Plagegeister aller Art und deren Bekämpfung: Computer wird bei Verbindung mit dem Internet gesperrt
Computer wird bei Verbindung mit dem Internet gesperrt Hallo liebe Helfer, seit heute Mittag habe ich dass Problem, dass mein PC bei bestehender Verbindung mit dem Internet gesperrt wird. Das Problem ist exakt Deckungsgleich zum dem, welches hier in der Community ebenfalls schon aufgekommen ist: http://www.trojaner-board.de/129974-...-gesperrt.html Ich hoffe ihr könnt mir schnell helfen, ich brauche meinen PC eigentlich dringend für die Uni und habe wenig Lust alles neu zu installieren (Die Daten könnte ich ja retten denke ich) Viele Grüße Manuel
Computer wird bei Verbindung mit dem Internet gesperrt hi
starte neu, drücke f8 wähle abgesicherter Modus mit Netzwerk, melde dich im betroffenen Konto an, inet sollte funktionieren Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
Computer wird bei Verbindung mit dem Internet gesperrt Hallo markus,
ich bedanke mich für die Antwort und wqerde das gleich mal testen. Ich hoffe du kannst mir bei meinem Problem helfen. Gruß Manuel Ich komme leider garnicht erst in den abgesicherten Modus ... was soll ich jetzt tun ?? OK nachdem ich meinen PC abgewürgt hatte kam ich doch rein ;-) So lange der Scan läuft kläre ich dich kurz über mein System auf: Also ich denke was besonderst wichtig ist: Ich habe Windows 7 Außerdem habe ich bereits mit Antivir gescannt: ohne Erfolg Also hier die Ergebnisse des Scans: Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT Code:
ATTFilter OTL logfile created on: 24.01.2013 19:43:43 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Manuel\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,98 Gb Total Physical Memory | 5,23 Gb Available Physical Memory | 87,38% Memory free 11,96 Gb Paging File | 11,24 Gb Available in Paging File | 93,92% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 457,21 Gb Total Space | 305,62 Gb Free Space | 66,85% Space Free | Partition Type: NTFS Drive D: | 457,21 Gb Total Space | 326,18 Gb Free Space | 71,34% Space Free | Partition Type: NTFS Drive F: | 992,70 Mb Total Space | 899,61 Mb Free Space | 90,62% Space Free | Partition Type: FAT Drive M: | 1828,85 Gb Total Space | 1425,08 Gb Free Space | 77,92% Space Free | Partition Type: NTFS Drive P: | 1828,85 Gb Total Space | 1425,08 Gb Free Space | 77,92% Space Free | Partition Type: NTFS Drive V: | 1828,85 Gb Total Space | 1425,08 Gb Free Space | 77,92% Space Free | Partition Type: NTFS Drive X: | 1828,85 Gb Total Space | 1425,08 Gb Free Space | 77,92% Space Free | Partition Type: NTFS Drive Y: | 1828,85 Gb Total Space | 1425,08 Gb Free Space | 77,92% Space Free | Partition Type: NTFS Computer Name: M-PC2 | User Name: Manuel | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.01.24 19:24:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Manuel\Desktop\OTL.exe ========== Modules (No Company Name) ========== ========== Services (SafeList) ========== SRV - [2013.01.18 18:47:54 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.01.09 13:31:16 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.12.29 11:34:47 | 001,260,472 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.12.29 02:53:20 | 000,383,416 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.13 14:44:31 | 000,544,840 | ---- | M] (Cisco Systems, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe -- (vpnagent) SRV - [2012.11.26 19:06:13 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.07.02 11:33:28 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2012.05.08 17:35:57 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.05.08 17:35:57 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.01.31 02:10:36 | 000,339,776 | ---- | M] ( ) [Auto | Stopped] -- C:\Programme\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe -- (mitsijm2013) SRV - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2011.09.15 05:19:54 | 000,086,016 | ---- | M] () [Auto | Stopped] -- C:\Programme\Autodesk\3ds Max 2013\NVIDIA\raysat_3dsmax2013_64server.exe -- (mi-raysat_3dsmax2013_64) SRV - [2011.03.28 21:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2011.02.01 06:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011.02.01 06:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2011.01.31 22:55:14 | 000,244,624 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Live Updater Service) SRV - [2010.11.06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010.10.12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService) SRV - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0) SRV - [2010.09.22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV - [2010.05.04 21:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2010.01.08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService) SRV - [2009.08.27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008.08.07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) SRV - [2008.06.03 16:18:08 | 000,066,560 | ---- | M] () [Auto | Stopped] -- C:\Windows\jwpen.exe -- (HWSuperPowerTablet) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.12.13 14:26:36 | 000,112,080 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acsock64.sys -- (acsock) DRV:64bit: - [2012.09.20 05:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) DRV:64bit: - [2012.09.20 05:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) DRV:64bit: - [2012.08.03 20:38:55 | 000,027,048 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva) DRV:64bit: - [2012.07.03 16:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2012.07.02 11:23:05 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn) DRV:64bit: - [2012.05.08 17:35:57 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2012.05.08 17:35:57 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.01.18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) DRV:64bit: - [2012.01.18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64) DRV:64bit: - [2011.12.20 07:59:12 | 002,727,936 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmudaxp.sys -- (cmudaxp) DRV:64bit: - [2011.10.11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:64bit: - [2011.08.01 14:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64) DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.12.24 08:32:54 | 000,412,264 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.11.06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010.10.19 09:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.06.14 08:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk) DRV:64bit: - [2010.03.19 02:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2009.08.13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 01:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV:64bit: - [2009.07.14 01:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007.10.19 10:37:56 | 000,543,232 | ---- | M] (LITEON) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ltn_stk7070P_64.sys -- (Ltn_stk7070P_64) DRV:64bit: - [2007.10.19 10:37:56 | 000,016,256 | ---- | M] (LITEON) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ltn_stkrc_64.sys -- (Ltn_stkrc_64) DRV:64bit: - [2007.03.26 11:17:00 | 000,008,320 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HWDrawing.sys -- (VHWDrawing) DRV - [2010.06.14 08:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@ptc.com/ProductViewLite: C:\Program Files (x86)\Common Files\PTC\np6_pvapplite9.dll (PTC) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VLCVideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.18 18:47:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.11.05 16:55:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Manuel\AppData\Roaming\mozilla\Extensions [2012.09.12 22:01:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Manuel\AppData\Roaming\mozilla\Firefox\Profiles\6zvrdmdc.default\extensions [2012.09.12 22:01:38 | 000,621,521 | ---- | M] () (No name found) -- C:\Users\Manuel\AppData\Roaming\mozilla\firefox\profiles\6zvrdmdc.default\extensions\testpilot@labs.mozilla.com.xpi [2013.01.18 18:47:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.01.18 18:47:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013.01.18 18:47:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2013.01.18 18:47:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions [2013.01.18 18:47:55 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.11.27 21:31:27 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.11.27 21:31:27 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.11.27 21:31:27 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.11.27 21:31:27 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.11.27 21:31:27 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.11.27 21:31:27 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.75\pdf.