|
Log-Analyse und Auswertung: Windows System Repair VirusWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.02.2013, 17:52 | #1 |
| Windows System Repair Virus Hallo zusammen Wahrscheinlich habe ich mir den Windows System Repair-Virus eingefangen. Auf die daraufgehende forderung nach angabe der mail bin ich nicht eingegangen. Nachdem wir den PC wiederhergestellt hatten war der bekannte schwarze Bildschirm und die zig-tausenden Fehlermeldungen verschwunden.. Leider waren aber alle Dateien verschwunden. Nun habe ich dank der Hilfe "alle Dateien anzeigen lassen" diese wieder sichtbar machen können, jedoch sind sie bei meinem Windows 7-System "hell" dargestellt, also mit keiner Farbinsensität und bei vielen ist ein Schloss-Symbol ersichtlich. Wie bekomm ich das weg? Rechtsklick und Freigabemöglichkeiten auswählen hat nichts gebracht. Habe mich schon ein wenig in das Thema eingelesen und deswegen auch den Malware-Byte durchlauf gemacht.. Untenstehend findet ihr den Log-bericht. Infisziert war nur eine Datei. ( Softonic, lustig da ich Malware-Byte über diese Plattform geladen habe). Was sollte ich als nächtes tun, bzw. habt ihr mir sonstige Tipps? Leider habe ich auch schon ein ähnliches Thema hier im Forum gesehen wo der Problemlösungsprozess darin geendet hat, dass der PC nicht mehr funktioniert. Ist die Gefahr diesbezüglich gross? Vielen Dank im Voraus Swiss Malwarebytes Anti-Malware (Test) 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.02.21.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 usche :: USCHE-PC [Administrator] Schutz: Aktiviert 21.02.2013 17:31:41 MBAM-log-2013-02-21 (17-35-16).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 207870 Laufzeit: 2 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\usche\Downloads\SoftonicDownloader_fuer_eclipsecrossword.exe (PUP.OfferBundler.ST) -> Keine Aktion durchgeführt. (Ende) |
21.02.2013, 18:10 | #2 |
/// Helfer-Team | Windows System Repair VirusSystemscan mit OTL (bebilderte Anleitung) Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
dann: http://www.trojaner-board.de/96905-r...-sichtbar.html
__________________ |
21.02.2013, 19:49 | #3 |
| Windows System Repair Virus OTL Logfile:
__________________Code:
ATTFilter OTL logfile created on: 21.02.2013 19:38:01 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\usche\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 56,31% Memory free 8,00 Gb Paging File | 6,08 Gb Available in Paging File | 76,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1384,15 Gb Total Space | 1253,44 Gb Free Space | 90,56% Space Free | Partition Type: NTFS Drive D: | 13,01 Gb Total Space | 1,79 Gb Free Space | 13,78% Space Free | Partition Type: NTFS Computer Name: USCHE-PC | User Name: usche | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\usche\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) PRC - C:\Users\usche\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.) PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) PRC - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.) PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH) PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH) PRC - C:\Program Files (x86)\Greenshot\Greenshot.exe () PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink) PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard) ========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () MOD - C:\Program Files (x86)\Greenshot\Greenshot.exe () MOD - C:\Program Files (x86)\Greenshot\GreenshotPlugin.dll () MOD - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll () ========== Services (SafeList) ========== SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software) SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.) SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH) SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (Macromedia Licensing Service) -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe () SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS) ========== Driver Services (SafeList) ========== DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH) DRV:64bit: - (81215182) -- C:\Windows\SysNative\drivers\81215182.sys (Kaspersky Lab) DRV:64bit: - (81215181) -- C:\Windows\SysNative\drivers\81215181.sys (Kaspersky Lab) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (pavboot) -- C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (netr28x) -- C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.) DRV:64bit: - (s217bus) -- C:\Windows\SysNative\drivers\s217bus.sys (MCCI Corporation) DRV:64bit: - (s217mdm) -- C:\Windows\SysNative\drivers\s217mdm.sys (MCCI Corporation) DRV:64bit: - (s217unic) -- C:\Windows\SysNative\drivers\s217unic.sys (MCCI) DRV:64bit: - (s217obex) -- C:\Windows\SysNative\drivers\s217obex.sys (MCCI Corporation) DRV:64bit: - (s217nd5) -- C:\Windows\SysNative\drivers\s217nd5.sys (MCCI Corporation) DRV:64bit: - (s217mdfl) -- C:\Windows\SysNative\drivers\s217mdfl.sys (MCCI Corporation) DRV:64bit: - (LVUSBS64) -- C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.) DRV:64bit: - (PID_0928) -- C:\Windows\SysNative\drivers\LV561V64.sys (Logitech Inc.) DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software) DRV - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) -- c:\Programme\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (Exfvcpsmv) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (PxHelp20) -- C:\Windows\SysWOW64\drivers\pxhelp20.sys (Sonic Solutions) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/12 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/12 IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0788A278-0871-4CAB-A008-D692A747C31D} IE:64bit: - HKLM\..\SearchScopes\{0788A278-0871-4CAB-A008-D692A747C31D}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/12 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/12 IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} IE - HKLM\..\SearchScopes\{0788A278-0871-4CAB-A008-D692A747C31D}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031785 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bluewin.ch/ IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\SearchScopes,DefaultScope = {C7D69E10-6CCC-4959-AFEF-EEDE56D0A4CD} IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\SearchScopes\{0788A278-0871-4CAB-A008-D692A747C31D}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=9011 IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031785 IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\SearchScopes\{C7D69E10-6CCC-4959-AFEF-EEDE56D0A4CD}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "Winload Customized Web Search" FF - prefs.js..browser.startup.homepage: "www.bluewin.ch" FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.2.0 FF - prefs.js..extensions.enabledAddons: testpilot%40labs.mozilla.com:1.2.2 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.0 FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5 FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.3 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94 FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94 FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2010.9.0.6 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9 FF - prefs.js..extensions.enabledItems: {19f54e13-741b-423c-ab48-fd8c43be2e46}:3.6.0.10 FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.6.0.10 FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:3.0.2 FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?babsrc=toolbar2&q=" FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.03.13 13:11:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011.04.06 20:07:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011.04.06 20:07:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.03.12 22:23:56 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\usche\AppData\Roaming\mozilla\Extensions [2013.02.21 12:47:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\usche\AppData\Roaming\mozilla\Firefox\Profiles\e40hyr28.default\extensions [2013.02.21 12:53:30 | 000,000,000 | ---D | M] (SFT-Switzerland DE_ Community Toolbar) -- C:\Users\usche\AppData\Roaming\mozilla\Firefox\Profiles\e40hyr28.default\extensions\{19f54e13-741b-423c-ab48-fd8c43be2e46} [2013.02.21 12:53:30 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\usche\AppData\Roaming\mozilla\Firefox\Profiles\e40hyr28.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2013.02.21 12:53:30 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\usche\AppData\Roaming\mozilla\Firefox\Profiles\e40hyr28.default\extensions\ffxtlbr@babylon.com [2012.09.12 07:44:06 | 000,621,521 | -H-- | M] () (No name found) -- C:\Users\usche\AppData\Roaming\mozilla\firefox\profiles\e40hyr28.default\extensions\testpilot@labs.mozilla.com.xpi [2013.02.14 07:46:19 | 000,817,280 | -H-- | M] () (No name found) -- C:\Users\usche\AppData\Roaming\mozilla\firefox\profiles\e40hyr28.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011.08.14 13:52:46 | 000,000,917 | -H-- | M] () -- C:\Users\usche\AppData\Roaming\mozilla\firefox\profiles\e40hyr28.default\searchplugins\conduit.xml ========== Chrome ========== CHR - homepage: hxxp://www.google.com/ CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - Extension: YouTube = C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: DivX HiQ = C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\ CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\ CHR - Extension: Google Mail = C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\Toolbar\WebBrowser: (no name) - {19F54E13-741B-423C-AB48-FD8C43BE2E46} - No CLSID value found. O3 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\Toolbar\WebBrowser: (no name) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - No CLSID value found. O3 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Programme\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS) O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe (Hewlett-Packard) O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) O4 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001..\Run: [Greenshot] C:\Program Files (x86)\Greenshot\Greenshot.exe () O4 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) O4 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\usche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\usche\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0 O7 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O7 - HKU\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0 O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5F3B3B9B-B754-42F4-91FF-674F1866868F}: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E8DC73D6-81F1-4EA7-98A6-DB1513B2AB5B}: DhcpNameServer = 192.168.1.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{f69045b1-14bc-11e0-a8e3-e0cb4e3ecc07}\Shell - "" = AutoRun O33 - MountPoints2\{f69045b1-14bc-11e0-a8e3-e0cb4e3ecc07}\Shell\AutoRun\command - "" = K:\Startme.