Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 06.01.2013, 15:17   #1
mika78
 
Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c) - Standard

Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)



Hallo, ich habe heute festgestellt, dass meine Firewall off ist, sie lässt sich auch nicht mehr aktiveren. Es erscheint beim Versuch sie zu aktiveren folgende Fehlermeldung: "Error 0x8007042c".

Scan meines Rechners mit AVG erbrachte keine Ergebnisse.
Nochmaliger Scan mit ESET-Onlinescanner zeigt folgende Ergebnisse:

C:\Users\Mika\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\3819bb10-199379cb Mehrere Bedrohungen gelöscht - in Quarantäne kopiert
C:\Users\Mika\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\350b95e3-14970de5 Mehrere Bedrohungen gelöscht - in Quarantäne kopiert
C:\Users\Mika\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\207256a7-4ba89c38 Mehrere Bedrohungen gelöscht - in Quarantäne kopiert
D:\Desktop Cleo\PSD\Software\Gepackt\Pokerseiten\Everest Poker.exe Variante von Win32/Casino Anwendung Gesäubert durch Löschen - in Quarantäne kopiert
D:\Desktop Cleo\PSD\Software\Gepackt\Pokerseiten\SetupPoker(2).exe Win32/PTCasino Anwendung Gesäubert durch Löschen - in Quarantäne kopiert
D:\Poker\PSD\Software\Gepackt\Pokerseiten\Everest Poker.exe Variante von Win32/Casino Anwendung Gesäubert durch Löschen - in Quarantäne kopiert
D:\Poker\PSD\Software\Gepackt\Pokerseiten\SetupPoker(2).exe Win32/PTCasino Anwendung Gesäubert durch Löschen - in Quarantäne kopiert

gmerLOG:
Zitat:
GMER 2.0.18327 - hxxp://www.gmer.net
Rootkit scan 2013-01-06 14:55:16
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST3500418AS rev.CC38 465,76GB
Running: gyzvpohx.exe; Driver: C:\Users\Mika\AppData\Local\Temp\kxldypow.sys


---- User code sections - GMER 2.0 ----

.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076371401 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076371419 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076371431 2 bytes [37, 76]
.text ... * 9
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000763714dd 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000763714f5 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007637150d 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076371525 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007637153d 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076371555 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007637156d 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076371585 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007637159d 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000763715b5 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000763715cd 2 bytes [37, 76]
.text C:\Program Files (x86)\Skype\Updater\Updater.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000763716b2 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076371401 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076371419 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076371431 2 bytes [37, 76]
.text ... * 9
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000763714dd 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000763714f5 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007637150d 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076371525 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007637153d 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076371555 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007637156d 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076371585 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007637159d 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000763715b5 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000763715cd 2 bytes [37, 76]
.text C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe[2212] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000763716b2 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000076371401 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000076371419 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000076371431 2 bytes [37, 76]
.text ... * 9
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 00000000763714dd 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 00000000763714f5 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 000000007637150d 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000076371525 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 000000007637153d 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000076371555 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 000000007637156d 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000076371585 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 000000007637159d 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 00000000763715b5 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 00000000763715cd 2 bytes [37, 76]
.text C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe[3048] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 00000000763716b2 2 bytes [37, 76]

---- Threads - GMER 2.0 ----

Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3144] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3148] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3160] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3164] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3188] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3200] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3204] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3208] 0000000073d229e1
Thread C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388:3212] 0000000073d229e1
---- Processes - GMER 2.0 ----

Library ? (*** suspicious ***) @ C:\Program Files (x86)\AVG\AVG9\avgtray.exe [2388] 0000000072e70000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2620] 00000000769c0000

---- Registry - GMER 2.0 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x8C 0x4B 0xE2 0xA7 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9E 0xE4 0x53 0xDD ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xFB 0x96 0x18 0xD7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x8C 0x4B 0xE2 0xA7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9E 0xE4 0x53 0xDD ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xFB 0x96 0x18 0xD7 ...