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VLCVideoLAN\VLC\npvlc.dll CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: YouTube = C:\Users\Manuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\ CHR - Extension: Google-Suche = C:\Users\Manuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: Google Mail = C:\Users\Manuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\ O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [Autodesk Sync] C:\Programme\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.) O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4:64bit: - HKLM..\Run: [Cmaudio8788] C:\Windows\Syswow64\cmicnfgp.dll (C-Media Corporation) O4:64bit: - HKLM..\Run: [Cmaudio8788GX] C:\Windows\syswow64\HsMgr.exe () O4:64bit: - HKLM..\Run: [Cmaudio8788GX64] C:\Windows\system\HsMgr64.exe () O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Autodesk, Inc.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.) O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe () O4 - HKLM..\Run: [HWTablet KeyPlus] C:\Windows\SysWOW64\HWKeyPlus.exe () O4 - HKLM..\Run: [HWTablet Service] C:\Windows\SysWOW64\HWTabTray.exe () O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [TrayServer] C:\Program Files (x86)\MAGIX\Video_deluxe_17_Premium_Sonderedition\TrayServer.exe (MAGIX AG) O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung) O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Manuel\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung) O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung) O4 - HKCU..\Run: [Software Suite SE] C:\Program Files (x86)\Packard Bell\Software Suite SE\SoftSuiteSE.exe (Acer Incorporated) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DDFA9DF7-7226-4B4B-B1B3-F93EDF312F18}: NameServer = O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{c00a5ab8-b769-11e0-a2ac-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c00a5ab8-b769-11e0-a2ac-806e6f6e6963}\Shell\AutoRun\command - "" = Z:\cdstart.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX:64bit: {0AB324FA-DF78-6EFA-4598-91C1D14D0C44} - Themes Setup ActiveX:64bit: {143D5D37-881A-AF39-0679-1C54239533A1} - Microsoft Windows Media Player ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {370C3286-5717-3F99-D4C7-920316FC9D89} - Themes Setup ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {3F24D6E7-F128-36E6-06CD-331F1CCE1D53} - Internet Explorer ActiveX:64bit: {400D3158-9F53-5179-8E4E-11B750D7661A} - Internet Explorer ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {8D115047-4358-16B9-443D-94C55A9EEDB2} - Themes Setup ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F04A7E29-C694-639F-6283-C6536C1EF220} - Browser Customizations ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP CREATERESTOREPOINT Unable to start System Restore Service. Error code 1084 ========== Files/Folders - Created Within 30 Days ========== [2013.01.24 19:42:37 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Manuel\Desktop\OTL.exe [2013.01.24 14:33:47 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{636BD44D-8DEB-4A0C-B9A0-BBC77DF03BE2} [2013.01.23 12:34:24 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{6C507BA3-7D42-4467-9784-16410627D227} [2013.01.22 21:27:28 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{2C5AAD76-6AB4-4D3C-91AF-623656C726F7} [2013.01.21 18:52:40 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{D89AA588-5297-423E-97D6-338BC90CAAB0} [2013.01.20 15:04:30 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{267BB2F6-6879-4EEE-8EDC-E65CDC148855} [2013.01.19 23:28:36 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{7ED4A46D-8178-414C-A337-2BC897DDDFBF} [2013.01.19 15:21:47 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{81C893D2-44EF-4404-8E06-8183F401A467} [2013.01.18 22:29:15 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{9D6B6910-C2D9-49B9-94C2-0AB71CD44BDE} [2013.01.18 18:47:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.01.18 12:34:03 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{64E51A94-3D2B-4BB3-8EDA-2BD0865482B7} [2013.01.17 15:24:36 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{88318385-008A-44FF-A261-9E1C8DBB2B3D} [2013.01.16 21:24:31 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{3C43DF0A-AAF8-46C4-B465-436B39E117B2} [2013.01.16 18:15:05 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{4252B951-033B-4010-8A12-78E8AE11A1AE} [2013.01.15 21:01:57 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{06A352C3-7011-4D40-8712-0A8ADDB6A396} [2013.01.14 18:59:01 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{2DCC7127-7B87-40E3-B66B-4613429F76BF} [2013.01.13 14:42:18 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{50DC0841-C5BF-46BF-9B3E-F30C3A63E1F6} [2013.01.12 15:22:01 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{7C6B8B93-7D62-471D-BA11-8799E4E7FE57} [2013.01.11 17:46:03 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{2BC61DE6-0BBF-4B65-A1D3-9C954C4CA535} [2013.01.10 16:11:41 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{FE843118-63B5-4347-8141-33147D16C7A9} [2013.01.09 17:38:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco [2013.01.09 14:54:59 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{B9A9FBF9-3FF9-4C8A-AC95-6F4679B81D74} [2013.01.08 22:18:22 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{CE337FD7-B5E2-4167-AB16-A6FDB96F0D4A} [2013.01.07 21:24:37 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{6B83C634-265C-4326-97A3-F7FF280DBDF1} [2013.01.06 16:44:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2013.01.06 13:09:54 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{B0C3021C-51B5-4D4D-A5A5-26F4A07FD593} [2013.01.05 17:04:13 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{F956E350-687F-4F28-8F0E-FCDD5743E822} [2013.01.04 23:18:42 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{F396AF30-B5B9-48BA-8425-4E56E31AD0BC} [2013.01.03 09:36:20 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{63D832BB-A18B-4E37-A13C-2E05814F4580} [2013.01.01 23:11:40 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{25D3BAE8-004C-4F0F-89EF-8E8953BBDD57} [2012.12.31 18:30:54 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{7C7D805D-224A-4F66-89F7-2D88F9807C1D} [2012.12.31 13:00:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump [2012.12.30 23:41:54 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{CF9B229F-B2C2-4421-AEBA-4140FE030D8D} [2012.12.29 23:33:49 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{12CBA199-ABDE-4124-8D3F-78E5FE0DE9C9} [2012.12.29 23:02:58 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{509149E7-8B54-4073-BC0D-842064CB92D0} [2012.12.28 20:26:16 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{2ED54A71-311C-4E49-A0A6-BF001B52FB29} [2012.12.27 12:42:36 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{B8F557D7-F1FC-4900-A5C9-EF921A5FA6C7} [2012.12.25 22:53:30 | 000,000,000 | ---D | C] -- C:\Users\Manuel\AppData\Local\{951FDEB3-D114-44D7-B442-AA9A2F4B720B} [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Manuel\*.tmp