|
Log-Analyse und Auswertung: wie entferne ich delta search?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.03.2013, 14:52 | #1 |
| wie entferne ich delta search? Guten Tag, ich habe das Problem, dass sobald ich einen neuen Tab öffne, Delta Search immer erscheint. Ich habe auch keine Ahnung wie ich das gekriegt habe. Ich hab mich schon nach ein paar Lösungswegen für dieses Problem umgesehen, aber leider hat mir keiner weitergeholfen. Bei meiner Suche nach einer Lösung, habe ich auch diese Seite gefunden und gemerkt, dass hier schon einigen anderen mit diesem Problem geholfen wurde. Da ich mich aber mit diesen Problemen auskenne, würde ich mich über jede Hilfe freuen. :-) |
03.03.2013, 16:31 | #2 |
/// TB-Ausbilder | wie entferne ich delta search? Ich weiß genau wie du das gemacht hast. Du hast dir irgendwas kostenloses installiert und einfach immer weiter geklickt.
__________________Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Bitte Lesen: Regeln für die Bereinigung Damit die Bereinigung funktioniert bitte ich dich, die folgenden Punkte aufmerksam zu lesen:
Gelesen und verstanden? Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Deinstallation von Programmen Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Downloade Dir bitte AdwCleaner auf deinen Desktop. Schritt 3: Temporäre Dateien löschen mit TFC
Schritt 4: Scan mit DDS+ (mit attach) Downloade dir bitte DDS (von sUBs) und speichere die Datei auf deinem Desktop.
__________________ |
04.03.2013, 12:22 | #3 |
| wie entferne ich delta search?Code:
ATTFilter # AdwCleaner v2.113 - Datei am 04/03/2013 um 12:01:15 erstellt # Aktualisiert am 23/02/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Stefan - ERWIN-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Stefan.Erwin-PC\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Gelöscht mit Neustart : C:\Program Files (x86)\Common Files\AVG Secure Search Ordner Gelöscht : C:\ProgramData\AVG Secure Search ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16464 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v25.0.1364.97 -\\ Opera v11.60.1185.0 ************************* AdwCleaner[S1].txt - [382 octets] - [03/03/2013 13:44:44] AdwCleaner[S2].txt - [20432 octets] - [03/03/2013 13:51:30] AdwCleaner[S3].txt - [1023 octets] - [03/03/2013 13:53:37] AdwCleaner[S4].txt - [380 octets] - [04/03/2013 09:17:49] AdwCleaner[S5].txt - [1144 octets] - [04/03/2013 09:21:26] AdwCleaner[S6].txt - [1069 octets] - [04/03/2013 12:01:15] ########## EOF - C:\AdwCleaner[S6].txt - [1129 octets] ########## Code:
ATTFilter DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.4.1 Run by Stefan at 12:15:14 on 2013-03-04 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.4092.2146 [GMT 1:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG2012\avgrsa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Windows\SysWOW64\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Microsoft LifeCam\MSCamS64.exe c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe C:\Program Files (x86)\Steam\steam.exe C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Users\Stefan.Erwin-PC\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe C:\Games\Game Alarm\gamealarm.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin C:\Windows\SysWOW64\mmrtkrnl.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb uProxyOverride = local mWinlogon: Userinit = C:\Windows\System32\userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll BHO: Windows Live ID-Anmelde-Hilfsprogramm: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent uRun: [Facebook Update] "C:\Users\Stefan.Erwin-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver uRun: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" uRun: [GoogleChromeAutoLaunch_6428AB03B42E92A86FFF32455D8C7359] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun: [Realtime Audio Engine] "mmrtkrnl.exe" /i mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min StartupFolder: C:\Users\STEFAN~1.ERW\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FACEBO~1.LNK - C:\Users\Stefan.Erwin-PC\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe StartupFolder: C:\Users\STEFAN~1.ERW\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\GAMEAL~1.LNK - C:\Games\Game Alarm\gamealarm.exe StartupFolder: C:\Users\STEFAN~1.ERW\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe uPolicies-System: WallpaperStyle = 2 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:28 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: HideFastUserSwitching = dword:0 mPolicies-System: WallpaperStyle = 2 IE: &Alles mit BitComet herunterladen - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm IE: An OneNote s&enden - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - C:\Users\Stefan.Erwin-PC\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: Mit BitComet herunter&laden - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab TCP: NameServer = 193.170.234.122 193.170.109.23 TCP: Interfaces\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618} : DHCPNameServer = 195.34.133.21 212.186.211.21 TCP: Interfaces\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618}\4544F445 : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618}\74E4148484848484 : DHCPNameServer = 10.0.0.1 TCP: Interfaces\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618}\76E616868686 : DHCPNameServer = 192.168.137.1 TCP: Interfaces\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618}\E4564576541625 : DHCPNameServer = 10.40.27.22 193.170.109.23 TCP: Interfaces\{FA92405A-2AA9-4546-964D-8016BF7078D0} : DHCPNameServer = 193.170.234.122 193.170.109.23 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - <orphaned> mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb x64-mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Stefan.Erwin-PC\AppData\Roaming\Mozilla\Firefox\Profiles\0\ . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-11-8 307040] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-8-24 384352] R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-8-15 39768] R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-3-3 27800] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-7-5 254528] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-11-9 89600] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-7-2 203264] R2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-3-3 86752] R2 AntiVirService;Avira Echtzeit-Scanner;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-3-3 110816] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-11-2 5174392] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-3-3 99912] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-14 27136] R2 Giraffic;Veoh Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service --> C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [?] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2009-7-8 30520] R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-5-14 2280312] R2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [2013-2-19 968880] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-12-10 127328] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776] R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-10-1 228408] R3 enecir;ENE CIR Receiver;C:\Windows\System32\drivers\enecir.sys [2009-6-29 70656] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-11-9 215040] R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2009-11-9 36408] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536] S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service --> C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service [?] S3 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832] S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\System32\drivers\ewusbnet.sys [2011-6-8 216576] S3 hwusbdev;Huawei DataCard USB PNP Device;C:\Windows\System32\drivers\ewusbdev.sys [2011-6-8 114560] S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2009-7-21 140712] S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\System32\drivers\nx6000.sys [2010-5-20 36720] S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-14 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712] S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-20 1255736] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976] S4 RsFx0103;RsFx0103 Driver;C:\Windows\System32\drivers\RsFx0103.sys [2009-3-30 311656] S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 427880] . =============== Created Last 30 ================ . 2013-03-04 08:11:13 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{331E2223-D362-4393-A7D2-63FDA9B2D30D} 2013-03-03 12:45:02 714 ----a-w- C:\Windows\DeleteOnReboot.bat 2013-03-03 11:22:48 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{96ABA07D-4C76-4BBD-86FE-1CD48060D4D2} 2013-03-03 10:34:33 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Roaming\Avira 2013-03-03 10:28:48 27800 ----a-w- C:\Windows\System32\drivers\avkmgr.sys 2013-03-03 10:28:47 99912 ----a-w- C:\Windows\System32\drivers\avgntflt.sys 2013-03-03 10:28:40 -------- d-----w- C:\ProgramData\Avira 2013-03-03 10:28:40 -------- d-----w- C:\Program Files (x86)\Avira 2013-03-03 09:55:44 -------- d-----w- C:\Program Files (x86)\Gophoto.it 2013-03-03 09:47:24 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Roaming\SynthMaker 2013-03-03 09:44:51 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Roaming\Image-Line 2013-03-02 09:43:39 1700352 ----a-w- C:\Windows\SysWow64\gdiplus.dll 2013-03-01 23:22:03 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{107A3117-BCF3-43FC-A48D-2F804C92A9D1} 2013-03-01 00:08:27 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{F24DB414-02F9-49BE-97C2-8A544313DB2A} 2013-02-28 12:08:02 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{88CD3757-8038-463F-800C-66221F2A8D00} 2013-02-28 00:07:26 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{8AA749A5-C77E-42E7-83FE-11BB179E4CF1} 2013-02-27 12:07:01 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{89248735-3931-41BE-97B2-34CFA8552AC2} 