|
Log-Analyse und Auswertung: BKA Trojaner weißer DesktopWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.04.2013, 01:44 | #1 |
| BKA Trojaner weißer Desktop Hallo, leider bin ich dem BKA Trojaner auf den Leim gegangen. Meine PC-Fähigkeiten sind überschaubar, daher bitte ich bei fehlender fachlicher Ausdrucksweise um Nachsicht. Ich habe nach dem Anmelden bzw. der Passwort eingabe einen weißen Desktop und kann kein Taskmanager oder sonstiges aufrufen. Ich habe bisher 2 recherchierte Ansätze zur Behebung des Problems versucht. 1. die HitmanPro-Software, 2. die OTL.exe, beide habe ich versucht durch die Eingabeaufforderung zu starten. Leider ohne durschlagenden Erfolg. Bei 1. kann ich den Scan, aufgrund der fehlenden Internetverbindung, nicht starten. Bei 2. erscheint nach meiner Eingabe: "Das zum Unterstützen des Abbildtyps erforderliche Subsystem ist nicht vorhanden." Vielleicht liegt der Fehler ja bei mir und es besteht Grund zur Hoffnung. Hoffentlich findet sich jemand der mir einen Tipp geben kann. Schoneinmal vorab besten Dank für eure/deine Zeit. Gruß Ben |
13.04.2013, 02:00 | #2 |
/// TB-Ausbilder | BKA Trojaner weißer Desktop Hi Ben,
__________________welches Betriebssystem ist das? XP, Vista, 7? Ist es ein 32-bit oder 64-bit System?
__________________ |
13.04.2013, 09:57 | #3 | |
| BKA Trojaner weißer DesktopZitat:
Es handelt sich um Windows 7 und müsste 64-bit System sein, wobei ich mir nicht 100% sicher bin. |
13.04.2013, 12:30 | #4 | |
/// TB-Ausbilder | BKA Trojaner weißer DesktopZitat:
Schritt 1 Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere diese auf einen USB Stick (nicht in einen Unterordner!). Schliesse den USB Stick an den infizierten Rechner an. Du musst das System nun in die System Reparatur Option booten: Variante 1 - Über den Boot Manager Wenn du jetzt in den Reparaturoptionen bist, wähle Eingabeaufforderung.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
13.04.2013, 13:13 | #5 |
| BKA Trojaner weißer Desktop Ok, hier Inhalt. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2013 Ran by SYSTEM at 13-04-2013 14:02:09 Running from G:\ Windows 7 Home Premium (X64) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [508472 2009-10-09] (Conexant Systems, Inc.) HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [200704 2009-11-20] () HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-21] (Alps Electric Co., Ltd.) HKLM\...\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated) HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-11-18] (Egis Technology Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k [262912 2009-08-20] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED [588648 2009-07-24] (Symantec Corporation) HKLM-x32\...\Run: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe" [600688 2009-12-03] (Chicony) HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-01] (Dritek System Inc.) HKLM-x32\...\Run: [RemoteControl8] "c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [50472 2009-04-15] (CyberLink Corp.) HKLM-x32\...\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [200488 2009-10-22] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" 196609 [401192 2009-10-22] (Egis Technology Inc.) HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Launch SilverCrest GML807] C:\Program Files (x86)\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe [862208 2010-09-02] (Siliten) HKLM-x32\...\Run: [USBestCR] C:\Program Files (x86)\USIM Editor\iconcs2189692.exe RunFromReg [7041024 2010-07-02] () HKLM-x32\...\Run: [ClickPotatoLiteSA] "C:\Program Files (x86)\ClickPotatoLite\bin\10.0.659.0\ClickPotatoLiteSA.exe" [742192 2011-01-26] (Pinball Corporation.) HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1219248 2013-04-11] () HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4394032 2013-03-13] (AVG Technologies CZ, s.r.o.) HKU\Benjasmin\...\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [33120 2009-11-15] (Alcohol Soft Development Team) HKU\Benjasmin\...\Run: [Facebook Update] "C:\Users\Benjasmin\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-15] (Facebook Inc.) HKU\Benjasmin\...\Winlogon: [Shell] explorer.exe,C:\Users\Benjasmin\AppData\Roaming\skype.dat [94208 2011-11-16] () HKU\Default\...\RunOnce: [ScrSav] C:\Windows\Screensavers\PackardBell\run_PackardBel [x] HKU\Default User\...\RunOnce: [ScrSav] C:\Windows\Screensavers\PackardBell\run_PackardBel [x] HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$5dea2983d24ea7233ddf5eb48bd3a915\n. ATTENTION! ====> ZeroAccess Tcpip\..\Interfaces\{A9BA50EF-97C8-4C30-AF96-1E571E0DB1CE}: [NameServer]208.67.222.222 208.67.220.220 Startup: C:\ProgramData\Start Menu\Programs\Startup\DL-10.lnk ShortcutTarget: DL-10.lnk -> C:\Program Files (x86)\DC Software\DL10XP.exe () Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\ProgramData\Start Menu\Programs\Startup\Philips Device Manager.lnk ShortcutTarget: Philips Device Manager.lnk -> C:\Philips\SA32xx Device Manager\SA32xx_DeviceManager.exe (Philips) Startup: C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0.34811057727011485.exe.lnk ShortcutTarget: 0.34811057727011485.exe.lnk -> C:\Users\BENJAS~1\AppData\Local\Temp\0.34811057727011485.exe (No File) Startup: C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk ShortcutTarget: LimeWire On Startup.lnk -> C:\Program Files (x86)\LimeWire\LimeWire.exe (Lime Wire, LLC) Startup: C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Services (Whitelisted) =================== 2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe" [4937264 2013-02-27] (AVG Technologies CZ, s.r.o.) 2 avgwd; "C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe" [282624 2013-02-18] (AVG Technologies CZ, s.r.o.) 3 DfSdkS; "C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe" [544768 2009-08-24] (mst software GmbH, Germany) 2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [844320 2009-09-30] (Acer Incorporated) 2 FreemakeVideoCapture; "C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe" [9216 2013-02-25] (Ellora Assets Corp.) 2 Greg_Service; C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [1150496 2009-08-28] (Acer Incorporated) 2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [305448 2009-11-18] (Egis Technology Inc.) 2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [62720 2009-08-20] (NewTech Infosystems, Inc.) 2 OberonGameConsoleService; "C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe" [44312 2009-08-28] () 2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2010-01-26] () 2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [240160 2009-07-03] (Acer) 2 vToolbarUpdater15.0.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe [990896 2013-04-11] () 2 AfaService; C:\Windows\system32\afasrv64.exe [x] 2 Application Updater; "C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe" [x] 3 AVG Security Toolbar Service; C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe [x] ==================== Drivers (Whitelisted) ===================== 1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-02-26] (AVG Technologies CZ, s.r.o.) 0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [71480 2013-02-07] (AVG Technologies CZ, s.r.o.) 1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [206136 2013-02-07] (AVG Technologies CZ, s.r.o.) 0 Avgloga; C:\Windows\System32\Drivers\Avgloga.sys [311096 2013-02-07] (AVG Technologies CZ, s.r.o.) 0 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [116536 2013-02-07] (AVG Technologies CZ, s.r.o.) 0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [45880 2013-02-07] (AVG Technologies CZ, s.r.o.) 1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [239416 2013-02-13] (AVG Technologies CZ, s.r.o.) 1 avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-04-11] (AVG Technologies) 3 InputFilter_Hid_FlexDef2c; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2c.sys [19968 2010-08-06] (Siliten) 3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [59392 2010-04-09] (Generic USB smartcard reader) 2 npf; C:\Windows\System32\Drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-03-08] (Duplex Secure Ltd.) 3 SWDUMon; C:\Windows\System32\Drivers\SWDUMon.sys [15672 2013-04-13] () 3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [16896 2007-07-11] (LG Electronics Inc.) 3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2007-07-11] (LG Electronics Inc.) 3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [29696 2007-07-11] (LG Electronics Inc.) 3 RtsUIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x] 0 sr; [x] 3 USBCCID; C:\Windows\System32\DRIVERS\RtsUCcid.sys [x] ==================== NetSvcs (Whitelisted) ==================== ==================== One Month Created Files and Folders ======== 2013-04-13 14:01 - 2013-04-13 14:01 - 00000000 ____D C:\FRST 2013-04-12 14:08 - 2013-04-13 03:59 - 00000004 ____A C:\Users\Benjasmin\AppData\Roaming\skype.ini 2013-04-12 08:49 - 2013-04-12 08:49 - 00657030 ____N C:\Windows\Minidump\041213-56612-01.dmp 2013-04-12 00:40 - 2013-04-12 00:40 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\LumacDaemon 2013-04-12 00:40 - 2013-04-12 00:40 - 00000000 ____D C:\Users\Benjasmin\AppData\Local\Firstload 2013-04-12 00:39 - 2013-04-12 00:39 - 00000000 ____D C:\Program Files (x86)\Lumac 2013-04-11 22:40 - 2013-04-11 22:40 - 00000953 ____A C:\Users\Public\Desktop\AVG 2013.lnk 2013-04-11 22:40 - 2013-04-11 22:40 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-04-10 13:27 - 2013-04-12 11:40 - 00000000 ____D C:\Users\Benjasmin\dwhelper 2013-04-10 13:16 - 2013-04-10 13:16 - 01291144 ____A (Conduit) C:\Users\Benjasmin\Downloads\FileConverter_1.3(1).exe 2013-04-10 13:13 - 2013-04-10 13:13 - 01291144 ____A (Conduit) C:\Users\Benjasmin\Downloads\FileConverter_1.3.exe 2013-04-10 13:04 - 2013-04-10 13:04 - 00767041 ____A C:\Users\Benjasmin\Downloads\video_downloadhelper-4.9.14-fx_sm.zip 2013-04-10 08:46 - 2013-04-10 08:46 - 00000791 ____A C:\Users\Benjasmin\Documents\ant2.txt 2013-04-09 03:31 - 2013-04-13 03:57 - 00002128 ____A C:\Windows\setupact.log 2013-04-09 03:31 - 2013-04-09 03:31 - 00000000 ____A C:\Windows\setuperr.log 2013-04-07 04:42 - 2013-04-07 04:42 - 00391689 ____N C:\Windows\Minidump\040713-46067-01.dmp 2013-04-01 00:35 - 2013-04-01 00:36 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Umox 2013-04-01 00:35 - 2013-04-01 00:36 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Apoz 2013-04-01 00:35 - 2013-04-01 00:35 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Ocbyo 2013-03-27 12:57 - 2013-03-28 10:04 - 00000670 ____A C:\Users\Benjasmin\Documents\ant.txt 2013-03-26 14:43 - 2013-03-26 14:43 - 00371816 ____N C:\Windows\Minidump\032613-46862-01.dmp 2013-03-25 23:49 - 2013-04-12 08:38 - 00027054 ____A C:\Users\Benjasmin\Documents\Statistik.xlsx 2013-03-25 23:49 - 2013-03-25 23:49 - 00000165 ___AH C:\Users\Benjasmin\Documents\~$ Statistik.xlsx 2013-03-19 