files -> C:\Users\Manuel\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.01.24 19:42:24 | 001,614,736 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.01.24 19:42:24 | 000,697,336 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.01.24 19:42:24 | 000,652,654 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.01.24 19:42:24 | 000,148,632 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.01.24 19:42:24 | 000,121,586 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.01.24 19:40:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.01.24 19:40:15 | 523,104,255 | -HS- | M] () -- C:\hiberfil.sys [2013.01.24 19:38:56 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.01.24 19:38:37 | 000,003,116 | ---- | M] () -- C:\Windows\HWTablet.bin [2013.01.24 19:38:27 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs [2013.01.24 19:35:59 | 000,533,608 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.01.24 19:24:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Manuel\Desktop\OTL.exe [2013.01.24 15:32:19 | 095,023,320 | ---- | M] () -- C:\ProgramData\HizKK03.pad [2013.01.24 15:31:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.01.24 15:25:17 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.01.24 15:06:43 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.01.24 15:06:43 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.01.24 14:41:39 | 000,003,223 | ---- | M] () -- C:\ProgramData\HizKK03.js [2013.01.24 14:41:39 | 000,001,085 | ---- | M] () -- C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk [2013.01.24 14:41:39 | 000,000,153 | ---- | M] () -- C:\ProgramData\HizKK03.reg [2013.01.24 14:41:39 | 000,000,080 | ---- | M] () -- C:\ProgramData\HizKK03.bat [2013.01.24 14:16:07 | 001,591,518 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013.01.19 21:09:49 | 688,613,278 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013.01.09 15:02:19 | 000,002,853 | ---- | M] () -- C:\Users\Manuel\AppData\Local\recently-used.xbel [2013.01.05 12:26:03 | 000,000,847 | ---- | M] () -- C:\Users\Manuel\Desktop\TX-NR414 - Verknüpfung.lnk [2012.12.29 11:34:47 | 000,017,266 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb [2012.12.29 09:40:11 | 002,923,201 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin [2012.12.25 23:06:06 | 000,000,036 | ---- | M] () -- C:\Users\Manuel\.org.eclipse.epp.usagedata.recording.userId [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\Manuel\*.tmp files -> C:\Users\Manuel\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.01.24 14:41:39 | 000,003,223 | ---- | C] () -- C:\ProgramData\HizKK03.js [2013.01.24 14:41:39 | 000,001,085 | ---- | C] () -- C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk [2013.01.24 14:41:39 | 000,000,153 | ---- | C] () -- C:\ProgramData\HizKK03.reg [2013.01.24 14:41:39 | 000,000,080 | ---- | C] () -- C:\ProgramData\HizKK03.bat [2013.01.24 14:41:38 | 095,023,320 | ---- | C] () -- C:\ProgramData\HizKK03.pad [2013.01.09 15:02:19 | 000,002,853 | ---- | C] () -- C:\Users\Manuel\AppData\Local\recently-used.xbel [2013.01.05 12:26:03 | 000,000,847 | ---- | C] () -- C:\Users\Manuel\Desktop\TX-NR414 - Verknüpfung.lnk [2012.12.25 23:06:06 | 000,000,036 | ---- | C] () -- C:\Users\Manuel\.org.eclipse.epp.usagedata.recording.userId [2012.11.30 18:51:56 | 000,007,605 | ---- | C] () -- C:\Users\Manuel\AppData\Local\Resmon.ResmonCfg [2012.11.26 18:49:36 | 001,591,518 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012.11.06 21:16:22 | 000,000,032 | ---- | C] () -- C:\Windows\DVD_Start.INI [2012.11.01 10:57:44 | 000,000,049 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini [2012.11.01 10:57:42 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe [2012.11.01 10:57:30 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll [2012.11.01 10:56:58 | 000,044,950 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl [2012.11.01 10:56:12 | 000,000,872 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi [2012.11.01 10:56:01 | 000,005,066 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg [2012.09.26 14:12:26 | 000,000,072 | ---- | C] () -- C:\Windows\wininit.ini [2012.05.09 14:03:21 | 000,000,028 | ---- | C] () -- C:\Users\Manuel\.gtk-bookmarks [2012.03.28 21:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012.03.28 21:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll [2012.03.28 21:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll [2012.03.28 21:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll [2012.03.28 21:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll [2012.02.16 15:12:48 | 000,004,608 | ---- | C] () -- C:\Users\Manuel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.01.18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll [2012.01.18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll [2012.01.18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe [2011.11.24 11:46:10 | 000,000,594 | ---- | C] () -- C:\Windows\cmudaxp.ini [2011.11.22 19:08:50 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI [2011.11.06 14:45:23 | 000,066,560 | ---- | C] () -- C:\Windows\jwpen.exe [2011.11.06 14:45:23 | 000,028,672 | ---- | C] () -- C:\Windows\HWCkPenT.dll [2011.11.06 14:45:23 | 000,013,824 | ---- | C] () -- C:\Windows\DevInst.exe [2011.11.06 14:45:23 | 000,011,264 | ---- | C] () -- C:\Windows\HWDevInst.exe [2011.11.06 14:45:23 | 000,003,116 | ---- | C] () -- C:\Windows\HWTablet.bin [2011.11.06 14:45:22 | 000,184,320 | ---- | C] () -- C:\Windows\SysWow64\HWTabTray.exe [2011.11.06 14:45:22 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\WinTab32.dll [2011.11.06 14:45:22 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\jwusbchk32.dll [2011.11.06 14:45:22 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\JWKey.dll [2011.11.06 14:45:22 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\HWKeyPlus.exe [2011.11.06 14:45:22 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\JWPen.dll ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.11.01 11:02:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ASUS [2012.12.01 20:33:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Autodesk [2011.11.19 11:04:41 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Foxit Software [2012.06.23 14:53:42 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\FreeCommander [2012.05.16 19:02:55 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\gtk-2.0 [2011.11.06 16:54:14 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\IrfanView [2011.11.05 16:12:18 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Leadertech [2011.11.12 15:48:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\MAGIX [2011.11.05 15:36:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\OEM [2012.11.30 13:53:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Origin [2011.11.12 16:07:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\proDAD [2011.12.20 18:08:40 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ProtectDISC [2012.01.31 15:45:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\PTC [2012.11.15 16:45:51 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Samsung [2012.07.12 18:03:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TeamViewer [2012.04.24 18:36:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Temp [2011.11.05 21:23:08 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Windows Live Writer [2011.11.06 19:22:40 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\XnView ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.11.05 15:36:43 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2011.07.26 10:36:56 | 000,000,000 | ---D | M] -- C:\book [2013.01.24 14:16:11 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2011.11.05 15:32:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2011.03.11 10:11:28 | 000,000,000 | ---D | M] -- C:\Intel [2011.11.05 15:53:55 | 000,000,000 | RH-D | M] -- C:\MSOCache [2012.09.28 07:31:04 | 000,000,000 | ---D | M] -- C:\NVIDIA [2012.10.21 16:09:27 | 000,000,000 | -H-D | M] -- C:\OEM [2009.07.14 04:20:08 | 000,000,000 | -H-D | M] -- C:\PerfLogs [2011.11.05 21:34:58 | 000,000,000 | ---D | M] -- C:\prgs [2012.11.30 18:45:59 | 000,000,000 | R--D | M] -- C:\Program Files [2013.01.18 21:58:55 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2013.01.24 14:41:39 | 000,000,000 | -H-D | M] -- C:\ProgramData [2011.11.05 15:32:49 | 000,000,000 | -HSD | M] -- C:\Programme [2011.11.05 15:32:49 | 000,000,000 | -HSD | M] -- C:\Recovery [2013.01.24 15:28:02 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2013.01.21 22:03:03 | 000,000,000 | ---D | M] -- C:\Temp [2012.09.28 07:32:59 | 000,000,000 | R--D | M] -- C:\Users [2013.01.24 14:42:46 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < C:\Windows\system32\*.tsp > [2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp [2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp [2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp [2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp [2010.11.21 04:23:55 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp [2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] [2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2009.07.14 06:08:49 | 000,032,640 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011.11.06 17:17:08 | 000,001,106 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2011.11.06 17:17:08 | 000,001,110 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [2012.04.03 10:29:13 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job < MD5 for: AGP440.SYS > [2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys [2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys < MD5 for: AHCIX86S.SYS > [2010.09.24 02:48:00 | 000,222,288 | ---- | M] (Advanced Micro Devices, Inc) MD5=A3F4FEE7E8C40242FD6CD77DAE51370F -- C:\OEM\Preload\Autorun\DRV\AMD VGA Generic Driver\Packages\Drivers\SBDrv\SB8xx\RAID\W7\ahcix86s.sys < MD5 for: ATAPI.SYS > [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll [2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: EXPLORER.EXE > [2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe [2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe [2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe [2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe [2010.11.21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe [2010.11.21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe < MD5 for: IASTOR.SYS > [2010.11.06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- C:\Windows\SysNative\drivers\iaStor.sys [2010.11.06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_710b330fb3531234\iaStor.sys < MD5 for: IASTORV.SYS > [2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys [2010.11.21 04:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys [2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys [2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys [2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll [2010.11.21 04:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll [2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll [2010.11.21 04:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys [2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys [2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys [2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys [2010.11.21 04:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys < MD5 for: SCECLI.DLL > [2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll [2010.11.21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll [2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll [2010.11.21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll < MD5 for: USER32.DLL > [2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll [2010.11.21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll [2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll [2010.11.21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll < MD5 for: USERINIT.EXE > [2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe [2010.11.21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe [2010.11.21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe < MD5 for: WINLOGON.EXE > [2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010.11.21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys [2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\*.dll /lockedfiles > [2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < %USERPROFILE%\*.* > [2012.05.09 14:03:21 | 000,000,028 | ---- | M] () -- C:\Users\Manuel\.gtk-bookmarks [2012.12.25 23:06:06 | 000,000,036 | ---- | M] () -- C:\Users\Manuel\.org.eclipse.epp.usagedata.recording.userId [2013.01.24 19:54:42 | 006,029,312 | -HS- | M] () -- C:\Users\Manuel\NTUSER.DAT [2013.01.24 19:54:42 | 000,262,144 | -HS- | M] () -- C:\Users\Manuel\ntuser.dat.LOG1 [2011.11.05 15:33:07 | 000,000,000 | -HS- | M] () -- C:\Users\Manuel\ntuser.dat.LOG2 [2011.11.05 15:45:00 | 000,065,536 | -HS- | M] () -- C:\Users\Manuel\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2011.11.05 15:45:00 | 000,524,288 | -HS- | M] () -- C:\Users\Manuel\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2011.11.05 15:45:00 | 000,524,288 | -HS- | M] () -- C:\Users\Manuel\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.11.21 03:50:53 | 000,000,020 | -HS- | M] () -- C:\Users\Manuel\ntuser.ini [2012.10.27 16:27:01 | 000,000,326 | ---- | M] () -- C:\Users\Manuel\stools_.log [2012.10.27 17:04:36 | 000,005,516 | ---- | M] () -- C:\Users\Manuel\stools_proe.log [1 C:\Users\Manuel\*.tmp files -> C:\Users\Manuel\*.tmp -> ] < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < > < End of report > |
Computer wird bei Verbindung mit dem Internet gesperrt hi dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL [2013.01.24 15:32:19 | 095,023,320 | ---- | M] () -- C:\ProgramData\HizKK03.pad [2013.01.24 14:41:39 | 000,003,223 | ---- | M] () -- C:\ProgramData\HizKK03.js [2013.01.24 14:41:39 | 000,001,085 | ---- | M] () -- C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk [2013.01.24 14:41:39 | 000,000,153 | ---- | M] () -- C:\ProgramData\HizKK03.reg [2013.01.24 14:41:39 | 000,000,080 | ---- | M] () -- C:\ProgramData\HizKK03.bat :Files :Commands [EMPTYFLASH] [emptytemp] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden
-Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet
Computer wird bei Verbindung mit dem Internet gesperrtCode:
ATTFilter All processes killed Error: Unable to interpret <%:OTL> in the current context! Error: Unable to interpret <[2013.01.24 15:32:19 | 095,023,320 | ---- | M] () -- C:\ProgramData\HizKK03.pad> in the current context! Error: Unable to interpret <[2013.01.24 14:41:39 | 000,003,223 | ---- | M] () -- C:\ProgramData\HizKK03.js> in the current context! Error: Unable to interpret <[2013.01.24 14:41:39 | 000,001,085 | ---- | M] () -- C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk> in the current context! Error: Unable to interpret <[2013.01.24 14:41:39 | 000,000,153 | ---- | M] () -- C:\ProgramData\HizKK03.reg> in the current context! Error: Unable to interpret <[2013.01.24 14:41:39 | 000,000,080 | ---- | M] () -- C:\ProgramData\HizKK03.bat> in the current context! ========== FILES ========== ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 42016 bytes User: Default User ->Flash cache emptied: 0 bytes User: Manuel ->Flash cache emptied: 42148 bytes User: Public User: UpdatusUser ->Flash cache emptied: 42016 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Manuel ->Temp folder emptied: 1243166758 bytes ->Temporary Internet Files folder emptied: 491266648 bytes ->Java cache emptied: 7153767 bytes ->FireFox cache emptied: 325477772 bytes ->Google Chrome cache emptied: 32072876 bytes ->Flash cache emptied: 0 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 356352 bytes %systemroot%\System32 .tmp files removed: 1564672 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8136530440 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 279610 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 763 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes RecycleBin emptied: 6308995229 bytes Total Files Cleaned = 15.780,00 mb OTL by OldTimer - Version log created on 01242013_210404 Files\Folders moved on Reboot... C:\Users\Manuel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Computer wird bei Verbindung mit dem Internet gesperrt hi du hast da beim kopieren n fehler gemacht, füre das Script noch mal aus bitte