2013-02-27 02:01:29 2284544 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll 2013-02-27 02:01:28 2776576 ----a-w- C:\Windows\System32\msmpeg2vdec.dll 2013-02-27 02:01:28 221184 ----a-w- C:\Windows\System32\UIAnimation.dll 2013-02-27 02:01:28 187392 ----a-w- C:\Windows\SysWow64\UIAnimation.dll 2013-02-27 02:01:07 465920 ----a-w- C:\Windows\System32\WMPhoto.dll 2013-02-27 02:01:07 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll 2013-02-27 00:06:25 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{65AEFE18-C43D-49E5-B284-1BCE0F0C67E8} 2013-02-26 12:06:00 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{3A02F330-C720-4D48-AA91-16C7AB340866} 2013-02-26 00:05:23 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{E5B052E9-A8C4-4864-827B-F544343EEB3D} 2013-02-25 12:03:24 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{F2DBCBB7-2881-471A-ABC6-E99DDBA272E5} 2013-02-24 11:45:39 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{9527A4B9-B7F2-4D76-9946-20C917491A67} 2013-02-23 15:04:53 -------- d-----r- C:\Program Files (x86)\Skype 2013-02-23 13:42:19 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{AC24E795-B5EF-49CB-AB4E-E897837A3EAC} 2013-02-22 09:11:12 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{1B8E6ECA-38E7-4457-8DAD-3A7896A228A1} 2013-02-21 21:27:31 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{A0E696F7-300F-4388-9D1E-41870471E661} 2013-02-21 09:27:05 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{BD05C9C4-7E0E-4F94-AC04-CEFB78222CBF} 2013-02-20 20:23:40 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{34E8E101-98C2-467B-B466-A5421E1B248A} 2013-02-20 08:23:16 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{9A8E0CAB-B295-4583-9951-826EFC9387FA} 2013-02-19 20:22:40 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{A9BE55A3-343A-4D24-B51B-5D3D4D813A7C} 2013-02-19 08:21:40 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{3BA7A012-1D06-44BD-97A0-723DDF79A8FD} 2013-02-18 15:38:28 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{B634AC71-8CD7-4BAD-89D1-FB8753EC9AEB} 2013-02-17 23:59:53 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{7B245D2A-5A99-446C-BBF5-632E562D4908} 2013-02-17 12:48:36 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Roaming\PerformerSoft 2013-02-17 12:48:29 19632 ----a-w- C:\Windows\System32\roboot64.exe 2013-02-17 12:48:03 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2 2013-02-17 12:19:07 225280 ----a-w- C:\Windows\SysWow64\rewire.dll 2013-02-17 12:19:07 -------- d-----w- C:\Program Files (x86)\VstPlugins 2013-02-17 12:18:40 1554944 ----a-w- C:\Windows\SysWow64\vorbis.acm 2013-02-17 12:18:32 -------- d-----w- C:\Program Files (x86)\Outsim 2013-02-17 11:59:30 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{78604B88-C301-4040-8644-9891C98079F2} 2013-02-17 10:51:00 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Roaming\YourFileDownloader 2013-02-16 23:58:53 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{00EC3AFC-CF97-468D-85D9-5FAA4E2BA841} 2013-02-16 11:58:28 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{421E5410-1939-486F-A4D5-5AEC55FFCB1E} 2013-02-15 23:58:04 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{6DD0DB7F-AC16-468A-A341-B9C5503000E6} 2013-02-15 19:52:42 -------- d-----w- C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} 2013-02-15 11:57:04 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{B6518FC0-CFA2-4556-8759-4CFCB2F0A7FC} 2013-02-15 10:27:15 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{E7D0D2AD-BC62-4977-A0A5-CC679C5F81C2} 2013-02-14 21:09:20 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{9F2D1B11-C0F4-448F-83BC-7339621D9C28} 2013-02-14 07:23:42 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{503C538E-5339-44A8-8B8E-A84CD93EDE23} 2013-02-14 02:05:28 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-14 02:05:28 768000 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-14 00:31:04 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe 2013-02-14 00:31:03 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-02-14 00:31:02 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-02-14 00:30:50 3153408 ----a-w- C:\Windows\System32\win32k.sys 2013-02-14 00:30:42 215040 ----a-w- C:\Windows\System32\winsrv.dll 2013-02-14 00:30:40 25600 ----a-w- C:\Windows\SysWow64\setup16.exe 2013-02-14 00:30:39 7680 ----a-w- C:\Windows\SysWow64\instnm.exe 2013-02-14 00:30:39 5120 ----a-w- C:\Windows\SysWow64\wow32.dll 2013-02-14 00:30:39 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll 2013-02-14 00:30:30 2048 ----a-w- C:\Windows\SysWow64\user.exe 2013-02-14 00:30:22 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2013-02-14 00:30:21 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2013-02-13 07:51:40 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{2211D6A0-1A10-4DA2-BB6D-6617A97967C2} 2013-02-13 06:35:36 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{2C59A54D-1515-44AB-8467-3503E5A62BEB} 2013-02-12 20:15:52 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{4C6722BE-A543-41C4-8660-14AB700C6E92} 2013-02-12 08:15:26 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{6A33D9A3-FC33-4057-B5A7-EB458F4217ED} 2013-02-11 13:31:55 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{EFE25F64-735D-4C38-A0CD-520433077D05} 2013-02-10 14:24:05 -------- d-----w- C:\ProgramData\TERA 2013-02-10 14:23:53 -------- d-----w- C:\Program Files (x86)\TERA 2013-02-10 11:25:29 -------- d-----w- C:\Users\Stefan.Erwin-PC\AppData\Local\{41AA09DE-A736-40F3-B6F8-A9E656F5F47B} . ==================== Find3M ==================== . 2013-02-26 21:07:30 71024 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-26 21:07:30 691568 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-02-19 16:44:37 39768 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys 2013-01-21 10:12:12 2177664 ----a-w- C:\Windows\System32\coin93.dll 2013-01-13 21:17:03 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 21:17:02 2560 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 21:16:42 10752 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 21:12:46 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 21:11:21 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 21:11:08 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 21:11:07 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 21:11:07 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 21:11:07 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:35:31 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 20:35:31 2560 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 20:35:18 10752 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 20:32:07 3584 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 20:31:48 4096 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 20:31:41 5632 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 20:31:40 5632 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 20:31:40 3072 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 20:31:40 3072 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:31:00 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll 2013-01-13 20:22:22 1988096 ----a-w- C:\Windows\SysWow64\d3d10warp.dll 2013-01-13 20:20:31 293376 ----a-w- C:\Windows\SysWow64\dxgi.dll 2013-01-13 20:09:00 249856 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll 2013-01-13 20:08:43 220160 ----a-w- C:\Windows\SysWow64\d3d10core.dll 2013-01-13 20:08:35 1504768 ----a-w- C:\Windows\SysWow64\d3d11.dll 2013-01-13 19:59:04 1643520 ----a-w- C:\Windows\System32\DWrite.dll 2013-01-13 19:58:28 1175552 ----a-w- C:\Windows\System32\FntCache.dll 2013-01-13 19:54:01 604160 ----a-w- C:\Windows\SysWow64\d3d10level9.dll 2013-01-13 19:53:58 207872 ----a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll 2013-01-13 19:51:30 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll 2013-01-13 19:49:17 363008 ----a-w- C:\Windows\System32\dxgi.dll 2013-01-13 19:48:47 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll 2013-01-13 19:46:25 1080832 ----a-w- C:\Windows\SysWow64\d3d10.dll 2013-01-13 19:43:21 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-01-13 19:38:39 333312 ----a-w- C:\Windows\System32\d3d10_1core.dll 2013-01-13 19:38:32 1887232 ----a-w- C:\Windows\System32\d3d11.dll 2013-01-13 19:38:21 296960 ----a-w- C:\Windows\System32\d3d10core.dll 2013-01-13 19:37:57 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll 2013-01-13 19:25:04 245248 ----a-w- C:\Windows\System32\WindowsCodecsExt.dll 2013-01-13 19:24:33 648192 ----a-w- C:\Windows\System32\d3d10level9.dll 2013-01-13 19:20:42 194560 ----a-w- C:\Windows\System32\d3d10_1.dll 2013-01-13 19:20:04 1238528 ----a-w- C:\Windows\System32\d3d10.dll 2013-01-13 19:15:40 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll 2013-01-13 19:10:36 3928064 ----a-w- C:\Windows\System32\d2d1.dll 2013-01-13 18:34:58 364544 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2013-01-13 18:09:52 522752 ----a-w- C:\Windows\System32\XpsGdiConverter.dll 2013-01-13 17:26:42 1158144 ----a-w- C:\Windows\SysWow64\XpsPrint.dll 2013-01-13 17:05:09 1682432 ----a-w- C:\Windows\System32\XpsPrint.dll 2013-01-09 01:19:09 2312704 ----a-w- C:\Windows\System32\jscript9.dll 2013-01-09 01:12:03 1392128 ----a-w- C:\Windows\System32\wininet.dll 2013-01-09 01:11:06 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl 2013-01-09 01:07:51 173056 ----a-w- C:\Windows\System32\ieUnatt.exe 2013-01-09 01:07:47 599040 ----a-w- C:\Windows\System32\vbscript.dll 2013-01-09 01:04:42 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2013-01-08 22:11:21 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll 2013-01-08 22:03:20 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll 2013-01-08 22:03:12 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-01-08 21:59:02 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-01-08 21:58:29 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll 2013-01-08 21:56:23 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll 2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll 2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll 2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-10 02:28:34 127328 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys 2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll 2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll 2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll 2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll 2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs 2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs 2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs 2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs 2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs 2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs 2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs 2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs 2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs 2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs 2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs 2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs 2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs 2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs . ============= FINISH: 12:18:12,93 =============== Code:
ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 30.05.2010 11:17:27 System Uptime: 04.03.2013 12:09:32 (0 hours ago) . Motherboard: Quanta | | 3637 Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 452 GiB total, 175,463 GiB free. D: is FIXED (NTFS) - 13 GiB total, 2,204 GiB free. E: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP506: 24.02.2013 19:13:52 - Geplanter Prüfpunkt RP507: 27.02.2013 03:00:18 - Windows Update RP508: 03.03.2013 13:28:55 - Removed Java(TM) 6 Update 14 (64-bit) RP509: 03.03.2013 13:31:02 - Removed Java(TM) 6 Update 27 RP510: 03.03.2013 13:32:20 - Removed Java(TM) SE Development Kit 6 Update 27 RP511: 03.03.2013 13:35:49 - TuneUp Utilities 2012 wird entfernt RP512: 03.03.2013 13:36:58 - TuneUp Utilities Language Pack (de-DE) wird entfernt RP513: 04.03.2013 09:31:50 - Entfernt Empire Earth RP514: 04.03.2013 09:33:38 - Entfernt EE-ZDE RP515: 04.03.2013 09:35:02 - Removed Hitman Blood Money RP516: 04.03.2013 09:36:19 - Removed Project64 1.6 RP517: 04.03.2013 09:37:04 - Removed VirtualDJ Home FREE RP518: 04.03.2013 09:39:25 - Entfernt Rome - Total War - Gold Edition RP519: 04.03.2013 10:00:06 - Removed Project64 1.6 . ==== Installed Programs ====================== . A1 Dashboard Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.2 MUI AMD USB Filter Driver Android SDK Tools Apple Application Support Apple Mobile Device Support Apple Software Update ASIO4ALL Aspire Atheros Driver Installation Program ATI Catalyst Install Manager Aufstieg des Hexenkönigs™ AVG 2012 Avira Free Antivirus BattlEye Uninstall BitComet 1.29 Bonjour BPM-Studio 4 Demo Call of Duty: Modern Warfare 2 Call of Duty: Modern Warfare 2 - Multiplayer Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Cisco Packet Tracer 5.3.2 Company of Heroes Compatibility Pack für 2007 Office System Counter-Strike: Source Crystal Reports for Visual Studio CyberLink DVD Suite D3DX10 DAEMON Tools Lite Dead Rising 2 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Diablo II Die Schlacht um Mittelerde™ II Direkt Foto System 3.x DivX-Setup Dotfuscator Software Services - Community Edition Dragon Age: Origins Dual-Core Optimizer EAX(tm) Unified (SHELL) Empire: Total War ENE CIR Receiver Driver Facebook Messenger 2.1.4651.0 Facebook Video Calling 1.2.0.287 Fallout: New Vegas Far Cry FINAL FANTASY VIII Floris Mod Pack 2.533 Free Audio CD Burner version 1.4.8 Free YouTube Download version 3.1.25.423 Free YouTube to MP3 Converter version 3.11.37.1212 Game Alarm Google Chrome Google Earth Google Update Helper Hamachi 1.0.1.5 Hewlett-Packard ACLM.NET v1.2.1.1 Hotfix for Microsoft Visual Studio 2010 Professional - ENU (KB2455033) HP 3D DriveGuard HP Customer Experience Enhancements HP Games HP MediaSmart DVD HP MediaSmart Internet TV HP MediaSmart Live TV HP MediaSmart Movie Themes HP MediaSmart Music/Photo/Video HP MediaSmart Webcam HP Quick Launch Buttons HP Setup HP Support Assistant HP Update HP User Guides 0154 HP Wireless Assistant IDT Audio IL Download Manager iTunes Java Auto Updater Java(TM) 7 Update 4 JavaFX 2.1.0 JMicron Flash Media Controller Driver Junk Mail filter update LabelPrint Left 4 Dead 2 LightScribe System Software LogMeIn Hamachi Medieval II Total War Medieval II Total War : Kingdoms : Americas Medieval II Total War : Kingdoms : Britannia Medieval II Total War : Kingdoms : Crusades Medieval II Total War : Kingdoms : Teutonic Microsoft .NET Framework 1.1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft .NET Framework 4 Extended Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Access 2010 Microsoft Application Error Reporting Microsoft ASP.NET MVC 2 Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools Microsoft Corporation Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Help Viewer 1.0 Microsoft LifeCam Microsoft Office 2010 Language Pack Service Pack 1 (SP1) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access 2010 Microsoft Office Access MUI (German) 2010 Microsoft Office Excel MUI (German) 2010 Microsoft Office Home and Student 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (German) 2010 Microsoft Office Outlook MUI (German) 2010 Microsoft Office PowerPoint MUI (German) 2010 Microsoft Office PowerPoint Viewer 2007 (German) Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proof (Italian) 2010 Microsoft Office Proofing (German) 2010 Microsoft Office Publisher MUI (German) 2010 Microsoft Office Shared 64-bit MUI (German) 2010 Microsoft Office Shared MUI (German) 2010 Microsoft Office Single Image 2010 Microsoft Office Suite Activation Assistant Microsoft Office Visio 2010 Microsoft Office Visio MUI (German) 2010 Microsoft Office Word MUI (German) 2010 Microsoft Silverlight Microsoft Silverlight 3 SDK Microsoft SQL Server 2008 (64-bit) Microsoft SQL Server 2008 Browser Microsoft SQL Server 2008 Common Files Microsoft SQL Server 2008 Database Engine Services Microsoft SQL Server 2008 Database Engine Shared Microsoft SQL Server 2008 Native Client Microsoft SQL Server 2008 R2 Data-Tier Application Framework Microsoft SQL Server 2008 R2 Data-Tier Application Project Microsoft SQL Server 2008 R2 Management Objects Microsoft SQL Server 2008 R2 Management Objects (x64) Microsoft SQL Server 2008 R2 Transact-SQL Language Service Microsoft SQL Server 2008 RsFx Driver Microsoft SQL Server 2008 Setup Support Files Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft SQL Server Compact 3.5 SP2 x64 ENU Microsoft SQL Server Database Publishing Wizard 1.4 Microsoft SQL Server System CLR Types Microsoft SQL Server System CLR Types (x64) Microsoft SQL Server VSS Writer Microsoft Sync Framework Runtime v1.0 SP1 (x64) Microsoft Sync Framework SDK v1.0 SP1 Microsoft Sync Framework Services v1.0 SP1 (x64) Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) Microsoft Team Foundation Server 2010 Object Model - ENU Microsoft Visio 2010 Service Pack 1 (SP1) Microsoft Visio Professional 2010 Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319 Microsoft Visual F# 2.0 Runtime Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools Microsoft Visual Studio 2010 Office Developer Tools (x64) Microsoft Visual Studio 2010 Professional - ENU Microsoft Visual Studio 2010 SharePoint Developer Tools Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU Microsoft Visual Studio Macro Tools Microsoft Works Microsoft XNA Framework Redistributable 4.0 Microsoft XNA Game Studio 4.0 Microsoft XNA Game Studio 4.0 (ARP entry) Microsoft XNA Game Studio 4.0 (Redists) Microsoft XNA Game Studio 4.0 (Shared Components) Microsoft XNA Game Studio 4.0 (Visual Studio) Microsoft XNA Game Studio 4.0 (XnaLiveProxy) Microsoft XNA Game Studio 4.0 Documentation Microsoft XNA Game Studio Platform Tools Mount & Blade Mount & Blade: Warband Mozilla Firefox 19.0 (x86 de) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NC Launcher (GameForge) NVIDIA PhysX Oblivion OpenAL OpenOffice.org 3.2 Opera 11.60 osu! Paint.NET v3.5.8 Pando Media Booster PCSX2 - Playstation 2 Emulator PhotoMail Maker Pixia Power2Go PowerDirector PowerRecover PunkBuster Services QLBCASL QuickTime Realtek 8136 8168 8169 Ethernet Driver S4 League_EU Screenbrush 1.3.1 Secure Download Manager Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Visual Studio 2010 Professional - ENU (KB2251489) Security Update for Microsoft Visual Studio 2010 Professional - ENU (KB2644980) Security Update for Microsoft Visual Studio Macro Tools (KB2669970) Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) Ski Challenge 12 (AT) Ski Challenge 13 (AT) Skype™ 6.1 SpeechRedist Sql Server Customer Experience Improvement Program SQLTools 1.6 (remove only) Steam Synaptics Pointing Device Driver TeamSpeak 3 Client TeamViewer 6 TERA Third Age - Total War 2.0 (Part1of2) Third Age - Total War 2.0 (Part2of2) Two Worlds II Ubisoft Game Launcher Uninstall 1.0.0.1 Unity Web Player Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition VC80CRTRedist - 8.0.50727.6195 Veoh Giraffic Video Accelerator Veoh Web Player Visual Studio 2008 x64 Redistributables Visual Studio 2010 Prerequisites - English Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU VLC media player 1.1.9 Vuze Web Deployment Tool Webocton - Scriptly 0.8.95.6 Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Messenger Windows Live MIME IFilter Windows Live OneCare safety scanner Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinRAR WinRAR 4.00 (64-Bit) XAMPP 1.8.1 . ==== End Of File =========================== |
05.03.2013, 14:37 | #4 |
/// TB-Ausbilder | wie entferne ich delta search? Du hast zwei Virenscanner! Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Entferne einen der beiden Virenscanner. Ich würde Avira entfernen - ist aber deine Entscheidung. Schritt 2: Bevor es weitergeht: Besteht das Problem mit Delta noch?