---- EOF - GMER 2.0 ----
OTL: OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 06.01.2013 14:22:30 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mika\Desktop\Trojan Board Softw
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,26 Gb Available Physical Memory | 56,42% Memory free
8,00 Gb Paging File | 6,33 Gb Available in Paging File | 79,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 79,98 Gb Total Space | 26,65 Gb Free Space | 33,32% Space Free | Partition Type: NTFS
Drive D: | 385,68 Gb Total Space | 141,49 Gb Free Space | 36,69% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive H: | 931,28 Gb Total Space | 103,26 Gb Free Space | 11,09% Space Free | Partition Type: FAT32
 
Computer Name: MIKA-PC | User Name: Mika | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Mika\Desktop\Trojan Board Softw\OTL.exe (OldTimer Tools)
PRC - C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe ()
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe ()
MOD - C:\Program Files (x86)\phonostar-Player\QtCore4.dll ()
MOD - C:\Program Files (x86)\phonostar-Player\plugins\sqldrivers\qsqlite4.dll ()
MOD - C:\Program Files (x86)\phonostar-Player\QtGui4.dll ()
MOD - C:\Program Files (x86)\phonostar-Player\QtSql4.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (TeamViewer8) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MSCamSvc) -- C:\Programme\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (avg9emc) -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (pgsql-8.3) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (andnetadb) -- C:\Windows\SysNative\drivers\lgandnetadb.sys (Google Inc)
DRV:64bit: - (andnetndis) -- C:\Windows\SysNative\drivers\lgandnetndis64.sys (LG Electronics Inc.)
DRV:64bit: - (ANDNetModem) -- C:\Windows\SysNative\drivers\lgandnetmodem64.sys (LG Electronics Inc.)
DRV:64bit: - (AndNetDiag) -- C:\Windows\SysNative\drivers\lgandnetdiag64.sys (LG Electronics Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AvgMfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (ggsemc) -- C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) -- C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (AvgTdiA) -- C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (FTSER2K) -- C:\Windows\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (MSHUSBVideo) -- C:\Windows\SysNative\drivers\nx6000.sys (Microsoft Corporation)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AvgLdx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (TFsExDisk) -- C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc)
DRV:64bit: - (ss_mdm) -- C:\Windows\SysNative\drivers\ss_mdm.sys (MCCI Corporation)
DRV:64bit: - (ss_bus) -- C:\Windows\SysNative\drivers\ss_bus.sys (MCCI Corporation)
DRV:64bit: - (ss_mdfl) -- C:\Windows\SysNative\drivers\ss_mdfl.sys (MCCI Corporation)
DRV:64bit: - (FTDIBUS) -- C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (s1039mdm) -- C:\Windows\SysNative\drivers\s1039mdm.sys (MCCI Corporation)
DRV:64bit: - (s1039unic) -- C:\Windows\SysNative\drivers\s1039unic.sys (MCCI Corporation)