16:02 - 2013-03-19 16:07 - 00450664 ____N C:\Windows\Minidump\032013-49686-01.dmp 2013-03-16 17:46 - 2013-03-16 17:46 - 00467187 ____N C:\Windows\Minidump\031713-55115-01.dmp 2013-03-15 10:06 - 2013-03-18 10:51 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\WinHost ==================== One Month Modified Files and Folders ======= 2013-04-13 14:01 - 2013-04-13 14:01 - 00000000 ____D C:\FRST 2013-04-13 03:59 - 2013-04-12 14:08 - 00000004 ____A C:\Users\Benjasmin\AppData\Roaming\skype.ini 2013-04-13 03:58 - 2011-12-15 23:49 - 00015672 ____A C:\Windows\System32\Drivers\SWDUMon.sys 2013-04-13 03:57 - 2013-04-09 03:31 - 00002128 ____A C:\Windows\setupact.log 2013-04-13 03:57 - 2011-12-15 23:49 - 00000418 ____A C:\Windows\Tasks\SlimDrivers Startup.job 2013-04-13 03:57 - 2010-06-06 06:04 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-04-13 03:57 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-12 14:25 - 2010-06-27 07:06 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\LimeWire 2013-04-12 14:17 - 2012-03-24 05:14 - 01348161 ____A C:\Windows\WindowsUpdate.log 2013-04-12 14:17 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-12 14:17 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-12 13:39 - 2010-06-06 06:04 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-04-12 11:40 - 2013-04-10 13:27 - 00000000 ____D C:\Users\Benjasmin\dwhelper 2013-04-12 11:17 - 2010-11-16 02:17 - 00000000 ____D C:\ProgramData\MFAData 2013-04-12 11:14 - 2011-10-27 23:04 - 00001154 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000UA.job 2013-04-12 10:15 - 2011-04-10 10:53 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\vlc 2013-04-12 10:07 - 2010-04-21 09:08 - 00000000 ____D C:\Windows\Minidump 2013-04-12 08:49 - 2013-04-12 08:49 - 00657030 ____N C:\Windows\Minidump\041213-56612-01.dmp 2013-04-12 08:38 - 2013-03-25 23:49 - 00027054 ____A C:\Users\Benjasmin\Documents\Statistik.xlsx 2013-04-12 08:14 - 2011-10-27 23:04 - 00001132 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000Core.job 2013-04-12 06:48 - 2012-04-01 09:26 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\UseNeXT 2013-04-12 06:46 - 2011-04-09 06:58 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Firstload 2013-04-12 00:40 - 2013-04-12 00:40 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\LumacDaemon 2013-04-12 00:40 - 2013-04-12 00:40 - 00000000 ____D C:\Users\Benjasmin\AppData\Local\Firstload 2013-04-12 00:39 - 2013-04-12 00:39 - 00000000 ____D C:\Program Files (x86)\Lumac 2013-04-12 00:39 - 2009-10-29 21:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-04-12 00:18 - 2011-04-09 06:58 - 00000000 ____D C:\Users\Benjasmin\Documents\Firstload 2013-04-12 00:18 - 2011-04-09 06:58 - 00000000 ____D C:\Program Files (x86)\Firstload 2013-04-11 22:40 - 2013-04-11 22:40 - 00000953 ____A C:\Users\Public\Desktop\AVG 2013.lnk 2013-04-11 22:40 - 2013-04-11 22:40 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-04-11 22:40 - 2012-07-27 03:08 - 00039768 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys 2013-04-10 13:27 - 2010-01-22 08:17 - 00000000 ____D C:\users\Benjasmin 2013-04-10 13:16 - 2013-04-10 13:16 - 01291144 ____A (Conduit) C:\Users\Benjasmin\Downloads\FileConverter_1.3(1).exe 2013-04-10 13:13 - 2013-04-10 13:13 - 01291144 ____A (Conduit) C:\Users\Benjasmin\Downloads\FileConverter_1.3.exe 2013-04-10 13:04 - 2013-04-10 13:04 - 00767041 ____A C:\Users\Benjasmin\Downloads\video_downloadhelper-4.9.14-fx_sm.zip 2013-04-10 11:45 - 2010-02-08 10:45 - 00030922 ____A C:\Users\Benjasmin\AppData\Roaming\wklnhst.dat 2013-04-10 10:34 - 2013-03-12 07:23 - 00000000 ____D C:\Users\Benjasmin\Documents\Freemake 2013-04-10 08:46 - 2013-04-10 08:46 - 00000791 ____A C:\Users\Benjasmin\Documents\ant2.txt 2013-04-09 08:24 - 2012-08-23 05:06 - 00000000 ____D C:\Users\Benjasmin\Desktop\Kamera 2013-04-09 08:24 - 2009-12-16 02:45 - 03867774 ____A C:\Windows\System32\perfh007.dat 2013-04-09 08:24 - 2009-12-16 02:45 - 01158962 ____A C:\Windows\System32\perfc007.dat 2013-04-09 08:24 - 2009-07-13 21:13 - 00005390 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-09 03:31 - 2013-04-09 03:31 - 00000000 ____A C:\Windows\setuperr.log 2013-04-09 00:24 - 2010-04-03 02:16 - 03298304 __ASH C:\Users\Benjasmin\Desktop\Thumbs.db 2013-04-08 13:45 - 2011-11-22 09:11 - 00000000 ____D C:\Users\Benjasmin\Desktop\Wirtschaftsakademie 2013-04-07 04:42 - 2013-04-07 04:42 - 00391689 ____N C:\Windows\Minidump\040713-46067-01.dmp 2013-04-01 00:36 - 2013-04-01 00:35 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Umox 2013-04-01 00:36 - 2013-04-01 00:35 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Apoz 2013-04-01 00:35 - 2013-04-01 00:35 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\Ocbyo 2013-03-28 10:04 - 2013-03-27 12:57 - 00000670 ____A C:\Users\Benjasmin\Documents\ant.txt 2013-03-26 14:43 - 2013-03-26 14:43 - 00371816 ____N C:\Windows\Minidump\032613-46862-01.dmp 2013-03-25 23:49 - 2013-03-25 23:49 - 00000165 ___AH C:\Users\Benjasmin\Documents\~$Statistik.xlsx 2013-03-24 14:57 - 2011-11-11 06:09 - 00000000 ____D C:\Users\Benjasmin\Documents\Digital Camera 2013-03-19 16:07 - 2013-03-19 16:02 - 00450664 ____N C:\Windows\Minidump\032013-49686-01.dmp 2013-03-19 07:04 - 2009-07-13 21:08 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-03-18 13:00 - 2012-06-14 11:26 - 00000000 ____D C:\Program Files (x86)\KaloMa 2013-03-18 10:51 - 2013-03-15 10:06 - 00000000 ____D