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.02.21 19:36:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\usche\Desktop\OTL.exe [2013.02.21 17:30:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.02.21 17:30:31 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.02.21 17:30:08 | 000,000,000 | ---D | C] -- C:\Users\usche\AppData\Local\Programs [2013.02.21 17:29:46 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\usche\Desktop\mbam-setup-1-70-0-1100.exe [2013.02.21 16:53:04 | 081,819,288 | ---- | C] (Microsoft Corporation) -- C:\Users\usche\Desktop\msert.exe [2013.02.21 12:29:38 | 000,000,000 | ---D | C] -- C:\Users\usche\Documents\Eigene Datenquellen [2013.02.19 17:37:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013.02.19 17:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2013.02.19 13:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security [2013.02.19 09:02:50 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013.02.19 09:02:50 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013.02.19 09:02:49 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.02.19 09:02:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.02.19 09:02:48 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013.02.19 09:02:48 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013.02.19 09:02:48 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013.02.19 09:02:48 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013.02.19 09:02:47 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013.02.19 09:02:47 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013.02.19 09:02:46 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.02.19 09:02:46 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.02.19 09:02:44 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.02.19 09:02:44 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.02.19 09:02:44 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013.02.19 08:31:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus [2013.02.19 08:15:59 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.02.19 08:15:59 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.02.19 08:14:37 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2013.02.19 08:14:37 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013.02.19 08:14:37 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013.02.19 08:14:36 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013.02.19 08:14:36 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013.02.19 08:14:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013.02.19 08:13:57 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2013.02.14 07:55:32 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.02.08 11:58:16 | 000,000,000 | ---D | C] -- C:\Users\usche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ski Challenge 13 (CH) [2013.01.29 15:15:30 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\usche\*.tmp files -> C:\Users\usche\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.02.21 19:37:07 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.02.21 19:37:07 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.02.21 19:36:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\usche\Desktop\OTL.exe [2013.02.21 19:29:48 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.02.21 19:29:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.02.21 19:29:37 | 3220,627,456 | -HS- | M] () -- C:\hiberfil.sys [2013.02.21 18:48:01 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.02.21 17:30:33 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.02.21 17:30:04 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\usche\Desktop\mbam-setup-1-70-0-1100.exe [2013.02.21 17:03:56 | 000,000,850 | ---- | M] () -- C:\Users\usche\Desktop\msert.exe - Verknüpfung.lnk [2013.02.21 16:55:03 | 081,819,288 | ---- | M] (Microsoft Corporation) -- C:\Users\usche\Desktop\msert.exe [2013.02.21 07:39:07 | 000,405,512 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.02.19 16:25:10 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2013.02.19 13:16:45 | 000,001,288 | ---- | M] () -- C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk [2013.02.19 09:06:33 | 001,634,468 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.02.19 09:06:33 | 000,696,848 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.02.19 09:06:33 | 000,652,166 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.02.19 09:06:33 | 000,148,144 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.02.19 09:06:33 | 000,121,098 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.02.19 08:31:17 | 000,002,048 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2013.02.19 08:31:17 | 000,002,048 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2013.02.18 17:07:43 | 000,000,160 | -H-- | M] () -- C:\ProgramData\-xUFNiAkNknT [2013.02.18 17:07:37 | 000,000,168 | -H-- | M] () -- C:\ProgramData\xUFNiAkNknT [2013.02.18 16:08:35 | 000,000,176 | -H-- | M] () -- C:\ProgramData\-xUFNiAkNknTr [2013.02.17 09:32:04 | 001,840,050 | -H-- | M] () -- C:\Users\usche\Documents\Strahlung_VasenSY2013.pdf [2013.02.08 11:58:16 | 000,001,666 | ---- | M] () -- C:\Users\usche\Desktop\Ski Challenge 13 (CH) starten.lnk [2013.02.03 09:26:38 | 000,001,053 | ---- | M] () -- C:\Users\usche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013.02.03 09:26:03 | 000,001,021 | ---- | M] () -- C:\Users\usche\Desktop\Dropbox.lnk [2013.01.31 12:56:13 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Users\usche\*.tmp files -> C:\Users\usche\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.02.21 17:30:33 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.02.21 17:03:56 | 000,000,850 | ---- | C] () -- C:\Users\usche\Desktop\msert.exe - Verknüpfung.lnk [2013.02.19 13:16:45 | 000,001,288 | ---- | C] () -- C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk [2013.02.18 15:44:31 | 000,000,176 | -H-- | C] () -- C:\ProgramData\-xUFNiAkNknTr [2013.02.18 15:44:31 | 000,000,160 | -H-- | C] () -- C:\ProgramData\-xUFNiAkNknT [2013.02.18 15:44:30 | 000,000,168 | -H-- | C] () -- C:\ProgramData\xUFNiAkNknT [2013.02.17 09:32:04 | 001,840,050 | -H-- | C] () -- C:\Users\usche\Documents\Strahlung_VasenSY2013.pdf [2013.02.08 11:58:16 | 000,001,666 | ---- | C] () -- C:\Users\usche\Desktop\Ski Challenge 13 (CH) starten.lnk [2013.02.03 09:26:38 | 000,001,053 | ---- | C] () -- C:\Users\usche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013.01.09 16:59:46 | 018,686,770 | -H-- | C] () -- C:\Users\usche\Homepage.web [2012.12.28 23:01:41 | 001,590,370 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012.12.19 14:29:51 | 001,239,556 | -H-- | C] () -- C:\Users\usche\güni.jpg [2012.10.22 19:09:42 | 001,063,164 | -H-- | C] () -- C:\Users\usche\IMG_4596.JPG [2012.09.02 11:01:44 | 000,004,608 | ---- | C] () -- C:\Users\usche\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.06.25 11:29:33 | 004,503,728 | -H-- | C] () -- C:\ProgramData\kcap_0paos.pad [2011.08.18 20:05:57 | 000,090,610 | -H-- | C] () -- C:\Users\usche\oeri-ade.jpg [2011.07.23 17:50:40 | 000,089,831 | -H-- | C] () -- C:\Users\usche\ni2.jpg ========== ZeroAccess Check ========== [2012.01.12 17:41:28 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.01.16 21:02:29 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\9AF095B4 [2010.12.29 15:22:49 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\AnvSoft [2013.02.21 12:53:29 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\Audacity [2013.02.21 19:30:33 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\Dropbox [2012.03.08 07:40:26 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Greenshot [2013.02.21 12:53:29 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\MAGIX [2012.10.11 17:48:42 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Origin [2013.02.21 12:53:30 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\ProtectDISC [2011.10.14 09:47:24 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\redsn0w [2013.02.21 12:53:30 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\simplitec [2013.02.21 12:53:30 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\TeamViewer [2010.03.12 20:35:50 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Tific [2013.02.21 12:47:33 | 000,000,000 | ---D | M] -- C:\Users\usche\AppData\Roaming\TuneUp Software [2013.01.10 17:08:08 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Uzse [2010.03.12 20:00:06 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\WildTangent [2013.01.10 17:11:27 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Ybfi [2013.01.09 11:06:13 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Ybyga [2010.03.12 20:00:55 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\_MDLogs ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 304 bytes -> C:\Users\usche\oeri-ade.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\ni2.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\IMG_4596.JPG:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\güni.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\tactical.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\Sandstrahlung GHC.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\Reinigungskugeln.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\menshealthz.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\HR-Auszug.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\GQ.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\forbes.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Documents\dogsillustrated.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\Desktop\oeri-ade.jpg:Updt_SummaryInformation < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 21.02.2013 19:38:01 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\usche\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 56,31% Memory free 8,00 Gb Paging File | 6,08 Gb Available in Paging File | 76,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1384,15 Gb Total Space | 1253,44 Gb Free Space | 90,56% Space Free | Partition Type: NTFS Drive D: | 13,01 Gb Total Space | 1,79 Gb Free Space | 13,78% Space Free | Partition Type: NTFS Computer Name: USCHE-PC | User Name: usche | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .js [@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.) [HKEY_USERS\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05C7CD6F-C10E-4477-A151-D4F4F7A3C622}" = lport=445 | protocol=6 | dir=in | app=system | "{10539D84-51F3-4C83-9552-9F184D604ECA}" = rport=10243 | protocol=6 | dir=out | app=system | "{15DF45E8-C58F-4E27-AB6D-2CAF3406F7D6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{234A29DA-1A9A-43B0-BDBD-D3BED798A6D0}" = lport=10243 | protocol=6 | dir=in | app=system | "{2391B5C9-2A8B-4474-9252-3993A1E1BAB3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{28A4D17B-7DFA-4CA7-8FB4-85F7F1A5B385}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{3EDDAC26-0069-49BC-B167-459AC37AC0B8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{4189B5E3-52FD-4C15-90A2-321145F3F169}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{489B06D0-792B-4AB5-8F6C-C4DF58DEEBF2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{48D2DE2C-5849-4340-9946-9898DCD82CE7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4BFEE9AD-F81A-467A-ACC6-42262E0CACA1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{54C3B82A-C4E1-4FED-9896-31BC8482C6AA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{773B7E60-D733-4D99-BEA8-6299F56F2E28}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{86942CF3-6C64-4096-A841-29A3664C33C0}" = lport=2869 | protocol=6 | dir=in | app=system | "{872C8572-E915-4F61-8A46-D67351CAB30B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9B5BFC77-38C7-49C1-B426-086F44CC5E6E}" = rport=138 | protocol=17 | dir=out | app=system | "{9BF57F17-72BB-42B3-893F-B939E1F2A8AA}" = rport=137 | protocol=17 | dir=out | app=system | "{A26912AC-88F4-4486-A5A0-39ECD132914F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AD754B25-DFB5-4646-B92B-4F1FCC8D1487}" = rport=445 | protocol=6 | dir=out | app=system | "{B0D5D95D-12DF-4D01-AF52-148540533A14}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D39DF288-9FE4-4B78-8CCE-EFC329EC83A1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D53DB5F3-AD88-412F-821E-C9125FF06746}" = lport=137 | protocol=17 | dir=in | app=system | "{DCD87F10-F214-44DC-850F-BEE75334D46C}" = rport=139 | protocol=6 | dir=out | app=system | "{E321CDFC-1FA9-48CD-B992-C001E98D9A00}" = lport=139 | protocol=6 | dir=in | app=system | "{E9F8AC5C-B3E7-438A-8A01-9601132066B2}" = lport=138 | protocol=17 | dir=in | app=system | "{F98F416C-FF16-4A73-8408-9B03D67EBFCE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0263EA28-7475-49AB-957E-360B95BC8BCC}" = protocol=6 | dir=out | app=system | "{0B36D5CB-CE55-4AE5-94E0-BA3AB1AED776}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{1560074B-D468-40B9-9B0F-F2BCE9B2FE46}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{19DC41BA-32EB-432D-9D4E-CBA59811DD11}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\f1 2012 review\f1_2012.exe | "{1BD6D562-B119-4E30-9786-71F89E8E17A3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{1EE0B441-7D56-4604-A9D0-A6DB2B0B421E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\f1 2012 review\f1_2012.exe | "{210CCA5A-DB02-4C3E-BAB4-B083E9B947DB}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{2651AC4F-AA92-4555-A329-9499AADA243B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion demo\bastion.exe | "{2875DBC7-A2D4-4CCF-A58E-8D9BB2031C2E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe | "{2B6DFB83-AB70-4F36-8B63-2626F926FC5A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{2C487BAE-86B0-49CA-B830-8F12DCC21D0B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{2C9486DB-EDC7-44F4-B8C3-58CBD439E8FD}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe | "{2CA1F140-6EFF-4C2A-8434-96D01F14452F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2D9BFBDD-A973-42DC-9411-A3AA25B9D162}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{3147B7BA-45C4-45A3-AF53-9ACD9DFCA4D4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3353AAFA-209B-42FA-A23E-4E3E3A65D7AD}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe | "{35E7F343-03C5-47C9-B5E2-002E55905CA2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{36D86069-D0A2-4846-AA37-818E3C8BB9C2}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe | "{37F378DF-D0C5-4674-94B4-A666EE93CF19}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe | "{380E2C4C-BC0D-418C-977A-9023243AA2CB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3F5E8ECA-444C-40AF-BB10-333A69D330AA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{452EB9C0-E48D-417F-BE7C-FED54010F157}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{4734FFD5-5E27-4491-9344-849AEFDE44B1}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "{4757D357-BA1F-4FA8-8184-610E03377573}" = protocol=17 | dir=in | app=c:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe | "{47986008-AD1D-493D-B75C-6597D07A983A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{47E1BAA5-2234-4130-86E8-DDB5B0FF401A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\giana sisters twisted dreams\launcher\gslauncher.exe | "{499A4507-86A6-4F9D-8763-A2A99701E158}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa manager 13\manager13.exe | "{4B5527C5-F8CB-4820-9FE2-DBD33C75FAE1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\botanicula\botanicula.exe | "{517BAA4F-B71A-4B36-93BC-BBF926EBD46D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\botanicula\botanicula.exe | "{52857C73-D065-4248-9CE4-6945E6101775}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe | "{534661C8-53BE-43FC-8DF2-6400CCCF59DA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{560ECA71-0E85-4326-A77C-4C95B7DD0C3C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5BB726F6-4D2F-428D-AD0D-298661ADE7FF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{5BF48AB1-4C37-47CD-A403-2973D234EFC2}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{5C241DE6-52D8-477D-A59B-A2C20E89DD81}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5D81F3E1-9102-4A2F-BB88-36CC3DBC0414}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{5DB7587B-D9C4-413B-8A51-B0AD90B0A372}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe | "{5F8FD742-56AF-4B51-9BD5-C8B78C8A506C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{63684DA7-87C9-44C5-99C6-94EDCEF8094D}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe | "{679F799D-B8F1-4107-92FA-611920941493}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{69F32AC0-A6D3-485A-AE7E-7B986A442676}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{6AB3E54E-339F-411A-BD36-B6E1B78F8809}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe | "{6BE8003A-269F-4F40-BEAD-A06C60A72AEA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{74EECEE0-4EB2-42C0-89DA-992F70430675}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\flyn\source\flyn.exe | "{795EE7B2-21C9-421B-A241-E89BCEDFD869}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{79B4EC39-5DD1-412A-8295-034BB3303B07}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{7B4F0072-A595-4C71-B849-800CBE32FCC8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{80E3DBE8-43A0-4F0C-877F-9B0AEF75653A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{80F9EBE9-1083-4AE9-B3A1-951B2F270E7D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lume\lume.exe | "{88ED411C-599D-4A49-9D6E-A47FF5954B2F}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa manager 13\manager13.exe | "{89F2606B-2BFD-4C08-B299-9D62B5B2E74D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{8C5A325B-FAED-4204-A0BD-A1A30FB0F359}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{8C69FEA5-8140-4958-A627-3ADEA72417E9}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe | "{90E7237C-C1CD-4CCD-92F4-70040B378193}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{946DE116-A0A2-477E-AEDA-BDECB9F6EA8F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{94B425C9-AD0D-48B1-A769-3A930EEA0CFC}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | "{94E41423-AB1E-42FA-95AE-67FFD2C52CCC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{967DBDBE-F61F-49C8-9B9E-2EA719B855BD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{99C70282-B2F9-4DA2-846C-0A52EE0063A9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A4D41135-62B1-4C0B-A3A3-40DFBE0C8C5C}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe | "{A6F70ADA-C4C8-4DF9-80CA-AECE84A3DDBA}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "{A8E32F21-2C9F-478E-88DD-5DCC6A4C1EA5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{AEA0DF85-D18E-4E46-923F-0A834C4101C8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{C7EBEE75-02A1-4BDD-9208-CBC774A537F3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lume\lume.exe | "{CACA9E90-B16F-4443-985C-2112BF5D3357}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{CCDC5820-89B3-416C-BB45-73C1C2027F01}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | "{CE22311B-BDBD-48EE-9384-A3BF4D5C8966}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\giana sisters twisted dreams\launcher\gslauncher.exe | "{D5260F56-A76D-4FF0-A3CB-A9732AEA0618}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\techland\call of juarez - bound in blood\cojbibgame_x86.exe | "{D80ADBC5-170E-4485-88FF-A52DC598CC49}" = protocol=6 | dir=in | app=c:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe | "{D8E68B6C-957B-464C-B1C3-778F2990B8AA}" = protocol=6 | dir=in | app=c:\program files (x86)\ultravnc\vncviewer.exe | "{DB23C53B-DEFF-479A-BEF7-FDFEF26DA875}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{DB8ABE64-60DC-4DDB-A15A-DE0E02FFB34E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DB9D6167-B9D1-43CA-8150-C24E7FA98674}" = protocol=17 | dir=in | app=c:\program files (x86)\ultravnc\vncviewer.exe | "{DC9FB86B-E5B3-4530-B999-FBF726A554EE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{DE5436B3-81FF-4503-9CDD-8B62FC426040}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe | "{E4B79237-6FE1-4E1D-AFDF-C36B77CB5D94}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe | "{E567AF57-A3F6-4947-823D-D45B786F5022}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe | "{E5FF737B-E3C0-44CA-8DCB-4C3D4B43F635}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\flyn\source\flyn.exe | "{EB46CB90-8708-49F8-AA3B-6F292E0CF574}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{F07D4792-6441-4509-962D-BACFE3A986B0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{F1514392-584D-467E-9ECA-B1ECD8F009A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{F3B49FF6-D1DC-4AF0-83EC-9BF52D06B04B}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\techland\call of juarez - bound in blood\cojbibgame_x86.exe | "{F4620238-3AA9-4E4A-919B-EEF85E0874CA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{FFABF96E-D8EC-4954-BF28-CD53F8C49270}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion demo\bastion.exe | "TCP Query User{25A64869-5560-48E7-9BD9-5E9604FBAC99}C:\program files (x86)\magix\web designer mx premium\webdesigner.exe" = protocol=6 | dir=in | app=c:\program files (x86)\magix\web designer mx premium\webdesigner.exe | "TCP Query User{BAEA2968-A817-4875-AEF7-AB3E4413F3D6}C:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{D0C59EE0-70D1-4B34-B8CC-1CC3B903C0B6}C:\users\usche\appdata\roaming\ybfi\akda.exe" = protocol=6 | dir=in | app=c:\users\usche\appdata\roaming\ybfi\akda.exe | "UDP Query User{38734545-3998-43F9-A7BA-5A1CEA04829C}C:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\usche\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{45DD8B1A-51B7-4DE2-8F90-034317798DB1}C:\users\usche\appdata\roaming\ybfi\akda.exe" = protocol=17 | dir=in | app=c:\users\usche\appdata\roaming\ybfi\akda.exe | "UDP Query User{950AC29F-CD72-48DC-9173-118F48677AE7}C:\program files (x86)\magix\web designer mx premium\webdesigner.exe" = protocol=17 | dir=in | app=c:\program files (x86)\magix\web designer mx premium\webdesigner.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{44C81D1A-0520-49BB-B510-98B8DD414EA1}" = HP Photosmart C4600 All-In-One Driver Software 13.0 Rel .5 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{739FE2DC-0C7E-4A1C-AC6E-46348169E27E}" = MAGIX Web Designer MX Premium "{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CCleaner" = CCleaner "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Print Projects" = HP Print Projects 1.0 "HP Smart Web Printing" = HP Smart Web Printing 4.