DRV:64bit: - (s1039mgmt) -- C:\Windows\SysNative\drivers\s1039mgmt.sys (MCCI Corporation)
DRV:64bit: - (s1039obex) -- C:\Windows\SysNative\drivers\s1039obex.sys (MCCI Corporation)
DRV:64bit: - (s1039nd5) -- C:\Windows\SysNative\drivers\s1039nd5.sys (MCCI Corporation)
DRV:64bit: - (s1039mdfl) -- C:\Windows\SysNative\drivers\s1039mdfl.sys (MCCI Corporation)
DRV:64bit: - (s1039bus) -- C:\Windows\SysNative\drivers\s1039bus.sys (MCCI Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (StarOpen) -- C:\Windows\SysNative\drivers\StarOpen.sys ()
DRV:64bit: - (LgBttPort) -- C:\Windows\SysNative\drivers\lgbtpt64.sys (LG Electronics Inc.)
DRV:64bit: - (LGVMODEM) -- C:\Windows\SysNative\drivers\lgvmdm64.sys (LG Electronics Inc.)
DRV:64bit: - (lgbusenum) -- C:\Windows\SysNative\drivers\lgbtbs64.sys (LG Electronics Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (s0016mdm) -- C:\Windows\SysNative\drivers\s0016mdm.sys (MCCI Corporation)
DRV:64bit: - (s0016unic) -- C:\Windows\SysNative\drivers\s0016unic.sys (MCCI Corporation)
DRV:64bit: - (s0016mgmt) -- C:\Windows\SysNative\drivers\s0016mgmt.sys (MCCI Corporation)
DRV:64bit: - (s0016obex) -- C:\Windows\SysNative\drivers\s0016obex.sys (MCCI Corporation)
DRV:64bit: - (s0016nd5) -- C:\Windows\SysNative\drivers\s0016nd5.sys (MCCI Corporation)
DRV:64bit: - (s0016mdfl) -- C:\Windows\SysNative\drivers\s0016mdfl.sys (MCCI Corporation)
DRV:64bit: - (s0016bus) -- C:\Windows\SysNative\drivers\s0016bus.sys (MCCI Corporation)
DRV - (TFsExDisk) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (StarOpen) -- C:\Windows\SysWow64\drivers\StarOpen.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {ff88a983-649d-4207-9336-9b999280b436} - C:\Program Files (x86)\SFT_de3\prxtbSFT0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031778
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 D8 A3 EC F8 EB CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\..\URLSearchHook: {ff88a983-649d-4207-9336-9b999280b436} - C:\Program Files (x86)\SFT_de3\prxtbSFT0.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031778
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.spiegel.de/"
FF - prefs.js..extensions.enabledAddons: personas%40christopher.beard:1.6.2
FF - prefs.js..extensions.enabledAddons: %7Bec8030f7-c20a-464f-9b1e-13a3a9e97399%7D:2011.05
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..network.proxy.ftp: "proxyus4.stealthy.co"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.http: "proxyus4.stealthy.co"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxyus4.stealthy.co"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "proxyus4.stealthy.co"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.09.08 13:57:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.05 19:54:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.27 20:00:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.12.08 15:04:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.09.08 13:57:11 | 000,000,000 | ---D | M]
 