C:\Users\Benjasmin\AppData\Roaming\WinHost 2013-03-16 17:46 - 2013-03-16 17:46 - 00467187 ____N C:\Windows\Minidump\031713-55115-01.dmp 2013-03-15 17:41 - 2012-06-17 01:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox ZeroAccess: C:\$Recycle.Bin\S-1-5-21-2259796694-2473700428-155409205-1000\$5dea2983d24ea7233ddf5eb48bd3a915 ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$5dea2983d24ea7233ddf5eb48bd3a915 ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 4090.93 MB Available physical RAM: 3378.91 MB Total Pagefile: 4089.08 MB Available Pagefile: 3369.99 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ==================== Partitions ============================= 1 Drive c: (Packard Bell) (Fixed) (Total:453.94 GB) (Free:262.86 GB) NTFS 2 Drive e: (PQSERVICE) (Fixed) (Total:11.72 GB) (Free:2.29 GB) NTFS 4 Drive g: (HITMANPRO) (Removable) (Total:0.96 GB) (Free:0.94 GB) FAT32 5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 465 GB 0 B Datentr„ger 1 Online 995 MB 0 B Partitions of Disk 0: =============== Datentr„ger-ID: 1A171A17 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Wiederherstellun 11 GB 1024 KB Partition 2 Prim„r 100 MB 11 GB Partition 3 Prim„r 453 GB 11 GB ================================================================================== Disk: 0 Partition 1 Typ : 27 Versteckt: Ja Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 E PQSERVICE NTFS Partition 11 GB Fehlerfre Versteck ========================================================= Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Fehlerfre ========================================================= Disk: 0 Partition 3 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C Packard Bel NTFS Partition 453 GB Fehlerfre ========================================================= Partitions of Disk 1: =============== Datentr„ger-ID: D7CF5A1B Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 988 MB 31 KB ================================================================================== Disk: 1 Partition 1 Typ : 0B Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 G HITMANPRO FAT32 Wechselmed 988 MB Fehlerfre ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: 1A171A17 Partition 1: ========= Hex: 0020210027FEFFFF0008000000007701 Active: NO Type: 27 Size: 12 GB Partition 2: ========= Hex: 80FEFFFF07FEFFFF0008770100200300 Active: YES Type: 07 (NTFS) Size: 100 MB Partition 3: ========= Hex: 00FEFFFF07FEFFFF00287A013030BE38 Active: NO Type: 07 (NTFS) Size: 454 GB ============================== Partitions of Disk 1: =============== Disk ID: D7CF5A1B Partition 1: ========= Hex: 800101000BFE3F7D3F000000FEE21E00 Active: YES Type: 0B Size: 988 MB Last Boot: 2013-04-09 08:59 ==================== End Of Log ============================= Geändert von Brock88 (13.04.2013 um 13:19 Uhr) |
13.04.2013, 13:50 | #6 |
/// TB-Ausbilder | BKA Trojaner weißer Desktop Also: Schritt 1 entsperrt den Rechner, so dass du danach wieder normal nach Windows starten und die weiteren Schritte dort ausführen kannst. Wir sollten auch unbedingt noch weitermachen, denn da ist noch anderes drauf, unter anderem das ZeroAccess-Rootkit. Schritt 1 Drücke auf einem Zweitrechner bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument: Code:
ATTFilter HKU\Benjasmin\...\Winlogon: [Shell] explorer.exe,C:\Users\Benjasmin\AppData\Roaming\skype.dat [94208 2011-11-16] () C:\Users\Benjasmin\AppData\Roaming\skype.dat C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0.34811057727011485.exe.lnk C:\Users\BENJAS~1\AppData\Local\Temp\0.34811057727011485.exe 2013-04-12 14:08 - 2013-04-13 03:59 - 00000004 ____A C:\Users\Benjasmin\AppData\Roaming\skype.ini
Wieder im normalen Modus: Schritt 2 Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
Schritt 3 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 4 Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ --> BKA Trojaner weißer Desktop |
13.04.2013, 18:15 | #7 |
| BKA Trojaner weißer Desktop Ich bin wirklich begeistert, ich kann meinen PC wieder normal starten. Danke schoneinmal für diese Hilfe! Leider konnte Schritt 3 nicht beenden. Gmer hat meinen PC ca. 1 Stunde gescannt nach dem Save drücken gab es ein Problem beim "speichern unter" Menü ich weiß nicht ob es am aktuellen Virus liegt oder allgemein an meinem PC denn das passiert öfter einmal wenn man speichern will. Hier die original Meldung "gmer.exe funktioniert nicht mehr Das Programm wird aufgrund eines Problems nicht richtig ausgeführt. Das Programm wird geschlossen und Sie werden benachrichtigt, wenn eine Lösung verfügbar ist." Soll ich das Programm nocheinmal durchlaufen lassen? Hier noch der Inhalt der Fixlog Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-04-2013 Ran by SYSTEM at 2013-04-13 17:26:42 Run:1 Running from G:\ ============================================== HKEY_USERS\Benjasmin\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell Value deleted successfully. C:\Users\Benjasmin\AppData\Roaming\skype.dat moved successfully. C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0.34811057727011485.exe.lnk moved successfully. C:\Users\BENJAS~1\AppData\Local\Temp\0.34811057727011485.exe not found. C:\Users\Benjasmin\AppData\Roaming\skype.ini moved successfully. ==== End of Fixlog ==== |
13.04.2013, 18:38 | #8 |
/// TB-Ausbilder | BKA Trojaner weißer Desktop Hi, Gmer kann schon mal rumzicken, das ist nicht aussergewöhnlich. Überspring das und mach mit OTL (Schritt 4) weiter.