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "NVIDIA Drivers" = NVIDIA Drivers "PC-Doctor for Windows" = Hardwarediagnosetools "Shop for HP Supplies" = Shop for HP Supplies "WinRAR archiver" = WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00405945-70C1-4B1D-9A3C-45A2883366AF}" = PS_AIO_05_C4600_Software_Min "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004 "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup "{183D780B-28F9-41BA-A2CB-605F324A5781}" = simplitec simplicheck "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 26 "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012 "{33286280-8617-11E1-8FF6-B8AC6F97B88E}" = Google Earth Plug-in "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{741CFE3A-1C0B-4A7D-8E08-5D78C911C09D}" = HP Support Assistant "{765BF404-2FEE-492B-9E7F-A55143796EF1}" = Geheimakte 3 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7C5E7C19-CED0-4698-8828-0B41BEEADE7C}" = FUSSBALL MANAGER 13 "{7CDD7C4C-5224-40E4-951F-51C12FEAB8AB}" = C4600 "{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE) "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_STANDARDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_STANDARDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_STANDARDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_STANDARDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_STANDARDR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_STANDARDR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002A-0000-1000-0000000FF1CE}_STANDARDR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0407-1000-0000000FF1CE}_STANDARDR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_STANDARDR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007 "{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1" = Panda Cloud Cleaner "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{97BBECCF-B1FD-4010-8D4B-EFC9E3CCEECF}" = Driver Whiz "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Foto Designer-Bibliothek 9 "{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.3 - Deutsch "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status "{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video "{B4089055-D468-45A4-A6BA-5A138DD715FC}" = Bing Bar "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer "{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX "{C61177FD-37C4-4C5F-BE6C-E04A8AC399B6}" = EclipseCrossword "{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution "{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update "{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software "{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE) "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update "{DBA8B9E1-C6FF-4624-9598-73D3B41A0905}" = Microsoft Foto Designer Pro 9 "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004) "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FA4C2D53-205F-4245-9717-F3761154824D}" = Safari "{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video "{FEFAF112-4DA8-479C-89E2-7DE25091711A}" = Call of Juarez - Bound in Blood "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Photoshop Elements 1.0" = Adobe Photoshop Elements "Adobe SVG Viewer" = Adobe SVG Viewer "Any Video Converter_is1" = Any Video Converter 3.2.7 "Arensus Crossword Puzzle Editor_is1" = Arensus Crossword Puzzle Editor 1.1.8 "Audacity_is1" = Audacity 2.0.2 "DivX Setup.divx.com" = DivX-Setup "EasyBits Magic Desktop" = Magic Desktop "Google Chrome" = Google Chrome "Greenshot_is1" = Greenshot "HP Remote Solution" = HP Remote Solution "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video "InstallShield_{FEFAF112-4DA8-479C-89E2-7DE25091711A}" = Call of Juarez - Bound in Blood "MAGIX_{739FE2DC-0C7E-4A1C-AC6E-46348169E27E}" = MAGIX Web Designer MX Premium "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100 "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 19.0 (x86 de)" = Mozilla Firefox 19.0 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Origin" = Origin "PictureIt_POD_v9" = Microsoft Foto Designer-Bibliothek 9 "PictureIt_v9" = Microsoft Foto Designer Pro 9 "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "Runaway - A road adventure_is1" = Runaway - A road adventure 1.00 "STANDARDR" = Microsoft Office Standard 2007 "Steam App 105100" = Lume "Steam App 107110" = Bastion - Demo "Steam App 207690" = Botanicula "Steam App 218390" = F1 2012 Review "Steam App 223220" = Giana Sisters: Twisted Dreams "Steam App 223730" = FLY'N "Steam App 440" = Team Fortress 2 "TeamViewer 6" = TeamViewer 6 "TuneUp Utilities 2012" = TuneUp Utilities 2012 "Ultravnc2_is1" = UltraVNC 1.0.5 "Urlaub Unter Tage" = W&G - Urlaub Unter Tage "WildTangent hp Master Uninstall" = HP Games "WinLiveSuite" = Windows Live Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-3842263682-3274598964-2826866350-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "gamealarm-DEFAULT" = Game Alarm "sc13-CH_MAIN" = Ski Challenge 13 (CH) ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = ERROR: mDNSPlatformReadTCP - recv: 10053 Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = 540: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = ERROR: mDNSPlatformReadTCP - recv: 10053 Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = 540: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = ERROR: mDNSPlatformReadTCP - recv: 10053 Error - 21.02.2013 04:07:30 | Computer Name = usche-PC | Source = Bonjour Service | ID = 100 Description = 540: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error - 21.02.2013 07:56:37 | Computer Name = usche-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: ApplePhotoStreams.exe, Version: 7.2.5.1, Zeitstempel: 0x4f3a19cc Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6195, Zeitstempel: 0x4dcddbf3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001500a ID des fehlerhaften Prozesses: 0xd40 Startzeit der fehlerhaften Anwendung: 0x01ce102a5d1796b5 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe Pfad des fehlerhaften Moduls: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll Berichtskennung: be39b8fb-7c1d-11e2-b8d1-e0cb4e3ecc07 Error - 21.02.2013 12:28:56 | Computer Name = usche-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\usche\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ECOGEL8G\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 21.02.2013 12:28:58 | Computer Name = usche-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\usche\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ECOGEL8G\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error - 21.02.2013 12:29:00 | Computer Name = usche-PC | Source = SideBySide | ID = 16842832 Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\usche\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ECOGEL8G\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. [ Hewlett-Packard Events ] Error - 28.01.2012 16:03:00 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 28.04.2012 14:36:51 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 28.04.2012 14:36:51 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 19.05.2012 14:39:12 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 19.05.2012 14:39:12 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 09.06.2012 14:53:33 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 09.06.2012 14:53:33 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 12.07.2012 11:10:22 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 12.07.2012 11:10:22 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) Error - 08.12.2012 15:41:54 | Computer Name = usche-PC | Source = Hewlett-Packard | ID = 0 Description = de-CH Die Datei "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml" konnte nicht gefunden werden. mscorlib bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) bei System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) bei System.IO.StreamReader..ctor(String path, Encoding encoding) bei System.IO.File.ReadAllText(String path, Encoding encoding) bei n.a(Object A_0, EventArgs A_1) [ OSession Events ] Error - 13.10.2011 12:37:12 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error - 28.11.2011 13:43:28 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error - 11.03.2012 06:00:35 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. Error - 21.04.2012 02:26:16 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. Error - 28.04.2012 04:07:49 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error - 03.05.2012 01:29:04 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error - 25.07.2012 06:55:32 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error - 15.01.2013 12:50:05 | Computer Name = usche-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 21.02.2013 12:05:38 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 21.02.2013 12:05:38 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 21.02.2013 12:05:38 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 21.02.2013 12:14:54 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: PxHelp20 Error - 21.02.2013 12:15:38 | Computer Name = usche-PC | Source = NetBT | ID = 4319 Description = Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error - 21.02.2013 12:15:39 | Computer Name = usche-PC | Source = NetBT | ID = 4319 Description = Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error - 21.02.2013 12:15:41 | Computer Name = usche-PC | Source = NetBT | ID = 4319 Description = Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error - 21.02.2013 12:15:43 | Computer Name = usche-PC | Source = NetBT | ID = 4319 Description = Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error - 21.02.2013 12:36:54 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: PxHelp20 Error - 21.02.2013 14:29:53 | Computer Name = usche-PC | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: PxHelp20 < End of report > |
21.02.2013, 20:24 | #4 |
/// Helfer-Team | Windows System Repair Virus Hast du unhide.exe laufen lassen? Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL [2013.02.18 17:07:43 | 000,000,160 | -H-- | M] () -- C:\ProgramData\-xUFNiAkNknT [2013.02.18 17:07:37 | 000,000,168 | -H-- | M] () -- C:\ProgramData\xUFNiAkNknT [2013.02.18 16:08:35 | 000,000,176 | -H-- | M] () -- C:\ProgramData\-xUFNiAkNknTr @Alternate Data Stream - 304 bytes -> C:\Users\usche\oeri-ade.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\ni2.jpg:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\IMG_4596.JPG:Updt_SummaryInformation @Alternate Data Stream - 304 bytes -> C:\Users\usche\güni.jpg:Updt_SummaryInformation [2012.06.25 11:29:33 | 004,503,728 | -H-- | C] () -- C:\ProgramData\kcap_0paos.pad [2013.01.09 11:06:13 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Ybyga [2013.01.10 17:11:27 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Ybfi [2013.01.10 17:08:08 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Uzse [2010.03.12 20:35:50 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\Tific [2013.01.16 21:02:29 | 000,000,000 | -H-D | M] -- C:\Users\usche\AppData\Roaming\9AF095B4 :Files C:\ProgramData\*.exe C:\ProgramData\*.dll C:\ProgramData\*.tmp C:\ProgramData\TEMP C:\Users\usche\*.tmp C:\Users\usche\AppData\*.dll C:\Users\usche\AppData\*.exe C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache ipconfig /flushdns /c
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade Dir bitte Malwarebytes Anti-Malware
danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
21.02.2013, 21:00 | #5 |
| Windows System Repair Virus Danke vielmal, btw. für deine Mühe bereits jetzt. Also ich habe folgendes bisher gemacht: 1. Scan mit Malwarebyte 2. Die Logfiles von OTL (die beiden die bereits gepostet wurden) 3. parallel den unhide.exe ausgeführt.(war das ein Fehler?) Im Übrigen funktioniert dadurch nun wieder Firefox und alle Dateien sind sichtbar!:-D. Nun versteh ich deinen Post möglicherweise nicht ganz. Du hast geschrieben: Hast du unhide.exe laufen lassen? Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. Bezieht sich das mit den 3 Logs auf die bisher gemachten oder, die die ich jetzt gemäss deinem anschliessenden Textbeitrag durchführen sollte? Vielen Dank für die Aufklärung LG Swiss |
22.02.2013, 11:58 | #6 |
/// Helfer-Team | Windows System Repair Virus Wchtig war nur, dass du Unhide gestartet hast, bevor wir weiter bereinigen. Bitte ab Schritt 1 weitermachen.