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
05.03.2013, 20:52 | #5 |
| wie entferne ich delta search? Ich habe Avira entfernt. Das Problem mit Delta Search besteht aber leider immer noch. |
05.03.2013, 21:21 | #6 |
/// TB-Ausbilder | wie entferne ich delta search? Dann geht es weiter: Scan mit Combofix
__________________ --> wie entferne ich delta search? |
05.03.2013, 23:42 | #7 |
| wie entferne ich delta search?Code:
ATTFilter ComboFix 13-03-05.01 - Stefan 05.03.2013 21:54:41.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.4092.2232 [GMT 1:00] ausgeführt von:: c:\users\Stefan.Erwin-PC\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\users\Stefan.Erwin-PC\AppData\Local\assembly\tmp c:\users\Stefan.Erwin-PC\videos\Aspire.exe c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-05 bis 2013-03-05 )))))))))))))))))))))))))))))) . . 2013-03-05 21:10 . 2013-03-05 21:10 -------- d-----w- c:\users\STEFAN~1~ERW\AppData\Local\temp 2013-03-05 21:10 . 2013-03-05 21:10 -------- d-----w- c:\users\Mcx1-ERWIN-PC\AppData\Local\temp 2013-03-05 21:10 . 2013-03-05 21:10 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-03 12:45 . 2013-03-04 11:01 714 ----a-w- c:\windows\DeleteOnReboot.bat 2013-03-03 09:55 . 2013-03-03 09:55 -------- d-----w- c:\program files (x86)\Gophoto.it 2013-03-02 09:43 . 2013-03-02 09:43 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll 2013-02-27 02:01 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-27 02:01 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-27 02:01 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-27 02:01 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-02-27 02:01 . 2013-01-13 19:02 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-02-27 02:01 . 2013-01-13 18:32 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-02-23 15:04 . 2013-02-23 15:04 -------- d-----r- c:\program files (x86)\Skype 2013-02-23 15:04 . 2013-02-23 15:04 -------- d-----w- c:\program files (x86)\Common Files\Skype 2013-02-21 09:47 . 2013-02-21 09:47 -------- d-----w- c:\users\Stefan 2013-02-17 12:48 . 2012-12-19 14:53 19632 ----a-w- c:\windows\system32\roboot64.exe 2013-02-17 12:48 . 2013-02-17 12:48 -------- d-----w- c:\program files (x86)\ASIO4ALL v2 2013-02-17 12:19 . 2013-03-03 10:03 -------- d-----w- c:\program files (x86)\VstPlugins 2013-02-17 12:19 . 2006-06-20 08:56 225280 ----a-w- c:\windows\SysWow64\rewire.dll 2013-02-17 12:18 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\SysWow64\vorbis.acm 2013-02-17 12:18 . 2013-02-17 12:18 -------- d-----w- c:\program files (x86)\Outsim 2013-02-15 19:52 . 2013-02-15 19:52 -------- d-----w- c:\programdata\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} 2013-02-14 02:05 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-14 02:05 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-02-14 02:00 . 2013-01-09 01:22 10925568 ----a-w- c:\windows\system32\ieframe.dll 2013-02-14 00:31 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-02-14 00:31 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-02-14 00:31 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-02-14 00:30 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-02-14 00:30 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-02-14 00:30 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-02-14 00:30 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-02-14 00:30 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-02-14 00:30 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-02-14 00:30 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-02-14 00:30 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-14 00:30 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-10 14:24 . 2013-02-10 14:24 -------- d-----w- c:\programdata\TERA 2013-02-10 14:23 . 2013-02-10 14:24 -------- d-----w- c:\program files (x86)\TERA . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-26 21:07 . 2012-04-01 01:48 691568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-26 21:07 . 2011-08-16 21:10 71024 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-19 16:44 . 2012-08-15 21:35 39768 ----a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-01-21 10:12 . 2013-01-21 10:12 2177664 ----a-w- c:\windows\system32\coin93.dll 2013-01-04 04:43 . 2013-02-14 00:30 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-12-16 17:11 . 2012-12-21 05:41 46080 ----a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 05:41 367616 ----a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 05:41 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 05:41 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2012-12-10 02:28 . 2012-12-10 02:28 127328 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys 2012-12-07 13:20 . 2013-01-10 07:35 441856 ----a-w- c:\windows\system32\Wpc.dll 2012-12-07 13:15 . 2013-01-10 07:35 2746368 ----a-w- c:\windows\system32\gameux.dll 2012-12-07 12:26 . 2013-01-10 07:35 308736 ----a-w- c:\windows\SysWow64\Wpc.dll 2012-12-07 12:20 . 2013-01-10 07:35 2576384 ----a-w- c:\windows\SysWow64\gameux.dll 2012-12-07 11:20 . 2013-01-10 07:35 30720 ----a-w- c:\windows\system32\usk.rs 2012-12-07 11:20 . 2013-01-10 07:35 43520 ----a-w- c:\windows\system32\csrr.rs 2012-12-07 11:20 . 2013-01-10 07:35 23552 ----a-w- c:\windows\system32\oflc.rs 2012-12-07 11:20 . 2013-01-10 07:35 45568 ----a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 11:20 . 2013-01-10 07:35 44544 ----a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 11:20 . 2013-01-10 07:35 20480 ----a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 11:20 . 2013-01-10 07:35 20480 ----a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 11:19 . 2013-01-10 07:35 20480 ----a-w- c:\windows\system32\pegi.rs 2012-12-07 11:19 . 2013-01-10 07:35 46592 ----a-w- c:\windows\system32\fpb.rs 2012-12-07 11:19 . 2013-01-10 07:35 40960 ----a-w- c:\windows\system32\cob-au.rs 2012-12-07 11:19 . 2013-01-10 07:35 21504 ----a-w- c:\windows\system32\grb.rs 2012-12-07 11:19 . 2013-01-10 07:35 15360 ----a-w- c:\windows\system32\djctq.rs 2012-12-07 11:19 . 2013-01-10 07:35 55296 ----a-w- c:\windows\system32\cero.rs 2012-12-07 11:19 . 2013-01-10 07:35 51712 ----a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-10 07:35 43520 ----a-w- c:\windows\SysWow64\csrr.rs 2012-12-07 10:46 . 2013-01-10 07:35 30720 ----a-w- c:\windows\SysWow64\usk.rs 2012-12-07 10:46 . 2013-01-10 07:35 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs 2012-12-07 10:46 . 2013-01-10 07:35 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs 2012-12-07 10:46 . 2013-01-10 07:35 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs 2012-12-07 10:46 . 2013-01-10 07:35 23552 ----a-w- c:\windows\SysWow64\oflc.rs 2012-12-07 10:46 . 2013-01-10 07:35 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs 2012-12-07 10:46 . 2013-01-10 07:35 46592 ----a-w- c:\windows\SysWow64\fpb.rs 2012-12-07 10:46 . 2013-01-10 07:35 20480 ----a-w- c:\windows\SysWow64\pegi.rs 2012-12-07 10:46 . 2013-01-10 07:35 21504 ----a-w- c:\windows\SysWow64\grb.rs 2012-12-07 10:46 . 2013-01-10 07:35 40960 ----a-w- c:\windows\SysWow64\cob-au.rs 2012-12-07 10:46 . 2013-01-10 07:35 15360 ----a-w- c:\windows\SysWow64\djctq.rs 2012-12-07 10:46 . 2013-01-10 07:35 51712 ----a-w- c:\windows\SysWow64\esrb.rs 2012-12-07 10:46 . 2013-01-10 07:35 55296 ----a-w- c:\windows\SysWow64\cero.rs . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . c:\users\Stefan.Erwin-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Facebook Messenger.lnk - c:\users\Stefan.Erwin-PC\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe [2012-9-25 247728] Game Alarm.lnk - c:\games\Game Alarm\gamealarm.exe [2012-12-5 19721728] OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system] "WallpaperStyle"= 2 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="c:\windows\system32\userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\program files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam" "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "HP Software Update"=c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files (x86)\BitComet\tools\BitCometService.exe [2010-12-28 1296728] R3 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 47616] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-09-04 216576] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 114560] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 140712] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-05-20 36720] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-02-18 51712] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-20 1255736] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-11-08 307040] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2013-02-19 39768] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-05 254528] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-03-02 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 203264] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\avgidsagent.exe [2012-11-02 5174392] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] S2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-07-02 2232504] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 30520] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312] S2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [2013-02-19 968880] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-12-10 127328] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776] S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408] . . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 11:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-24 16:10 1629648 ----a-w- c:\program files (x86)\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-03-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 21:07] . 2013-03-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1462203106-3395138808-3887170014-1005Core.job - c:\users\Stefan.Erwin-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-17 21:11] . 2013-03-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1462203106-3395138808-3887170014-1005UA.job - c:\users\Stefan.Erwin-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-17 21:11] . 2013-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-30 09:38] . 2013-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-30 09:38] . 2013-02-15 c:\windows\Tasks\HPCeeScheduleForStefan.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 02:22] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com uLocal Page = c:\windows\system32\blank.htm uSearch Page = mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_AT&c=94&bd=Pavilion&pf=cnnb mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = local IE: &Alles mit BitComet herunterladen - c:\program files (x86)\BitComet\BitComet.exe/AddAllLink.htm IE: An OneNote s&enden - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - c:\users\Stefan.Erwin-PC\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: Mit BitComet herunter&laden - c:\program files (x86)\BitComet\BitComet.exe/AddLink.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 195.34.133.21 212.186.211.21 FF - ProfilePath - c:\users\Stefan.Erwin-PC\AppData\Roaming\Mozilla\Firefox\Profiles\0\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-BattlEye - c:\program files\Bohemia Interactive\ArmABattlEye\UnInstallBE.exe AddRemove-BattlEye for A2 - c:\program files (x86)\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe AddRemove-FINAL FANTASY VIII - c:\program files (x86)\Eidos Interactive\Square Soft AddRemove-Free Audio CD Burner_is1 - c:\program files (x86)\DVDVideoSoft\Free Audio CD Burner\unins000.exe AddRemove-IL Download Manager - c:\program files (x86)\Image-Line\Downloader\uninstall.exe AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Data] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Networking] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Networking 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET Data Provider for Oracle] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET Data Provider for SqlServer] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET Memory Cache 4.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NETFramework] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\1394ohci] "ImagePath"="\SystemRoot\system32\drivers\1394ohci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Accelerometer] "ImagePath"="system32\DRIVERS\Accelerometer.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ACPI] "ImagePath"="system32\drivers\ACPI.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AcpiPmi] "ImagePath"="\SystemRoot\system32\drivers\acpipmi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AdobeFlashPlayerUpdateSvc] "ImagePath"="c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adp94xx] "ImagePath"="system32\DRIVERS\adp94xx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adpahci] "ImagePath"="system32\DRIVERS\adpahci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adpu320] "ImagePath"="system32\DRIVERS\adpu320.