|
Plagegeister aller Art und deren Bekämpfung: PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.03.2013, 22:20 | #1 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo User, ich habe mir offentsichtlich folgender Virus eingefangen: PWS:WIn32/ZBOT.gen!aj (Zeus?) Ich verwende MSE. Die Malware wurde entdeckt und entfernt. Nach dem Neustart entdeckt MSE den Virus aber erneut und fordert einen Neustart an. Diese Schleife habe ich schon ohne Erfolg mehrmals durchlaufen. Ich habe im Forum schon ähnliche Fälle entdeckt, aber offentsichtlich ist jeder Fall individuell zu lösen.... Ich würde mich daher sehr über eure Unterstützung freuen! Viele Dank und grüße aus dem hohen Norden... Stefan |
24.03.2013, 00:39 | #2 | |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo Stefan und
__________________Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten. Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schliessen von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich. Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist. Arbeite daher in deinem eigenen Interesse solange mit, bis du das OK bekommst, dass alles erledigt ist. Hinweise zum Ablauf
Zitat:
Schauen wir mal: Schritt 1 Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
Schritt 2 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 3 Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ |
24.03.2013, 12:48 | #3 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo Leo!
__________________erstmal vielen Dank für die schnelle Antwort. Ich habe die Schritte wie beschrieben durchgeführt. 1. Defogger: Keine Probleme 2. Gmer: Als ich den PC heute gestartet habe, hat MSE "grünes Licht" gegeben. Es war mir aber nicht möglich auf MSE zuzugreifen. Ich habe dann LAN und WLAN deaktiviert und den Scan durchgeführt. Nach dem Neustart startet / erscheint MSE nicht mehr... 3. OTL: Keine Probleme Ich habe die Files gezippt und angehängt. Ich hoffe das war in deinem Sinne.... Gruß Stefan |
24.03.2013, 13:56 | #4 | |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo Stefan, Zitat:
Wenn sie zu gross sind, dann bitte in eine zip-Datei (nicht *.7z) packen und anhängen.
__________________ cheers, Leo |
24.03.2013, 14:27 | #5 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Alles klar! Dann hier innerhalb von Codetags: GMER Code:
ATTFilter GMER 2.1.19155 - hxxp://www.gmer.net Rootkit scan 2013-03-24 11:37:21 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST315005 rev.CC34 1397,27GB Running: gmer_2.1.19155.exe; Driver: C:\Users\STEFAN~1\AppData\Local\Temp\axriyuow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000771c08fc 6 bytes [68, 5E, 16, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000771d25fd 6 bytes [68, 63, AB, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000771dc45a 6 bytes [68, 89, 17, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000771e2a63 6 bytes [68, A9, AB, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077204128 6 bytes [68, EF, AB, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007720e659 6 bytes [68, 35, AC, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007672455c 6 bytes [68, F2, 19, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767279f8 6 bytes [68, B1, 19, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetDC 0000000074d372c4 6 bytes [68, 89, 2F, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074d37446 6 bytes [68, 07, 30, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074d37809 6 bytes [68, C6, 48, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074d378e2 6 bytes [68, 11, 38, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074d37bd3 6 bytes [68, 39, 38, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074d38048 6 bytes [68, C8, 2F, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074d38a65 6 bytes [68, 67, AE, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074d3b17d 6 bytes [68, 01, AF, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074d3db98 6 bytes [68, 53, AF, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074d405ba 6 bytes [68, 61, 38, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074d40d32 6 bytes [68, 99, AD, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074d41218 6 bytes [68, 44, 36, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074d41341 6 bytes [68, EE, 2E, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074d41361 6 bytes [68, 7E, 2E, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074d42a8d 6 bytes [68, 12, 36, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074d42aac 6 bytes [68, 72, 37, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074d43391 6 bytes [68, 2E, 2F, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074d4434b 6 bytes [68, B4, AE, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074d45f74 6 bytes [68, 8C, 38, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074d46222 6 bytes [68, DA, 30, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074d4792f 6 bytes [68, E2, AD, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074d47fbb 6 bytes [68, C4, AC, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074d4810c 6 bytes [68, 53, AD, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074d485c1 6 bytes [68, 7B, AC, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074d486b4 6 bytes [68, 0D, AD, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074d5d41f 6 bytes [68, 47, 30, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074d5ed49 6 bytes [68, 22, 37, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074d5ed56 6 bytes [68, C8, 36, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074d79854 6 bytes [68, 45, AB, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074d79cfd 6 bytes [68, 8B, 36, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074d79f1d 6 bytes [68, 75, 4A, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074d987cb 6 bytes [68, F5, AA, 83, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007659c592 6 bytes [68, 6F, 1A, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000765d2538 6 bytes [68, 58, 1A, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076823918 6 bytes [68, C5, C1, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076824296 6 bytes [68, D6, BD, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076824406 6 bytes [68, 1E, C2, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WS2_32.dll!send 0000000076826f01 6 bytes [68, FD, C1, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076837673 6 bytes [68, 66, BD, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000074e2c664 6 bytes [68, 1E, 6D, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000074e2e13a 6 bytes [68, BE, 6E, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000074e2f8d8 6 bytes [68, 8B, 6D, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000074e33184 6 bytes [68, 92, 6E, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000074e55761 6 bytes [68, 60, 6A, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000074e55fef 6 bytes [68, 1C, 6A, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000074e5632d 6 bytes [68, A4, 6A, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000074e5fa49 6 bytes [68, B9, 6D, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000074e6f564 6 bytes [68, 4E, 6B, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000074e6f639 6 bytes [68, 88, 6C, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000074e84f2f 6 bytes [68, 38, 6E, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000074e8525a 6 bytes [68, F9, 6A, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000074ecece5 6 bytes [68, EB, 6B, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000074ecedb7 6 bytes [68, D3, 6C, 84, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[3068] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000763f1224 6 bytes [68, 38, 50, 85, 02, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000771c08fc 6 bytes [68, 5E, 16, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000771d25fd 6 bytes [68, 63, AB, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000771dc45a 6 bytes [68, 89, 17, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000771e2a63 6 bytes [68, A9, AB, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077204128 6 bytes [68, EF, AB, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007720e659 6 bytes [68, 35, AC, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007672455c 6 bytes [68, F2, 19, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767279f8 6 bytes [68, B1, 19, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetDC 0000000074d372c4 6 bytes [68, 89, 2F, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074d37446 6 bytes [68, 07, 30, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074d37809 6 bytes [68, C6, 48, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074d378e2 6 bytes [68, 11, 38, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074d37bd3 6 bytes [68, 39, 38, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074d38048 6 bytes [68, C8, 2F, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074d38a65 6 bytes [68, 67, AE, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074d3b17d 6 bytes [68, 01, AF, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074d3db98 6 bytes [68, 53, AF, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074d405ba 6 bytes [68, 61, 38, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074d40d32 6 bytes [68, 99, AD, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074d41218 6 bytes [68, 44, 36, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074d41341 6 bytes [68, EE, 2E, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074d41361 6 bytes [68, 7E, 2E, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074d42a8d 6 bytes [68, 12, 36, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074d42aac 6 bytes [68, 72, 37, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074d43391 6 bytes [68, 2E, 2F, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074d4434b 6 bytes [68, B4, AE, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074d45f74 6 bytes [68, 8C, 38, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074d46222 6 bytes [68, DA, 30, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074d4792f 6 bytes [68, E2, AD, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074d47fbb 6 bytes [68, C4, AC, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074d4810c 6 bytes [68, 53, AD, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074d485c1 6 bytes [68, 7B, AC, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074d486b4 6 bytes [68, 0D, AD, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074d5d41f 6 bytes [68, 47, 30, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074d5ed49 6 bytes [68, 22, 37, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074d5ed56 6 bytes [68, C8, 36, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074d79854 6 bytes [68, 45, AB, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074d79cfd 6 bytes [68, 8B, 36, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074d79f1d 6 bytes [68, 75, 4A, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074d987cb 6 bytes [68, F5, AA, 92, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007659c592 6 bytes [68, 6F, 1A, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000765d2538 6 bytes [68, 58, 1A, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076823918 6 bytes [68, C5, C1, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076824296 6 bytes [68, D6, BD, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076824406 6 bytes [68, 1E, C2, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WS2_32.dll!send 0000000076826f01 6 bytes [68, FD, C1, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076837673 6 bytes [68, 66, BD, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000763f1224 6 bytes [68, 38, 50, 94, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000074e2c664 6 bytes [68, 1E, 6D, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000074e2e13a 6 bytes [68, BE, 6E, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000074e2f8d8 6 bytes [68, 8B, 6D, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000074e33184 6 bytes [68, 92, 6E, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000074e55761 6 bytes [68, 60, 6A, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000074e55fef 6 bytes [68, 1C, 6A, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000074e5632d 6 bytes [68, A4, 6A, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000074e5fa49 6 bytes [68, B9, 6D, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000074e6f564 6 bytes [68, 4E, 6B, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000074e6f639 6 bytes [68, 88, 6C, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000074e84f2f 6 bytes [68, 38, 6E, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000074e8525a 6 bytes [68, F9, 6A, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000074ecece5 6 bytes [68, EB, 6B, 93, 03, C3] .text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2440] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000074ecedb7 6 bytes [68, D3, 6C, 93, 03, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000771c08fc 6 bytes [68, 5E, 16, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000771d25fd 6 bytes [68, 63, AB, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000771dc45a 6 bytes [68, 89, 17, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000771e2a63 6 bytes [68, A9, AB, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077204128 6 bytes [68, EF, AB, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007720e659 6 bytes [68, 35, AC, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007672455c 6 bytes [68, F2, 19, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767279f8 6 bytes [68, B1, 19, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetDC 0000000074d372c4 6 bytes [68, 89, 2F, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074d37446 6 bytes [68, 07, 30, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074d37809 6 bytes [68, C6, 48, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074d378e2 6 bytes [68, 11, 38, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074d37bd3 6 bytes [68, 39, 38, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074d38048 6 bytes [68, C8, 2F, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074d38a65 6 bytes [68, 67, AE, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074d3b17d 6 bytes [68, 01, AF, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074d3db98 6 bytes [68, 53, AF, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074d405ba 6 bytes [68, 61, 38, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074d40d32 6 bytes [68, 99, AD, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074d41218 6 bytes [68, 44, 36, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074d41341 6 bytes [68, EE, 2E, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074d41361 6 bytes [68, 7E, 2E, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074d42a8d 6 bytes [68, 12, 36, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074d42aac 6 bytes [68, 72, 37, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074d43391 6 bytes [68, 2E, 2F, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074d4434b 6 bytes [68, B4, AE, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074d45f74 6 bytes [68, 8C, 38, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074d46222 6 bytes [68, DA, 30, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074d4792f 6 bytes [68, E2, AD, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074d47fbb 6 bytes [68, C4, AC, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074d4810c 6 bytes [68, 53, AD, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074d485c1 6 bytes [68, 7B, AC, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074d486b4 6 bytes [68, 0D, AD, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074d5d41f 6 bytes [68, 47, 30, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074d5ed49 6 bytes [68, 22, 37, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074d5ed56 6 bytes [68, C8, 36, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074d79854 6 bytes [68, 45, AB, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074d79cfd 6 bytes [68, 8B, 36, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074d79f1d 6 bytes [68, 75, 4A, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074d987cb 6 bytes [68, F5, AA, 26, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007659c592 6 bytes [68, 6F, 1A, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000765d2538 6 bytes [68, 58, 1A, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000763f1224 6 bytes [68, 38, 50, 28, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076823918 6 bytes [68, C5, C1, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076824296 6 bytes [68, D6, BD, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076824406 6 bytes [68, 1E, C2, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WS2_32.dll!send 0000000076826f01 6 bytes [68, FD, C1, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076837673 6 bytes [68, 66, BD, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000074e2c664 6 bytes [68, 1E, 6D, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000074e2e13a 6 bytes [68, BE, 6E, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000074e2f8d8 6 bytes [68, 8B, 6D, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000074e33184 6 bytes [68, 92, 6E, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000074e55761 6 bytes [68, 60, 6A, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000074e55fef 6 bytes [68, 1C, 6A, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000074e5632d 6 bytes [68, A4, 6A, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000074e5fa49 6 bytes [68, B9, 6D, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000074e6f564 6 bytes [68, 4E, 6B, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000074e6f639 6 bytes [68, 88, 6C, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000074e84f2f 6 bytes [68, 38, 6E, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000074e8525a 6 bytes [68, F9, 6A, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000074ecece5 6 bytes [68, EB, 6B, 27, 02, C3] .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3220] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000074ecedb7 6 bytes [68, D3, 6C, 27, 02, C3] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x04 0x72 0x15 0xE8 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9E 0xDE 0xEF 0x64 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x34 0xB4 0x89 0xC0 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xA7 0x97 0xFA 0x17 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x1E 0x86 0x96 0xAE ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x04 0x72 0x15 0xE8 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x9E 0xDE 0xEF 0x64 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x34 0xB4 0x89 0xC0 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xA7 0x97 0xFA 0x17 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x1E 0x86 0x96 0xAE ... ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Code:
ATTFilter OTL logfile created on: 3/24/2013 12:04:34 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.85 Gb Available Physical Memory | 73.26% Memory free 15.96 Gb Paging File | 13.59 Gb Available in Paging File | 85.12% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 729.18 Gb Free Space | 53.37% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe PRC - [2013/03/13 19:39:42 | 001,822,424 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe PRC - [2013/03/08 08:18:53 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/10 12:51:16 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe PRC - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe PRC - [2010/11/17 18:53:00 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/11/06 08:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2008/01/22 10:13:32 | 001,201,448 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2008/01/22 10:13:20 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe ========== Modules (No Company Name) ========== MOD - [2013/03/13 19:39:42 | 014,717,144 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll MOD - [2013/03/08 08:18:39 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013/02/13 18:03:04 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013/01/09 18:57:18 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ab54c04b3df40416205883b4049fe273\IAStorUtil.ni.dll MOD - [2013/01/09 18:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\4d6518ef6ae8d6f005c49ab1c86de7fe\IAStorCommon.ni.dll MOD - [2013/01/09 17:31:05 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013/01/09 17:30:44 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013/01/09 17:30:35 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013/01/09 17:30:32 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013/01/09 17:30:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013/01/09 17:30:29 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013/01/09 17:30:22 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf MOD - [2010/11/13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ========== Services (SafeList) ========== SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2012/12/19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/08/13 00:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2013/03/15 17:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013/03/13 19:39:43 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/03/08 08:18:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/03/02 17:00:26 | 000,025,504 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2012/03/02 17:00:20 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus) SRV - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012/12/19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/12/19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/11/10 11:46:25 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012/11/06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/05/16 15:27:11 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011/05/16 15:27:11 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011/05/13 13:55:41 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/01/03 17:32:46 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010/12/17 10:57:03 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) DRV:64bit: - [2010/11/25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/19 19:34:00 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2010/11/19 19:34:00 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2010/11/06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010/09/02 07:26:30 | 000,032,936 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iqvw64e.sys -- (NAL) DRV:64bit: - [2010/02/24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009/11/16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:64bit: - [2009/11/16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/06/10 21:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007/04/11 23:30:04 | 000,043,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTVE.sys -- (IAMTVE) DRV:64bit: - [2007/04/11 23:29:58 | 000,051,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTXPE.sys -- (IAMTXPE) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=MDND&bmod=MDND IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.funmoods.com/?f=1&a=drive IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes,DefaultScope = {28C204E3-FC61-4EAB-8F6D-BE793949C69D} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{28C204E3-FC61-4EAB-8F6D-BE793949C69D}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=drive&q={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{63DC52A0-A1ED-4FEE-A13A-DEFFCE92CAD7}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDND_enDE393 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{F097D89E-E315-4C3F-9760-15AA4E34C76E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions [2011/07/24 17:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de [2013/02/14 20:09:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions [2012/05/28 09:57:52 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions\ffxtlbr@funmoods.com [2013/02/14 20:09:53 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012/05/28 09:57:51 | 000,001,799 | ---- | M] () -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\searchplugins\funmoods.xml [2013/03/08 08:18:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013/03/08 08:18:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/07/31 07:54:25 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/08/30 08:43:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/07/31 07:54:25 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/07/31 07:54:25 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/31 07:54:25 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/31 07:54:25 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [Ixakdoifl] C:\Users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe (Ig}u) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A5E6DDE-142E-4A4E-A349-35C75B1CF2BB}: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EC3C12-8A2E-4718-A015-31D79615CA4A}: DhcpNameServer = 62.109.123.197 192.168.0.1 O18:64bit: - Protocol\Handler\haufereader - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\haufereader - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{7f7037fa-7d60-11e0-9396-6c626d43bcfb}\Shell - "" = AutoRun O33 - MountPoints2\{7f7037fa-7d60-11e0-9396-6c626d43bcfb}\Shell\AutoRun\command - "" = J:\autorun.exe O33 - MountPoints2\{8a452085-8dc3-11e0-94b2-6c626d43bcfb}\Shell - "" = AutoRun O33 - MountPoints2\{8a452085-8dc3-11e0-94b2-6c626d43bcfb}\Shell\AutoRun\command - "" = I:\SETUP.EXE O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/03/23 23:50:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\PC Rettung [2013/03/23 22:30:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 20:06:22 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Programs [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2013/03/17 09:53:39 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Kega Fusion 3.64 [2013/03/17 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Alex-Kidd [2013/03/14 07:18:55 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013/03/14 07:18:55 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013/03/14 07:18:54 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013/03/14 07:18:54 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013/03/14 07:18:54 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013/03/14 07:18:54 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013/03/14 07:18:54 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013/03/14 07:18:54 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013/03/14 07:18:54 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013/03/14 07:18:53 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013/03/14 07:18:53 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013/03/14 07:18:53 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013/03/14 07:18:52 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013/03/14 07:18:52 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013/03/14 07:18:52 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013/03/14 07:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013/03/14 07:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/03/14 07:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/11 18:58:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Shop [2013/03/10 00:27:54 | 000,000,000 | ---D | C] -- C:\Download [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\My Videos [2013/03/10 00:25:17 | 000,000,000 | ---D | C] -- C:\AllShare [2013/03/10 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2013/03/10 00:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2013/03/10 00:04:23 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Downloaded Installations [2013/03/08 08:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/03/06 07:25:28 | 000,000,000 | R--D | C] -- C:\Users\Stefan Möller\Documents\Scanned Documents [2013/03/06 07:25:28 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Fax [2013/02/27 10:19:07 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll [2013/02/27 10:19:07 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll [2013/02/27 10:19:07 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll [2013/02/27 10:19:07 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll [2013/02/27 10:18:57 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll [2013/02/27 10:18:57 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll [2013/02/27 10:18:52 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll [2013/02/27 10:18:52 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll [2013/02/27 10:18:52 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll [2013/02/27 10:18:52 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll [2013/02/27 10:18:52 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013/02/27 10:18:52 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll [2013/02/27 10:18:52 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013/02/27 10:18:52 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2013/02/27 10:18:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013/02/27 10:18:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll [2013/02/27 10:18:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll [2013/02/27 10:18:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll [2013/02/27 10:18:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll [2013/02/27 10:18:52 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013/02/27 10:18:52 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll [2013/02/27 10:18:51 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll [2013/02/27 10:18:51 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll [2013/02/27 10:18:51 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll [2013/02/27 10:18:51 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll [2013/02/27 10:18:51 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll [2013/02/27 10:18:51 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll [2013/02/27 10:18:51 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll [2013/02/27 10:18:51 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll [2013/02/27 10:18:51 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013/02/27 10:18:51 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2013/02/27 10:18:51 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll [2013/02/27 10:18:51 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll [2013/02/27 10:18:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll [2013/02/27 10:18:51 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll [2013/02/27 10:18:51 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll [2013/02/27 10:18:50 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll [2013/02/27 10:18:50 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll [2013/02/27 10:18:50 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2013/02/27 10:18:50 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll [2013/02/27 10:18:50 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll [2012/01/15 08:09:47 | 001,080,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Stefan Möller\dbghelp.dll [2012/01/15 08:09:47 | 000,366,080 | ---- | C] (RAD Game Tools, Inc.) -- C:\Users\Stefan Möller\Mss32.dll [2012/01/15 08:09:47 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\Stefan Möller\steam_api.dll [2012/01/15 08:09:46 | 002,410,496 | ---- | C] (Firaxis Games) -- C:\Users\Stefan Möller\CvGameCoreDLLFinal Release.dll ========== Files - Modified Within 30 Days ========== [2013/03/24 12:06:34 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 12:06:34 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 11:59:21 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2013/03/24 11:49:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/03/24 11:49:46 | 1460,638,987 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013/03/24 11:49:13 | 2133,037,055 | -HS- | M] () -- C:\hiberfil.sys [2013/03/24 11:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/03/23 22:35:19 | 000,000,188 | ---- | M] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:33 | 000,377,856 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 22:29:05 | 000,050,477 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 20:06:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/03/23 19:31:56 | 000,001,186 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/23 10:43:34 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\QuickSteuer Deluxe 2013.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/13 19:39:43 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013/03/13 19:39:42 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013/03/12 13:30:38 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/03/12 13:30:38 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013/03/12 13:30:38 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/03/12 13:30:38 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013/03/12 13:30:38 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/03/11 20:24:51 | 000,007,485 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:44 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/02/27 10:21:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif ========== Files Created - No Company Name ========== [2013/03/23 22:35:18 | 000,000,188 | ---- | C] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:51 | 000,377,856 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:23 | 000,050,477 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 19:31:56 | 000,001,186 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/11 20:24:50 | 000,007,485 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:41 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/01/03 20:02:06 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2012/10/11 20:31:31 | 000,010,599 | ---- | C] () -- C:\Users\Stefan Möller\Bünning_elster_2048.pfx [2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012/03/25 14:56:35 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ2414N.DAT [2012/02/27 10:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll [2012/02/27 10:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll [2012/02/27 10:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll [2012/02/27 10:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll [2012/02/15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/15 08:09:47 | 000,900,978 | ---- | C] () -- C:\Users\Stefan Möller\libeay32.dll [2012/01/15 08:09:47 | 000,568,397 | ---- | C] () -- C:\Users\Stefan Möller\Read Me English.pdf [2012/01/15 08:09:47 | 000,563,920 | ---- | C] () -- C:\Users\Stefan Möller\Read Me French.pdf [2012/01/15 08:09:47 | 000,517,549 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Spanish.pdf [2012/01/15 08:09:47 | 000,515,418 | ---- | C] () -- C:\Users\Stefan Möller\Read Me German.pdf [2012/01/15 08:09:47 | 000,454,270 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Italian.pdf [2012/01/15 08:09:47 | 000,232,409 | ---- | C] () -- C:\Users\Stefan Möller\ssleay32.dll [2012/01/15 08:09:47 | 000,231,936 | ---- | C] () -- C:\Users\Stefan Möller\mss32midi.dll [2012/01/15 08:09:47 | 000,151,040 | ---- | C] () -- C:\Users\Stefan Möller\lua51_Win32.dll [2012/01/15 08:09:47 | 000,059,904 | ---- | C] () -- C:\Users\Stefan Möller\zlib1.dll [2012/01/15 08:09:46 | 000,818,688 | ---- | C] () -- C:\Users\Stefan Möller\CvLocalizationWin32Final Release.dll [2012/01/15 08:09:46 | 000,507,904 | ---- | C] () -- C:\Users\Stefan Möller\CvGameDatabaseWin32Final Release.dll [2012/01/15 08:09:46 | 000,241,664 | ---- | C] () -- C:\Users\Stefan Möller\Civ5GDF.dll [2012/01/15 08:09:39 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_it_IT.wmv [2012/01/15 08:09:31 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_fr_FR.wmv [2012/01/15 08:09:25 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_es_ES.wmv [2012/01/15 08:09:17 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_en_US.wmv [2012/01/15 08:09:11 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_de_DE.wmv [2011/11/03 22:17:12 | 001,881,740 | ---- | C] () -- C:\Users\Stefan Möller\Bewerbung Britta Carstensen.pdf [2011/11/03 22:11:49 | 004,974,710 | ---- | C] () -- C:\Users\Stefan Möller\Zeugnisse Britta Carstensen 11.09..pdf [2011/11/03 22:10:19 | 001,406,786 | ---- | C] () -- C:\Users\Stefan Möller\pdf24 Job Printing.pdf [2011/09/13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/22 18:50:31 | 000,162,409 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\census.cache [2011/08/22 18:50:28 | 000,130,957 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\ars.cache [2011/08/22 18:45:29 | 000,000,036 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\housecall.guid.cache [2011/05/16 19:09:46 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/05/15 18:26:20 | 000,001,819 | ---- | C] () -- C:\Users\Stefan Möller\140.jpg [2011/05/15 18:12:22 | 000,005,097 | ---- | C] () -- C:\Users\Stefan Möller\Sony-Sdm-hs75s.jpg [2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2011/11/17 07:41:18 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\@ [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2012/10/13 20:29:45 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2013/03/23 18:52:39 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\n. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] < End of report > |