__________________ --> Windows System Repair Virus |
22.02.2013, 14:01 | #7 |
| Windows System Repair Virus Ok, ok das ganze ist durchlaufen... Code:
ATTFilter ========== OTL ========== C:\ProgramData\-xUFNiAkNknT moved successfully. C:\ProgramData\xUFNiAkNknT moved successfully. C:\ProgramData\-xUFNiAkNknTr moved successfully. ADS C:\Users\usche\oeri-ade.jpg:Updt_SummaryInformation deleted successfully. ADS C:\Users\usche\ni2.jpg:Updt_SummaryInformation deleted successfully. ADS C:\Users\usche\IMG_4596.JPG:Updt_SummaryInformation deleted successfully. ADS C:\Users\usche\güni.jpg:Updt_SummaryInformation deleted successfully. C:\ProgramData\kcap_0paos.pad moved successfully. C:\Users\usche\AppData\Roaming\Ybyga folder moved successfully. C:\Users\usche\AppData\Roaming\Ybfi folder moved successfully. C:\Users\usche\AppData\Roaming\Uzse folder moved successfully. C:\Users\usche\AppData\Roaming\Tific folder moved successfully. C:\Users\usche\AppData\Roaming\9AF095B4 folder moved successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF} folder moved successfully. C:\ProgramData\Temp\{DCCAD079-F92C-44DA-B258-624FC6517A5A} folder moved successfully. C:\ProgramData\Temp\{CB099890-1D5F-11D5-9EA9-0050BAE317E1} folder moved successfully. C:\ProgramData\Temp\{C59C179C-668D-49A9-B6EA-0121CCFC1243} folder moved successfully. C:\ProgramData\Temp\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E} folder moved successfully. C:\ProgramData\Temp\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5} folder moved successfully. C:\ProgramData\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658} folder moved successfully. C:\ProgramData\Temp\{3023EBDA-BF1B-4831-B347-E5018555F26E} folder moved successfully. C:\ProgramData\Temp\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} folder moved successfully. C:\ProgramData\Temp folder moved successfully. C:\Users\usche\048298C9A4D3490B9FF9AB023A9238F3.TMP folder moved successfully. File\Folder C:\Users\usche\AppData\*.dll not found. File\Folder C:\Users\usche\AppData\*.exe not found. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\usche\Desktop\cmd.bat deleted successfully. C:\Users\usche\Desktop\cmd.txt deleted successfully. OTL by OldTimer - Version 3.2.69.0 log created on 02222013_123459 Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.02.22.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 usche :: USCHE-PC [Administrator] Schutz: Aktiviert 22.02.2013 12:39:54 mbam-log-2013-02-22 (12-39-54).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 519466 Laufzeit: 1 Stunde(n), 9 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) Das ADW-Cleaner Log ist ganz schön gross ( ca. 16 Word Seiten mit Text).. Code:
ATTFilter # AdwCleaner v2.112 - Datei am 22/02/2013 um 13:55:24 erstellt # Aktualisiert am 10/02/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : usche - USCHE-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\usche\Downloads\adwcleaner0.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\searchplugins\Conduit.xml Ordner Gelöscht : C:\Program Files\Babylon Ordner Gelöscht : C:\Users\usche\AppData\Local\Conduit Ordner Gelöscht : C:\Users\usche\AppData\Local\Temp\boost_interprocess Ordner Gelöscht : C:\Users\usche\AppData\LocalLow\BabylonToolbar Ordner Gelöscht : C:\Users\usche\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\usche\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\ConduitCommon Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\CT2319825 Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\CT3031785 Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\extensions\{19f54e13-741b-423c-ab48-fd8c43be2e46} Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} Ordner Gelöscht : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\extensions\ffxtlbr@babylon.com ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{40C3CC16-7269-4B32-9531-17F2950FB06F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C3CC16-7269-4B32-9531-17F2950FB06F} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2319825 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3031785 Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonTC_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonTC_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16464 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v19.0 (de) Datei : C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\prefs.js C:\Users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\user.js ... Gelöscht ! Gelöscht : user_pref("CT2319825..clientLogIsEnabled", true); Gelöscht : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gelöscht : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gelöscht : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gelöscht : user_pref("CT2319825.AppTrackingLastCheckTime", "Mon Aug 22 2011 12:32:35 GMT+0200"); Gelöscht : user_pref("CT2319825.CTID", "ct2319825"); Gelöscht : user_pref("CT2319825.CurrentServerDate", "9-11-2011"); Gelöscht : user_pref("CT2319825.DialogsAlignMode", "LTR"); Gelöscht : user_pref("CT2319825.DialogsGetterLastCheckTime", "Wed Nov 09 2011 12:56:33 GMT+0100"); Gelöscht : user_pref("CT2319825.DownloadReferralCookieData", ""); Gelöscht : user_pref("CT2319825.EMailNotifierPollDate", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.EnableClickToSearchBox", false); Gelöscht : user_pref("CT2319825.EnableSearchHistory", false); Gelöscht : user_pref("CT2319825.EnableSearchSuggest", false); Gelöscht : user_pref("CT2319825.FeedPollDate11908299", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.FirstServerDate", "22-8-2011"); Gelöscht : user_pref("CT2319825.FirstTime", true); Gelöscht : user_pref("CT2319825.FirstTimeFF3", true); Gelöscht : user_pref("CT2319825.FixPageNotFoundErrors", false); Gelöscht : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gelöscht : user_pref("CT2319825.HasUserGlobalKeys", true); Gelöscht : user_pref("CT2319825.HomePageProtectorEnabled", true); Gelöscht : user_pref("CT2319825.Initialize", true); Gelöscht : user_pref("CT2319825.InitializeCommonPrefs", true); Gelöscht : user_pref("CT2319825.InstallationAndCookieDataSentCount", 3); Gelöscht : user_pref("CT2319825.InstallationType", "ConduitIntegration"); Gelöscht : user_pref("CT2319825.InstalledDate", "Mon Aug 22 2011 12:32:24 GMT+0200"); Gelöscht : user_pref("CT2319825.IsAlertDBUpdated", true); Gelöscht : user_pref("CT2319825.IsGrouping", false); Gelöscht : user_pref("CT2319825.IsInitSetupIni", true); Gelöscht : user_pref("CT2319825.IsMulticommunity", false); Gelöscht : user_pref("CT2319825.IsOpenThankYouPage", false); Gelöscht : user_pref("CT2319825.IsOpenUninstallPage", true); Gelöscht : user_pref("CT2319825.IsProtectorsInit", true); Gelöscht : user_pref("CT2319825.LanguagePackLastCheckTime", "Mon Aug 22 2011 12:32:27 GMT+0200"); Gelöscht : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440); Gelöscht : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gelöscht : user_pref("CT2319825.LatestVersion", "3.8.0.8"); Gelöscht : user_pref("CT2319825.Locale", "de"); Gelöscht : user_pref("CT2319825.MCDetectTooltipHeight", "83"); Gelöscht : user_pref("CT2319825.MCDetectTooltipShow", false); Gelöscht : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gelöscht : user_pref("CT2319825.MCDetectTooltipWidth", "295"); Gelöscht : user_pref("CT2319825.RadioIsPodcast", false); Gelöscht : user_pref("CT2319825.RadioMediaID", "13288279"); Gelöscht : user_pref("CT2319825.RadioMediaType", "Media Player"); Gelöscht : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT2319825_RECENT13288279"); Gelöscht : user_pref("CT2319825.RadioShrinkedFromSetup", false); Gelöscht : user_pref("CT2319825.RadioStationName", "Sputnik%20Live"); Gelöscht : user_pref("CT2319825.RadioStationURL", "hxxp://www.sputnik.de/m3u/black.hi.m3u"); Gelöscht : user_pref("CT2319825.SavedHomepage", "hxxp://www.bluewin.ch/index.html.de"); Gelöscht : user_pref("CT2319825.SearchEngineBeforeUnload", "Winload Customized Web Search"); Gelöscht : user_pref("CT2319825.SearchFromAddressBarIsInit", true); Gelöscht : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT231[...] Gelöscht : user_pref("CT2319825.SearchInNewTabEnabled", true); Gelöscht : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440); Gelöscht : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Mon Aug 22 2011 12:32:25 GMT+0200"); Gelöscht : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gelöscht : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Gelöscht : user_pref("CT2319825.SearchProtectorEnabled", true); Gelöscht : user_pref("CT2319825.SearchProtectorToolbarDisabled", false); Gelöscht : user_pref("CT2319825.ServiceMapLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.SettingsLastCheckTime", "Mon Aug 22 2011 12:32:22 GMT+0200"); Gelöscht : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Mon Aug 22 2011 12:32:22 GMT+0200"); Gelöscht : user_pref("CT2319825.ToolbarShrinkedFromSetup", false); Gelöscht : user_pref("CT2319825.