--> Computer wird bei Verbindung mit dem Internet gesperrt
Computer wird bei Verbindung mit dem Internet gesperrt Kann ich die exe auch im normalen modus ausfuehren ??? Es wurde aber trotzdem gemeldet dass dateien fehlen ;-) habs jetzt nochmal probiert: Es ging dieses mal sehr schnell und demzufolge denke ich dass es schon beim ersten mal erfolgreich gewesen sein muss ... die zweite log folgt gleich Code:
ATTFilter All processes killed ========== OTL ========== C:\ProgramData\HizKK03.pad moved successfully. C:\ProgramData\HizKK03.js moved successfully. C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk moved successfully. C:\ProgramData\HizKK03.reg moved successfully. C:\ProgramData\HizKK03.bat moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Manuel ->Flash cache emptied: 492 bytes User: Public User: UpdatusUser ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Manuel ->Temp folder emptied: 66292 bytes ->Temporary Internet Files folder emptied: 1087916 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 840 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,00 mb OTL by OldTimer - Version log created on 01242013_214203 Files\Folders moved on Reboot... C:\Users\Manuel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Computer wird bei Verbindung mit dem Internet gesperrt jetzt hatts geklappt. download tdss killer: http://www.trojaner-board.de/82358-t...entfernen.html Klicke auf Change parameters • Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system • Klick auf OK und anschließend auf Start scan - bei funden erst mal immer skip wählen, log posten c: öffnen, tdsskiller-datum-version.txt öffnen, Inhalt posten
-Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet
Computer wird bei Verbindung mit dem Internet gesperrtCode:
ATTFilter 14:21:58.0396 5312 TDSS rootkit removing tool Oct 31 2012 21:47:35 14:21:58.0656 5312 ============================================================ 14:21:58.0656 5312 Current date / time: 2013/01/25 14:21:58.0656 14:21:58.0656 5312 SystemInfo: 14:21:58.0656 5312 14:21:58.0656 5312 OS Version: 6.1.7601 ServicePack: 1.0 14:21:58.0656 5312 Product type: Workstation 14:21:58.0656 5312 ComputerName: M-PC2 14:21:58.0656 5312 UserName: Manuel 14:21:58.0656 5312 Windows directory: C:\Windows 14:21:58.0656 5312 System windows directory: C:\Windows 14:21:58.0656 5312 Running under WOW64 14:21:58.0656 5312 Processor architecture: Intel x64 14:21:58.0656 5312 Number of processors: 8 14:21:58.0656 5312 Page size: 0x1000 14:21:58.0656 5312 Boot type: Normal boot 14:21:58.0656 5312 ============================================================ 14:21:59.0115 5312 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:21:59.0155 5312 Drive \Device\Harddisk6\DR6 - Size: 0x3E100000 (0.97 Gb), SectorSize: 0x200, Cylinders: 0x7E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 14:21:59.0157 5312 ============================================================ 14:21:59.0157 5312 \Device\Harddisk0\DR0: 14:21:59.0157 5312 MBR partitions: 14:21:59.0157 5312 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2200800, BlocksNum 0x32000 14:21:59.0157 5312 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2232800, BlocksNum 0x39269800 14:21:59.0157 5312 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x3B49C015, BlocksNum 0x392699AC 14:21:59.0157 5312 \Device\Harddisk6\DR6: 14:21:59.0159 5312 MBR partitions: 14:21:59.0159 5312 \Device\Harddisk6\DR6\Partition1: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x1F07DF 14:21:59.0159 5312 ============================================================ 14:21:59.0186 5312 C: <-> \Device\Harddisk0\DR0\Partition2 14:21:59.0207 5312 D: <-> \Device\Harddisk0\DR0\Partition3 14:21:59.0207 5312 ============================================================ 14:21:59.0209 5312 Initialize success 14:21:59.0209 5312 ============================================================ 14:22:37.0045 4820 ============================================================ 14:22:37.0045 4820 Scan started 14:22:37.0045 4820 Mode: Manual; SigCheck; TDLFS; 14:22:37.0045 4820 ============================================================ 14:22:37.0242 4820 ================ Scan system memory ======================== 14:22:37.0242 4820 System memory - ok 14:22:37.0242 4820 ================ Scan services ============================= 14:22:37.0500 4820 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 14:22:37.0582 4820 1394ohci - ok 14:22:37.0604 4820 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 14:22:37.0614 4820 ACPI - ok 14:22:37.0628 4820 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 14:22:37.0693 4820 AcpiPmi - ok 14:22:37.0747 4820 [ 5AE65DCD983077278A6173C2872BCA99 ] acsock C:\Windows\system32\DRIVERS\acsock64.sys 14:22:37.0769 4820 acsock - ok 14:22:37.0835 4820 [ 1474F121C3DF1232D3E7239C03691EE6 ] AdobeActiveFileMonitor9.0 c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe 14:22:37.0849 4820 AdobeActiveFileMonitor9.0 - ok 14:22:37.0928 4820 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 14:22:37.0940 4820 AdobeARMservice - ok 14:22:38.0058 4820 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 14:22:38.0074 4820 AdobeFlashPlayerUpdateSvc - ok 14:22:38.0084 4820 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 14:22:38.0104 4820 adp94xx - ok 14:22:38.0110 4820 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 14:22:38.0125 4820 adpahci - ok 14:22:38.0144 4820 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 14:22:38.0155 4820 adpu320 - ok 14:22:38.0173 4820 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 14:22:38.0304 4820 AeLookupSvc - ok 14:22:38.0357 4820 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 14:22:38.0388 4820 AFD - ok 14:22:38.0403 4820 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 14:22:38.0415 4820 agp440 - ok 14:22:38.0439 4820 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 14:22:38.0487 4820 ALG - Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.
Computer wird bei Verbindung mit dem Internet gesperrt