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adsi] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AeLookupSvc] "ServiceDll"="%SystemRoot%\System32\aelupsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AESTFilters] "ImagePath"="c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AFD] "ImagePath"="\SystemRoot\system32\drivers\afd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AgereSoftModem] "ImagePath"="system32\DRIVERS\agrsm64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\agp440] "ImagePath"="\SystemRoot\system32\drivers\agp440.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ALG] "ImagePath"="%SystemRoot%\System32\alg.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\aliide] "ImagePath"="system32\drivers\aliide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AMD External Events Utility] "ImagePath"="%SystemRoot%\system32\atiesrxx.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdide] "ImagePath"="system32\drivers\amdide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AmdK8] "ImagePath"="\SystemRoot\system32\DRIVERS\amdk8.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AmdPPM] "ImagePath"="system32\DRIVERS\amdppm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdsata] "ImagePath"="system32\drivers\amdsata.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdsbs] "ImagePath"="system32\DRIVERS\amdsbs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdxata] "ImagePath"="system32\drivers\amdxata.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppID] "ImagePath"="\SystemRoot\system32\drivers\appid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppIDSvc] "ServiceDll"="%SystemRoot%\System32\appidsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Appinfo] "ServiceDll"="%SystemRoot%\System32\appinfo.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Apple Mobile Device] "ImagePath"="\"c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppMgmt] "ServiceDll"="%SystemRoot%\System32\appmgmts.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\arc] "ImagePath"="system32\DRIVERS\arc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\arcsas] "ImagePath"="system32\DRIVERS\arcsas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ASP.NET] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ASP.NET_1.1.4322] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ASP.NET_4.0.30319] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\aspnet_state] "ImagePath"="%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AsyncMac] "ImagePath"="system32\DRIVERS\asyncmac.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\atapi] "ImagePath"="system32\drivers\atapi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\athr] "ImagePath"="system32\DRIVERS\athrx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Atierecord] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AtiHdmiService] "ImagePath"="system32\drivers\AtiHdmi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\atikmdag] "ImagePath"="system32\DRIVERS\atikmdag.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AtiPcie] "ImagePath"="system32\DRIVERS\AtiPcie.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\atksgt] "ImagePath"="system32\DRIVERS\atksgt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AudioEndpointBuilder] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AudioSrv] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avg] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSAgent] "ImagePath"="\"c:\program files (x86)\AVG\AVG2012\avgidsagent.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSDriver] "ImagePath"="system32\DRIVERS\avgidsdrivera.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSFilter] "ImagePath"="system32\DRIVERS\avgidsfiltera.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSHA] "ImagePath"="system32\DRIVERS\avgidsha.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgldx64] "ImagePath"="system32\DRIVERS\avgldx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgmfx64] "ImagePath"="system32\DRIVERS\avgmfx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgrkx64] "ImagePath"="system32\DRIVERS\avgrkx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgtdia] "ImagePath"="system32\DRIVERS\avgtdia.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\avgtp] "ImagePath"="\??\c:\windows\system32\drivers\avgtpx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\avgwd] "ImagePath"="\"c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AxInstSV] "ServiceDll"="%SystemRoot%\System32\AxInstSV.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\b06bdrv] "ImagePath"="\SystemRoot\system32\DRIVERS\bxvbda.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\b57nd60a] "ImagePath"="system32\DRIVERS\b57nd60a.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BattC] "MofImagePath"="system32\drivers\battc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BDESVC] "ServiceDll"="%SystemRoot%\System32\bdesvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Beep] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BFE] "ServiceDll"="%SystemRoot%\System32\bfe.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BITCOMET_HELPER_SERVICE] "ImagePath"="c:\program files (x86)\BitComet\tools\BitCometService.exe -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BITS] "ServiceDll"="%systemroot%\system32\qmgr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\blbdrive] "ImagePath"="\SystemRoot\system32\DRIVERS\blbdrive.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Bonjour Service] "ImagePath"="\"c:\program files (x86)\Bonjour\mDNSResponder.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\bowser] "ImagePath"="system32\DRIVERS\bowser.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrFiltLo] "ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltLo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrFiltUp] "ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltUp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BridgeMP] "ImagePath"="system32\DRIVERS\bridge.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Browser] "ServiceDll"="%SystemRoot%\System32\browser.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Brserid] "ImagePath"="\SystemRoot\System32\Drivers\Brserid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrSerWdm] "ImagePath"="\SystemRoot\System32\Drivers\BrSerWdm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrUsbMdm] "ImagePath"="\SystemRoot\System32\Drivers\BrUsbMdm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrUsbSer] "ImagePath"="\SystemRoot\System32\Drivers\BrUsbSer.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BTHMODEM] "ImagePath"="\SystemRoot\system32\DRIVERS\bthmodem.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BTHPORT] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\bthserv] "ServiceDll"="%SystemRoot%\system32\bthserv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\catchme] "ImagePath"="\??\c:\combofix\catchme.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cdfs] "ImagePath"="system32\DRIVERS\cdfs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cdrom] "ImagePath"="\SystemRoot\system32\drivers\cdrom.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CertPropSvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\circlass] "ImagePath"="system32\DRIVERS\circlass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CLFS] "ImagePath"="System32\CLFS.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v2.0.50727_32] "ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v2.0.50727_64] "ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v4.0.30319_32] "ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v4.0.30319_64] "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CmBatt] "ImagePath"="\SystemRoot\system32\DRIVERS\CmBatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cmdide] "ImagePath"="system32\drivers\cmdide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CNG] "ImagePath"="System32\Drivers\cng.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Com4QLBEx] "ImagePath"="\"c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Compbatt] "ImagePath"="system32\DRIVERS\compbatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CompositeBus] "ImagePath"="\SystemRoot\system32\drivers\CompositeBus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\COMSysApp] "ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\crcdisk] "ImagePath"="\SystemRoot\system32\DRIVERS\crcdisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\crypt32] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CryptSvc] "ServiceDll"="%SystemRoot%\system32\cryptsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DAUpdaterSvc] "ImagePath"="c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\dc3d] "ImagePath"="system32\DRIVERS\dc3d.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DCLocator] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DcomLaunch] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\defragsvc] "ServiceDll"="%Systemroot%\System32\defragsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DfsC] "ImagePath"="System32\Drivers\dfsc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dhcp] "ServiceDll"="%SystemRoot%\system32\dhcpcore.dll" -- . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\discache] "ImagePath"="System32\drivers\discache.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Disk] "ImagePath"="system32\DRIVERS\disk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dnscache] "ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\dot3svc] "ServiceDll"="%SystemRoot%\System32\dot3svc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DPS] "ServiceDll"="%SystemRoot%\system32\dps.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\drmkaud] "ImagePath"="system32\drivers\drmkaud.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\dtsoftbus01] "ImagePath"="system32\DRIVERS\dtsoftbus01.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DXGKrnl] "ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EagleX64] "ImagePath"="\??\c:\windows\system32\drivers\EagleX64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EapHost] "ServiceDll"="%SystemRoot%\System32\eapsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ebdrv] "ImagePath"="\SystemRoot\system32\DRIVERS\evbda.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EFS] "ImagePath"="%SystemRoot%\System32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ehRecvr] "ImagePath"="%systemroot%\ehome\ehRecvr.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ehSched] "ImagePath"="%systemroot%\ehome\ehsched.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\elxstor] "ImagePath"="system32\DRIVERS\elxstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\enecir] "ImagePath"="system32\DRIVERS\enecir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ErrDev] "ImagePath"="\SystemRoot\system32\drivers\errdev.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ESENT] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\eventlog] "ServiceDll"="%SystemRoot%\System32\wevtsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EventSystem] "ServiceDll"="%systemroot%\system32\es.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ewusbnet] "ImagePath"="system32\DRIVERS\ewusbnet.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\exfat] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ezntsvc] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ezSharedSvc] "ServiceDll"="c:\windows\System32\ezsvc7.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fastfat] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Fax] "ImagePath"="%systemroot%\system32\fxssvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fdc] "ImagePath"="\SystemRoot\system32\DRIVERS\fdc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fdPHost] "ServiceDll"="%SystemRoot%\system32\fdPHost.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FDResPub] "ServiceDll"="%SystemRoot%\system32\fdrespub.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FileInfo] "ImagePath"="system32\drivers\fileinfo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Filetrace] "ImagePath"="system32\drivers\filetrace.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\flpydisk] "ImagePath"="\SystemRoot\system32\DRIVERS\flpydisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FltMgr] "ImagePath"="system32\drivers\fltmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FontCache] "ServiceDll"="%SystemRoot%\system32\FntCache.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FontCache3.0.0.0] "ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FsDepends] "ImagePath"="System32\drivers\FsDepends.