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gelöscht : user_pref("CT2319825.UserID", "UN23222007019988067"); Gelöscht : user_pref("CT2319825.ValidationData_Search", 0); Gelöscht : user_pref("CT2319825.ValidationData_Toolbar", 2); Gelöscht : user_pref("CT2319825.WeatherNetwork", ""); Gelöscht : user_pref("CT2319825.WeatherPollDate", "Sun Oct 09 2011 12:05:06 GMT+0200"); Gelöscht : user_pref("CT2319825.WeatherUnit", "C"); Gelöscht : user_pref("CT2319825.alertChannelId", "715912"); Gelöscht : user_pref("CT2319825.approveUntrustedApps", false); Gelöscht : user_pref("CT2319825.backendstorage.id", "3232303132333037"); Gelöscht : user_pref("CT2319825.components.1000234", false); Gelöscht : user_pref("CT2319825.ct2319825.AppTrackingLastCheckTime", "Thu Nov 10 2011 19:25:34 GMT+0100"); Gelöscht : user_pref("CT2319825.ct2319825.InvalidateCache", false); Gelöscht : user_pref("CT2319825.ct2319825.LanguagePackLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.ct2319825.Locale", "de"); Gelöscht : user_pref("CT2319825.ct2319825.RadioLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.ct2319825.RadioLastUpdateIPServer", "3"); Gelöscht : user_pref("CT2319825.ct2319825.SearchInNewTabLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.ct2319825.SettingsLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT2319825.ct2319825.SettingsLastUpdate", "1313478201"); Gelöscht : user_pref("CT2319825.ct2319825.ThirdPartyComponentsLastCheck", "Mon Oct 24 2011 15:36:45 GMT+0200"); Gelöscht : user_pref("CT2319825.ct2319825.components.129264512281565287", false); Gelöscht : user_pref("CT2319825.ct2319825.components.129277509933662715", false); Gelöscht : user_pref("CT2319825.ct2319825.components.129309281463312841", false); Gelöscht : user_pref("CT2319825.ct2319825.components.129453462855350877", false); Gelöscht : user_pref("CT2319825.ct2319825.globalFirstTimeInfoLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100[...] Gelöscht : user_pref("CT2319825.ct2319825.toolbarAppMetaDataLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"[...] Gelöscht : user_pref("CT2319825.ct2319825.toolbarContextMenuLastCheckTime", "Fri Nov 04 2011 22:36:31 GMT+0100"[...] Gelöscht : user_pref("CT2319825.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gelöscht : user_pref("CT2319825.globalFirstTimeInfoLastCheckTime", "Mon Aug 22 2011 12:32:24 GMT+0200"); Gelöscht : user_pref("CT2319825.homepageProtectorEnableByLogin", true); Gelöscht : user_pref("CT2319825.initDone", true); Gelöscht : user_pref("CT2319825.isAppTrackingManagerOn", true); Gelöscht : user_pref("CT2319825.isFirstRadioInstallation", false); Gelöscht : user_pref("CT2319825.myStuffEnabled", true); Gelöscht : user_pref("CT2319825.myStuffPublihserMinWidth", 400); Gelöscht : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gelöscht : user_pref("CT2319825.myStuffServiceIntervalMM", 1440); Gelöscht : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gelöscht : user_pref("CT2319825.oldAppsList", "128898076802619665,128898076802619666,111,129309281463312841,129[...] Gelöscht : user_pref("CT2319825.searchProtectorDialogDelayInSec", 10); Gelöscht : user_pref("CT2319825.searchProtectorEnableByLogin", true); Gelöscht : user_pref("CT2319825.testingCtid", ""); Gelöscht : user_pref("CT2319825.toolbarAppMetaDataLastCheckTime", "Mon Aug 22 2011 12:32:24 GMT+0200"); Gelöscht : user_pref("CT2319825.toolbarContextMenuLastCheckTime", "Mon Aug 22 2011 12:32:27 GMT+0200"); Gelöscht : user_pref("CT2319825.usageEnabled", false); Gelöscht : user_pref("CT2319825.usagesFlag", 2); Gelöscht : user_pref("CT3031785..clientLogIsEnabled", true); Gelöscht : user_pref("CT3031785..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Gelöscht : user_pref("CT3031785..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Gelöscht : user_pref("CT3031785.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Gelöscht : user_pref("CT3031785.AppTrackingLastCheckTime", "Thu Nov 10 2011 19:25:34 GMT+0100"); Gelöscht : user_pref("CT3031785.BrowserCompStateIsOpen_1167878818199967311", true); Gelöscht : user_pref("CT3031785.CTID", "CT3031785"); Gelöscht : user_pref("CT3031785.CurrentServerDate", "9-11-2011"); Gelöscht : user_pref("CT3031785.DialogsAlignMode", "LTR"); Gelöscht : user_pref("CT3031785.DialogsGetterLastCheckTime", "Wed Nov 09 2011 12:56:33 GMT+0100"); Gelöscht : user_pref("CT3031785.DownloadReferralCookieData", ""); Gelöscht : user_pref("CT3031785.EMailNotifierPollDate", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.EnableSearchHistory", false); Gelöscht : user_pref("CT3031785.EnableSearchSuggest", false); Gelöscht : user_pref("CT3031785.FirstServerDate", "22-8-2011"); Gelöscht : user_pref("CT3031785.FirstTime", true); Gelöscht : user_pref("CT3031785.FirstTimeFF3", true); Gelöscht : user_pref("CT3031785.FixPageNotFoundErrors", false); Gelöscht : user_pref("CT3031785.GroupingServerCheckInterval", 1440); Gelöscht : user_pref("CT3031785.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Gelöscht : user_pref("CT3031785.HasUserGlobalKeys", true); Gelöscht : user_pref("CT3031785.Initialize", true); Gelöscht : user_pref("CT3031785.InitializeCommonPrefs", true); Gelöscht : user_pref("CT3031785.InstallationId", "CT3031785_softonic-Switzerland_DE_.exe"); Gelöscht : user_pref("CT3031785.InstalledDate", "Mon Aug 22 2011 12:32:24 GMT+0200"); Gelöscht : user_pref("CT3031785.InvalidateCache", false); Gelöscht : user_pref("CT3031785.IsAlertDBUpdated", true); Gelöscht : user_pref("CT3031785.IsGrouping", false); Gelöscht : user_pref("CT3031785.IsInitSetupIni", true); Gelöscht : user_pref("CT3031785.IsMulticommunity", false); Gelöscht : user_pref("CT3031785.IsOpenThankYouPage", false); Gelöscht : user_pref("CT3031785.IsOpenUninstallPage", true); Gelöscht : user_pref("CT3031785.LanguagePackLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Gelöscht : user_pref("CT3031785.LastLogin_3.6.0.10", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.LatestVersion", "3.8.0.8"); Gelöscht : user_pref("CT3031785.Locale", "de"); Gelöscht : user_pref("CT3031785.MCDetectTooltipHeight", "83"); Gelöscht : user_pref("CT3031785.MCDetectTooltipShow", false); Gelöscht : user_pref("CT3031785.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Gelöscht : user_pref("CT3031785.MCDetectTooltipWidth", "295"); Gelöscht : user_pref("CT3031785.MyStuffEnabledAtInstallation", true); Gelöscht : user_pref("CT3031785.RadioIsPodcast", false); Gelöscht : user_pref("CT3031785.RadioLastUpdateIPServer", "3"); Gelöscht : user_pref("CT3031785.RadioLastUpdateServer", "3"); Gelöscht : user_pref("CT3031785.RadioMediaID", "9962"); Gelöscht : user_pref("CT3031785.RadioMediaType", "Media Player"); Gelöscht : user_pref("CT3031785.RadioMenuSelectedID", "EBRadioMenu_CT30317859962"); Gelöscht : user_pref("CT3031785.RadioShrinkedFromSetup", false); Gelöscht : user_pref("CT3031785.RadioStationName", "California%20Rock"); Gelöscht : user_pref("CT3031785.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT303[...] Gelöscht : user_pref("CT3031785.SearchInNewTabEnabled", true); Gelöscht : user_pref("CT3031785.SearchInNewTabIntervalMM", 1440); Gelöscht : user_pref("CT3031785.SearchInNewTabLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Gelöscht : user_pref("CT3031785.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] Gelöscht : user_pref("CT3031785.ServiceMapLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.SettingsLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.ThirdPartyComponentsInterval", 504); Gelöscht : user_pref("CT3031785.ThirdPartyComponentsLastCheck", "Mon Oct 24 2011 15:36:45 GMT+0200"); Gelöscht : user_pref("CT3031785.ThirdPartyComponentsLastUpdate", "1255344657"); Gelöscht : user_pref("CT3031785.ToolbarShrinkedFromSetup", false); Gelöscht : user_pref("CT3031785.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Gelöscht : user_pref("CT3031785.UserID", "UN56099105909519428"); Gelöscht : user_pref("CT3031785.ValidationData_Toolbar", 2); Gelöscht : user_pref("CT3031785.alertChannelId", "1423364"); Gelöscht : user_pref("CT3031785.approveUntrustedApps", false); Gelöscht : user_pref("CT3031785.components.129524549768878097", false); Gelöscht : user_pref("CT3031785.components.129524549769044104", false); Gelöscht : user_pref("CT3031785.components.129524549769317526", false); Gelöscht : user_pref("CT3031785.components.129562363499000054", false); Gelöscht : user_pref("CT3031785.components.1541230140527782385", false); Gelöscht : user_pref("CT3031785.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Gelöscht : user_pref("CT3031785.globalFirstTimeInfoLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.homepageProtectorEnableByLogin", true); Gelöscht : user_pref("CT3031785.initDone", true); Gelöscht : user_pref("CT3031785.isAppTrackingManagerOn", true); Gelöscht : user_pref("CT3031785.isFirstRadioInstallation", false); Gelöscht : user_pref("CT3031785.myStuffEnabled", true); Gelöscht : user_pref("CT3031785.myStuffPublihserMinWidth", 400); Gelöscht : user_pref("CT3031785.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Gelöscht : user_pref("CT3031785.myStuffServiceIntervalMM", 1440); Gelöscht : user_pref("CT3031785.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Gelöscht : user_pref("CT3031785.oldAppsList", "129524549768038300,129524549768458197,111,4752028818586724616,89[...] Gelöscht : user_pref("CT3031785.searchProtectorEnableByLogin", true); Gelöscht : user_pref("CT3031785.testingCtid", ""); Gelöscht : user_pref("CT3031785.toolbarAppMetaDataLastCheckTime", "Thu Nov 10 2011 19:25:24 GMT+0100"); Gelöscht : user_pref("CT3031785.toolbarContextMenuLastCheckTime", "Fri Nov 04 2011 22:36:31 GMT+0100"); Gelöscht : user_pref("CT3031785.usagesFlag", 2); Gelöscht : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2319825&Search[...] Gelöscht : user_pref("CommunityToolbar.ConduitSearchList", "Winload Customized Web Search"); Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1423364/1419019/CH", "\"0\"[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2319825", [...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3031785", [...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2319825", [...