ATTFilter ComboFix 13-01-24.02 - Manuel 25.01.2013 15:04:16.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6126.4160 [GMT 1:00] ausgeführt von:: c:\users\Manuel\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Manuel\~app.tmp c:\windows\Downloaded Program Files\IDropPTB.dll c:\windows\IsUn0407.exe c:\windows\SysWow64\muzapp.exe c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2012-12-25 bis 2013-01-25 )))))))))))))))))))))))))))))) . . 2013-01-25 14:09 . 2013-01-25 14:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-01-25 14:09 . 2013-01-25 14:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-01-25 13:49 . 2013-01-25 13:49 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{82AACAF2-271D-4F0A-95D7-03160217CFFF}\offreg.dll 2013-01-25 13:12 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{82AACAF2-271D-4F0A-95D7-03160217CFFF}\mpengine.dll 2013-01-24 20:11 . 2013-01-24 20:11 -------- d-----w- C:\found.000 2013-01-24 20:04 . 2013-01-24 20:04 -------- d-----w- C:\_OTL 2013-01-10 13:16 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll 2013-01-06 15:44 . 2013-01-06 15:44 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2012-12-29 01:54 . 2012-12-29 01:54 550328 ----a-w- c:\windows\SysWow64\nvStreaming.exe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-10 22:22 . 2011-11-05 16:22 67599240 ----a-w- c:\windows\system32\MRT.exe 2013-01-09 12:31 . 2012-04-03 09:29 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-09 12:31 . 2011-11-05 17:04 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-29 10:34 . 2012-10-10 20:23 2824656 ----a-w- c:\windows\system32\nvapi64.dll 2012-12-29 10:34 . 2012-10-10 20:23 1107592 ----a-w- c:\windows\system32\nvumdshimx.dll 2012-12-29 10:34 . 2012-10-10 20:23 15052368 ----a-w- c:\windows\system32\nvwgf2umx.dll 2012-12-29 10:34 . 2012-10-10 20:23 12641120 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2012-12-29 10:34 . 2012-10-10 20:22 2504248 ----a-w- c:\windows\SysWow64\nvapi.dll 2012-12-29 10:34 . 2012-10-10 20:22 15129064 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2012-12-29 10:34 . 2012-09-28 06:31 1813432 ----a-w- c:\windows\system32\nvdispco64.dll 2012-12-29 10:34 . 2012-09-28 06:31 1504696 ----a-w- c:\windows\system32\nvdispgenco64.dll 2012-12-29 08:40 . 2011-03-23 22:53 6382008 ----a-w- c:\windows\system32\nvcpl.dll 2012-12-29 08:40 . 2011-03-23 22:52 3455416 ----a-w- c:\windows\system32\nvsvc64.dll 2012-12-29 08:40 . 2012-09-28 06:32 2923201 ----a-w- c:\windows\system32\nvcoproc.bin 2012-12-29 08:40 . 2011-03-23 22:53 884152 ----a-w- c:\windows\system32\nvvsvc.exe 2012-12-29 08:40 . 2011-03-23 22:53 63928 ----a-w- c:\windows\system32\nvshext.dll 2012-12-29 08:40 . 2011-03-23 22:53 2558392 ----a-w- c:\windows\system32\nvsvcr.dll 2012-12-29 08:40 . 2011-03-23 22:53 118712 ----a-w- c:\windows\system32\nvmctray.dll 2012-12-18 22:06 . 2012-12-18 22:06 289768 ----a-w- c:\windows\system32\javaws.exe 2012-12-18 22:06 . 2012-12-18 22:06 189416 ----a-w- c:\windows\system32\javaw.exe 2012-12-18 22:06 . 2012-12-18 22:06 188904 ----a-w- c:\windows\system32\java.exe 2012-12-18 22:06 . 2012-12-18 22:06 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2012-12-18 22:06 . 2012-04-27 16:02 916456 ----a-w- c:\windows\system32\deployJava1.dll 2012-12-18 22:06 . 2012-04-27 16:02 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-12-16 17:11 . 2012-12-21 22:16 46080 ----a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 22:16 367616 ----a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 22:16 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 22:16 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2012-12-13 13:44 . 2012-12-13 13:44 11336 ----a-w- c:\windows\SysWow64\vpncategories.dll 2012-12-13 13:44 . 2012-12-13 13:44 34376 ----a-w- c:\windows\SysWow64\vpnevents.dll 2012-12-13 13:26 . 2011-09-09 15:59 112080 ----a-r- c:\windows\system32\drivers\acsock64.sys 2012-11-30 04:45 . 2013-01-10 13:16 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-11-14 07:06 . 2012-12-13 22:19 17811968 ----a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-13 22:19 10925568 ----a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-13 22:19 2312704 ----a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-13 22:19 1346048 ----a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-13 22:19 1392128 ----a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-13 22:19 1494528 ----a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-13 22:19 237056 ----a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-13 22:19 85504 ----a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-13 22:19 816640 ----a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-13 22:19 599040 ----a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-13 22:19 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-13 22:19 2144768 ----a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-13 22:19 729088 ----a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-13 22:19 96768 ----a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-13 22:19 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-13 22:19 248320 ----a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-13 22:19 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-13 22:19 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-13 22:19 1129472 ----a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-13 22:19 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-13 22:19 420864 ----a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-13 22:19 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-13 19:09 2048 ----a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-13 19:09 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2012-11-02 05:59 . 2012-12-13 19:08 478208 ----a-w- c:\windows\system32\dpnet.dll 2012-11-02 05:11 . 2012-12-13 19:08 376832 ----a-w- c:\windows\SysWow64\dpnet.dll 2012-11-01 10:02 . 2011-12-23 12:12 419840 ----a-w- c:\windows\system32\wrap_oal.dll 2012-11-01 10:02 . 2011-12-23 12:12 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2012-11-01 10:02 . 2011-12-23 12:12 111616 ----a-w- c:\windows\system32\OpenAL32.dll 2012-11-01 10:02 . 2011-12-23 12:12 102400 ----a-w- c:\windows\SysWow64\OpenAL32.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Software Suite SE"="c:\program files (x86)\Packard Bell\Software Suite SE\SoftSuiteSE.exe" [2009-09-29 2275360] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-10-11 842680] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-10-11 966072] "KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096] "Akamai NetSession Interface"="c:\users\Manuel\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "Hotkey Utility"="c:\program files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe" [2011-01-19 620136] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336] "HWTablet KeyPlus"="c:\windows\SysWOW64\HWKeyPlus.exe" [2008-06-03 53248] "HWTablet Service"="c:\windows\SysWOW64\HWTabTray.exe" [2009-03-05 184320] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280] "TrayServer"="c:\program files (x86)\MAGIX\Video_deluxe_17_Premium_Sonderedition\TrayServer.exe" [2008-08-07 90112] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "ADSK DLMSession"="c:\program files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe" [2012-07-23 1632216] "Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2012-12-13 702024] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Photo Frame.lnk - c:\program files (x86)\Northstar\Photo Frame\Photo Frame.exe [2011-7-26 516688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HWSuperPowerTablet;HWSuperPowerTablet;c:\windows\jwpen.exe [2008-06-03 66560] R2 HYRDBios;HYRDBios;c:\windows\system32\DRIVERS\HYRDBios.sys [x] R2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit;c:\program files\Autodesk\3ds Max 2013\NVIDIA\raysat_3dsmax2013_64server.exe [2011-09-15 86016] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys [2012-12-13 112080] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-26 1432400] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-12-24 412264] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104] R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-11 27760] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224] S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376] S2 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] S2 Live Updater Service;Live Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2011-01-31 244624] S2 mitsijm2013;Autodesk Moldflow Inventor Tool Suite Integration 2013 Job Manager;c:\program files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [2012-01-31 339776] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-07-02 2673064] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2012-12-13 544840] S3 cmudaxp;ASUS Xonar DGX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2011-12-20 2727936] S3 Ltn_stk7070P_64;PCTV based TV tuner device;c:\windows\system32\DRIVERS\Ltn_stk7070P_64.sys [2007-10-19 543232] S3 Ltn_stkrc_64;PCTV Infrared Receiver;c:\windows\system32\DRIVERS\Ltn_stkrc_64.sys [2007-10-19 16256] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136] S3 LVUVC64;Logitech Webcam 500(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2012-07-02 35112] S3 VHWDrawing;HanWang Drawing Tablet;c:\windows\system32\DRIVERS\HWDrawing.sys [2007-03-26 8320] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - 62758286 *Deregistered* - 62758286 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-24 20:54 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.56\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-01-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 12:31] . 