[2010.09.08 14:10:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\Extensions
[2010.09.08 14:10:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.12.14 18:40:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\Firefox\Profiles\stoamvwx.default\extensions
[2012.12.14 18:40:46 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Mika\AppData\Roaming\mozilla\Firefox\Profiles\stoamvwx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.11.23 19:20:10 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Mika\AppData\Roaming\mozilla\Firefox\Profiles\stoamvwx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012.09.25 17:31:03 | 000,000,000 | ---D | M] (Cryptload Link Copier) -- C:\Users\Mika\AppData\Roaming\mozilla\Firefox\Profiles\stoamvwx.default\extensions\{ec8030f7-c20a-464f-9b1e-13a3a9e97399}
[2011.03.12 18:48:52 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Mika\AppData\Roaming\mozilla\Firefox\Profiles\stoamvwx.default\extensions\personas@christopher.beard
[2012.06.22 19:41:12 | 000,013,955 | ---- | M] () (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\firefox\profiles\stoamvwx.default\extensions\admin@proxy-listen.de.xpi
[2012.10.22 16:01:51 | 000,183,174 | ---- | M] () (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\firefox\profiles\stoamvwx.default\extensions\stealthyextension@gmail.com.xpi
[2012.11.23 19:20:05 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\firefox\profiles\stoamvwx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.09.14 06:16:16 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\Mika\AppData\Roaming\mozilla\firefox\profiles\stoamvwx.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012.10.27 20:00:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.10.27 20:00:59 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.12.05 19:54:48 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.03.22 19:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011.11.09 18:42:41 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.08 19:37:35 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.11.09 18:42:41 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.09 18:42:41 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.09 18:42:41 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.09 18:42:41 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.06.10 08:35:02 | 000,000,154 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Program Files (x86)\SFT_de3\prxtbSFT0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SFT_de3 Toolbar) - {ff88a983-649d-4207-9336-9b999280b436} - C:\Program Files (x86)\SFT_de3\prxtbSFT0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKCU..\Run: [dradio-RecorderTimer] C:\Program Files (x86)\dradio-Recorder\phonostarTimer.exe ()
O4 - HKCU..\Run: [LG LinkAir] File not found
O4 - HKCU..\Run: [phonostarTimer] C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe ()
O4 - Startup: C:\Users\Mika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Mika\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Mika\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Mika\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC33787F-FB1B-49FF-BB4C-8A31D4BE29C4}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{036b5e58-30da-11e2-925f-4061862e10d9}\Shell - "" = AutoRun
O33 - MountPoints2\{036b5e58-30da-11e2-925f-4061862e10d9}\Shell\AutoRun\command - "" = G:\LGAutoRun.exe
O33 - MountPoints2\{2749a1e2-e436-11df-9eed-4061862e10d9}\Shell - "" = AutoRun
O33 - MountPoints2\{2749a1e2-e436-11df-9eed-4061862e10d9}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Start.hta
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.01.06 12:29:58 | 000,000,000 | ---D | C] -- C:\Users\Mika\Desktop\Trojan Board Softw
[2013.01.06 11:32:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013.01.05 20:36:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013.01.05 17:43:36 | 000,000,000 | ---D | C] -- C:\Users\Mika\Documents\atari
[2013.01.05 16:05:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
[2013.01.02 16:13:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer
[2013.01.02 16:13:51 | 000,000,000 | ---D | C] -- C:\Users\Mika\AppData\Roaming\ProtectDisc
[2012.12.24 08:56:38 | 000,000,000 | ---D | C] -- C:\Users\Mika\Desktop\log
[2012.12.23 17:15:24 | 000,000,000 | ---D | C] -- C:\Users\Mika\AppData\Local\LIMBO
[2012.12.14 18:42:04 | 000,000,000 | ---D | C] -- C:\Users\Mika\dwhelper
[2012.12.08 15:04:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.01.06 14:01:08 | 000,014,800 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.06 14:01:08 | 000,014,800 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.06 14:00:53 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.06 14:00:53 | 000,696,832 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.06 14:00:53 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.06 14:00:53 | 000,148,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.06 14:00:53 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.06 13:54:00 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.06 13:53:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.06 13:53:39 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.06 13:52:52 | 000,000,020 | ---- | M] () -- C:\Users\Mika\defogger_reenable
[2013.01.06 13:44:51 | 000,002,120 | ---- | M] () -- C:\scu.dat
[2013.01.06 13:39:04 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.06 11:30:38 | 000,000,364 | ---- | M] () -- C:\Users\Mika\Documents\cc_20130106_113036.reg