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Fs_Rec] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fvevol] "ImagePath"="System32\DRIVERS\fvevol.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gagp30kx] "ImagePath"="\SystemRoot\system32\DRIVERS\gagp30kx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\GameConsoleService] "ImagePath"="\"c:\program files (x86)\HP Games\HP Game Console\GameConsoleService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\GEARAspiWDM] "ImagePath"="system32\DRIVERS\GEARAspiWDM.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Giraffic] "ImagePath"="c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gpsvc] "ServiceDll"="%SystemRoot%\System32\gpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gupdate] "ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gupdatem] "ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hamachi] "ImagePath"="system32\DRIVERS\hamachi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Hamachi2Svc] "ImagePath"="\"c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe\" -s" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hcw85cir] "ImagePath"="\SystemRoot\system32\drivers\hcw85cir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HdAudAddService] "ImagePath"="\SystemRoot\system32\drivers\HdAudio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HDAudBus] "ImagePath"="\SystemRoot\system32\drivers\HDAudBus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidBatt] "ImagePath"="\SystemRoot\system32\DRIVERS\HidBatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidBth] "ImagePath"="\SystemRoot\system32\DRIVERS\hidbth.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidIr] "ImagePath"="system32\DRIVERS\hidir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hidserv] "ServiceDll"="%SystemRoot%\System32\hidserv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidUsb] "ImagePath"="system32\DRIVERS\hidusb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hkmsvc] "ServiceDLL"="%SystemRoot%\system32\kmsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HomeGroupListener] "ServiceDll"="%SystemRoot%\system32\ListSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HomeGroupProvider] "ServiceDll"="%SystemRoot%\system32\provsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HP Support Assistant Service] "ImagePath"="\"c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hpdskflt] "ImagePath"="system32\DRIVERS\hpdskflt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HpqKbFiltr] "ImagePath"="\SystemRoot\system32\DRIVERS\HpqKbFiltr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hpqwmiex] "ImagePath"="\"c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HpSAMD] "ImagePath"="system32\drivers\HpSAMD.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hpsrv] "ImagePath"="%SystemRoot%\system32\Hpservice.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HTTP] "ImagePath"="system32\drivers\HTTP.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwcdcmdm0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwdatacard] "ImagePath"="system32\DRIVERS\ewusbmdm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwpolicy] "ImagePath"="System32\drivers\hwpolicy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwusbapp] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwusbdev] "ImagePath"="system32\DRIVERS\ewusbdev.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwusbser] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\i8042prt] "ImagePath"="\SystemRoot\system32\drivers\i8042prt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iaStorV] "ImagePath"="system32\drivers\iaStorV.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\idsvc] "ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\igfx] "ImagePath"="system32\DRIVERS\igdkmd64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iirsp] "ImagePath"="system32\DRIVERS\iirsp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IKEEXT] "ServiceDll"="%SystemRoot%\System32\ikeext.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\inetaccs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\intelide] "ImagePath"="system32\drivers\intelide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\intelppm] "ImagePath"="\SystemRoot\system32\DRIVERS\intelppm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPBusEnum] "ServiceDll"="%SystemRoot%\system32\ipbusenum.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IpFilterDriver] "ImagePath"="system32\DRIVERS\ipfltdrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iphlpsvc] "ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPMIDRV] "ImagePath"="\SystemRoot\system32\drivers\IPMIDrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPNAT] "ImagePath"="System32\drivers\ipnat.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iPod Service] "ImagePath"="\"c:\program files\iPod\bin\iPodService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IRENUM] "ImagePath"="system32\drivers\irenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\isapnp] "ImagePath"="system32\drivers\isapnp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iScsiPrt] "ImagePath"="\SystemRoot\system32\drivers\msiscsi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\JMCR] "ImagePath"="system32\DRIVERS\jmcr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\kbdclass] "ImagePath"="system32\DRIVERS\kbdclass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\kbdhid] "ImagePath"="system32\DRIVERS\kbdhid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KeyIso] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KSecDD] "ImagePath"="System32\Drivers\ksecdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KSecPkg] "ImagePath"="System32\Drivers\ksecpkg.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ksthunk] "ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KtmRm] "ServiceDll"="%systemroot%\system32\msdtckrm.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LanmanServer] "ServiceDll"="%SystemRoot%\System32\srvsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LanmanWorkstation] "ServiceDll"="%SystemRoot%\System32\wkssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ldap] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LightScribeService] "ImagePath"="\"c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lirsgt] "ImagePath"="system32\DRIVERS\lirsgt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lltdio] "ImagePath"="system32\DRIVERS\lltdio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lltdsvc] "ServiceDll"="%SystemRoot%\System32\lltdsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lmhosts] "ServiceDll"="%SystemRoot%\System32\lmhsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Lsa] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_FC] "ImagePath"="system32\DRIVERS\lsi_fc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SAS] "ImagePath"="system32\DRIVERS\lsi_sas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SAS2] "ImagePath"="system32\DRIVERS\lsi_sas2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SCSI] "ImagePath"="system32\DRIVERS\lsi_scsi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\luafv] "ImagePath"="\SystemRoot\system32\drivers\luafv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Mcx2Svc] "ServiceDll"="%SystemRoot%\system32\Mcx2Svc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\megasas] "ImagePath"="system32\DRIVERS\megasas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MegaSR] "ImagePath"="system32\DRIVERS\MegaSR.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MMCSS] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Modem] "ImagePath"="system32\drivers\modem.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\monitor] "ImagePath"="system32\DRIVERS\monitor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mouclass] "ImagePath"="system32\DRIVERS\mouclass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mouhid] "ImagePath"="system32\DRIVERS\mouhid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mountmgr] "ImagePath"="System32\drivers\mountmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MozillaMaintenance] "ImagePath"="\"c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mpio] "ImagePath"="system32\drivers\mpio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mpsdrv] "ImagePath"="System32\drivers\mpsdrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MpsSvc] "ServiceDll"="%SystemRoot%\system32\mpssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MRxDAV] "ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb] "ImagePath"="system32\DRIVERS\mrxsmb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb10] "ImagePath"="system32\DRIVERS\mrxsmb10.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb20] "ImagePath"="system32\DRIVERS\mrxsmb20.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msahci] "ImagePath"="system32\drivers\msahci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSCamSvc] "ImagePath"="\"c:\program files\Microsoft LifeCam\MSCamS64.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msdsm] "ImagePath"="system32\drivers\msdsm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC] "ImagePath"="%SystemRoot%\System32\msdtc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC Bridge 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC Bridge 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Msfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mshidkmdf] "ImagePath"="\SystemRoot\System32\drivers\mshidkmdf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSHUSBVideo] "ImagePath"="System32\Drivers\nx6000.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msisadrv] "ImagePath"="system32\drivers\msisadrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSiSCSI] "ServiceDll"="%systemroot%\system32\iscsiexe.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msiserver] "ImagePath"="%systemroot%\system32\msiexec.exe /V" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSKSSRV] "ImagePath"="system32\drivers\MSKSSRV.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSPCLOCK] "ImagePath"="system32\drivers\MSPCLOCK.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSPQM] "ImagePath"="system32\drivers\MSPQM.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsRPC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSSCNTRS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mssmbios] "ImagePath"="\SystemRoot\system32\drivers\mssmbios.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSSQL$SQLEXPRESS] "ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe\" -sSQLEXPRESS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSSQLServerADHelper100] "ImagePath"="\"c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSTEE] "ImagePath"="system32\drivers\MSTEE.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MTConfig] "ImagePath"="\SystemRoot\system32\DRIVERS\MTConfig.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Mup] "ImagePath"="System32\Drivers\mup.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\napagent] "ServiceDLL"="%SystemRoot%\system32\qagentRT.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NativeWifiP] "ImagePath"="system32\DRIVERS\nwifi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NDIS] "ImagePath"="system32\drivers\ndis.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisCap] "ImagePath"="system32\DRIVERS\ndiscap.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisTapi] "ImagePath"="system32\DRIVERS\ndistapi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Ndisuio] "ImagePath"="system32\DRIVERS\ndisuio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisWan] "ImagePath"="system32\DRIVERS\ndiswan.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NDProxy] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetBIOS] "ImagePath"="system32\DRIVERS\netbios.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetBT] "ImagePath"="System32\DRIVERS\netbt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Netlogon] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Netman] "ServiceDll"="%SystemRoot%\System32\netman.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetMsmqActivator] "ImagePath"="\"c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe\" -NetMsmqActivator" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetPipeActivator] "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\netprofm] "ServiceDll"="%SystemRoot%\System32\netprofm.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetTcpActivator] "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetTcpPortSharing] "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\netw5v64] "ImagePath"="system32\DRIVERS\netw5v64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nfrd960] "ImagePath"="system32\DRIVERS\nfrd960.