2013-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-06 16:17] . 2013-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-06 16:17] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-28 497648] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 2184520] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2011-05-12 8769536] "Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704] "Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112] "Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.de/ mDefault_Page_URL = hxxp://packardbell.msn.com mStart Page = hxxp://packardbell.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 TCP: Interfaces\{DDFA9DF7-7226-4B4B-B1B3-F93EDF312F18}: NameServer = FF - ProfilePath - c:\users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\6zvrdmdc.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-NPSStartup - (no file) Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-01-25 15:10:47 ComboFix-quarantined-files.txt 2013-01-25 14:10 . Vor Suchlauf: 11 Verzeichnis(se), 338.914.459.648 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 338.757.087.232 Bytes frei . - - End Of File - - 6BED520448483E08583C0B1CB215F418 Wie gehts weiter ?? |
Computer wird bei Verbindung mit dem Internet gesperrt
ATTFilter Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2013.01.25.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Manuel :: M-PC2 [Administrator] Schutz: Aktiviert 25.01.2013 17:42:42 mbam-log-2013-01-25 (17-42-42).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 706685 Laufzeit: 2 Stunde(n), 10 Minute(n), 37 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 D:\Downloads\vdownloader112\vdownloader_setup.exe (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Es wurde allerdings nur eine Datein gefunden ... Symptome sind aber schon seit ner weile weg ... Also mittlerweile geht so ziemlich alles ... aber ich habe so das gefühl das hochfahren dauert länger als vorher .... |
Computer wird bei Verbindung mit dem Internet gesperrt
ATTFilter 7-Zip 9.23 (x64 edition) Igor Pavlov 06.11.2011 4,21MB Notwendig Acrobat.com Adobe Systems Incorporated 11.03.2011 1,60MB 1.6.65 Notwendig ActiveX контрола на Windows Live Mesh за отдалечени връзки Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt ActiveX-kontroll för fjärranslutningar för Windows Live Mesh Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Adobe AIR Adobe Systems Inc. 26.07.2011 Unbekannt Adobe Community Help Adobe Systems Incorporated 26.07.2011 Unbekannt Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 08.01.2013 6,00MB 11.5.502.146 Unbekannt Adobe Flash Player 11 Plugin Adobe Systems Incorporated 09.01.2013 6,00MB 11.5.502.146 Unbekannt Adobe Photoshop Elements 9 Adobe Systems Incorporated 11.02.2012 2,60GB Notwendig Adobe Premiere Elements 9 Adobe Systems Incorporated 26.07.2011 1,23GB 9.0 Unbekannt Adobe Reader X (10.1.5) - Deutsch Adobe Systems Incorporated 10.01.2013 122MB 10.1.5 Notwendig Akamai NetSession Interface Akamai Technologies, Inc 26.11.2012 Unbekannt Apple Application Support Apple Inc. 08.11.2012 65,0MB 2.3 Unbekannt Apple Software Update Apple Inc. 10.11.2011 2,38MB Unbekannt ASUS Xonar DG Audio Driver 01.11.2012 Notwendig Audacity 1.2.6 06.11.2011 Notwendig Autodesk 3ds Max 2013 64-bit Autodesk 01.12.2012 Notwendig Autodesk Backburner 2013.0.0 Autodesk, Inc. 29.11.2012 12,8MB 2013.0.0 Notwendig Autodesk Design Review 2013 Autodesk, Inc. 26.11.2012 Notwendig Autodesk DirectConnect 2013 64-bit Autodesk 29.11.2012 1,06GB Notwendig Autodesk Download Manager Autodesk, Inc. 26.11.2012 15,0MB Notwendig Autodesk Essential Skills Movies for 3ds Max 2013 64-bit Autodesk 01.12.2012 337MB Notwendig Autodesk FBX Plug-in 2013.1 - 3ds Max 2013 64-bit Autodesk 01.12.2012 Notwendig Autodesk FBX Plug-in 2013.1 - Maya 2013 64-bit Autodesk 29.11.2012 Notwendig Autodesk Inventor Content Center Libraries 2013 (Desktop Content) Autodesk 26.11.2012 1,31MB 17.0.13800.0000 Notwendig Autodesk Inventor Fusion 2013 Autodesk, Inc. 26.11.2012 585MB Notwendig Autodesk Inventor Fusion for Inventor 2013 Add-in Autodesk 26.11.2012 12,9MB Notwendig Autodesk Inventor Professional 2013 Deutsch (German) Autodesk 26.11.2012 3,48GB 17.0.13800.0000 Notwendig Autodesk Inventor Server Engine for 3ds Max 2013 64-bit Autodesk 01.12.2012 332MB 15.0 Notwendig Autodesk MatchMover 2013 64-bit Autodesk 29.11.2012 361MB 14.00.0000 Notwendig Autodesk Material Library 2013 Autodesk 26.11.2012 94,9MB 3.0.13 Notwendig Autodesk Material Library Base Resolution Image Library 2013 Autodesk 26.11.2012 71,4MB 3.0.13 Notwendig Autodesk Material Library Low Resolution Image Library 2013 Autodesk 26.11.2012 245MB 3.0.13 Notwendig Autodesk Material Library Medium Resolution Image Library 2013 Autodesk 01.12.2012 739MB 3.0.13 Notwendig Autodesk Maya 2013 64-bit Autodesk 29.11.2012 Notwendig Autodesk Revit Interoperability for 3ds Max and 3ds Max Design 2013 64-bit Autodesk 01.12.2012 589MB Notwendig Autodesk Sync Autodesk, Inc. 26.11.2012 45,3MB Notwendig Autodesk Vault Basic 2013 (Client) Autodesk 26.11.2012 Notwendig Avira Free Antivirus Avira 14.11.2012 104MB Notwendig Bridge Building Game 16.02.2012 Unnötig Canon MP640 series Benutzerregistrierung 16.05.2012 Notwendig Canon MP640 series MP Drivers 16.05.2012 Notwendig Canon Utilities My Printer 16.05.2012 Notwendig CCleaner Piriform 23.01.2013 3.27 ------------------- CD-LabelPrint 16.05.2012 Notwendig Cisco AnyConnect Secure Mobility Client Cisco Systems, Inc. 09.01.2013 3.1.02026 Notwendig Composite 2013 64-bit Autodesk 29.11.2012 621MB 8.0.0 Notwendig Control ActiveX de Windows Live Mesh para conexiones remotas Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Control ActiveX del Windows Live Mesh per a connexions remotes Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Control ActiveX Windows Live Mesh pentru conexiuni la distanță Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Controle ActiveX do Windows Live Mesh para Conexões Remotas Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Controlo ActiveX do Windows Live Mesh para Ligações Remotas Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Contrôle ActiveX Windows Live Mesh pour connexions à distance Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt CyberLink MediaEspresso CyberLink Corp. 26.07.2011 164MB 6.5.1615_36053b Notwendig DWG TrueView 2013 Autodesk 26.11.2012 Notwendig Eco Materials Adviser for Autodesk Inventor 2013 Granta Design Limited 26.11.2012 50,0MB Notwendig Emergency 2012 Deluxe Quadriga Games GmbH 20.12.2011 Unnötig Emergency4 25.11.2011 1.03.001 Unnötig EVEREST Home Edition v2.20 Lavalys Inc 21.10.2012 2.20 Notwendig FIFA 13 Electronic Arts 26.09.2012 5,26GB Notwendig Firebird SQL Server - MAGIX Edition MAGIX AG 09.11.2011 10,1MB Notwendig Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Franzis 3D-Eisenbahnplaner 11 Franzis 04.01.2012 Notwendig FreeCommander 2009.02b Marek Jasinski 23.06.2012 2009.02 Notwendig GIMP 2.8.0 The GIMP Team 10.05.2012 241MB 2.8.0 Notwendig Google Chrome Google Inc. 06.11.2011 24.0.1312.56 Notwendig Google Earth Google 06.11.2011 92,7MB Notwendig Hotkey Utility Packard Bell 26.07.2011 2.05.3014 Unbekannt Identity Card Packard Bell 26.07.2011 1.00.3006 