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2319825",[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3031785",[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2319825&octid=[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT3031785&octid=[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=ct2319825&octid=[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/idel.gif", "[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/minimize.gif[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/play.gif", "[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/stop.gif", "[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Tapuz/vol.gif", "\[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...] Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"07b[...] Gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\usche\\AppData\\Roaming\\Mozilla\\F[...] Gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.6.0.10"); Gelöscht : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://toolbarapi.winload.de/html/wltb/download_[...] Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.babylon.com/?babsrc=toolba[...] Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT3031785,CT2319825"); Gelöscht : user_pref("CommunityToolbar.ToolbarsList4", "CT3031785,CT2319825"); Gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Oct 08 2011 12:45:13 GMT+0200"); Gelöscht : user_pref("CommunityToolbar.globalUserId", "9aa9ce95-d769-4f0e-9817-897296dd8260"); Gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Fri Nov 04 2011 22:36:3[...] Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60); Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 10 2011 19:25:32 GMT+010[...] Gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Gelöscht : user_pref("CommunityToolbar.notifications.locale", ""); Gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 10 2011 19:25:57 GMT+0100"); Gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Gelöscht : user_pref("CommunityToolbar.notifications.userId", "1d4c14f3-ab1f-43a6-a615-30e91771e7e3"); Gelöscht : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search"); Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&Sea[...] Gelöscht : user_pref("browser.search.selectedEngine", "Winload Customized Web Search"); Gelöscht : user_pref("extensions.BabylonToolbar.admin", false); Gelöscht : user_pref("extensions.BabylonToolbar.aflt", "orgnl"); Gelöscht : user_pref("extensions.BabylonToolbar.bbDpng", 22); Gelöscht : user_pref("extensions.BabylonToolbar.cntry", "CH"); Gelöscht : user_pref("extensions.BabylonToolbar.dfltSrch", false); Gelöscht : user_pref("extensions.BabylonToolbar.excTlbr", false); Gelöscht : user_pref("extensions.BabylonToolbar.firstRun", false); Gelöscht : user_pref("extensions.BabylonToolbar.hdrMd5", "58413F12F6896D0FFB0187571FA3F4F2"); Gelöscht : user_pref("extensions.BabylonToolbar.hmpg", false); Gelöscht : user_pref("extensions.BabylonToolbar.lastActv", "23"); Gelöscht : user_pref("extensions.BabylonToolbar.lastDP", 22); Gelöscht : user_pref("extensions.BabylonToolbar.lastVrsnTs", ""); Gelöscht : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "19.0"); Gelöscht : user_pref("extensions.BabylonToolbar.newTab", true); Gelöscht : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP"); Gelöscht : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Gelöscht : user_pref("extensions.BabylonToolbar.propectorlck", 100092926); Gelöscht : user_pref("extensions.BabylonToolbar.smplGrp", "czb"); Gelöscht : user_pref("extensions.enabledAddons", "testpilot%40labs.mozilla.com:1.2.2,ffxtlbr%40babylon.com:1.2.[...] Gelöscht : user_pref("extensions.ffxtlbr@babylon.com.install-event-fired", true); Gelöscht : user_pref("keyword.URL", "hxxp://search.babylon.com/?babsrc=toolbar2&q="); -\\ Google Chrome v24.0.1312.57 Datei : C:\Users\usche\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [27024 octets] - [22/02/2013 13:55:24] ########## EOF - C:\AdwCleaner[S1].txt - [27085 octets] ########## Geändert von Swiss (22.02.2013 um 14:32 Uhr) |
23.02.2013, 15:07 | #8 |
/// Helfer-Team | Windows System Repair Virus Sehr gut! Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). danach: ESET Online Scanner
danach: Downloade Dir bitte SecurityCheck und:
|
23.02.2013, 18:51 | #9 |
| Windows System Repair Virus sodele 1. Code:
ATTFilter aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Run date: 2013-02-23 16:19:55 ----------------------------- 16:19:55.921 OS Version: Windows x64 6.1.7601 Service Pack 1 16:19:55.921 Number of processors: 4 586 0x170A 16:19:55.921 ComputerName: USCHE-PC UserName: usche 16:19:57.751 Initialize success 16:20:04.682 AVAST engine defs: 13022300 16:20:19.182 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 16:20:19.182 Disk 0 Vendor: WDC_WD15EADS-65P8B0 01.00A01 Size: 1430799MB BusType: 3 16:20:19.192 Disk 0 MBR read successfully 16:20:19.192 Disk 0 MBR scan 16:20:19.202 Disk 0 unknown MBR code 16:20:19.202 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 16:20:19.212 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 1417366 MB offset 206848 16:20:19.252 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 13317 MB offset 2902972416 16:20:19.272 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS 10 MB offset 2930247680 16:20:19.322 Disk 0 scanning C:\Windows\system32\drivers 16:20:27.671 Service scanning 16:20:31.872 Service Exfvcpsmv C:\Windows\C:\Windows\system32\drivers\wimmount.sys **LOCKED** 123 16:20:45.652 Modules scanning 16:20:45.662 Disk 0 trace - called modules: 16:20:45.692 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys 16:20:45.692 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a21060] 16:20:45.702 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> [0xfffffa80047c1520] 16:20:45.702 5 ACPI.sys[fffff88000f0e7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80047b9060] 16:20:48.693 AVAST engine scan C:\Windows 16:20:51.571 AVAST engine scan C:\Windows\system32 16:23:52.492 AVAST engine scan C:\Windows\system32\drivers 16:24:03.393 AVAST engine scan C:\Users\usche 16:45:26.875 AVAST engine scan C:\ProgramData 16:51:12.307 Scan finished successfully 16:53:48.556 Disk 0 MBR has been saved successfully to "C:\Users\usche\Desktop\MBR.dat" 16:53:48.556 The log file has been saved successfully to "C:\Users\usche\Desktop\aswMBR.txt" Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=fb97f3000eba6340a6c8f049d136c761 # engine=13227 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-02-23 05:39:54 # local_time=2013-02-23 06:39:54 (+0100, Mitteleuropäische Zeit) # country="Switzerland" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 16714374 113271044 0 0 # scanned=335882 # found=1 # cleaned=0 # scan_time=6116 sh=7D8422D9645DE9B7CD265B24E262B746900136C1 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NGS trojan" ac=I fn="C:\_OTL\MovedFiles\02222013_123459\C_Users\usche\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\6383f1ae-20c17033" Code:
ATTFilter Results of screen317's Security Check version 0.99.59 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 TuneUp Utilities 2012 TuneUp Utilities Language Pack (de-DE) Panda Cloud Cleaner Java(TM) 6 Update 26 Java version out of Date! Adobe Flash Player 11.5.502.135 Flash Player out of Date! Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (19.0) Google Chrome 24.0.1312.56 Google Chrome 24.0.1312.57 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Geändert von Swiss (23.02.2013 um 19:09 Uhr) |
23.02.2013, 20:36 | #10 |
/// Helfer-Team | Windows System Repair Virus Nun: Scan mit Combofix
|
23.02.2013, 21:57 | #11 |
| Windows System Repair VirusCode:
ATTFilter ComboFix 13-02-23.01 - usche 23.02.2013 21:37:02.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.41.1031.18.4095.2352 [GMT 1:00] ausgeführt von:: c:\users\usche\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ntuser.dat c:\windows\IsUn0407.exe c:\windows\SysWow64\SET70ED.tmp c:\windows\SysWow64\SET86FF.tmp c:\windows\TEMP\~ef6c85\~de1a55.tmp c:\windows\TEMP\~ef6c85\~df394b.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2013-01-23 bis 2013-02-23 )))))))))))))))))))))))))))))) . . 2013-02-23 20:44 . 2013-02-23 20:44 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-02-22 11:34 . 2013-02-22 11:34 -------- d-----w- C:\_OTL 2013-02-21 16:30 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-02-21 16:30 . 2013-02-21 16:30 -------- d-----w- c:\users\usche\AppData\Local\Programs 2013-02-19 16:37 . 2013-02-22 06:44 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-02-19 16:33 . 2013-02-21 11:53 -------- d-----w- c:\program files\CCleaner 2013-02-19 08:04 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-19 08:04 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-19 07:15 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-02-19 07:15 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-02-19 07:14 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-02-19 07:14 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-02-19 07:14 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-02-19 07:14 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-02-19 07:14 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-02-19 07:14 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-02-19 07:14 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-02-19 07:13 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-19 07:13 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-14 06:55 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-19 08:08 . 2011-11-11 08:11 70004024 ----a-w- c:\windows\system32\MRT.exe 2013-01-04 04:43 . 2013-02-19 07:14 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-12-16 17:11 . 2012-12-22 02:01 46080 ----a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-22 02:01 367616 ----a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-22 02:01 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-22 02:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2012-12-12 12:21 . 2007-04-27 08:43 120200 ----a-w- c:\windows\SysWow64\DLLDEV32i.dll 2012-12-12 06:42 . 