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NlaSvc] "ServiceDll"="%SystemRoot%\System32\nlasvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Npfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nsi] "ServiceDll"="%systemroot%\system32\nsisvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nsiproxy] "ImagePath"="system32\drivers\nsiproxy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTDS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Ntfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Null] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nvraid] "ImagePath"="system32\drivers\nvraid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nvstor] "ImagePath"="system32\drivers\nvstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nv_agp] "ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ohci1394] "ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ose] "ImagePath"="\"c:\program files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\osppsvc] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Outlook] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\p2pimsvc] "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\p2psvc] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Parport] "ImagePath"="\SystemRoot\system32\DRIVERS\parport.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\partmgr] "ImagePath"="System32\drivers\partmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PcaSvc] "ServiceDll"="%SystemRoot%\System32\pcasvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pci] "ImagePath"="system32\drivers\pci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pciide] "ImagePath"="system32\drivers\pciide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pcmcia] "ImagePath"="\SystemRoot\system32\DRIVERS\pcmcia.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pcw] "ImagePath"="System32\drivers\pcw.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PEAUTH] "ImagePath"="system32\drivers\peauth.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfDisk] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfHost] "ImagePath"="%SystemRoot%\SysWow64\perfhost.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfNet] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfOS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfProc] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pla] "ServiceDll"="%systemroot%\system32\pla.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PlugPlay] "ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PnkBstrA] "ImagePath"="c:\windows\system32\PnkBstrA.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PNRPAutoReg] "ServiceDll"="%SystemRoot%\system32\pnrpauto.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PNRPsvc] "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PolicyAgent] "ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PortProxy] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Power] "ServiceDll"="%SystemRoot%\system32\umpo.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PptpMiniport] "ImagePath"="system32\DRIVERS\raspptp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Processor] "ImagePath"="\SystemRoot\system32\DRIVERS\processr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ProfSvc] "ServiceDll"="%systemroot%\system32\profsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ProtectedStorage] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Psched] "ImagePath"="system32\DRIVERS\pacer.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ql2300] "ImagePath"="system32\DRIVERS\ql2300.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ql40xx] "ImagePath"="system32\DRIVERS\ql40xx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\QWAVE] "ServiceDll"="%windir%\system32\qwave.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\QWAVEdrv] "ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAcd] "ImagePath"="System32\DRIVERS\rasacd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAgileVpn] "ImagePath"="system32\DRIVERS\AgileVpn.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAuto] "ServiceDll"="%SystemRoot%\System32\rasauto.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Rasl2tp] "ImagePath"="system32\DRIVERS\rasl2tp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasMan] "ServiceDll"="%SystemRoot%\System32\rasmans.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasPppoe] "ImagePath"="system32\DRIVERS\raspppoe.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasSstp] "ImagePath"="system32\DRIVERS\rassstp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdbss] "ImagePath"="system32\DRIVERS\rdbss.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdpbus] "ImagePath"="\SystemRoot\system32\DRIVERS\rdpbus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPCDD] "ImagePath"="System32\DRIVERS\RDPCDD.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPDD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPENCDD] "ImagePath"="system32\drivers\rdpencdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPNP] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPREFMP] "ImagePath"="system32\drivers\rdprefmp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPWD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdyboost] "ImagePath"="System32\drivers\rdyboost.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RemoteAccess] "ServiceDLL"="%SystemRoot%\System32\mprdim.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RemoteRegistry] "ServiceDll"="%SystemRoot%\system32\regsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RichVideo] "ImagePath"="\"c:\program files (x86)\CyberLink\Shared files\RichVideo.exe\"\00\01\03\01\03\01\03\01\03\01\03\01\03\01\03\01\03\01\03\01\03\01\03\01\03\10\02\01\03\01\03\01\03\01\03\01\03\01\03\01\03\02\03\02\03\02\03\02\03\02\03\02\03\02\03\02\03\02\03\02\03\02\03" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RimUsb] "ImagePath"="System32\Drivers\RimUsb_AMD64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcEptMapper] "ServiceDll"="%SystemRoot%\System32\RpcEpMap.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcLocator] "ImagePath"="%SystemRoot%\system32\locator.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcSs] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RsFx0103] "ImagePath"="system32\DRIVERS\RsFx0103.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rspndr] "ImagePath"="system32\DRIVERS\rspndr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RTL8167] "ImagePath"="system32\DRIVERS\Rt64win7.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SamSs] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sbp2port] "ImagePath"="system32\drivers\sbp2port.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SCardSvr] "ServiceDll"="%SystemRoot%\System32\SCardSvr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\scfilter] "ImagePath"="System32\DRIVERS\scfilter.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Schedule] "ServiceDll"="%systemroot%\system32\schedsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SCPolicySvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sdbus] "ImagePath"="\SystemRoot\system32\drivers\sdbus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SDRSVC] "ServiceDll"="%Systemroot%\System32\SDRSVC.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\secdrv] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\seclogon] "ServiceDll"="%windir%\system32\seclogon.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SENS] "ServiceDll"="%SystemRoot%\system32\sens.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SensrSvc] "ServiceDll"="%SystemRoot%\system32\sensrsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Serenum] "ImagePath"="\SystemRoot\system32\DRIVERS\serenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Serial] "ImagePath"="\SystemRoot\system32\DRIVERS\serial.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sermouse] "ImagePath"="\SystemRoot\system32\DRIVERS\sermouse.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelEndpoint 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelOperation 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelService 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SessionEnv] "ServiceDLL"="%SystemRoot%\system32\sessenv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffdisk] "ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffp_mmc] "ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffp_sd] "ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sfloppy] "ImagePath"="\SystemRoot\system32\DRIVERS\sfloppy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SharedAccess] "ServiceDll"="%SystemRoot%\System32\ipnathlp.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ShellHWDetection] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SiSRaid2] "ImagePath"="system32\DRIVERS\SiSRaid2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SiSRaid4] "ImagePath"="system32\DRIVERS\sisraid4.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SkypeUpdate] "ImagePath"="\"c:\program files (x86)\Skype\Updater\Updater.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Smb] "ImagePath"="system32\DRIVERS\smb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SMSvcHost 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SMSvcHost 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SNMPTRAP] "ImagePath"="%SystemRoot%\System32\snmptrap.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\spldr] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Spooler] "ImagePath"="%SystemRoot%\System32\spoolsv.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sppsvc] "ImagePath"="%SystemRoot%\system32\sppsvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sppuinotify] "ServiceDll"="%SystemRoot%\system32\sppuinotify.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SQLAgent$SQLEXPRESS] "ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE\" -i SQLEXPRESS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SQLBrowser] "ImagePath"="\"c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SQLWriter] "ImagePath"="\"c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srv] "ImagePath"="System32\DRIVERS\srv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srv2] "ImagePath"="System32\DRIVERS\srv2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfHDA] "ImagePath"="system32\DRIVERS\VSTAZL6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfV92] "ImagePath"="system32\DRIVERS\VSTDPV6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfWinac] "ImagePath"="system32\DRIVERS\VSTCNXT6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srvnet] "ImagePath"="System32\DRIVERS\srvnet.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SSDPSRV] "ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SstpSvc] "ServiceDll"="%SystemRoot%\system32\sstpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\STacSV] "ImagePath"="c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Steam Client Service] "ImagePath"="c:\program files (x86)\Common Files\Steam\SteamService.exe /RunAsService" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\stexstor] "ImagePath"="system32\DRIVERS\stexstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\STHDA] "ImagePath"="system32\DRIVERS\stwrt64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\stisvc] "ServiceDll"="%SystemRoot%\System32\wiaservc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\swenum] "ImagePath"="\SystemRoot\system32\drivers\swenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\swprv] "ServiceDll"="%Systemroot%\System32\swprv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SynTP] "ImagePath"="system32\DRIVERS\SynTP.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SysMain] "ServiceDll"="%systemroot%\system32\sysmain.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TabletInputService] "ServiceDll"="%SystemRoot%\System32\TabSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TapiSrv] "ServiceDll"="%SystemRoot%\System32\tapisrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TBS] "ServiceDll"="%SystemRoot%\System32\tbssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Tcpip] "ImagePath"="System32\drivers\tcpip.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIP6] "ImagePath"="system32\DRIVERS\tcpip.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIP6TUNNEL] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tcpipreg] "ImagePath"="System32\drivers\tcpipreg.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIPTUNNEL] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TDPIPE] "ImagePath"="system32\drivers\tdpipe.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TDTCP] "ImagePath"="system32\drivers\tdtcp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tdx] "ImagePath"="system32\DRIVERS\tdx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TeamViewer6] "ImagePath"="c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TermDD] "ImagePath"="\SystemRoot\system32\drivers\termdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TermService] "ServiceDll"="%SystemRoot%\System32\termsrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Themes] "ServiceDll"="%SystemRoot%\system32\themeservice.