[2013.01.06 11:30:10 | 000,002,836 | ---- | M] () -- C:\Users\Mika\Documents\cc_20130106_113007.reg
[2013.01.06 11:29:54 | 000,140,996 | ---- | M] () -- C:\Users\Mika\Documents\reg aenderg 060113.reg
[2013.01.06 09:31:44 | 105,261,858 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2013.01.06 09:25:02 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.01.05 20:36:24 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013.01.05 16:05:48 | 000,000,757 | ---- | M] () -- C:\Users\Public\Desktop\Fahrenheit (Indigo Prophecy).lnk
[2013.01.03 14:16:31 | 000,105,307 | ---- | M] () -- C:\Users\Mika\Desktop\Gentrifizierung.jpg
[2013.01.02 16:14:01 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00000E3E.LCS
[2013.01.02 06:01:20 | 000,001,047 | ---- | M] () -- C:\Users\Mika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.01.02 06:00:55 | 000,001,013 | ---- | M] () -- C:\Users\Mika\Desktop\Dropbox.lnk
[2012.12.29 08:18:14 | 004,873,184 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.12.28 19:11:24 | 000,001,090 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012.12.25 19:32:26 | 000,017,391 | ---- | M] () -- C:\Users\Mika\Desktop\Pilgern.odt
[2012.12.14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.01.06 13:52:51 | 000,000,020 | ---- | C] () -- C:\Users\Mika\defogger_reenable
[2013.01.06 13:44:44 | 000,002,120 | ---- | C] () -- C:\scu.dat
[2013.01.06 11:30:37 | 000,000,364 | ---- | C] () -- C:\Users\Mika\Documents\cc_20130106_113036.reg
[2013.01.06 11:30:09 | 000,002,836 | ---- | C] () -- C:\Users\Mika\Documents\cc_20130106_113007.reg
[2013.01.06 11:29:46 | 000,140,996 | ---- | C] () -- C:\Users\Mika\Documents\reg aenderg 060113.reg
[2013.01.05 20:36:24 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013.01.05 16:05:48 | 000,000,757 | ---- | C] () -- C:\Users\Public\Desktop\Fahrenheit (Indigo Prophecy).lnk
[2013.01.03 14:16:31 | 000,105,307 | ---- | C] () -- C:\Users\Mika\Desktop\Gentrifizierung.jpg
[2013.01.02 16:13:52 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00000E3E.LCS
[2012.12.28 19:11:24 | 000,001,102 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2012.12.28 19:11:24 | 000,001,090 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012.12.25 18:54:44 | 000,017,391 | ---- | C] () -- C:\Users\Mika\Desktop\Pilgern.odt
[2011.12.04 08:13:13 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011.06.02 08:26:19 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.24 20:40:48 | 000,000,109 | ---- | C] () -- C:\Windows\atarigo.ini
[2010.06.07 06:17:39 | 000,003,584 | ---- | C] () -- C:\Users\Mika\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.12.30 13:14:35 | 000,007,663 | ---- | C] () -- C:\Users\Mika\AppData\Local\Resmon.ResmonCfg
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2011.04.28 19:01:25 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\2Flyer
[2010.08.04 17:44:03 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Amazon
[2010.09.24 16:08:24 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Audacity
[2010.12.17 23:31:58 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Azureus
[2011.07.18 19:19:07 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Babylon
[2010.10.30 17:09:15 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\BSplayer
[2010.10.02 20:01:32 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\BSplayer Pro
[2010.05.03 13:56:02 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Canneverbe Limited
[2009.12.11 16:59:30 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\DAEMON Tools Lite
[2013.01.02 15:35:53 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Downloaded Installations
[2013.01.06 13:54:10 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Dropbox
[2010.07.02 16:21:57 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.26 18:39:01 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\elsterformular
[2011.07.30 08:08:39 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\HEM Data
[2011.05.19 15:08:13 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\LEGO Company
[2010.05.10 16:26:15 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Mp3tag
[2012.11.17 18:45:32 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\MyPhoneExplorer
[2011.11.26 12:23:34 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Nitro PDF
[2010.02.09 03:34:54 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\OpenOffice.org
[2012.09.22 20:47:06 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Party
[2010.10.10 09:18:11 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\phonostar GmbH
[2011.12.03 08:56:32 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Playrix Entertainment
[2009.12.31 14:04:26 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\postgresql
[2013.01.02 16:13:51 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\ProtectDisc
[2012.03.01 20:27:36 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Samsung
[2011.06.25 06:17:13 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Sony
[2012.06.11 18:44:43 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010.08.28 13:22:53 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Stereoscopic Player
[2010.10.25 17:20:30 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\streamripper
[2011.02.06 12:11:22 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\TeamViewer
[2010.09.08 14:10:23 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Thunderbird
[2010.02.22 08:59:07 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\Ubisoft
[2012.01.02 19:58:45 | 000,000,000 | ---D | M] -- C:\Users\Mika\AppData\Roaming\xrecode2
 