2012-04-19 05:41 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 06:42 . 2011-10-04 20:26 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-07 13:20 . 2013-01-09 07:07 441856 ----a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-09 07:07 2746368 ----a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-09 07:07 308736 ----a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-09 07:07 2576384 ----a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-09 07:07 30720 ----a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-09 07:07 43520 ----a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-09 07:07 23552 ----a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-09 07:07 45568 ----a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-09 07:07 44544 ----a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-09 07:07 20480 ----a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-09 07:07 20480 ----a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-09 07:07 20480 ----a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-09 07:07 46592 ----a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-09 07:07 40960 ----a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-09 07:07 21504 ----a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-09 07:07 15360 ----a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-09 07:07 55296 ----a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-09 07:07 51712 ----a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-09 07:07 43520 ----a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-09 07:07 30720 ----a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-09 07:07 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-09 07:07 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-09 07:07 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-09 07:07 23552 ----a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-09 07:07 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-09 07:07 46592 ----a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-09 07:07 20480 ----a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-09 07:07 21504 ----a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-09 07:07 40960 ----a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-09 07:07 15360 ----a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-09 07:07 51712 ----a-w- c:\windows\SysWow64\esrb.rs 2012-12-07 10:46 . 2013-01-09 07:07 55296 ----a-w- c:\windows\SysWow64\cero.rs 2012-11-30 05:45 . 2013-01-09 07:06 362496 ----a-w- c:\windows\system32\wow64win.dll 2012-11-30 05:45 . 2013-01-09 07:06 243200 ----a-w- c:\windows\system32\wow64.dll 2012-11-30 05:45 . 2013-01-09 07:06 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2012-11-30 05:45 . 2013-01-09 07:06 215040 ----a-w- c:\windows\system32\winsrv(67).dll 2012-11-30 05:43 . 2013-01-09 07:06 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2012-11-30 05:41 . 2013-01-09 07:06 424448 ----a-w- c:\windows\system32\KernelBase.dll 2012-11-30 05:41 . 2013-01-09 07:06 1161216 ----a-w- c:\windows\system32\kernel32.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2012-11-30 05:38 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2012-11-30 04:53 . 2013-01-09 07:06 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll 2012-11-30 04:45 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 04:45 . 2013-01-09 07:06 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-02-23 59240] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-02-24 59240] "Greenshot"="c:\program files (x86)\Greenshot\Greenshot.exe" [2010-07-01 540672] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-06-29 600936] "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240] . c:\users\usche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\usche\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\hp\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] simplicheck.lnk - c:\program files (x86)\simplitec\simplicheck\simplicheck.exe [2012-10-22 2936168] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "AppleSyncNotifier"=c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216] R3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-09-17 23536] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1255736] S0 81215182;81215182 Boot Guard Driver;c:\windows\system32\DRIVERS\81215182.sys [2009-10-22 40464] S0 pavboot;Panda Boot Driver;c:\windows\system32\drivers\pavboot64.sys [2009-06-30 33800] S1 81215181;81215181;c:\windows\system32\DRIVERS\81215181.sys [2009-09-25 157712] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616] S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-01-27 2253688] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2012-05-29 2143072] S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [2007-10-12 50072] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2009-05-19 702976] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-21 239616] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-08-09 11856] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-01 07:44 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-18 11:30] . 2013-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-18 11:30] . 2013-01-31 c:\windows\Tasks\PCDRScheduledMaintenance.job - c:\program files\PC-Doctor for Windows\pcdrcui.exe [2009-09-18 07:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 ----a-w- c:\users\usche\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-29 16335464] "PC-Doctor for Windows localizer"="c:\program files\PC-Doctor for Windows\localizer.exe" [2009-09-17 95728] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.bluewin.ch/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\usche\AppData\Roaming\Mozilla\Firefox\Profiles\e40hyr28.default\ FF - prefs.js: browser.startup.homepage - www.bluewin.ch FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKLM-Run-HP Remote Solution - %ProgramFiles(x86)%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe WebBrowser-{19F54E13-741B-423C-AB48-FD8C43BE2E46} - (no file) AddRemove-Adobe Photoshop Elements 1.0 - c:\windows\ISUN0407.EXE AddRemove-Adobe SVG Viewer - c:\windows\IsUn0407.exe AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0] "ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-02-23 21:53:39 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-02-23 20:53 . Vor Suchlauf: 14 Verzeichnis(se), 1'348'954'447'872 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 1'348'765'270'016 Bytes frei . - - End Of File - - 19DCFFD658F54811BBD67748DE907B3B |
24.02.2013, 10:55 | #12 |
/// Helfer-Team | Windows System Repair Virus Aktualisiere: Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck Java deaktivieren Aufgrund derezeitigen Sicherheitsluecke: http://www.trojaner-board.de/122961-...ktivieren.html Danach poste mir (kopieren und einfuegen), was du hier angezeigt bekommst: PluginCheck Hinweis: Registry Cleaner Ich sehe, dass du sogenannte Registry Cleaner installiert hast. In deinem Fall TuneUp Utilities 2012. Wir raten von der Verwendung jeglicher Art von Registry Cleaner ab. Der Grund ist ganz einfach: Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich. Man sollte nicht unnötigerweise an der Registry rumbasteln. Schon ein kleiner Fehler kann gravierende Folgen haben und auch Programme machen manchmal Fehler. Zerstörst du die Registry, zerstörst du Windows. Zudem ist der Nutzen zur Performancesteigerung umstritten und meist kaum im wahrnehmbaren Bereich. Ich würde dir empfehlen, Registry Cleaner nicht weiterhin zu verwenden und über Start --> Systemsteuerung --> Software (bei Windows XP)zu deinstallieren. |
24.02.2013, 12:04 | #13 |
| Windows System Repair Virus Hinweis: Ich habe deinen Rat befolgt und TuneUp deinstalliert. Danke:-) -> panda active scan ist allerdings noch drauf, ist der in Ordnung? Gemäss deiner Anleitung habe ich Adobe aktualisert und Java und danach gemäss den vorgeschlagenen Einstellungen eingestellt. Google Chrome habe ich inzwischen deinstalliert und im IE ist Java nicht aktiv(?). PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. • Firefox 19.0 ist aktuell • Flash 11,5,502,135 ist veraltet! Aktualisieren Sie bitte auf die neueste Version! • Java (1,7,0,15) ist aktuell. • Adobe Reader 11,0,2,0 ist aktuell. PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. • Firefox 19.0 ist aktuell • Flash 11,5,502,135 ist veraltet! Aktualisieren Sie bitte auf die neueste Version! • Java ist Installiert aber nicht aktiviert. • Adobe Reader 11,0,2,0 ist aktuell. Geändert von Swiss (24.02.2013 um 12:10 Uhr) |
24.02.2013, 12:17 | #14 | |
/// Helfer-Team | Windows System Repair VirusZitat:
Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html http://www.trojaner-board.de/109844-...ren-seite.html PC wird immer langsamer - was tun? |
24.02.2013, 20:23 | #15 |
| Windows System Repair Virus Klasse! Eine Frage: - Im Explorer sind einige Ordner noch verschlüsselt. (u.a Ordner Programme, der ganz sicher vorher noch funktioniert hat)Ich sende Dir ein Bild im Anhang. Zumindest den ersten Ordner "Recycle Bin", der jetzt zwar nicht verschlüsselt ist - glaube ich vor dem Anfall nicht dort gesehen zu haben. - Welchen aktiven Virenscanner (also à la Avast) empfiehlst du? Und natürlich... Tausend Dank für deinen Einsatz. Gibt es eine Form in der ich mich erkenntlich zeigen kann. Du hast mir schliesslich viel Kost und Müh gespart! |
Themen zu Windows System Repair Virus |
administrator, anti-malware, anzeige, anzeigen, autostart, bildschirm, dateien, explorer, fehlermeldungen, forum, mail, nicht mehr, nichts, rechtsklick, schwarze bildschirm, service, speicher, system, test, thema, tipps, version, virus, windows, windows 7 |