__________________ cheers, Leo |
14.04.2013, 18:40 | #9 |
| BKA Trojaner weißer Desktop Hallo Leo, ich habe GMER nocheinmal ein 2. mal versucht aber mit dem selben Problem. Mal rein interessehalber, was machen diese Programme eigentlich? Suchen diese speziell nach diesem Trojaner oder allgemein nach jeglicher Schadsoftware? Hier die Logs von OTL OTL.txtOTL Logfile: Code:
ATTFilter OTL logfile created on: 14.04.2013 19:10:02 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Benjasmin\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 62,45% Memory free 7,99 Gb Paging File | 6,36 Gb Available in Paging File | 79,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 453,94 Gb Total Space | 262,35 Gb Free Space | 57,79% Space Free | Partition Type: NTFS Drive F: | 985,45 Mb Total Space | 982,78 Mb Free Space | 99,73% Space Free | Partition Type: FAT32 Computer Name: BENJAMIN-PC | User Name: Benjasmin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.13 01:28:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Benjasmin\Desktop\OTL.exe PRC - [2013.04.12 08:40:19 | 001,219,248 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe PRC - [2013.04.12 08:40:19 | 000,990,896 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe PRC - [2013.03.13 17:15:00 | 004,394,032 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe PRC - [2013.02.27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe PRC - [2013.02.25 13:37:30 | 000,009,216 | ---- | M] (Ellora Assets Corp.) -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe PRC - [2013.02.19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe PRC - [2011.05.10 11:44:36 | 026,285,920 | ---- | M] (SlimWare Utilities, Inc.) -- C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe PRC - [2010.09.03 00:42:56 | 000,862,208 | ---- | M] (Siliten) -- C:\Program Files (x86)\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe PRC - [2010.07.02 12:07:02 | 007,041,024 | ---- | M] () -- C:\Program Files (x86)\USIM Editor\iconcs2189692.exe PRC - [2010.01.26 22:58:06 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2009.12.03 15:32:54 | 000,600,688 | ---- | M] (Chicony) -- C:\Program Files (x86)\Video Web Camera\traybar.exe PRC - [2009.11.21 01:34:06 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe PRC - [2009.11.18 18:30:32 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe PRC - [2009.11.18 18:30:14 | 000,305,448 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe PRC - [2009.11.02 01:39:48 | 001,094,736 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe PRC - [2009.10.22 19:35:08 | 000,401,192 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe PRC - [2009.10.22 19:34:56 | 000,200,488 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe PRC - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe PRC - [2009.08.25 19:38:06 | 000,935,208 | ---- | M] (Nero AG) -- c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe PRC - [2009.08.21 03:26:02 | 000,262,912 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe PRC - [2009.08.21 03:25:50 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe PRC - [2009.07.04 03:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe PRC - [2009.06.05 05:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe PRC - [2009.04.16 00:52:06 | 000,091,432 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe PRC - [2009.03.17 10:49:00 | 000,380,928 | ---- | M] () -- C:\Program Files (x86)\DC Software\DL10XP.exe PRC - [2008.12.08 16:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe ========== Modules (No Company Name) ========== MOD - [2013.04.12 08:40:19 | 001,219,248 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe MOD - [2013.04.12 08:40:19 | 000,157,360 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\SiteSafety.dll MOD - [2010.08.30 09:24:38 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\SilverCrest GML807 Driver\UniFunc.dll MOD - [2010.07.02 12:07:02 | 007,041,024 | ---- | M] () -- C:\Program Files (x86)\USIM Editor\iconcs2189692.exe MOD - [2009.11.21 01:34:06 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe MOD - [2009.03.17 10:49:00 | 000,380,928 | ---- | M] () -- C:\Program Files (x86)\DC Software\DL10XP.exe MOD - [2009.02.03 03:33:56 | 000,460,199 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll MOD - [2008.03.31 09:07:04 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\DC Software\imghdlr.dll MOD - [2004.05.11 11:38:20 | 000,061,952 | ---- | M] () -- C:\Program Files (x86)\DC Software\zlib.dll ========== Services (SafeList) ========== SRV - [2013.04.12 08:40:19 | 000,990,896 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe -- (vToolbarUpdater15.0.0) SRV - [2013.02.27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) SRV - [2013.02.25 13:37:30 | 000,009,216 | ---- | M] (Ellora Assets Corp.) [Auto | Running] -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe -- (FreemakeVideoCapture) SRV - [2013.02.19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2012.09.06 03:25:06 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.01.26 22:58:06 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2009.12.16 04:18:35 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009.11.18 18:30:14 | 000,305,448 | ---- | M] (Egis Technology Inc.) [Auto | Running] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe -- (MWLService) SRV - [2009.09.30 15:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc) SRV - [2009.08.29 03:05:56 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService) SRV - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe -- (Greg_Service) SRV - [2009.08.25 19:38:06 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2009.08.24 22:16:12 | 000,544,768 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS) SRV - [2009.08.21 03:25:50 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc) SRV - [2009.08.18 13:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2009.07.04 03:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) SRV - [2008.12.08 16:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.04.14 19:04:17 | 000,015,672 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon) DRV:64bit: - [2013.04.12 08:40:19 | 000,039,768 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp) DRV:64bit: - [2013.02.26 23:40:46 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver) DRV:64bit: - [2013.02.14 03:52:46 | 000,239,416 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia) DRV:64bit: - [2013.02.08 04:37:56 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64) DRV:64bit: - [2013.02.08 04:37:54 | 000,311,096 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga) DRV:64bit: - [2013.02.08 04:37:50 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA) DRV:64bit: - [2013.02.08 04:37:42 | 000,206,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64) DRV:64bit: - [2013.02.08 04:37:40 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64) DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011.02.11 23:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf) DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.08.06 17:54:56 | 000,019,968 | ---- | M] (Siliten) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\InputFilter_FlexDef2c.sys -- (InputFilter_Hid_FlexDef2c) DRV:64bit: - [2010.04.09 12:24:48 | 000,059,392 | ---- | M] (Generic USB smartcard reader) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MHIKEY10x64.sys -- (MHIKEY10) DRV:64bit: - [2010.03.08 22:20:00 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2009.09.15 22:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) DRV:64bit: - [2009.08.11 22:59:50 | 000,686,080 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.20 14:35:00 | 000,317,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) DRV:64bit: - [2009.06.10 23:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92) DRV:64bit: - [2009.06.10 23:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac) DRV:64bit: - [2009.06.10 23:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA) DRV:64bit: - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009.06.10 22:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.06.05 04:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2009.06.05 02:46:50 | 000,216,064 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:64bit: - [2009.06.02 19:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk) DRV:64bit: - [2009.06.02 19:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter) DRV:64bit: - [2009.06.02 19:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ) DRV:64bit: - [2009.05.25 05:57:42 | 000,243,760 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService) DRV:64bit: - [2009.05.06 02:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr) DRV:64bit: - [2009.05.06 02:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper) DRV:64bit: - [2009.04.09 13:38:26 | 000,167,424 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnet.sys -- (ZTEusbnet) DRV:64bit: - [2009.04.09 13:38:26 | 000,150,784 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\zteusbvoice.sys -- (ZTEusbvoice) DRV:64bit: - [2009.04.09 13:38:26 | 000,150,784 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV:64bit: - [2009.04.09 13:38:26 | 000,150,656 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV:64bit: - [2009.04.09 13:38:26 | 000,150,656 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV:64bit: - [2009.04.09 13:38:26 | 000,011,776 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter.sys -- (massfilter) DRV:64bit: - [2008.06.16 04:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2007.07.11 16:57:08 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag) DRV:64bit: - [2007.07.11 12:07:36 | 000,029,696 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem) DRV:64bit: - [2007.07.11 12:04:40 | 000,016,896 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus) DRV:64bit: - [2000.01.01 02:00:00 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = iGoogle Redirect IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = iGoogle Redirect IE - HKLM\..\URLSearchHook: {38542454-dfb6-44f5-b052-d4e071a3d073} - C:\Program Files (x86)\Elf_1.12\tbElf_.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = iGoogle [Binary data over 200 bytes] IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = DOLLARKURS | Euro Dollar Wechselkurs | EUR/USD | aktueller Kurs | finanzen.net IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\URLSearchHook: {38542454-dfb6-44f5-b052-d4e071a3d073} - C:\Program Files (x86)\Elf_1.12\tbElf_.dll (Conduit Ltd.) IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (Conduit Ltd.) IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\InprocServer32 File not found IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{20E025A1-E275-4670-8A5C-F107B713E40E}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms} IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW_deDE382 IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={EDBC5B61-8A46-407D-94CD-BB795BD324EC}&mid=ec21a782867ed2dbe52b8241d667db23-beeb2a70b4f1224f5e57960d02f971196e90034a&lang=de&ds=AVG&pr=fr&d=2013-04-12 08:40:31&v=15.0.0.2&pid=avg&sg=&sap=dsp&q={searchTerms} IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = hxxp://www.daemon-search.com/search?q={searchTerms} IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 IE - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: avg@toolbar:14.2.0.1 FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.14 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Benjasmin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\ClickPotatoLite@ClickPotatoLite.com: C:\Program Files (x86)\ClickPotatoLite\bin\10.0.659.0\firefox\extensions [2011.02.06 20:55:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.05.04 21:47:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013.02.19 23:23:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\fmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ [2013.03.12 17:23:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\ytfmdownloader@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ [2013.03.12 17:23:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.19 10:17:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.05.04 21:47:35 | 000,000,000 | ---D | M] [2010.06.27 17:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjasmin\AppData\Roaming\mozilla\Extensions [2010.06.27 17:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjasmin\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org [2013.04.10 23:20:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjasmin\AppData\Roaming\mozilla\Firefox\Profiles\d3d3hsr5.default\extensions [2013.04.10 23:20:38 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Benjasmin\AppData\Roaming\mozilla\Firefox\Profiles\d3d3hsr5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012.09.19 10:17:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2013.02.19 23:23:04 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\FIREFOXEXT\14.2.0.1 [2012.09.06 03:26:03 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.09.06 04:07:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.02.19 23:23:06 | 000,003,714 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml [2012.09.06 04:07:37 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.09.06 04:07:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.09.06 04:07:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.09.06 04:07:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.09.06 