________ Logfiles bitte immer in CODE-Tags posten |
03.12.2012, 20:16 | #23 |
| Windows Firewall wird immer wieder unbemerkt deaktiviertCode:
ATTFilter # AdwCleaner v2.011 - Datei am 03/12/2012 um 20:03:25 erstellt # Aktualisiert am 02/12/2012 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : Denise - DENISE-JÜRGENPC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Denise\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** # Aktualisiert am 02/12/2012 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : Denise - DENISE-JÜRGENPC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Denise\Downloads\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml Ordner Gefunden : C:\Program Files\AVG Secure Search Ordner Gefunden : C:\Program Files\Common Files\AVG Secure Search Ordner Gefunden : C:\Program Files\Conduit Ordner Gefunden : C:\Program Files\SweetIM Ordner Gefunden : C:\Program Files\Viewpoint Ordner Gefunden : C:\ProgramData\AVG Secure Search Ordner Gefunden : C:\ProgramData\boost_interprocess Ordner Gefunden : C:\ProgramData\Viewpoint Ordner Gefunden : C:\Users\Celine\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Celine\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Celine\AppData\Roaming\Mozilla\Firefox\Profiles\s3dw46u8.default\extensions\staged Ordner Gefunden : C:\Users\Denise\AppData\Local\AVG Secure Search Ordner Gefunden : C:\Users\Denise\AppData\Local\Conduit Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\AVG Secure Search Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Denise\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Denise\AppData\Roaming\OpenCandy ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gefunden : HKCU\Software\AVG Secure Search Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{08ED8855-4C2E-429B-A878-F129E1F624FA} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A6CC2CA2-2779-4F10-88BF-A3C9EB874C24} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1 Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : HKLM\Software\AVG Secure Search Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\Software\MetaStream Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Schlüssel Gefunden : HKLM\Software\Viewpoint Schlüssel Gefunden : HKU\S-1-5-21-3489115444-3111152892-1366146225-1003\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKU\S-1-5-21-3489115444-3111152892-1366146225-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16455 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={42DBA148-8D55-4D91-A7C5-A4F49F5CF8C2}&mid=1ba64ddc0bec47d1b6c5d15f9567fafc-91b532326ad25d70d2501b7f6309cd58319b5e48&lang=de&ds=AVG&pr=fr&d=2011-11-23 21:02:12&v=8.0.0.40&sap=nt -\\ Mozilla Firefox v17.0 (de) Profilname : default Datei : C:\Users\Denise\AppData\Roaming\Mozilla\Firefox\Profiles\xmour6lv.default\prefs.js Gefunden : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Profilname : default Datei : C:\Users\Celine\AppData\Roaming\Mozilla\Firefox\Profiles\s3dw46u8.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v23.0.1271.95 Datei : C:\Users\Denise\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [9028 octets] - [03/12/2012 13:32:34] ########## EOF - C:\AdwCleaner[R1].txt - [9088 octets] ########## [/code] |
03.12.2012, 20:32 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert Was postest du da für einen Brei? Und warum schon wieder ein Suchlog?
__________________ Logfiles bitte immer in CODE-Tags posten |
03.12.2012, 20:35 | #25 |
| Windows Firewall wird immer wieder unbemerkt deaktiviert sorry - irgendwie habe ich was falsch gemacht - glaub ich... ist der inhalt von den logs adwcleaner. ich musste auch nicht neu starten, wie beschrieben. und nun? |
03.12.2012, 20:38 | #26 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviertZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
03.12.2012, 20:41 | #27 |
| Windows Firewall wird immer wieder unbemerkt deaktiviertCode:
ATTFilter # AdwCleaner v2.011 - Datei am 03/12/2012 um 20:03:25 erstellt # Aktualisiert am 02/12/2012 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : Denise - DENISE-JÜRGENPC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Denise\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** |
03.12.2012, 20:42 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert Log ist leider unvollständig...
__________________ Logfiles bitte immer in CODE-Tags posten |
03.12.2012, 20:46 | #29 |
| Windows Firewall wird immer wieder unbemerkt deaktiviert die otl ist jetzt durch... soll ich die logs trotzdem posten? oder soll ich das alles nochmal durchführen? |
03.12.2012, 20:46 | #30 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Firewall wird immer wieder unbemerkt deaktiviert Ich möchte natürlich erstmal das richtige Log vom adwCleaner sehen
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Windows Firewall wird immer wieder unbemerkt deaktiviert |
avg, bereits, dateien, deaktiviert, defender, firewall, freigabe, gefunde, helfer, helferteam, immer wieder, infiziertes, inter, interne, internet, malwarebytes, nichts, objekt, problem, schließe, schonmal, security, unbemerkt, windows, windows firewall, überhaupt |