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\THREADORDER] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TrkWks] "ServiceDll"="%SystemRoot%\System32\trkwks.dll" -- . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TrustedInstaller] "ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TSDDD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tssecsrv] "ImagePath"="System32\DRIVERS\tssecsrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TsUsbFlt] "ImagePath"="system32\drivers\tsusbflt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tunnel] "ImagePath"="system32\DRIVERS\tunnel.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\uagp35] "ImagePath"="\SystemRoot\system32\DRIVERS\uagp35.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\udfs] "ImagePath"="system32\DRIVERS\udfs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UGatherer] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UGTHRSVC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UI0Detect] "ImagePath"="%SystemRoot%\system32\UI0Detect.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\uliagpkx] "ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\umbus] "ImagePath"="system32\DRIVERS\umbus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UmPass] "ImagePath"="system32\DRIVERS\umpass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\upnphost] "ServiceDll"="%SystemRoot%\System32\upnphost.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\USBAAPL64] "ImagePath"="System32\Drivers\usbaapl64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbaudio] "ImagePath"="system32\drivers\usbaudio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbccgp] "ImagePath"="system32\DRIVERS\usbccgp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbcir] "ImagePath"="\SystemRoot\system32\drivers\usbcir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbehci] "ImagePath"="system32\DRIVERS\usbehci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbfilter] "ImagePath"="system32\DRIVERS\usbfilter.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbhub] "ImagePath"="system32\DRIVERS\usbhub.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbohci] "ImagePath"="system32\DRIVERS\usbohci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbprint] "ImagePath"="system32\DRIVERS\usbprint.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbscan] "ImagePath"="system32\DRIVERS\usbscan.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\USBSTOR] "ImagePath"="system32\DRIVERS\USBSTOR.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbuhci] "ImagePath"="\SystemRoot\system32\drivers\usbuhci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbvideo] "ImagePath"="System32\Drivers\usbvideo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UxSms] "ServiceDll"="%SystemRoot%\System32\uxsms.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VaultSvc] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vdrvroot] "ImagePath"="system32\drivers\vdrvroot.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vds] "ImagePath"="%SystemRoot%\System32\vds.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vga] "ImagePath"="system32\DRIVERS\vgapnp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VgaSave] "ImagePath"="\SystemRoot\System32\drivers\vga.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vhdmp] "ImagePath"="\SystemRoot\system32\drivers\vhdmp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\viaide] "ImagePath"="system32\drivers\viaide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volmgr] "ImagePath"="system32\drivers\volmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volmgrx] "ImagePath"="System32\drivers\volmgrx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volsnap] "ImagePath"="system32\drivers\volsnap.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vsmraid] "ImagePath"="system32\DRIVERS\vsmraid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VSS] "ImagePath"="%systemroot%\system32\vssvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vToolbarUpdater14.2.0] "ImagePath"="c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vwifibus] "ImagePath"="system32\DRIVERS\vwifibus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vwififlt] "ImagePath"="system32\DRIVERS\vwififlt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\W32Time] "ServiceDll"="%systemroot%\system32\w32time.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\W3SVC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WacomPen] "ImagePath"="\SystemRoot\system32\DRIVERS\wacompen.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WANARP] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wanarpv6] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WatAdminSvc] "ImagePath"="%SystemRoot%\system32\Wat\WatAdminSvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wbengine] "ImagePath"="\"%systemroot%\system32\wbengine.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WbioSrvc] "ServiceDll"="%SystemRoot%\System32\wbiosrvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wcncsvc] "ServiceDll"="%SystemRoot%\System32\wcncsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WcsPlugInService] "ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wd] "ImagePath"="system32\DRIVERS\wd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wdf01000] "ImagePath"="system32\drivers\Wdf01000.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WdiServiceHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WdiSystemHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WebClient] "ServiceDll"="%SystemRoot%\System32\webclnt.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wecsvc] "ServiceDll"="%SystemRoot%\system32\wecsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wercplsupport] "ServiceDll"="%SystemRoot%\System32\wercplsupport.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WerSvc] "ServiceDll"="%SystemRoot%\System32\WerSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WfpLwf] "ImagePath"="system32\DRIVERS\wfplwf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WIMMount] "ImagePath"="system32\drivers\wimmount.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinDefend] "ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Windows Workflow Foundation 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Windows Workflow Foundation 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinHttpAutoProxySvc] "ServiceDll"="winhttp.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Winmgmt] "ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRM] "ServiceDll"="%SystemRoot%\system32\WsmSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Winsock] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinSock2] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinUsb] "ImagePath"="system32\DRIVERS\WinUsb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wlansvc] "ServiceDll"="%SystemRoot%\System32\wlansvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wlidsvc] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WmiAcpi] "ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WmiApRpl] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wmiApSrv] "ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WMPNetworkSvc] "ImagePath"="\"%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WPCSvc] "ServiceDll"="%SystemRoot%\System32\wpcsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WPDBusEnum] "ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ws2ifsl] "ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WSearch] "ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WSearchIdxPi] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wuauserv] "ServiceDll"="%systemroot%\system32\wuaueng.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WudfPf] "ImagePath"="system32\drivers\WudfPf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WUDFRd] "ImagePath"="system32\DRIVERS\WUDFRd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wudfsvc] "ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WwanSvc] "ServiceDll"="%SystemRoot%\System32\wwansvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\xmlprov] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\yukonw7] "ImagePath"="system32\DRIVERS\yk62x64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{1FD36556-5DC4-49AE-94F1-9B58F4A349F4}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{AA8917D5-FCDF-4B1D-9611-75A1895D67CB}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{DA7B6516-A663-4EAE-8E8F-8EDE6809C618}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{FA92405A-2AA9-4546-964D-8016BF7078D0}] . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-05 23:39:09 ComboFix-quarantined-files.txt 2013-03-05 22:39 . Vor Suchlauf: 16 Verzeichnis(se), 176.578.691.072 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 176.525.819.904 Bytes frei . - - End Of File - - 33FE260609553C2E6E1AF154C49EA274 |
06.03.2013, 14:33 | #8 |
/// TB-Ausbilder | wie entferne ich delta search? Gerade erst gesehen: Entferne Bitcomet als Programm und Browser-Addon.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
06.03.2013, 20:59 | #9 |
| wie entferne ich delta search? hab ich erledigt. |
06.03.2013, 21:59 | #10 |
/// TB-Ausbilder | wie entferne ich delta search? Du müßtest mir schon bitte jedesmal auch mitteilen, ob dein Problem weiter besteht.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
07.03.2013, 00:03 | #11 |
| wie entferne ich delta search? Das Porblem bsteht noch immer. |
07.03.2013, 12:25 | #12 |
/// TB-Ausbilder | wie entferne ich delta search? Ich sehe gerade, dass wir das hier noch nicht ausprobiert hatten: Adware entfernen mit JRT Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
08.03.2013, 09:44 | #13 |
| wie entferne ich delta search?Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.9 (03.06.2013:1) OS: Windows 7 Home Premium x64 Ran by Stefan on 08.03.2013 at 9:23:40,94 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\windows\currentversion\run\\veohplugin Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_current_user\software\sweetim Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 ~~~ Files Successfully deleted: [File] C:\eula.1028.txt Successfully deleted: [File] C:\eula.1031.txt Successfully deleted: [File] C:\eula.1033.txt Successfully deleted: [File] C:\eula.1036.txt Successfully deleted: [File] C:\eula.1040.txt Successfully deleted: [File] C:\eula.1041.txt Successfully deleted: [File] C:\eula.1042.txt Successfully deleted: [File] C:\eula.2052.txt Successfully deleted: [File] C:\install.res.1028.dll Successfully deleted: [File] C:\install.res.1031.dll Successfully deleted: [File] C:\install.res.1033.dll Successfully deleted: [File] C:\install.res.1036.dll Successfully deleted: [File] C:\install.res.1040.dll Successfully deleted: [File] C:\install.res.1041.dll Successfully deleted: [File] C:\install.res.1042.dll Successfully deleted: [File] C:\install.res.2052.dll Successfully deleted: [File] C:\install.res.3082.dll ~~~ Folders Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\AppData\Roaming\babylon" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\AppData\Roaming\dvdvideosoftiehelpers" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\AppData\Roaming\opencandy" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\AppData\Roaming\performersoft" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\AppData\Roaming\yourfiledownloader" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\local\conduit" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\locallow\dvdvideosofttb" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\locallow\pricegong" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\locallow\softonic" Successfully deleted: [Folder] "C:\Users\Stefan.Erwin-PC\appdata\locallow\asktoolbar" ~~~ Chrome Successfully deleted: [Registry Key] hkey_local_machine\software\policies\google\chrome\extensioninstallforcelist ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.03.2013 at 9:37:02,72 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
08.03.2013, 15:48 | #14 | |
/// TB-Ausbilder | wie entferne ich delta search?Zitat:
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
08.03.2013, 21:25 | #15 |
| wie entferne ich delta search? oh, entschuldigung. Habe ich vergessen. Delta Search ist noch immer da. |
Themen zu wie entferne ich delta search? |
ahnung, andere, anderen, delta, delta search, entferne, erschein, freue, gefunde, gemerkt, guten, keine ahnung, neue, neuen, problem, probleme, problemen, search, seite, sobald, suche, tab, würde |