04:07:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.03.15 19:48:50 | 000,001,159 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 CD and DVD Burning Software - Alcohol Soft copy and virtual drive software Alcohol 120 and 52% Free Edition O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com O1 - Hosts: 127.0.0.1 CD and DVD Burning Software - Alcohol Soft copy and virtual drive software Alcohol 120 and 52% Free Edition O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com O1 - Hosts: 127.0.0.1 CD and DVD Burning Software - Alcohol Soft copy and virtual drive software Alcohol 120 and 52% Free Edition O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com O1 - Hosts: 127.0.0.1 CD and DVD Burning Software - Alcohol Soft copy and virtual drive software Alcohol 120 and 52% Free Edition O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com O1 - Hosts: 127.0.0.1 CD and DVD Burning Software - Alcohol Soft copy and virtual drive software Alcohol 120 and 52% Free Edition O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Elf 1.12 Toolbar) - {38542454-dfb6-44f5-b052-d4e071a3d073} - C:\Program Files (x86)\Elf_1.12\tbElf_.dll (Conduit Ltd.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll () O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (Conduit Ltd.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbarIE.dll File not found O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (Elf 1.12 Toolbar) - {38542454-dfb6-44f5-b052-d4e071a3d073} - C:\Program Files (x86)\Elf_1.12\tbElf_.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbarIE.dll File not found O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:64bit: - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3:64bit: - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (Elf 1.12 Toolbar) - {38542454-DFB6-44F5-B052-D4E071A3D073} - C:\Program Files (x86)\Elf_1.12\tbElf_.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (MyAshampoo Toolbar) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated) O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.) O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.) O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe () O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.) O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony) O4 - HKLM..\Run: [ClickPotatoLiteSA] C:\Program Files (x86)\ClickPotatoLite\bin\10.0.659.0\ClickPotatoLiteSA.exe (Pinball Corporation.) O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.) O4 - HKLM..\Run: [Launch SilverCrest GML807] C:\Program Files (x86)\SilverCrest GML807 Driver\MouClient_FD2_1001RL.exe (Siliten) O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKLM..\Run: [PDVD8LanguageShortcut] c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.) O4 - HKLM..\Run: [RemoteControl8] c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.) O4 - HKLM..\Run: [USBestCR] C:\Program Files (x86)\USIM Editor\iconcs2189692.exe () O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000..\Run: [Facebook Update] C:\Users\Benjasmin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files (x86)\LimeWire\LimeWire.exe (Lime Wire, LLC) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0 O7 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0 O7 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0 O7 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0 O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Free YouTube Download - C:\Users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: ClickPotato - {B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} - C:\Program Files (x86)\ClickPotatoLite\bin\10.0.659.0\ClickPotatoLiteSABHO.dll File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..Trusted Domains: fritz.box ([]* in Local intranet) O15 - HKU\S-1-5-21-2259796694-2473700428-155409205-1000\..Trusted Ranges: Range1 ([*] in Local intranet) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9303A6B-F7AB-451D-9EE9-52E0EA50BBF0}: DhcpNameServer = 139.7.30.125 139.7.30.126 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9BA50EF-97C8-4C30-AF96-1E571E0DB1CE}: NameServer = 208.67.222.222 208.67.220.220 O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.0.0\ViProtocol.dll () O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{777a1fa2-af9b-11df-8ce9-001e64287b0c}\Shell - "" = AutoRun O33 - MountPoints2\{777a1fa2-af9b-11df-8ce9-001e64287b0c}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{777a1fab-af9b-11df-8ce9-001e64287b0c}\Shell - "" = AutoRun O33 - MountPoints2\{777a1fab-af9b-11df-8ce9-001e64287b0c}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{7cc0eb7d-305a-11df-a387-001e64287b0c}\Shell - "" = AutoRun O33 - MountPoints2\{7cc0eb7d-305a-11df-a387-001e64287b0c}\Shell\AutoRun\command - "" = E:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.14 19:09:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Benjasmin\Desktop\OTL.exe [2013.04.14 19:04:24 | 000,000,000 | R--D | C] -- C:\Users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8 [2013.04.14 00:01:40 | 000,000,000 | ---D | C] -- C:\FRST [2013.04.12 10:40:51 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Roaming\LumacDaemon [2013.04.12 10:40:43 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Local\Firstload [2013.04.12 10:39:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lumac [2013.04.12 08:40:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search [2013.04.10 23:27:22 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\dwhelper [2013.04.01 10:35:44 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Roaming\Umox [2013.04.01 10:35:44 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Roaming\Ocbyo [2013.04.01 10:35:44 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Roaming\Apoz [2013.03.15 20:06:29 | 000,000,000 | ---D | C] -- C:\Users\Benjasmin\AppData\Roaming\WinHost [2010.01.27 21:12:01 | 007,658,952 | ---- | C] (DT Soft Ltd.) -- C:\Users\Benjasmin\daemon4304-lite.exe [2 C:\Users\Benjasmin\Desktop\*.tmp files -> C:\Users\Benjasmin\Desktop\*.tmp -> ] [13 C:\Users\Benjasmin\Documents\*.tmp files -> C:\Users\Benjasmin\Documents\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.04.14 19:08:00 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.14 19:08:00 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.14 19:04:57 | 000,000,418 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job [2013.04.14 19:04:17 | 000,015,672 | ---- | M] () -- C:\Windows\SysNative\drivers\SWDUMon.sys [2013.04.14 19:04:15 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.14 19:00:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.14 19:00:12 | 3217,235,968 | -HS- | M] () -- C:\hiberfil.sys [2013.04.14 04:26:05 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.13 21:14:05 | 