24.03.2013, 14:28 | #6 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hier noch die OTL Extras Code:
ATTFilter OTL Extras logfile created on: 3/24/2013 12:04:34 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.85 Gb Available Physical Memory | 73.26% Memory free 15.96 Gb Paging File | 13.59 Gb Available in Paging File | 85.12% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 729.18 Gb Free Space | 53.37% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = ChromeHTML] -- Reg Error: Key error. File not found .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [HKEY_USERS\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- Reg Error: Key error. htmlfile [opennew] -- Reg Error: Key error. htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- Reg Error: Key error. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- Reg Error: Key error. htmlfile [opennew] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- Reg Error: Key error. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq2414" = CanoScan LiDE 110 Scanner Driver "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java(TM) 6 Update 23 (64-bit) "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{456FB9B5-AFBC-4761-BBDC-BA6BAFBB818F}" = Windows Live Remote Client Resources "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{5DF57DB1-D971-3DA3-B4BB-F6FC7D73A997}" = AMD Drag and Drop Transcoding "{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources "{6C9D3F1D-DBBE-46F9-96A0-726CC72935AF}" = Windows Live Remote Service Resources "{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources "{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64 "{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{BCCC97EE-E162-448C-8847-59718FF29B04}" = Intel(R) Network Connections 15.6.25.0 "{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources "{D1C1556C-7FF3-48A3-A5D6-7126F0FAFB66}" = Windows Live Remote Client Resources "{D3E4F422-7E0F-49C7-8B00-F42490D7A385}" = Windows Live Remote Service Resources "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft Security Client" = Microsoft Security Essentials "PROSetDX" = Intel(R) Network Connections 15.6.25.0 "WinRAR archiver" = WinRAR 4.01 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh "{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French "{0197D136-598D-4968-BEEA-91C1B764F05D}" = Lexware buchhalter 2012 "{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0513EE35-E0FB-4166-B663-BD1AE3A803DE}" = Anno 1404 "{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live "{0F32914F-A633-4516-B531-7084C8F19F93}" = Haufe iDesk-Browser "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail "{1203DC60-D9BD-44F9-B372-2B8F227E6094}" = Windows Live Temel Parçalar "{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{1923679F-C14B-4790-BC54-EFA3FCDE147B}" = Lexware Elster "{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger "{1D081AB0-B1CC-11E0-80C0-005056B12123}" = Haufe iDesk-Service "{1D6C2068-807F-4B76-A0C2-62ED05656593}" = Windows Live Writer "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish "{23835E30-BE98-428F-B59C-743D04DD80AF}" = Steuer Update 15.09 "{241E7104-937A-4366-AD57-8FDDDB003939}" = Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi "{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail "{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger "{2F54E453-8C93-4B3B-936A-233C909E6CAC}" = Windows Live Messenger "{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish "{3125D9DE-8D7A-4987-95F3-8A42389833D8}" = Windows Live Writer Resources "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{353EA50E-26A0-4ADD-A12A-3FE2E59E5BB3}" = QuickSteuer DELUXE Wissens-Center 2009 "{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404 "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English "{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh "{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack "{410DF0AA-882D-450D-9E1B-F5397ACFFA80}" = Windows Live Essentials "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery "{443B561F-DE1B-4DEF-ADD9-484B684653C7}" = Windows Live Messenger "{448DA1AD-D1CA-4967-8EFA-9482F31E7BFD}" = Lexware Datenbank plus 2012 "{44E1DE63-C8FA-4C70-B4AA-0C49A947ACDE}" = Sid Meier's Railroads! "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR "{48294D95-EE9A-4377-8213-44FC4265FB27}" = Windows Live Messenger "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{4B744C85-DBB1-4038-B989-4721EB22C582}" = Windows Live Messenger "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4D141929-141B-4605-95D6-2B8650C1C6DA}" = Windows Live UX Platform Language Pack "{523DF2BB-3A85-4047-9898-29DC8AEB7E69}" = Windows Live UX Platform Language Pack "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance "{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai "{5CF5B1A5-CBC3-42F0-8533-5A5090665862}" = Windows Live Mesh "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{63326924-3CAF-C858-3A8F-8598C87019D7}" = Catalyst Control Center "{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek "{63CF7D0C-B6E7-4EE9-8253-816B613CC437}" = Windows Live Mail "{640798A0-A4FB-4C52-AC72-755134767F1E}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6B556C37-8919-4991-AC34-93D018B9EA49}" = Windows Live Photo Common "{6BCC7669-A863-4C24-804B-9C811C102F71}" = QuickSteuer Deluxe 2011 "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz "{6E8AFC13-F7B8-41D8-88AB-F1D0CFC56305}" = Windows Live Messenger "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71A81378-79D5-40CC-9BDC-380642D1A87F}" = Windows Live Writer "{71C95134-F6A9-45E7-B7B3-07CA6012BF2A}" = Windows Live Mesh "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{76046298-768C-492C-8C93-2983C9E3719E}" = Windows Live UX Platform Language Pack "{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack "{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7BA19818-F717-4DFB-BC11-FAF17B2B8AEE}" = Pošta Windows Live "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer "{7E3137DC-4564-4267-A8A3-B4342D5106D6}" = QuickSteuer DELUXE Wissens-Center 2012 "{7E90B133-FF47-48BB-91B8-36FC5A548FE9}" = Windows Live Writer Resources "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{85373DA7-834E-4850-8AF5-1D99F7526857}" = Windows Live Photo Common "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian "{89863727-B08E-401F-995B-14398B28DE3D}" = QuickSteuer Deluxe 2009 "{8AE7E507-BC49-4DF0-A236-26878691AB53}" = Lexware Info Service "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources "{98EFD8F0-08DE-48DB-B922-A2EBAB711031}" = Nero 7 Ultra Edition "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A101F637-2E56-42C0-8E08-F1E9086BFAF3}" = Windows Live Movie Maker "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery "{A7056D45-C63A-4FE4-A69D-FB54EF9B21BB}" = Windows Live Messenger "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A733DC44-DC71-447D-AD6C-33B9AB537828}" = QuickSteuer Deluxe 2013 "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger "{AC76BA86-7AD7-5464-3428-A00000000004}" = Spelling Dictionaries Support For Adobe Reader X "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.6) MUI "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B2E90616-C50D-4B89-A40D-92377AC669E5}" = Windows Live Messenger "{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials "{BD695C2F-3EA0-4DA4-92D5-154072468721}" = Windows Live Fotoğraf Galerisi "{BE672587-331F-42F7-BC38-D59759311C75}" = Lexware reisekosten plus 2012 "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{BFBF5EEC-25F7-4DE5-9346-0EE4FB4CD2D7}" = QuickSteuer Deluxe 2009 "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean "{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner "{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections "{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{CA227A9D-09BE-4BFB-9764-48FED2DA5454}" = Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D34A78EB-78F2-48ab-8CAE-5D4DC255A491}" = Lexware reisekosten plus 2012 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common "{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail "{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional "{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack "{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer "{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DEE03A90-C723-4E3D-A661-86651D6F0668}" = QuickSteuer Deluxe 2010 "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials "{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{E4B7F2AF-AEDA-4DE8-8014-9ADAFF7B4164}" = QuickSteuer Deluxe 2012 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E59969EA-3B5B-4B24-8B94-43842A7FBFE9}" = Fotogalerija Windows Live "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{E9AD2143-26D5-4201-BED1-19DCC03B407D}" = Windows Live Messenger "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources "{EC2F8A30-787F-4DA5-9A8F-8E7DFE777CC2}" = Servicepack Datumsaktualisierung "{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live "{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian "{EE3FBD3C-782E-4A90-9507-0ECFE1FECCE4}" = Sid Meier's Railroads! "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Audiograbber" = Audiograbber 1.83 SE "Audiograbber-Lame" = Audiograbber MP3-Plugin (64 bit) "CanonSolutionMenuEX" = Canon Solution Menu EX "Civilization V" = Sid Meier's Civilization V "DAEMON Tools Lite" = DAEMON Tools Lite "ElsterFormular 13.2.0.8623k" = ElsterFormular "ElsterFormular 2008 - 2009 2008-2009" = ElsterFormular 2008 - 2009 "GMX SMS-Manager" = GMX SMS-Manager "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100 "Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MP Navigator EX 4.0" = Canon MP Navigator EX 4.0 "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "StarCraft II" = StarCraft II "Steam App 200510" = XCOM: Enemy Unknown "Steam App 31170" = Tales of Monkey Island: Chapter 1 - Launch of the Screaming Narwhal "Steam App 38400" = Fallout "Steam App 38410" = Fallout 2 "Steam App 38420" = Fallout Tactics "Steam App 40800" = Super Meat Boy "Steam App 48240" = Anno 2070 "Steam App 8930" = Sid Meier's Civilization V "Uplay" = Uplay "UseNeXT by Tangysoft_is1" = UseNeXT by Tangysoft "WinLiveSuite" = Windows Live Essentials "YTdetect" = Yahoo! Detect "ZMBV" = Zip Motion Block Video codec (Remove Only) ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "ActiveTrader 5.4.0_b7" = ActiveTrader 5.4.0_b7 ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 3/23/2013 2:43:14 PM | Computer Name = StefanMöller-PC | Source = .NET Runtime | ID = 1026 Description = Error - 3/23/2013 2:43:15 PM | Computer Name = StefanMöller-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: AllShareDMS.exe, Version: 2.1.1.0, Zeitstempel: 0x4f507dcf Name des fehlerhaften Moduls: avformat-52.dll, Version: 0.0.0.0, Zeitstempel: 0x4a9e21ae Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000952c ID des fehlerhaften Prozesses: 0x120c Startzeit der fehlerhaften Anwendung: 0x01ce27f623bdc20e Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\avformat-52.dll Berichtskennung: 853de2ee-93e9-11e2-a787-6c626d43bcfb Error - 3/23/2013 2:51:37 PM | Computer Name = StefanMöller-PC | Source = .NET Runtime | ID = 1026 Description = Error - 3/23/2013 2:51:38 PM | Computer Name = StefanMöller-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: AllShareDMS.exe, Version: 2.1.1.0, Zeitstempel: 0x4f507dcf Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0xff030302 ID des fehlerhaften Prozesses: 0x1038 Startzeit der fehlerhaften Anwendung: 0x01ce27f7576bceb6 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: b115478f-93ea-11e2-bf2e-6c626d43bcfb Error - 3/23/2013 3:16:59 PM | Computer Name = StefanMöller-PC | Source = .NET Runtime | ID = 1026 Description = Error - 3/23/2013 3:17:02 PM | Computer Name = StefanMöller-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: AllShareDMS.exe, Version: 2.1.1.0, Zeitstempel: 0x4f507dcf Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00037b24 ID des fehlerhaften Prozesses: 0x11d8 Startzeit der fehlerhaften Anwendung: 0x01ce27fa4763fd60 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 3d0d048e-93ee-11e2-9b9f-6c626d43bcfb Error - 3/24/2013 5:13:50 AM | Computer Name = StefanMöller-PC | Source = .NET Runtime | ID = 1026 Description = Error - 3/24/2013 5:13:50 AM | Computer Name = StefanMöller-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: AllShareDMS.exe, Version: 2.1.1.0, Zeitstempel: 0x4f507dcf Name des fehlerhaften Moduls: avformat-52.dll, Version: 0.0.0.0, Zeitstempel: 0x4a9e21ae Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000952c ID des fehlerhaften Prozesses: 0x678 Startzeit der fehlerhaften Anwendung: 0x01ce286fb70a04be Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\avformat-52.dll Berichtskennung: 23bbff2b-9463-11e2-953e-6c626d43bcfb Error - 3/24/2013 6:53:26 AM | Computer Name = StefanMöller-PC | Source = .NET Runtime | ID = 1026 Description = Error - 3/24/2013 6:53:29 AM | Computer Name = StefanMöller-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: AllShareDMS.exe, Version: 2.1.1.0, Zeitstempel: 0x4f507dcf Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00032cbb ID des fehlerhaften Prozesses: 0x8c8 Startzeit der fehlerhaften Anwendung: 0x01ce287da557e659 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 0f1c2e8d-9471-11e2-92d9-d141bafb4549 [ Media Center Events ] Error - 12/17/2012 3:34:04 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:34:04 - Fehler beim Herstellen der Internetverbindung. 08:34:04 - Serververbindung konnte nicht hergestellt werden.. Error - 12/17/2012 3:34:14 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:34:09 - Fehler beim Herstellen der Internetverbindung. 08:34:09 - Serververbindung konnte nicht hergestellt werden.. Error - 12/17/2012 5:06:42 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 10:06:42 - Fehler beim Herstellen der Internetverbindung. 10:06:42 - Serververbindung konnte nicht hergestellt werden.. Error - 12/17/2012 5:06:50 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 10:06:47 - Fehler beim Herstellen der Internetverbindung. 10:06:47 - Serververbindung konnte nicht hergestellt werden.. Error - 12/17/2012 8:51:55 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 13:51:55 - Fehler beim Herstellen der Internetverbindung. 13:51:55 - Serververbindung konnte nicht hergestellt werden.. Error - 12/17/2012 8:52:03 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 13:52:00 - Fehler beim Herstellen der Internetverbindung. 13:52:00 - Serververbindung konnte nicht hergestellt werden.. Error - 12/18/2012 3:30:24 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:30:24 - Fehler beim Herstellen der Internetverbindung. 08:30:24 - Serververbindung konnte nicht hergestellt werden.. Error - 12/18/2012 3:30:33 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:30:29 - Fehler beim Herstellen der Internetverbindung. 08:30:29 - Serververbindung konnte nicht hergestellt werden.. Error - 12/27/2012 3:27:13 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:27:13 - Fehler beim Herstellen der Internetverbindung. 08:27:13 - Serververbindung konnte nicht hergestellt werden.. Error - 12/27/2012 3:27:22 AM | Computer Name = StefanMöller-PC | Source = MCUpdate | ID = 0 Description = 08:27:18 - Fehler beim Herstellen der Internetverbindung. 08:27:18 - Serververbindung konnte nicht hergestellt werden.. [ System Events ] Error - 3/24/2013 7:00:48 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error - 3/24/2013 7:00:48 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = PNRPSvc | ID = 102 Description = Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Heimnetzgruppen-Listener" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147023143. Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = PNRPSvc | ID = 102 Description = Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Heimnetzgruppen-Listener" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147023143. Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error - 3/24/2013 7:00:59 AM | Computer Name = StefanMöller-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 < End of report > Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 10:21 on 24/03/2013 (Stefan Möller) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... SPTD -> Already disabled -=E.O.F=- Geändert von RedFlash78 (24.03.2013 um 14:34 Uhr) |
24.03.2013, 15:00 | #7 | |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo Stefan, hoppla, ZeroAccess ist ja auch noch drauf.. Warnung: Infostealer Aus deinen Logs ist ersichtlich, dass du Malware eingefangen hast, die es speziell auf deine sensitiven Daten (Benutzernamen, Passwörter, Onlinebankingzugangsdaten, etc.) abgesehen hat. Man kann nicht genau wissen, was alles mitgeloggt wurde, aber sicherheitshalber würd ich alle auf diesem Rechner eingegebenen Daten und Passwörter als bekannt voraussetzen. Ich würde dir daher raten, zum Schluss oder von einem sauberen Rechner aus sämtliche Zugangsdaten, welche an diesem Rechner verwendet wurden, zu ändern. Schritt 1 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 2 Warnung für Mitleser: Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix.