========== Purity Check ==========
 
 
 
< End of report >
         
--- --- ---


FSS-Log
Zitat:
Farbar Service Scanner Version: 05-01-2013
Ran by Mika (administrator) on 06-01-2013 at 15:05:20
Running from "C:\Users\Mika\Desktop\Trojan Board Softw"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.

bfe Service is not running. Checking service configuration:
The start type of bfe service is OK.
The ImagePath of bfe service is OK.
The ServiceDll of bfe service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============
Checking Start type of iphlpsvc: ATTENTION!=====> Unable to retrieve start type of iphlpsvc. The value does not exist.
Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to retrieve ImagePath of iphlpsvc. The value does not exist.
Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to retrieve ServiceDll of iphlpsvc. The value does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

 

Themen zu Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)
adblock, adobe, attention, avg, bho, cdburnerxp, converter, defender, desktop, error, explorer, farbar, fehlermeldung, firefox, firewall, google, home, logfile, mp3, plug-in, port, realtek, registry, rundll, software, svchost.exe, system, temp, trojan, usb




Ähnliche Themen: Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)


  1. Firewall lässt sich nicht mehr starten Fehlercode 0x8007042c
    Plagegeister aller Art und deren Bekämpfung - 26.05.2015 (12)
  2. Firewall lässt sich nicht mehr starten Fehlercode 0x8007042c
    Plagegeister aller Art und deren Bekämpfung - 15.12.2014 (11)
  3. Firewall lässt sich nicht mehr starten Fehlercode 0x8007042c
    Antiviren-, Firewall- und andere Schutzprogramme - 09.12.2014 (19)
  4. Windows Firewall lässt sich nicht aktivieren - Fehlercode: 0x80070424
    Antiviren-, Firewall- und andere Schutzprogramme - 28.09.2014 (10)
  5. Windows Firewall lässt sich nicht aktivieren fehlercode 0x80070424
    Plagegeister aller Art und deren Bekämpfung - 29.09.2013 (26)
  6. Windows Firewall lässt sich nicht aktivieren. Fehlercode 0x80070424
    Log-Analyse und Auswertung - 05.08.2013 (13)
  7. Firewall lässt sich nicht mehr aktivieren. Fehlercode 0x80070424
    Log-Analyse und Auswertung - 30.03.2013 (4)
  8. Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)
    Plagegeister aller Art und deren Bekämpfung - 16.01.2013 (22)
  9. Firewall und MSE lassen sich nicht mehr aktivieren Fehlercode: ,,0x80070424,,
    Log-Analyse und Auswertung - 03.11.2012 (50)
  10. AV Software lässt sich nicht mehr installieren und Firewall nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 06.09.2012 (7)
  11. Windows Firewall lässt sich nicht mehr aktivieren/deaktivieren
    Plagegeister aller Art und deren Bekämpfung - 25.05.2012 (1)
  12. Fehlercode 0x80070424 // Windows - Firewall lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 26.03.2012 (5)
  13. Firewall inaktiv und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 26.02.2012 (14)
  14. Firewall lässt sich nicht aktivieren / Fehlercode 0x80070424
    Plagegeister aller Art und deren Bekämpfung - 25.01.2012 (2)
  15. Firewall lässt sich nicht mehr Aktivieren ( Fehlercode : 0x80070424 )
    Plagegeister aller Art und deren Bekämpfung - 25.01.2012 (9)
  16. Firewall inaktiv und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 04.11.2011 (31)
  17. windows zeigt syp infected und firewall lässt sich nicht mehr aktivieren
    Antiviren-, Firewall- und andere Schutzprogramme - 14.10.2008 (1)

Zum Thema Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c) - Hallo, ich habe heute festgestellt, dass meine Firewall off ist, sie lässt sich auch nicht mehr aktiveren. Es erscheint beim Versuch sie zu aktiveren folgende Fehlermeldung: "Error 0x8007042c". Scan meines - Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c)...
Archiv
Du betrachtest: Win 7 Firewall lässt sich nicht mehr aktivieren (Fehlercode Error 0x8007042c) auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.