Unbekannt Intel(R) Management Engine Components Intel Corporation 26.07.2011 Unbekannt Intel(R) Rapid Storage Technology Intel Corporation 26.07.2011 Unbekannt Internet-TV für Windows Media Center Microsoft Corporation 06.11.2011 13,6MB Notwendig IrfanView (remove only) Irfan Skiljan 06.11.2011 1,50MB 4.30 Notwendig Java 7 Update 9 (64-bit) Oracle 18.12.2012 127MB 7.0.90 Notwendig Java SE Development Kit 7 Update 4 (64-bit) Oracle 27.04.2012 143MB Notwendig Java SE Development Kit 7 Update 9 (64-bit) Oracle 18.12.2012 188MB Notwendig Java(TM) 6 Update 37 Oracle 05.09.2012 95,7MB 6.0.370 Notwendig JavaFX 2.1.0 (64-bit) Oracle Corporation 27.04.2012 23,7MB 2.1.0 Notwendig JavaFX 2.1.0 SDK (64-bit) Oracle Corporation 27.04.2012 79,6MB 2.1.0 Notwendig Kontrola Windows Live Mesh ActiveX za daljinske veze Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Landwirtschafts Simulator 2013 GIANTS Software 03.11.2012 282MB 1.0 Notwendig Logitech Webcam-Software Logitech Inc. 05.11.2011 2.30 Notwendig MAGIX Screenshare MAGIX AG 12.11.2011 1,42MB Notwendig MAGIX Speed burnR (MSI) MAGIX AG 12.11.2011 51,1MB Notwendig MAGIX Video deluxe 17 Premium Sonderedition MAGIX AG 12.11.2011 Notwendig Malwarebytes Anti-Malware Version Malwarebytes Corporation 25.01.2013 18,4MB ------------------ Microsoft .NET Framework 4 Client Profile Microsoft Corporation 24.07.2012 38,8MB 4.0.30320 Unbekannt Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 24.07.2012 2,93MB 4.0.30320 Unbekannt Microsoft .NET Framework 4 Extended Microsoft Corporation 26.11.2012 51,9MB 4.0.30319 Unbekannt Microsoft .NET Framework 4 Extended DEU Language Pack Microsoft Corporation 26.11.2012 10,6MB 4.0.30319 Unbekannt Microsoft Image Composite Editor Microsoft Corporation 30.11.2012 5,16MB 1.4.4 Unbekannt Microsoft IntelliPoint 8.2 Microsoft Corporation 16.05.2012 8.20.468.0 Unbekannt Microsoft Office Home and Student 2010 Microsoft Corporation 05.11.2011 14.0.6029.1000 Unbekannt Microsoft Silverlight Microsoft Corporation 11.05.2012 80,3MB 4.1.10329.0 Unbekannt Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 26.07.2011 1,69MB 3.1.0000 Unbekannt Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 24.01.2012 250KB 8.0.50727.4053 Notwendig Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 05.11.2011 300KB 8.0.59193 Notwendig Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 26.11.2012 620KB 8.0.61000 Notwendig Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 11.03.2011 784KB 9.0.30729.4148 Notwendig Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 05.11.2011 788KB 9.0.30729.6161 Notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 10.12.2011 234KB 9.0.30729 Notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 11.03.2011 240KB 9.0.30729 Notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 11.03.2011 596KB 9.0.30729.4148 Notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 05.11.2011 600KB 9.0.30729.6161 Notwendig Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 28.09.2012 13,8MB 10.0.40219 Notwendig Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 05.11.2011 16,5MB 10.0.40219 Notwendig Microsoft WSE 3.0 Runtime Microsoft Corp. 26.11.2012 942KB 3.0.5305.0 Unbekannt Mozilla Firefox 19.0 (x86 de) Mozilla 26.01.2013 44,3MB 19.0 Notwendig Mozilla Maintenance Service Mozilla 11.01.2013 330KB 19.0 Unbekannt MSXML 4.0 SP2 (KB954430) Microsoft Corporation 05.11.2011 1,27MB 4.20.9870.0 Unbekannt MSXML 4.0 SP2 (KB973688) Microsoft Corporation 05.11.2011 1,33MB 4.20.9876.0 Unbekannt MyFreeCodec 24.04.2012 Unbekannt Nero DiscSpeed 10 Nero AG 11.03.2011 7,21MB 6.2.10500.2.100 Notwendig Nero Express 10 Nero AG 11.03.2011 165MB 10.2.12000.21.100 Notwendig Nero Multimedia Suite 10 Essentials Nero AG 11.03.2011 372MB 10.5.10300 Notwendig Nero StartSmart 10 Nero AG 11.03.2011 143MB 10.2.11600.14.100 Notwendig Nero Update Nero AG 11.03.2011 1,43MB 1.0.0018 Notwendig NewBlue Light Rays for Magix NewBlue 12.11.2011 1.4 Notwendig NewBlue Lightning for Magix NewBlue 12.11.2011 1.4 Notwendig NewBlueFX Premium Effects NewBlue 12.11.2011 1.4 Notwendig NVIDIA 3D Vision Controller-Treiber 310.90 NVIDIA Corporation 06.01.2013 310.90 Notwendig NVIDIA 3D Vision Treiber 310.90 NVIDIA Corporation 06.01.2013 310.90 Notwendig NVIDIA Grafiktreiber 310.90 NVIDIA Corporation 06.01.2013 310.90 Notwendig NVIDIA HD-Audiotreiber NVIDIA Corporation 06.01.2013 Notwendig NVIDIA PhysX-Systemsoftware 9.12.1031 NVIDIA Corporation 06.01.2013 9.12.1031 Notwendig NVIDIA Update 1.11.3 NVIDIA Corporation 06.01.2013 1.11.3 Notwendig OpenAL 01.11.2012 Unbekannt Origin Electronic Arts, Inc. 26.09.2012 Notwendig Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Packard Bell Games WildTangent 11.03.2011 Unbekannt Packard Bell Recovery Management Packard Bell 11.03.2011 5.00.3002 Unbekannt Packard Bell Registration Packard Bell 26.07.2011 1.03.3003 Unbekannt Packard Bell ScreenSaver Packard Bell 26.07.2011 1.1.0225.2011 Unbekannt Packard Bell Software Suite SE Packard Bell 26.07.2011 2.01.3003 Unbekannt Packard Bell Updater Packard Bell 11.03.2011 1.02.3005 Unbekannt PCTV Package - Windows Media Center PCTV Systems 05.11.2011 16,1MB Notwendig Photo Frame Northstar Systems Corp. 26.07.2011 17,8MB Notwendig PlayReady PC Runtime amd64 Microsoft Corporation 05.11.2011 2,05MB 1.3.0 Notwendig Pro/ENGINEER Release Wildfire 5.0 Datecode M060 PTC 09.11.2012 Wildfire 5.0 Notwendig Pro/ENGINEER Thumbnail Viewer 1.0 PTC 09.11.2012 15,6MB 28.10.280 Notwendig proDAD Adorage 3.0 proDAD GmbH 12.11.2011 3.0.61 Notwendig proDAD Heroglyph 2.5 proDAD GmbH 12.11.2011 2.6.32 Notwendig proDAD Mercalli 2.0 proDAD GmbH 12.11.2011 2.0.61 Notwendig ProductView Express 9.1 PTC 31.01.2012 269MB Notwendig QuickTime Apple Inc. 08.11.2012 73,1MB Notwendig Realtek Ethernet Controller Driver Realtek 11.03.2011 7.36.1224.2010 Notwendig Realtek High Definition Audio Driver Realtek Semiconductor Corp. 26.07.2011 Notwendig Samsung Kies Samsung Electronics Co., Ltd. 24.04.2012 207MB Notwendig SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 06.11.2012 42,9MB Notwendig Schnell-Deinstallations-Tool für Autodesk Inventor 2013 Autodesk 26.11.2012 1,78MB 17.0.13800.0000 Notwendig SDFormatter SD Association 03.10.2012 3,57MB 3.1.0 Notwendig Skype™ 5.10 Skype Technologies S.A. 20.09.2012 19,4MB 5.10.116 Notwendig Tabellenbuch Metall 7.0 Verlag Europa-Lehrmittel 22.11.2011 7.0 Notwendig Tablet Driver Hanwang technolgy 06.11.2011 2.05.0000 Notwendig TeamViewer 7 TeamViewer 07.07.2012 7.0.13852 Notwendig Urruneko konexioetarako Windows Live Mesh ActiveX kontrola Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Vasco da Gama 4 HDPro MotionStudios 12.11.2011 891MB 4.00.0000 Notwendig VLC media player 1.1.11 VideoLAN 06.11.2011 1.1.11 Notwendig Welcome Center Packard Bell 26.07.2011 1.02.3102 Unbekannt Windows Live Essentials Microsoft Corporation 03.05.2012 15.4.3555.0308 Unbekannt Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Windows Live Mesh ActiveX Control for Remote Connections Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Windows Live Mesh ActiveX control for remote connections Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt Windows Live Mesh ActiveX-objekt til fjernforbindelser Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz Microsoft Corporation 20.11.2011 5,38MB 15.4.5722.2 Unbekannt Windows Live Meshin etäyhteyksien ActiveX-komponentti Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt XnView 1.98.2 Gougelet Pierre-e 06.11.2011 36,7MB 1.98.2 Notwendig Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt Элемент управления Windows Live Mesh ActiveX для удаленных подключений Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة Microsoft Corporation 20.11.2011 5,57MB 15.4.5722.2 Unbekannt ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt 適用遠端連線的 Windows Live Mesh ActiveX 控制項 Microsoft Corporation 20.11.2011 5,37MB 15.4.5722.2 Unbekannt |