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
Schritt 3 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.03.2013, 16:13 | #8 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! So die Schritte wurden ausgeführt. Soweit keine Probleme! Aktuelle Trojaner Meldung von MSE: PWS:Win32/ZBOT.gen!aj TrojanDropper:Win32/Sirefef.gen!A Trojan:Win32/Sirefef!cfg Trojan:Win64/Sirefef.AE Hier die geforderten Logs: Code:
ATTFilter # AdwCleaner v2.115 - Datei am 24/03/2013 um 15:16:05 erstellt # Aktualisiert am 17/03/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Stefan Möller - STEFANMÖLLER-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Stefan Möller\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\user.js Datei Gelöscht : C:\Users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\searchplugins\funmoods.xml Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\extensions\ffxtlbr@funmoods.com Ordner Gelöscht : C:\Users\Stefan Möller\AppData\Roaming\pdfforge ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.funmoods.com/?f=1&a=drive --> hxxp://www.google.com -\\ Mozilla Firefox v19.0.2 (de) Datei : C:\Users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\prefs.js C:\Users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\user.js ... Gelöscht ! Gelöscht : user_pref("extensions.funmoods_i.aflt", "drive"); Gelöscht : user_pref("extensions.funmoods_i.dfltLng", ""); Gelöscht : user_pref("extensions.funmoods_i.dfltSrch", true); Gelöscht : user_pref("extensions.funmoods_i.dnsErr", true); Gelöscht : user_pref("extensions.funmoods_i.excTlbr", false); Gelöscht : user_pref("extensions.funmoods_i.hmpg", true); Gelöscht : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=drive"); Gelöscht : user_pref("extensions.funmoods_i.id", "7a32b2f90000000000006c626d43bcfb"); Gelöscht : user_pref("extensions.funmoods_i.instlDay", "15488"); Gelöscht : user_pref("extensions.funmoods_i.instlRef", ""); Gelöscht : user_pref("extensions.funmoods_i.newTab", true); Gelöscht : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=drive"); Gelöscht : user_pref("extensions.funmoods_i.prdct", "funmoods"); Gelöscht : user_pref("extensions.funmoods_i.prtnrId", "funmoods"); Gelöscht : user_pref("extensions.funmoods_i.smplGrp", "none"); Gelöscht : user_pref("extensions.funmoods_i.srchPrvdr", "Search"); Gelöscht : user_pref("extensions.funmoods_i.tlbrId", "base"); Gelöscht : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=drive&q=[...] Gelöscht : user_pref("extensions.funmoods_i.vrsn", "1.5.11.16"); Gelöscht : user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1610:57:52"); Gelöscht : user_pref("extensions.funmoods_i.vrsni", "1.5.11.16"); ************************* AdwCleaner[S1].txt - [3373 octets] - [24/03/2013 15:16:05] ########## EOF - C:\AdwCleaner[S1].txt - [3433 octets] ########## Code:
ATTFilter OTL logfile created on: 3/24/2013 4:04:44 PM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.63 Gb Available Physical Memory | 70.51% Memory free 15.96 Gb Paging File | 13.51 Gb Available in Paging File | 84.66% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 740.24 Gb Free Space | 54.18% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe PRC - [2013/03/08 08:18:53 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/10 12:51:16 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe PRC - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe PRC - [2010/11/17 18:53:00 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/11/06 08:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2008/01/22 10:13:32 | 001,201,448 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2008/01/22 10:13:20 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe ========== Modules (No Company Name) ========== MOD - [2013/03/08 08:18:39 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013/02/13 18:03:12 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll MOD - [2013/02/13 18:03:04 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013/01/09 18:57:18 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ab54c04b3df40416205883b4049fe273\IAStorUtil.ni.dll MOD - [2013/01/09 18:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\4d6518ef6ae8d6f005c49ab1c86de7fe\IAStorCommon.ni.dll MOD - [2013/01/09 17:31:05 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013/01/09 17:30:44 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013/01/09 17:30:35 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013/01/09 17:30:32 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013/01/09 17:30:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013/01/09 17:30:29 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013/01/09 17:30:22 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf MOD - [2010/11/25 17:26:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2010/11/13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ========== Services (SafeList) ========== SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2012/12/19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/08/13 00:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2013/03/15 17:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013/03/13 19:39:43 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/03/08 08:18:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/03/02 17:00:26 | 000,025,504 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2012/03/02 17:00:20 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus) SRV - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012/12/19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/12/19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/11/10 11:46:25 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012/11/06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/05/16 15:27:11 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011/05/16 15:27:11 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011/05/13 13:55:41 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/01/03 17:32:46 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010/12/17 10:57:03 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) DRV:64bit: - [2010/11/25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/19 19:34:00 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2010/11/19 19:34:00 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2010/11/06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010/09/02 07:26:30 | 000,032,936 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iqvw64e.sys -- (NAL) DRV:64bit: - [2010/02/24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009/11/16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:64bit: - [2009/11/16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/06/10 21:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007/04/11 23:30:04 | 000,043,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTVE.sys -- (IAMTVE) DRV:64bit: - [2007/04/11 23:29:58 | 000,051,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTXPE.sys -- (IAMTXPE) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{28C204E3-FC61-4EAB-8F6D-BE793949C69D}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=drive&q={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{63DC52A0-A1ED-4FEE-A13A-DEFFCE92CAD7}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDND_enDE393 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{F097D89E-E315-4C3F-9760-15AA4E34C76E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions [2011/07/24 17:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de [2013/03/24 15:16:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions [2013/02/14 20:09:53 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/03/08 08:18:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013/03/08 08:18:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/07/31 07:54:25 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/08/30 08:43:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/07/31 07:54:25 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/07/31 07:54:25 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/31 07:54:25 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/31 07:54:25 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013/03/24 15:57:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [Ixakdoifl] C:\Users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe (Ig}u) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.191.74.18 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A5E6DDE-142E-4A4E-A349-35C75B1CF2BB}: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EC3C12-8A2E-4718-A015-31D79615CA4A}: DhcpNameServer = 213.191.74.18 192.168.0.1 O18:64bit: - Protocol\Handler\haufereader - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\haufereader - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/03/24 16:03:29 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013/03/24 15:47:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013/03/24 15:47:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013/03/24 15:47:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013/03/24 15:36:43 | 000,000,000 | ---D | C] -- C:\Qoobox [2013/03/24 15:36:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013/03/24 15:34:56 | 005,044,071 | R--- | C] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/23 23:50:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\PC Rettung [2013/03/23 22:30:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 20:06:22 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Programs [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2013/03/17 09:53:39 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Kega Fusion 3.64 [2013/03/17 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Alex-Kidd [2013/03/14 07:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013/03/14 07:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/03/14 07:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/11 18:58:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Shop [2013/03/10 00:27:54 | 000,000,000 | ---D | C] -- C:\Download [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\My Videos [2013/03/10 00:25:17 | 000,000,000 | ---D | C] -- C:\AllShare [2013/03/10 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2013/03/10 00:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2013/03/10 00:04:23 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Downloaded Installations [2013/03/08 08:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/03/06 07:25:28 | 000,000,000 | R--D | C] -- C:\Users\Stefan Möller\Documents\Scanned Documents [2013/03/06 07:25:28 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Fax [2012/01/15 08:09:47 | 001,080,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Stefan Möller\dbghelp.dll [2012/01/15 08:09:47 | 000,366,080 | ---- | C] (RAD Game Tools, Inc.) -- C:\Users\Stefan Möller\Mss32.dll [2012/01/15 08:09:47 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\Stefan Möller\steam_api.dll [2012/01/15 08:09:46 | 002,410,496 | ---- | C] (Firaxis Games) -- C:\Users\Stefan Möller\CvGameCoreDLLFinal Release.dll ========== Files - Modified Within 30 Days ========== [2013/03/24 15:57:18 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013/03/24 15:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/03/24 15:37:51 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 15:37:51 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 15:34:33 | 005,044,071 | R--- | M] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 15:30:26 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2013/03/24 15:29:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/03/24 15:29:09 | 2133,037,055 | -HS- | M] () -- C:\hiberfil.sys [2013/03/24 15:15:24 | 000,609,993 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/24 11:49:46 | 1460,638,987 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013/03/23 22:35:19 | 000,000,188 | ---- | M] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:33 | 000,377,856 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 22:29:05 | 000,050,477 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 20:06:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/03/23 19:31:56 | 000,001,186 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/23 10:43:34 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\QuickSteuer Deluxe 2013.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/12 13:30:38 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/03/12 13:30:38 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013/03/12 13:30:38 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/03/12 13:30:38 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013/03/12 13:30:38 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/03/11 20:24:51 | 000,007,485 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:44 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/02/27 10:21:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif ========== Files Created - No Company Name ========== [2013/03/24 15:47:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013/03/24 15:47:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013/03/24 15:47:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013/03/24 15:47:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013/03/24 15:47:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013/03/24 15:15:53 | 000,609,993 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/23 22:35:18 | 000,000,188 | ---- | C] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:51 | 000,377,856 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:23 | 000,050,477 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 19:31:56 | 000,001,186 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/11 20:24:50 | 000,007,485 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:41 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/01/03 20:02:06 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2012/10/11 20:31:31 | 000,010,599 | ---- | C] () -- C:\Users\Stefan Möller\Bünning_elster_2048.pfx [2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012/03/25 14:56:35 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ2414N.DAT [2012/02/27 10:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll [2012/02/27 10:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll [2012/02/27 10:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll [2012/02/27 10:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll [2012/02/15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/15 08:09:47 | 000,900,978 | ---- | C] () -- C:\Users\Stefan Möller\libeay32.dll [2012/01/15 08:09:47 | 000,568,397 | ---- | C] () -- C:\Users\Stefan Möller\Read Me English.pdf [2012/01/15 08:09:47 | 000,563,920 | ---- | C] () -- C:\Users\Stefan Möller\Read Me French.pdf [2012/01/15 08:09:47 | 000,517,549 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Spanish.pdf [2012/01/15 08:09:47 | 000,515,418 | ---- | C] () -- C:\Users\Stefan Möller\Read Me German.pdf [2012/01/15 08:09:47 | 000,454,270 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Italian.pdf [2012/01/15 08:09:47 | 000,232,409 | ---- | C] () -- C:\Users\Stefan Möller\ssleay32.dll [2012/01/15 08:09:47 | 000,231,936 | ---- | C] () -- C:\Users\Stefan Möller\mss32midi.dll [2012/01/15 08:09:47 | 000,151,040 | ---- | C] () -- C:\Users\Stefan Möller\lua51_Win32.dll [2012/01/15 08:09:47 | 000,059,904 | ---- | C] () -- C:\Users\Stefan Möller\zlib1.dll [2012/01/15 08:09:46 | 000,818,688 | ---- | C] () -- C:\Users\Stefan Möller\CvLocalizationWin32Final Release.dll [2012/01/15 08:09:46 | 000,507,904 | ---- | C] () -- C:\Users\Stefan Möller\CvGameDatabaseWin32Final Release.dll [2012/01/15 08:09:46 | 000,241,664 | ---- | C] () -- C:\Users\Stefan Möller\Civ5GDF.dll [2012/01/15 08:09:39 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_it_IT.wmv [2012/01/15 08:09:31 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_fr_FR.wmv [2012/01/15 08:09:25 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_es_ES.wmv [2012/01/15 08:09:17 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_en_US.wmv [2012/01/15 08:09:11 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_de_DE.wmv [2011/11/03 22:17:12 | 001,881,740 | ---- | C] () -- C:\Users\Stefan Möller\Bewerbung Britta Carstensen.pdf [2011/11/03 22:11:49 | 004,974,710 | ---- | C] () -- C:\Users\Stefan Möller\Zeugnisse Britta Carstensen 11.09..pdf [2011/11/03 22:10:19 | 001,406,786 | ---- | C] () -- C:\Users\Stefan Möller\pdf24 Job Printing.pdf [2011/09/13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/22 18:50:31 | 000,162,409 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\census.cache [2011/08/22 18:50:28 | 000,130,957 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\ars.cache [2011/08/22 18:45:29 | 000,000,036 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\housecall.guid.cache [2011/05/16 19:09:46 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/05/15 18:26:20 | 000,001,819 | ---- | C] () -- C:\Users\Stefan Möller\140.jpg [2011/05/15 18:12:22 | 000,005,097 | ---- | C] () -- C:\Users\Stefan Möller\Sony-Sdm-hs75s.jpg [2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2011/11/17 07:41:18 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\@ [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2012/10/13 20:29:45 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2013/03/23 18:52:39 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2012/03/26 16:24:09 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Canon [2012/11/10 11:47:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\DAEMON Tools Lite [2012/02/04 10:58:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\elsterformular [2012/03/25 17:11:32 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Haufe Mediengruppe [2013/03/23 15:02:29 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2011/10/27 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Lexware [2011/07/18 12:44:21 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\ProtectDISC [2013/03/10 00:27:45 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2011/05/21 10:00:42 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\SoftGrid Client [2011/08/19 12:17:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TeamViewer [2011/07/24 17:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TomTom [2011/05/16 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TP [2011/08/22 19:20:22 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Ubisoft [2012/11/18 11:11:48 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Uniblue [2013/03/23 19:34:55 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\UseNeXT [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc ========== Purity Check ========== < End of report > Code:
ATTFilter ComboFix 13-03-24.03 - Stefan Möller 24.03.2013 15:48:33.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.5835 [GMT 1:00] ausgeführt von:: c:\users\Stefan M÷ller\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 )))))))))))))))))))))))))))))) . . 2013-03-24 14:54 . 2013-03-24 14:54 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-24 14:41 . 2013-03-24 14:41 972264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBEA5D7F-42D8-4B15-BC34-2D50C7E624CD}\gapaengine.dll 2013-03-24 14:41 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{129F4D28-EC5F-4117-BA33-DF55E20F42BA}\mpengine.dll 2013-03-24 10:53 . 2013-03-19 04:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2B4C762C-E80B-4D0F-8792-A2785B284782}\mpengine.dll 2013-03-23 19:06 . 2013-03-23 19:06 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Programs 2013-03-23 14:04 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-03-23 13:54 . 2013-03-23 14:02 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Inyf 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Zeyc 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Acawy 2013-03-09 23:27 . 2013-03-09 23:33 -------- d-----w- C:\Download 2013-03-09 23:27 . 2013-03-09 23:27 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Samsung 2013-03-09 23:25 . 2013-03-09 23:25 -------- d-----w- C:\AllShare 2013-03-09 23:24 . 2013-03-09 23:24 -------- d-----w- c:\program files (x86)\Samsung 2013-03-09 23:04 . 2013-03-09 23:04 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Downloaded Installations 2013-02-27 09:19 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-27 09:19 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-27 09:19 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-27 09:19 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-14 06:20 . 2010-11-26 17:57 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-13 18:39 . 2012-04-09 08:09 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-13 18:39 . 2011-05-27 17:27 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-12 05:45 . 2013-03-14 06:01 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 06:01 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 06:01 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 06:01 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2012-03-20 18:44 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-17 00:28 . 2010-11-26 17:22 273840 ------w- c:\windows\system32\MpSigStub.exe 2013-01-05 05:53 . 2013-02-13 06:51 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-01-05 05:00 . 2013-02-13 06:51 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00 . 2013-02-13 06:51 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46 . 2013-02-13 06:51 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-01-04 04:51 . 2013-02-13 06:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-01-04 04:43 . 2013-02-13 06:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-01-04 03:26 . 2013-02-13 06:51 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-01-04 02:47 . 2013-02-13 06:51 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-01-04 02:47 . 2013-02-13 06:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-01-04 02:47 . 2013-02-13 06:51 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-01-04 02:47 . 2013-02-13 06:51 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-01-03 06:00 . 2013-02-13 06:50 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-01-03 06:00 . 2013-02-13 06:50 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-12-27 08:28 . 2012-11-11 14:04 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-12-27 08:28 . 2012-11-11 14:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "DriverScanner"="c:\program files (x86)\Uniblue\DriverScanner\launcher.exe" [2012-07-10 338848] "Ixakdoifl"="c:\users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe" [2012-01-20 201216] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "LexwareInfoService"="c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "AllShareAgent"="c:\program files (x86)\Samsung\AllShare\AllShareAgent.exe" [2012-03-01 285072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616] . . Inhalt des "geplante Tasks" Ordners . 2013-03-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2013-03-24 c:\windows\Tasks\DriverScanner.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2012-11-18 11:51] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-09 11613288] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 TCP: DhcpNameServer = 213.191.74.18 192.168.0.1 FF - ProfilePath - c:\users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\ FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p= FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-BsScanner HKLM-Run-MSC - c:\program files\Microsoft Security Client\mssecex.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-24 15:58:51 ComboFix-quarantined-files.txt 2013-03-24 14:58 . Vor Suchlauf: 11 Verzeichnis(se), 788.808.179.712 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 794.729.222.144 Bytes frei . - - End Of File - - E4D9494ED0DEA7709AD65FBF808A63F9 |
24.03.2013, 16:39 | #9 |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo, die Meldungen von MSE zeigen das, was ich auch im Log sehe. Combofix hat das Ding nicht richtig erwischt. Dann helfen wir etwas nach: (Den Echtzeitschutz von MSE während des Combofixscans bitte ausschalten.) Schritt 1 Hinweis für Mitleser: Folgendes ComboFix Skript ist ausschliesslich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.03.2013, 17:47 | #10 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hier die Logs: OTL Code:
ATTFilter OTL logfile created on: 3/24/2013 5:35:38 PM - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.66 Gb Available Physical Memory | 70.90% Memory free 15.96 Gb Paging File | 13.60 Gb Available in Paging File | 85.21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 740.37 Gb Free Space | 54.19% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe PRC - [2013/03/08 08:18:53 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/10 12:51:16 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe PRC - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe PRC - [2010/11/17 18:53:00 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/11/06 08:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2008/01/22 10:13:32 | 001,201,448 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2008/01/22 10:13:20 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe ========== Modules (No Company Name) ========== MOD - [2013/03/08 08:18:39 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013/02/13 18:03:12 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll MOD - [2013/02/13 18:03:04 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013/01/09 18:57:18 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ab54c04b3df40416205883b4049fe273\IAStorUtil.ni.dll MOD - [2013/01/09 18:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\4d6518ef6ae8d6f005c49ab1c86de7fe\IAStorCommon.ni.dll MOD - [2013/01/09 17:31:05 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013/01/09 17:30:44 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013/01/09 17:30:35 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013/01/09 17:30:32 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013/01/09 17:30:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013/01/09 17:30:29 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013/01/09 17:30:22 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf MOD - [2010/11/25 17:26:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2010/11/13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ========== Services (SafeList) ========== SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2012/12/19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/08/13 00:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2013/03/15 17:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013/03/13 19:39:43 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/03/08 08:18:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/03/02 17:00:26 | 000,025,504 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2012/03/02 17:00:20 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus) SRV - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012/12/19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/12/19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/11/10 11:46:25 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012/11/06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/05/16 15:27:11 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011/05/16 15:27:11 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011/05/13 13:55:41 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/01/03 17:32:46 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010/12/17 10:57:03 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) DRV:64bit: - [2010/11/25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/19 19:34:00 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2010/11/19 19:34:00 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2010/11/06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010/09/02 07:26:30 | 000,032,936 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iqvw64e.sys -- (NAL) DRV:64bit: - [2010/02/24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009/11/16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:64bit: - [2009/11/16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/06/10 21:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007/04/11 23:30:04 | 000,043,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTVE.sys -- (IAMTVE) DRV:64bit: - [2007/04/11 23:29:58 | 000,051,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTXPE.sys -- (IAMTXPE) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{28C204E3-FC61-4EAB-8F6D-BE793949C69D}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=drive&q={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{63DC52A0-A1ED-4FEE-A13A-DEFFCE92CAD7}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDND_enDE393 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{F097D89E-E315-4C3F-9760-15AA4E34C76E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions [2011/07/24 17:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de [2013/03/24 15:16:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions [2013/02/14 20:09:53 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/03/08 08:18:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013/03/08 08:18:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/07/31 07:54:25 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/08/30 08:43:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/07/31 07:54:25 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/07/31 07:54:25 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/31 07:54:25 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/31 07:54:25 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013/03/24 15:57:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [Ixakdoifl] C:\Users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe (Ig}u) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.191.74.18 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A5E6DDE-142E-4A4E-A349-35C75B1CF2BB}: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EC3C12-8A2E-4718-A015-31D79615CA4A}: DhcpNameServer = 213.191.74.18 192.168.0.1 O18:64bit: - Protocol\Handler\haufereader - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\haufereader - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/03/24 16:46:17 | 005,044,071 | R--- | C] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 15:47:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013/03/24 15:47:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013/03/24 15:47:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013/03/24 15:36:43 | 000,000,000 | ---D | C] -- C:\Qoobox [2013/03/24 15:36:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013/03/23 23:50:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\PC Rettung [2013/03/23 22:30:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 20:06:22 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Programs [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2013/03/17 09:53:39 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Kega Fusion 3.64 [2013/03/17 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Alex-Kidd [2013/03/14 07:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013/03/14 07:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/03/14 07:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/11 18:58:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Shop [2013/03/10 00:27:54 | 000,000,000 | ---D | C] -- C:\Download [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\My Videos [2013/03/10 00:25:17 | 000,000,000 | ---D | C] -- C:\AllShare [2013/03/10 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2013/03/10 00:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2013/03/10 00:04:23 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Downloaded Installations [2013/03/08 08:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/03/06 07:25:28 | 000,000,000 | R--D | C] -- C:\Users\Stefan Möller\Documents\Scanned Documents [2013/03/06 07:25:28 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Fax [2012/01/15 08:09:47 | 001,080,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Stefan Möller\dbghelp.dll [2012/01/15 08:09:47 | 000,366,080 | ---- | C] (RAD Game Tools, Inc.) -- C:\Users\Stefan Möller\Mss32.dll [2012/01/15 08:09:47 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\Stefan Möller\steam_api.dll [2012/01/15 08:09:46 | 002,410,496 | ---- | C] (Firaxis Games) -- C:\Users\Stefan Möller\CvGameCoreDLLFinal Release.dll ========== Files - Modified Within 30 Days ========== [2013/03/24 16:46:01 | 005,044,071 | R--- | M] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 16:39:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/03/24 15:57:18 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013/03/24 15:37:51 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 15:37:51 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 15:30:26 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2013/03/24 15:29:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/03/24 15:29:09 | 2133,037,055 | -HS- | M] () -- C:\hiberfil.sys [2013/03/24 15:15:24 | 000,609,993 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/24 11:49:46 | 1460,638,987 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013/03/23 22:35:19 | 000,000,188 | ---- | M] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:33 | 000,377,856 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 22:29:05 | 000,050,477 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 20:06:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/03/23 19:31:56 | 000,001,186 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/23 10:43:34 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\QuickSteuer Deluxe 2013.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/12 13:30:38 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/03/12 13:30:38 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013/03/12 13:30:38 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/03/12 13:30:38 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013/03/12 13:30:38 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/03/11 20:24:51 | 000,007,485 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:44 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/02/27 10:21:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif ========== Files Created - No Company Name ========== [2013/03/24 15:47:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013/03/24 15:47:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013/03/24 15:47:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013/03/24 15:47:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013/03/24 15:47:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013/03/24 15:15:53 | 000,609,993 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/23 22:35:18 | 000,000,188 | ---- | C] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:51 | 000,377,856 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:23 | 000,050,477 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 19:31:56 | 000,001,186 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/11 20:24:50 | 000,007,485 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:41 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/01/03 20:02:06 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2012/10/11 20:31:31 | 000,010,599 | ---- | C] () -- C:\Users\Stefan Möller\Bünning_elster_2048.pfx [2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012/03/25 14:56:35 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ2414N.DAT [2012/02/27 10:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll [2012/02/27 10:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll [2012/02/27 10:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll [2012/02/27 10:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll [2012/02/15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/15 08:09:47 | 000,900,978 | ---- | C] () -- C:\Users\Stefan Möller\libeay32.dll [2012/01/15 08:09:47 | 000,568,397 | ---- | C] () -- C:\Users\Stefan Möller\Read Me English.pdf [2012/01/15 08:09:47 | 000,563,920 | ---- | C] () -- C:\Users\Stefan Möller\Read Me French.pdf [2012/01/15 08:09:47 | 000,517,549 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Spanish.pdf [2012/01/15 08:09:47 | 000,515,418 | ---- | C] () -- C:\Users\Stefan Möller\Read Me German.pdf [2012/01/15 08:09:47 | 000,454,270 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Italian.pdf [2012/01/15 08:09:47 | 000,232,409 | ---- | C] () -- C:\Users\Stefan Möller\ssleay32.dll [2012/01/15 08:09:47 | 000,231,936 | ---- | C] () -- C:\Users\Stefan Möller\mss32midi.dll [2012/01/15 08:09:47 | 000,151,040 | ---- | C] () -- C:\Users\Stefan Möller\lua51_Win32.dll [2012/01/15 08:09:47 | 000,059,904 | ---- | C] () -- C:\Users\Stefan Möller\zlib1.dll [2012/01/15 08:09:46 | 000,818,688 | ---- | C] () -- C:\Users\Stefan Möller\CvLocalizationWin32Final Release.dll [2012/01/15 08:09:46 | 000,507,904 | ---- | C] () -- C:\Users\Stefan Möller\CvGameDatabaseWin32Final Release.dll [2012/01/15 08:09:46 | 000,241,664 | ---- | C] () -- C:\Users\Stefan Möller\Civ5GDF.dll [2012/01/15 08:09:39 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_it_IT.wmv [2012/01/15 08:09:31 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_fr_FR.wmv [2012/01/15 08:09:25 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_es_ES.wmv [2012/01/15 08:09:17 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_en_US.wmv [2012/01/15 08:09:11 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_de_DE.wmv [2011/11/03 22:17:12 | 001,881,740 | ---- | C] () -- C:\Users\Stefan Möller\Bewerbung Britta Carstensen.pdf [2011/11/03 22:11:49 | 004,974,710 | ---- | C] () -- C:\Users\Stefan Möller\Zeugnisse Britta Carstensen 11.09..pdf [2011/11/03 22:10:19 | 001,406,786 | ---- | C] () -- C:\Users\Stefan Möller\pdf24 Job Printing.pdf [2011/09/13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/22 18:50:31 | 000,162,409 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\census.cache [2011/08/22 18:50:28 | 000,130,957 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\ars.cache [2011/08/22 18:45:29 | 000,000,036 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\housecall.guid.cache [2011/05/16 19:09:46 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/05/15 18:26:20 | 000,001,819 | ---- | C] () -- C:\Users\Stefan Möller\140.jpg [2011/05/15 18:12:22 | 000,005,097 | ---- | C] () -- C:\Users\Stefan Möller\Sony-Sdm-hs75s.jpg [2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2011/11/17 07:41:18 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\@ [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2012/10/13 20:29:45 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2013/03/23 18:52:39 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2012/03/26 16:24:09 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Canon [2012/11/10 11:47:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\DAEMON Tools Lite [2012/02/04 10:58:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\elsterformular [2012/03/25 17:11:32 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Haufe Mediengruppe [2013/03/23 15:02:29 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2011/10/27 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Lexware [2011/07/18 12:44:21 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\ProtectDISC [2013/03/10 00:27:45 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2011/05/21 10:00:42 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\SoftGrid Client [2011/08/19 12:17:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TeamViewer [2011/07/24 17:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TomTom [2011/05/16 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TP [2011/08/22 19:20:22 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Ubisoft [2012/11/18 11:11:48 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Uniblue [2013/03/23 19:34:55 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\UseNeXT [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc ========== Purity Check ========== < End of report > Code:
ATTFilter ComboFix 13-03-24.03 - Stefan Möller 24.03.2013 16:55:57.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.5981 [GMT 1:00] ausgeführt von:: c:\users\Stefan M÷ller\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\Stefan M÷ller\Desktop\CFScript.txt AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 )))))))))))))))))))))))))))))) . . 2013-03-24 15:58 . 2013-03-24 15:58 -------- d-----w- c:\users\Stefan M”ller\AppData\Local\temp 2013-03-24 15:58 . 2013-03-24 15:58 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-24 15:01 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{803D01AA-F76B-4D0E-A976-EBA84323EA7C}\mpengine.dll 2013-03-24 14:41 . 2013-03-24 14:41 972264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBEA5D7F-42D8-4B15-BC34-2D50C7E624CD}\gapaengine.dll 2013-03-24 10:53 . 2013-03-19 04:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2B4C762C-E80B-4D0F-8792-A2785B284782}\mpengine.dll 2013-03-23 19:06 . 2013-03-23 19:06 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Programs 2013-03-23 14:04 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-03-23 13:54 . 2013-03-23 14:02 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Inyf 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Zeyc 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Acawy 2013-03-09 23:27 . 2013-03-09 23:33 -------- d-----w- C:\Download 2013-03-09 23:27 . 2013-03-09 23:27 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Samsung 2013-03-09 23:25 . 2013-03-09 23:25 -------- d-----w- C:\AllShare 2013-03-09 23:24 . 2013-03-09 23:24 -------- d-----w- c:\program files (x86)\Samsung 2013-03-09 23:04 . 2013-03-09 23:04 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Downloaded Installations 2013-02-27 09:19 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-27 09:19 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-27 09:19 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-27 09:19 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-14 06:20 . 2010-11-26 17:57 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-13 18:39 . 2012-04-09 08:09 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-13 18:39 . 2011-05-27 17:27 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-12 05:45 . 2013-03-14 06:01 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 06:01 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 06:01 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 06:01 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2012-03-20 18:44 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-17 00:28 . 2010-11-26 17:22 273840 ------w- c:\windows\system32\MpSigStub.exe 2013-01-05 05:53 . 2013-02-13 06:51 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-01-05 05:00 . 2013-02-13 06:51 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00 . 2013-02-13 06:51 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46 . 2013-02-13 06:51 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-01-04 04:51 . 2013-02-13 06:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-01-04 04:43 . 2013-02-13 06:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-01-04 03:26 . 2013-02-13 06:51 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-01-04 02:47 . 2013-02-13 06:51 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-01-04 02:47 . 2013-02-13 06:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-01-04 02:47 . 2013-02-13 06:51 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-01-04 02:47 . 2013-02-13 06:51 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-01-03 06:00 . 2013-02-13 06:50 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-01-03 06:00 . 2013-02-13 06:50 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-12-27 08:28 . 2012-11-11 14:04 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-12-27 08:28 . 2012-11-11 14:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "DriverScanner"="c:\program files (x86)\Uniblue\DriverScanner\launcher.exe" [2012-07-10 338848] "Ixakdoifl"="c:\users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe" [2012-01-20 201216] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "LexwareInfoService"="c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "AllShareAgent"="c:\program files (x86)\Samsung\AllShare\AllShareAgent.exe" [2012-03-01 285072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616] . . Inhalt des "geplante Tasks" Ordners . 2013-03-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2013-03-24 c:\windows\Tasks\DriverScanner.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2012-11-18 11:51] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-09 11613288] "MSC"="c:\program files\Microsoft Security Client\mssecex.exe" [BU] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 TCP: DhcpNameServer = 213.191.74.18 192.168.0.1 FF - ProfilePath - c:\users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\ FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p= FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-24 17:00:23 ComboFix-quarantined-files.txt 2013-03-24 16:00 ComboFix2.txt 2013-03-24 14:58 . Vor Suchlauf: 14 Verzeichnis(se), 794.913.583.104 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 794.840.248.320 Bytes frei . - - End Of File - - C13B458415A6D6BCF42E3C4FD4BBEE63 |
24.03.2013, 18:07 | #11 |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo, das hat nicht geklappt, wie es sollte. Wir wiederholen den Schritt. Vergwissere dich bitte, dass das folgende Skript auch wirklich in der CFScript.txt gespeichert ist, bevor du es in die combofix.exe ziehst. Schritt 1 Hinweis für Mitleser: Folgendes ComboFix Skript ist ausschliesslich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.03.2013, 18:39 | #12 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Zur Info: Ich deaktiviere den Echtzeitschutz von MSE und beende dann MSE durch folgende eingaben: Windows + R net stop msmpsvc und anschließend sc config msmpsvc start= disabled Ich hoffe hierdurch wird MSE tatsächlich temporär deaktiviert! Die gewünschten Logs: ComboFix Code:
ATTFilter ComboFix 13-03-24.03 - Stefan Möller 24.03.2013 18:20:11.3.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.6200 [GMT 1:00] ausgeführt von:: c:\users\Stefan M÷ller\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\Stefan M÷ller\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 )))))))))))))))))))))))))))))) . . 2013-03-24 17:26 . 2013-03-24 17:26 -------- d-----w- c:\users\Stefan M”ller\AppData\Local\temp 2013-03-24 17:26 . 2013-03-24 17:26 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-24 17:03 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{49788566-C84A-41C7-80E5-6BF6BD973289}\mpengine.dll 2013-03-24 14:41 . 2013-03-24 14:41 972264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBEA5D7F-42D8-4B15-BC34-2D50C7E624CD}\gapaengine.dll 2013-03-24 10:53 . 2013-03-19 04:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2B4C762C-E80B-4D0F-8792-A2785B284782}\mpengine.dll 2013-03-23 19:06 . 2013-03-23 19:06 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Programs 2013-03-23 14:04 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-03-23 13:54 . 2013-03-23 14:02 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Inyf 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Zeyc 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Acawy 2013-03-09 23:27 . 2013-03-09 23:33 -------- d-----w- C:\Download 2013-03-09 23:27 . 2013-03-09 23:27 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Samsung 2013-03-09 23:25 . 2013-03-09 23:25 -------- d-----w- C:\AllShare 2013-03-09 23:24 . 2013-03-09 23:24 -------- d-----w- c:\program files (x86)\Samsung 2013-03-09 23:04 . 2013-03-09 23:04 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Downloaded Installations 2013-02-27 09:19 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-27 09:19 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-27 09:19 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-27 09:19 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-14 06:20 . 2010-11-26 17:57 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-13 18:39 . 2012-04-09 08:09 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-13 18:39 . 2011-05-27 17:27 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-12 05:45 . 2013-03-14 06:01 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 06:01 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 06:01 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 06:01 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2012-03-20 18:44 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-17 00:28 . 2010-11-26 17:22 273840 ------w- c:\windows\system32\MpSigStub.exe 2013-01-05 05:53 . 2013-02-13 06:51 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-01-05 05:00 . 2013-02-13 06:51 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00 . 2013-02-13 06:51 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46 . 2013-02-13 06:51 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-01-04 04:51 . 2013-02-13 06:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-01-04 04:43 . 2013-02-13 06:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-01-04 03:26 . 2013-02-13 06:51 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-01-04 02:47 . 2013-02-13 06:51 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-01-04 02:47 . 2013-02-13 06:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-01-04 02:47 . 2013-02-13 06:51 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-01-04 02:47 . 2013-02-13 06:51 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-01-03 06:00 . 2013-02-13 06:50 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-01-03 06:00 . 2013-02-13 06:50 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-12-27 08:28 . 2012-11-11 14:04 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-12-27 08:28 . 2012-11-11 14:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "DriverScanner"="c:\program files (x86)\Uniblue\DriverScanner\launcher.exe" [2012-07-10 338848] "Ixakdoifl"="c:\users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe" [2012-01-20 201216] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "LexwareInfoService"="c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "AllShareAgent"="c:\program files (x86)\Samsung\AllShare\AllShareAgent.exe" [2012-03-01 285072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 ccjetrqu;ccjetrqu;c:\windows\system32\drivers\ccjetrqu.sys [x] R1 mjbhavqv;mjbhavqv;c:\windows\system32\drivers\mjbhavqv.sys [x] R1 nqgzqtbc;nqgzqtbc;c:\windows\system32\drivers\nqgzqtbc.sys [x] R1 qsbzzqpe;qsbzzqpe;c:\windows\system32\drivers\qsbzzqpe.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] R2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504] R3 IAMTVE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTVE.sys [2007-04-11 43416] R3 IAMTXPE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTXPE.sys [2007-04-11 51096] R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [2009-11-16 40144] R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [2009-11-16 42192] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] R3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [2009-06-10 707072] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888] R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-05-13 834544] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-10 283200] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2010-08-12 133800] S2 Lexware_Datenbank_Plus;Lexware Datenbank Plus;c:\program files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2011-06-29 83248] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248] . . Inhalt des "geplante Tasks" Ordners . 2013-03-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2013-03-24 c:\windows\Tasks\DriverScanner.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2012-11-18 11:51] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-09 11613288] "MSC"="c:\program files\Microsoft Security Client\mssecex.exe" [BU] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 TCP: DhcpNameServer = 213.191.74.18 192.168.0.1 FF - ProfilePath - c:\users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\ FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p= FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-24 18:28:20 ComboFix-quarantined-files.txt 2013-03-24 17:28 ComboFix2.txt 2013-03-24 16:00 ComboFix3.txt 2013-03-24 14:58 . Vor Suchlauf: 14 Verzeichnis(se), 794.822.111.232 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 794.743.095.296 Bytes frei . - - End Of File - - B10E326683C2E9F41C4A096445D9E5FD Code:
ATTFilter OTL logfile created on: 3/24/2013 6:30:33 PM - Run 5 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.72 Gb Available Physical Memory | 71.63% Memory free 15.96 Gb Paging File | 13.63 Gb Available in Paging File | 85.42% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 740.26 Gb Free Space | 54.19% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe PRC - [2013/03/08 08:18:53 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/10 12:51:16 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe PRC - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe PRC - [2010/11/17 18:53:00 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/11/06 08:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2008/01/22 10:13:20 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe ========== Modules (No Company Name) ========== MOD - [2013/03/08 08:18:39 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013/02/13 18:03:12 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll MOD - [2013/02/13 18:03:04 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013/01/09 18:57:18 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ab54c04b3df40416205883b4049fe273\IAStorUtil.ni.dll MOD - [2013/01/09 18:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\4d6518ef6ae8d6f005c49ab1c86de7fe\IAStorCommon.ni.dll MOD - [2013/01/09 17:31:05 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013/01/09 17:30:44 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013/01/09 17:30:35 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013/01/09 17:30:32 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013/01/09 17:30:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013/01/09 17:30:29 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013/01/09 17:30:22 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf MOD - [2010/12/21 01:15:30 | 001,041,248 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll MOD - [2010/11/25 17:26:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2010/11/13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ========== Services (SafeList) ========== SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2012/12/19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/08/13 00:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2013/03/15 17:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013/03/13 19:39:43 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/03/08 08:18:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/03/02 17:00:26 | 000,025,504 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2012/03/02 17:00:20 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus) SRV - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012/12/19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/12/19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/11/10 11:46:25 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012/11/06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/05/16 15:27:11 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011/05/16 15:27:11 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011/05/13 13:55:41 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/01/03 17:32:46 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010/12/17 10:57:03 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) DRV:64bit: - [2010/11/25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/19 19:34:00 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2010/11/19 19:34:00 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2010/11/06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010/09/02 07:26:30 | 000,032,936 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iqvw64e.sys -- (NAL) DRV:64bit: - [2010/02/24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009/11/16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:64bit: - [2009/11/16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/06/10 21:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007/04/11 23:30:04 | 000,043,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTVE.sys -- (IAMTVE) DRV:64bit: - [2007/04/11 23:29:58 | 000,051,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTXPE.sys -- (IAMTXPE) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{28C204E3-FC61-4EAB-8F6D-BE793949C69D}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=drive&q={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{63DC52A0-A1ED-4FEE-A13A-DEFFCE92CAD7}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDND_enDE393 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{F097D89E-E315-4C3F-9760-15AA4E34C76E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions [2011/07/24 17:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de [2013/03/24 15:16:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions [2013/02/14 20:09:53 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/03/08 08:18:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013/03/08 08:18:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/07/31 07:54:25 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/08/30 08:43:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/07/31 07:54:25 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/07/31 07:54:25 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/31 07:54:25 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/31 07:54:25 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013/03/24 15:57:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [Ixakdoifl] C:\Users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe (Ig}u) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.191.74.18 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A5E6DDE-142E-4A4E-A349-35C75B1CF2BB}: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EC3C12-8A2E-4718-A015-31D79615CA4A}: DhcpNameServer = 213.191.74.18 192.168.0.1 O18:64bit: - Protocol\Handler\haufereader - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\haufereader - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/03/24 18:16:48 | 005,044,071 | R--- | C] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 15:47:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013/03/24 15:47:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013/03/24 15:47:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013/03/24 15:36:43 | 000,000,000 | ---D | C] -- C:\Qoobox [2013/03/24 15:36:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013/03/23 23:50:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\PC Rettung [2013/03/23 22:30:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 20:06:22 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Programs [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2013/03/17 09:53:39 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Kega Fusion 3.64 [2013/03/17 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Alex-Kidd [2013/03/14 07:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013/03/14 07:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/03/14 07:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/11 18:58:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Shop [2013/03/10 00:27:54 | 000,000,000 | ---D | C] -- C:\Download [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\My Videos [2013/03/10 00:25:17 | 000,000,000 | ---D | C] -- C:\AllShare [2013/03/10 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2013/03/10 00:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2013/03/10 00:04:23 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Downloaded Installations [2013/03/08 08:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/03/06 07:25:28 | 000,000,000 | R--D | C] -- C:\Users\Stefan Möller\Documents\Scanned Documents [2013/03/06 07:25:28 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Fax [2012/01/15 08:09:47 | 001,080,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Stefan Möller\dbghelp.dll [2012/01/15 08:09:47 | 000,366,080 | ---- | C] (RAD Game Tools, Inc.) -- C:\Users\Stefan Möller\Mss32.dll [2012/01/15 08:09:47 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\Stefan Möller\steam_api.dll [2012/01/15 08:09:46 | 002,410,496 | ---- | C] (Firaxis Games) -- C:\Users\Stefan Möller\CvGameCoreDLLFinal Release.dll ========== Files - Modified Within 30 Days ========== [2013/03/24 18:21:56 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 18:21:56 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 18:16:30 | 005,044,071 | R--- | M] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 18:14:39 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2013/03/24 18:14:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/03/24 18:13:30 | 2133,037,055 | -HS- | M] () -- C:\hiberfil.sys [2013/03/24 17:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/03/24 15:57:18 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013/03/24 15:15:24 | 000,609,993 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/24 11:49:46 | 1460,638,987 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013/03/23 22:35:19 | 000,000,188 | ---- | M] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:33 | 000,377,856 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 22:29:05 | 000,050,477 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 20:06:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/03/23 19:31:56 | 000,001,186 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/23 10:43:34 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\QuickSteuer Deluxe 2013.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/12 13:30:38 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/03/12 13:30:38 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013/03/12 13:30:38 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/03/12 13:30:38 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013/03/12 13:30:38 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/03/11 20:24:51 | 000,007,485 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:44 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/02/27 10:21:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif ========== Files Created - No Company Name ========== [2013/03/24 15:47:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013/03/24 15:47:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013/03/24 15:47:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013/03/24 15:47:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013/03/24 15:47:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013/03/24 15:15:53 | 000,609,993 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/23 22:35:18 | 000,000,188 | ---- | C] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:51 | 000,377,856 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:23 | 000,050,477 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 19:31:56 | 000,001,186 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/11 20:24:50 | 000,007,485 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:41 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/01/03 20:02:06 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2012/10/11 20:31:31 | 000,010,599 | ---- | C] () -- C:\Users\Stefan Möller\Bünning_elster_2048.pfx [2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012/03/25 14:56:35 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ2414N.DAT [2012/02/27 10:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll [2012/02/27 10:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll [2012/02/27 10:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll [2012/02/27 10:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll [2012/02/15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/15 08:09:47 | 000,900,978 | ---- | C] () -- C:\Users\Stefan Möller\libeay32.dll [2012/01/15 08:09:47 | 000,568,397 | ---- | C] () -- C:\Users\Stefan Möller\Read Me English.pdf [2012/01/15 08:09:47 | 000,563,920 | ---- | C] () -- C:\Users\Stefan Möller\Read Me French.pdf [2012/01/15 08:09:47 | 000,517,549 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Spanish.pdf [2012/01/15 08:09:47 | 000,515,418 | ---- | C] () -- C:\Users\Stefan Möller\Read Me German.pdf [2012/01/15 08:09:47 | 000,454,270 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Italian.pdf [2012/01/15 08:09:47 | 000,232,409 | ---- | C] () -- C:\Users\Stefan Möller\ssleay32.dll [2012/01/15 08:09:47 | 000,231,936 | ---- | C] () -- C:\Users\Stefan Möller\mss32midi.dll [2012/01/15 08:09:47 | 000,151,040 | ---- | C] () -- C:\Users\Stefan Möller\lua51_Win32.dll [2012/01/15 08:09:47 | 000,059,904 | ---- | C] () -- C:\Users\Stefan Möller\zlib1.dll [2012/01/15 08:09:46 | 000,818,688 | ---- | C] () -- C:\Users\Stefan Möller\CvLocalizationWin32Final Release.dll [2012/01/15 08:09:46 | 000,507,904 | ---- | C] () -- C:\Users\Stefan Möller\CvGameDatabaseWin32Final Release.dll [2012/01/15 08:09:46 | 000,241,664 | ---- | C] () -- C:\Users\Stefan Möller\Civ5GDF.dll [2012/01/15 08:09:39 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_it_IT.wmv [2012/01/15 08:09:31 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_fr_FR.wmv [2012/01/15 08:09:25 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_es_ES.wmv [2012/01/15 08:09:17 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_en_US.wmv [2012/01/15 08:09:11 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_de_DE.wmv [2011/11/03 22:17:12 | 001,881,740 | ---- | C] () -- C:\Users\Stefan Möller\Bewerbung Britta Carstensen.pdf [2011/11/03 22:11:49 | 004,974,710 | ---- | C] () -- C:\Users\Stefan Möller\Zeugnisse Britta Carstensen 11.09..pdf [2011/11/03 22:10:19 | 001,406,786 | ---- | C] () -- C:\Users\Stefan Möller\pdf24 Job Printing.pdf [2011/09/13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/22 18:50:31 | 000,162,409 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\census.cache [2011/08/22 18:50:28 | 000,130,957 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\ars.cache [2011/08/22 18:45:29 | 000,000,036 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\housecall.guid.cache [2011/05/16 19:09:46 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/05/15 18:26:20 | 000,001,819 | ---- | C] () -- C:\Users\Stefan Möller\140.jpg [2011/05/15 18:12:22 | 000,005,097 | ---- | C] () -- C:\Users\Stefan Möller\Sony-Sdm-hs75s.jpg [2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2011/11/17 07:41:18 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\@ [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2012/10/13 20:29:45 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2013/03/23 18:52:39 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2012/03/26 16:24:09 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Canon [2012/11/10 11:47:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\DAEMON Tools Lite [2012/02/04 10:58:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\elsterformular [2012/03/25 17:11:32 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Haufe Mediengruppe [2013/03/23 15:02:29 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2011/10/27 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Lexware [2011/07/18 12:44:21 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\ProtectDISC [2013/03/10 00:27:45 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2011/05/21 10:00:42 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\SoftGrid Client [2011/08/19 12:17:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TeamViewer [2011/07/24 17:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TomTom [2011/05/16 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TP [2011/08/22 19:20:22 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Ubisoft [2012/11/18 11:11:48 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Uniblue [2013/03/23 19:34:55 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\UseNeXT [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc ========== Purity Check ========== < End of report > |
24.03.2013, 19:15 | #13 |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Hallo, der MSE-Echtzeitschutz war ausgeschaltet, das ist ok. Aber das Skript wurde wieder nicht ausgeführt. Dieses Mal versuch ich es anders: Schritt 1 Hinweis für Mitleser: Folgendes ComboFix Skript ist ausschliesslich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.03.2013, 19:33 | #14 |
| PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Ich hoffe jetzt hat es geklappt..... Combofix Code:
ATTFilter ComboFix 13-03-24.03 - Stefan Möller 24.03.2013 19:20:22.4.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.6062 [GMT 1:00] ausgeführt von:: c:\users\Stefan M÷ller\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\Stefan M÷ller\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-24 bis 2013-03-24 )))))))))))))))))))))))))))))) . . 2013-03-24 18:23 . 2013-03-24 18:23 -------- d-----w- c:\users\Stefan M”ller\AppData\Local\temp 2013-03-24 18:23 . 2013-03-24 18:23 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-24 17:28 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BEE38232-F600-4569-B97A-D9DCF91565B7}\mpengine.dll 2013-03-24 14:41 . 2013-03-24 14:41 972264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBEA5D7F-42D8-4B15-BC34-2D50C7E624CD}\gapaengine.dll 2013-03-24 10:53 . 2013-03-19 04:50 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2B4C762C-E80B-4D0F-8792-A2785B284782}\mpengine.dll 2013-03-23 19:06 . 2013-03-23 19:06 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Programs 2013-03-23 14:04 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-03-23 13:54 . 2013-03-23 14:02 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Inyf 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Zeyc 2013-03-23 13:54 . 2013-03-23 13:54 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Acawy 2013-03-09 23:27 . 2013-03-09 23:33 -------- d-----w- C:\Download 2013-03-09 23:27 . 2013-03-09 23:27 -------- d-----w- c:\users\Stefan Möller\AppData\Roaming\Samsung 2013-03-09 23:25 . 2013-03-09 23:25 -------- d-----w- C:\AllShare 2013-03-09 23:24 . 2013-03-09 23:24 -------- d-----w- c:\program files (x86)\Samsung 2013-03-09 23:04 . 2013-03-09 23:04 -------- d-----w- c:\users\Stefan Möller\AppData\Local\Downloaded Installations 2013-02-27 09:19 . 2013-01-13 19:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-27 09:19 . 2013-01-13 19:24 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-27 09:19 . 2013-01-04 06:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-27 09:19 . 2013-01-04 06:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-14 06:20 . 2010-11-26 17:57 72013344 ----a-w- c:\windows\system32\MRT.exe 2013-03-13 18:39 . 2012-04-09 08:09 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-13 18:39 . 2011-05-27 17:27 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-02-12 05:45 . 2013-03-14 06:01 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 06:01 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 06:01 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 06:01 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 06:01 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 14:59 . 2012-03-20 18:44 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-17 00:28 . 2010-11-26 17:22 273840 ------w- c:\windows\system32\MpSigStub.exe 2013-01-05 05:53 . 2013-02-13 06:51 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-01-05 05:00 . 2013-02-13 06:51 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00 . 2013-02-13 06:51 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46 . 2013-02-13 06:51 215040 ----a-w- c:\windows\system32\winsrv.dll 2013-01-04 04:51 . 2013-02-13 06:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-01-04 04:43 . 2013-02-13 06:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-01-04 03:26 . 2013-02-13 06:51 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-01-04 02:47 . 2013-02-13 06:51 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-01-04 02:47 . 2013-02-13 06:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-01-04 02:47 . 2013-02-13 06:51 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-01-04 02:47 . 2013-02-13 06:51 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-01-03 06:00 . 2013-02-13 06:50 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-01-03 06:00 . 2013-02-13 06:50 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-12-27 08:28 . 2012-11-11 14:04 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-12-27 08:28 . 2012-11-11 14:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872] "DriverScanner"="c:\program files (x86)\Uniblue\DriverScanner\launcher.exe" [2012-07-10 338848] "Ixakdoifl"="c:\users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe" [2012-01-20 201216] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "LexwareInfoService"="c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "AllShareAgent"="c:\program files (x86)\Samsung\AllShare\AllShareAgent.exe" [2012-03-01 285072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 ccjetrqu;ccjetrqu;c:\windows\system32\drivers\ccjetrqu.sys [x] R1 mjbhavqv;mjbhavqv;c:\windows\system32\drivers\mjbhavqv.sys [x] R1 nqgzqtbc;nqgzqtbc;c:\windows\system32\drivers\nqgzqtbc.sys [x] R1 qsbzzqpe;qsbzzqpe;c:\windows\system32\drivers\qsbzzqpe.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] R2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504] R3 IAMTVE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTVE.sys [2007-04-11 43416] R3 IAMTXPE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTXPE.sys [2007-04-11 51096] R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [2009-11-16 40144] R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [2009-11-16 42192] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] R3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [2009-06-10 707072] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888] R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-05-13 834544] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-10 283200] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2010-08-12 133800] S2 Lexware_Datenbank_Plus;Lexware Datenbank Plus;c:\program files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2011-06-29 83248] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248] . . Inhalt des "geplante Tasks" Ordners . 2013-03-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2013-03-24 c:\windows\Tasks\DriverScanner.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2012-11-18 11:51] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-09 11613288] "MSC"="c:\program files\Microsoft Security Client\mssecex.exe" [BU] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 TCP: DhcpNameServer = 213.191.74.18 192.168.0.1 FF - ProfilePath - c:\users\Stefan Möller\AppData\Roaming\Mozilla\Firefox\Profiles\iepy89s1.default\ FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p= FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-24 19:24:38 ComboFix-quarantined-files.txt 2013-03-24 18:24 ComboFix2.txt 2013-03-24 17:28 ComboFix3.txt 2013-03-24 16:00 ComboFix4.txt 2013-03-24 14:58 . Vor Suchlauf: 14 Verzeichnis(se), 794.933.018.624 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 794.623.500.288 Bytes frei . - - End Of File - - 350AE7691E2D211F76CF8479AF22C877 Code:
ATTFilter OTL logfile created on: 3/24/2013 7:29:06 PM - Run 6 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stefan Möller\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 5.89 Gb Available Physical Memory | 73.80% Memory free 15.96 Gb Paging File | 13.86 Gb Available in Paging File | 86.86% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1366.17 Gb Total Space | 740.15 Gb Free Space | 54.18% Space Free | Partition Type: NTFS Drive D: | 30.00 Gb Total Space | 9.30 Gb Free Space | 31.01% Space Free | Partition Type: NTFS Computer Name: STEFANMÖLLER-PC | User Name: Stefan Möller | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/10 12:51:16 | 000,026,016 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe PRC - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe PRC - [2010/11/17 18:53:00 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/11/06 08:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2008/01/22 10:13:20 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe ========== Modules (No Company Name) ========== MOD - [2013/02/13 18:03:12 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll MOD - [2013/02/13 18:03:04 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll MOD - [2013/01/09 18:57:18 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ab54c04b3df40416205883b4049fe273\IAStorUtil.ni.dll MOD - [2013/01/09 18:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\4d6518ef6ae8d6f005c49ab1c86de7fe\IAStorCommon.ni.dll MOD - [2013/01/09 17:31:05 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll MOD - [2013/01/09 17:30:44 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll MOD - [2013/01/09 17:30:35 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll MOD - [2013/01/09 17:30:32 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll MOD - [2013/01/09 17:30:30 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll MOD - [2013/01/09 17:30:29 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll MOD - [2013/01/09 17:30:22 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll MOD - [2010/11/25 17:26:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2010/11/13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ========== Services (SafeList) ========== SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2012/12/19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/08/13 00:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2013/03/15 17:29:10 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013/03/13 19:39:43 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/03/08 08:18:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/03/02 17:00:26 | 000,025,504 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2012/03/02 17:00:20 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2011/06/29 15:16:30 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus) SRV - [2010/11/06 08:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Disabled | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012/12/19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/12/19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/11/10 11:46:25 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012/11/06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/05/16 15:27:11 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011/05/16 15:27:11 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011/05/13 13:55:41 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/01/03 17:32:46 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010/12/17 10:57:03 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) DRV:64bit: - [2010/11/25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/19 19:34:00 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2010/11/19 19:34:00 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2010/11/06 08:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010/09/02 07:26:30 | 000,032,936 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iqvw64e.sys -- (NAL) DRV:64bit: - [2010/02/24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009/11/16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:64bit: - [2009/11/16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/06/10 21:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2007/04/11 23:30:04 | 000,043,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTVE.sys -- (IAMTVE) DRV:64bit: - [2007/04/11 23:29:58 | 000,051,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IAMTXPE.sys -- (IAMTXPE) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{28C204E3-FC61-4EAB-8F6D-BE793949C69D}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=drive&q={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{63DC52A0-A1ED-4FEE-A13A-DEFFCE92CAD7}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDND_enDE393 IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\..\SearchScopes\{F097D89E-E315-4C3F-9760-15AA4E34C76E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 08:18:53 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions [2011/07/24 17:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2012/03/25 17:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de [2013/03/24 15:16:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\Firefox\Profiles\iepy89s1.default\extensions [2013/02/14 20:09:53 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Stefan Möller\AppData\Roaming\mozilla\firefox\profiles\iepy89s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/03/08 08:18:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013/03/08 08:18:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/07/31 07:54:25 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/08/30 08:43:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/07/31 07:54:25 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/07/31 07:54:25 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/31 07:54:25 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/31 07:54:25 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013/03/24 15:57:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000..\Run: [Ixakdoifl] C:\Users\Stefan Möller\AppData\Roaming\Acawy\ipazu.exe (Ig}u) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-26567397-2684912437-3830085727-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.191.74.18 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A5E6DDE-142E-4A4E-A349-35C75B1CF2BB}: DhcpNameServer = 62.109.123.197 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EC3C12-8A2E-4718-A015-31D79615CA4A}: DhcpNameServer = 213.191.74.18 192.168.0.1 O18:64bit: - Protocol\Handler\haufereader - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\haufereader - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/03/24 19:28:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013/03/24 19:18:05 | 005,044,071 | R--- | C] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 15:47:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013/03/24 15:47:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013/03/24 15:47:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013/03/24 15:36:43 | 000,000,000 | ---D | C] -- C:\Qoobox [2013/03/24 15:36:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013/03/23 23:50:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\PC Rettung [2013/03/23 22:30:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 20:06:22 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Programs [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2013/03/23 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2013/03/17 09:53:39 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Kega Fusion 3.64 [2013/03/17 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Alex-Kidd [2013/03/14 07:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013/03/14 07:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013/03/14 07:18:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/11 18:58:18 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Desktop\Shop [2013/03/10 00:27:54 | 000,000,000 | ---D | C] -- C:\Download [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2013/03/10 00:27:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\My Videos [2013/03/10 00:25:17 | 000,000,000 | ---D | C] -- C:\AllShare [2013/03/10 00:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [2013/03/10 00:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung [2013/03/10 00:04:23 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\AppData\Local\Downloaded Installations [2013/03/08 08:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/03/06 07:25:28 | 000,000,000 | R--D | C] -- C:\Users\Stefan Möller\Documents\Scanned Documents [2013/03/06 07:25:28 | 000,000,000 | ---D | C] -- C:\Users\Stefan Möller\Documents\Fax [2012/01/15 08:09:47 | 001,080,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Stefan Möller\dbghelp.dll [2012/01/15 08:09:47 | 000,366,080 | ---- | C] (RAD Game Tools, Inc.) -- C:\Users\Stefan Möller\Mss32.dll [2012/01/15 08:09:47 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\Stefan Möller\steam_api.dll [2012/01/15 08:09:46 | 002,410,496 | ---- | C] (Firaxis Games) -- C:\Users\Stefan Möller\CvGameCoreDLLFinal Release.dll ========== Files - Modified Within 30 Days ========== [2013/03/24 19:18:16 | 005,044,071 | R--- | M] (Swearware) -- C:\Users\Stefan Möller\Desktop\ComboFix.exe [2013/03/24 18:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/03/24 18:21:56 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 18:21:56 | 000,009,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/03/24 18:14:39 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2013/03/24 18:14:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/03/24 18:13:30 | 2133,037,055 | -HS- | M] () -- C:\hiberfil.sys [2013/03/24 15:57:18 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013/03/24 15:15:24 | 000,609,993 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/24 11:49:46 | 1460,638,987 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013/03/23 22:35:19 | 000,000,188 | ---- | M] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:33 | 000,377,856 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan Möller\Desktop\OTL.exe [2013/03/23 22:29:05 | 000,050,477 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 20:06:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/03/23 19:31:56 | 000,001,186 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/23 10:43:34 | 000,002,675 | ---- | M] () -- C:\Users\Public\Desktop\QuickSteuer Deluxe 2013.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/12 13:30:38 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/03/12 13:30:38 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013/03/12 13:30:38 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/03/12 13:30:38 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013/03/12 13:30:38 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/03/11 20:24:51 | 000,007,485 | ---- | M] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:44 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/02/27 10:21:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif ========== Files Created - No Company Name ========== [2013/03/24 15:47:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013/03/24 15:47:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013/03/24 15:47:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013/03/24 15:47:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013/03/24 15:47:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013/03/24 15:15:53 | 000,609,993 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\adwcleaner.exe [2013/03/23 22:35:18 | 000,000,188 | ---- | C] () -- C:\Users\Stefan Möller\defogger_reenable [2013/03/23 22:31:51 | 000,377,856 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\gmer_2.1.19155.exe [2013/03/23 22:29:23 | 000,050,477 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Defogger.exe [2013/03/23 19:31:56 | 000,001,186 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\wizard - Verknüpfung.lnk [2013/03/19 19:02:07 | 000,000,903 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\Fusion.exe - Verknüpfung.lnk [2013/03/14 21:44:58 | 000,001,861 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\UseNeXT by Tangysoft.lnk [2013/03/11 20:24:50 | 000,007,485 | ---- | C] () -- C:\Users\Stefan Möller\Desktop\eBay Kleinanzeigen _ Kostenlos. Einfach. Lokal..pdf [2013/03/10 00:27:41 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Samsung AllShare.lnk [2013/01/03 20:02:06 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI [2012/10/11 20:31:31 | 000,010,599 | ---- | C] () -- C:\Users\Stefan Möller\Bünning_elster_2048.pfx [2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012/03/25 14:56:35 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ2414N.DAT [2012/02/27 10:41:52 | 000,202,240 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll [2012/02/27 10:40:44 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll [2012/02/27 10:38:36 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll [2012/02/27 10:38:18 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll [2012/02/15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/15 08:09:47 | 000,900,978 | ---- | C] () -- C:\Users\Stefan Möller\libeay32.dll [2012/01/15 08:09:47 | 000,568,397 | ---- | C] () -- C:\Users\Stefan Möller\Read Me English.pdf [2012/01/15 08:09:47 | 000,563,920 | ---- | C] () -- C:\Users\Stefan Möller\Read Me French.pdf [2012/01/15 08:09:47 | 000,517,549 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Spanish.pdf [2012/01/15 08:09:47 | 000,515,418 | ---- | C] () -- C:\Users\Stefan Möller\Read Me German.pdf [2012/01/15 08:09:47 | 000,454,270 | ---- | C] () -- C:\Users\Stefan Möller\Read Me Italian.pdf [2012/01/15 08:09:47 | 000,232,409 | ---- | C] () -- C:\Users\Stefan Möller\ssleay32.dll [2012/01/15 08:09:47 | 000,231,936 | ---- | C] () -- C:\Users\Stefan Möller\mss32midi.dll [2012/01/15 08:09:47 | 000,151,040 | ---- | C] () -- C:\Users\Stefan Möller\lua51_Win32.dll [2012/01/15 08:09:47 | 000,059,904 | ---- | C] () -- C:\Users\Stefan Möller\zlib1.dll [2012/01/15 08:09:46 | 000,818,688 | ---- | C] () -- C:\Users\Stefan Möller\CvLocalizationWin32Final Release.dll [2012/01/15 08:09:46 | 000,507,904 | ---- | C] () -- C:\Users\Stefan Möller\CvGameDatabaseWin32Final Release.dll [2012/01/15 08:09:46 | 000,241,664 | ---- | C] () -- C:\Users\Stefan Möller\Civ5GDF.dll [2012/01/15 08:09:39 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_it_IT.wmv [2012/01/15 08:09:31 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_fr_FR.wmv [2012/01/15 08:09:25 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_es_ES.wmv [2012/01/15 08:09:17 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_en_US.wmv [2012/01/15 08:09:11 | 096,781,893 | ---- | C] () -- C:\Users\Stefan Möller\Civ5_Opening_Movie_de_DE.wmv [2011/11/03 22:17:12 | 001,881,740 | ---- | C] () -- C:\Users\Stefan Möller\Bewerbung Britta Carstensen.pdf [2011/11/03 22:11:49 | 004,974,710 | ---- | C] () -- C:\Users\Stefan Möller\Zeugnisse Britta Carstensen 11.09..pdf [2011/11/03 22:10:19 | 001,406,786 | ---- | C] () -- C:\Users\Stefan Möller\pdf24 Job Printing.pdf [2011/09/13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/22 18:50:31 | 000,162,409 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\census.cache [2011/08/22 18:50:28 | 000,130,957 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\ars.cache [2011/08/22 18:45:29 | 000,000,036 | ---- | C] () -- C:\Users\Stefan Möller\AppData\Local\housecall.guid.cache [2011/05/16 19:09:46 | 001,526,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/05/15 18:26:20 | 000,001,819 | ---- | C] () -- C:\Users\Stefan Möller\140.jpg [2011/05/15 18:12:22 | 000,005,097 | ---- | C] () -- C:\Users\Stefan Möller\Sony-Sdm-hs75s.jpg [2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2011/11/17 07:41:18 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\@ [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2012/10/13 20:29:45 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2011/11/17 07:41:18 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\L [2013/03/23 18:52:39 | 000,000,000 | -HSD | M] -- C:\Users\Stefan Möller\AppData\Local\{7ff75794-de0d-fbc5-6d19-b7f4c81cb5d4}\U [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Acawy [2012/03/26 16:24:09 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Canon [2012/11/10 11:47:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\DAEMON Tools Lite [2012/02/04 10:58:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\elsterformular [2012/03/25 17:11:32 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Haufe Mediengruppe [2013/03/23 15:02:29 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Inyf [2011/10/27 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Lexware [2011/07/18 12:44:21 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\ProtectDISC [2013/03/10 00:27:45 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Samsung [2011/05/21 10:00:42 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\SoftGrid Client [2011/08/19 12:17:16 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TeamViewer [2011/07/24 17:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TomTom [2011/05/16 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\TP [2011/08/22 19:20:22 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Ubisoft [2012/11/18 11:11:48 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Uniblue [2013/03/23 19:34:55 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\UseNeXT [2013/03/23 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan Möller\AppData\Roaming\Zeyc ========== Purity Check ========== < End of report > |
24.03.2013, 20:08 | #15 |
/// TB-Ausbilder | PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! Wieder nicht.. Ich hab das Gefühl, der tut sich schwer mit dem Umlaut.. Lade nochmals das angehängte CFScript.txt herunter, aber speichere es dieses Mal direkt nach C:\. Starte danach Combofix folgendermassen (und folge ansonsten derselben Anleitung wie zuvor): Drücke die + R Taste, kopiere Folgendes in das Ausführen Fenster und drücke OK. Code:
ATTFilter Combofix "C:\CFScript.txt"
__________________ cheers, Leo |
Themen zu PWS:WIn32/ZBOT.gen!aj unter Windows 7 / MSE lässt sich nicht entfernen! |
eingefangen, entdeck, entdeckt, entferne, entfernen, erfolg, erneut, folge, folgender, fordert, forum, freue, gefangen, hohe, hohen, lässt sich nicht entfernen, malware, neustart, offen, pws:win32/zbot.gen!aj, schleife, unterstützung, virus, win, win32/zbot.gen!aj, windows, windows 7, würde |