000,001,154 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000UA.job [2013.04.13 18:14:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000Core.job [2013.04.13 17:52:57 | 003,882,566 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.04.13 17:52:57 | 001,591,862 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.04.13 17:52:57 | 001,163,698 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.04.13 17:52:57 | 001,038,326 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.04.13 17:52:57 | 000,005,390 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.04.13 17:44:57 | 000,000,216 | ---- | M] () -- C:\Users\Benjasmin\defogger_reenable [2013.04.13 17:43:12 | 000,377,856 | ---- | M] () -- C:\Users\Benjasmin\Desktop\gmer.exe [2013.04.13 01:28:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Benjasmin\Desktop\OTL.exe [2013.04.12 08:40:39 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2013.04.12 08:40:19 | 000,039,768 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys [2013.04.10 21:45:10 | 000,030,922 | ---- | M] () -- C:\Users\Benjasmin\AppData\Roaming\wklnhst.dat [2013.04.01 11:08:20 | 000,874,246 | ---- | M] () -- C:\Users\Benjasmin\Documents\Investitionstheorie 2011.pdf [2013.03.31 18:06:26 | 000,046,995 | ---- | M] () -- C:\Users\Benjasmin\Documents\607_2012-12-09.pdf [2013.03.21 20:53:28 | 000,538,052 | ---- | M] () -- C:\Users\Benjasmin\Documents\Licht.pdf [2 C:\Users\Benjasmin\Desktop\*.tmp files -> C:\Users\Benjasmin\Desktop\*.tmp -> ] [13 C:\Users\Benjasmin\Documents\*.tmp files -> C:\Users\Benjasmin\Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.04.13 17:49:40 | 000,377,856 | ---- | C] () -- C:\Users\Benjasmin\Desktop\gmer.exe [2013.04.13 17:44:57 | 000,000,216 | ---- | C] () -- C:\Users\Benjasmin\defogger_reenable [2013.04.12 10:39:26 | 000,002,763 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lumac.lnk [2013.04.12 08:40:39 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2013.04.01 11:08:20 | 000,874,246 | ---- | C] () -- C:\Users\Benjasmin\Documents\Investitionstheorie 2011.pdf [2013.03.31 18:06:26 | 000,046,995 | ---- | C] () -- C:\Users\Benjasmin\Documents\607_2012-12-09.pdf [2013.03.21 20:53:28 | 000,538,052 | ---- | C] () -- C:\Users\Benjasmin\Documents\Licht.pdf [2011.10.19 16:11:30 | 000,011,264 | ---- | C] () -- C:\Users\Benjasmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.07.21 08:44:32 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011.06.05 02:31:01 | 000,000,041 | ---- | C] () -- C:\Windows\SysWow64\SUPPORT.INI [2011.05.04 23:20:43 | 000,000,000 | ---- | C] () -- C:\Users\Benjasmin\AppData\Local\{04ABFE4E-36B7-4DE4-AB9F-67EFD117EEE3} [2011.05.04 21:44:21 | 000,182,044 | ---- | C] () -- C:\Windows\hpoins28.dat [2011.05.04 21:44:21 | 000,000,442 | ---- | C] () -- C:\Windows\hpomdl28.dat [2010.02.08 20:45:19 | 000,030,922 | ---- | C] () -- C:\Users\Benjasmin\AppData\Roaming\wklnhst.dat [2010.02.06 15:19:40 | 000,001,125 | ---- | C] () -- C:\Users\Benjasmin\Dokumente - Verknüpfung.lnk [2010.01.25 19:09:07 | 000,007,607 | ---- | C] () -- C:\Users\Benjasmin\AppData\Local\Resmon.ResmonCfg [2009.11.02 22:43:23 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\$Recycle.Bin\S-1-5-21-2259796694-2473700428-155409205-1000\$5dea2983d24ea7233ddf5eb48bd3a915\n. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.01.04 12:44:25 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.01.04 10:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\$Recycle.Bin\S-1-5-18\$5dea2983d24ea7233ddf5eb48bd3a915\n. "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== Alternate Data Streams ========== @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:AB689DEA < End of report > Extras.txtOTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 14.04.2013 19:10:02 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Benjasmin\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 62,45% Memory free 7,99 Gb Paging File | 6,36 Gb Available in Paging File | 79,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 453,94 Gb Total Space | 262,35 Gb Free Space | 57,79% Space Free | Partition Type: NTFS Drive F: | 985,45 Mb Total Space | 982,78 Mb Free Space | 99,73% Space Free | Partition Type: FAT32 Computer Name: BENJAMIN-PC | User Name: Benjasmin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 "AutoUpdateDisableNotify" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{4FD80311-508F-42C3-A004-4CC8D08231F5}" = AVG 2013 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver "{A00C9114-40E6-4C70-A619-7DF264B23485}" = HP Deskjet F4200 All-In-One Driver Software 13.0 Rel. 3 "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 "{AD27BE4B-A261-4F0A-AB5A-476C83EDAED2}" = AVG 2013 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 268.00 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 268.00 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.2.22.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "AVG" = AVG 2013 "CNXT_AUDIO_HDA" = Conexant HD Audio "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Photosmart Essential" = HP Photosmart Essential 3.5 "HP Smart Web Printing" = HP Smart Web Printing 4.51 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Shop for HP Supplies" = Shop for HP Supplies "WinRAR archiver" = WinRAR 4.11 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{05440044-64A6-4248-A026-9745C1E9E159}" = Microsoft Encarta Enzyklopädie 2005 "{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{117E3AE2-10D1-41C1-9FA6-F4C382F767A8}_is1" = Packard Bell GameZone Console "{12A1B519-5934-4508-ADBD-335347B0DC87}" = Video Web Camera "{1431b9be-1399-464c-b38d-3a240aec3a2f}" = Nero 9 Essentials "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1A4052AB-BA77-44F7-8EE7-9F9131BFD7A6}" = OF Dragon Rising "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help "{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{2A708B4E-B226-4EBB-AA55-639C17E7939E}" = DC Software "{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64) "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery "{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed "{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in "{363CEA5C-C9D0-45DD-9511-A461DBDEE94B}" = DJ_AIO_03_F4200_Software_Min "{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2 "{3AC9D33E-918B-4171-91F4-EFDD43F32501}" = SilverCrest GML807 Driver "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3BB33584-3860-4772-AEE9-D8E61F552896}" = Tom Clancy's Rainbow Six: Lockdown "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy "{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management "{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport "{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Fotostory 3 für Windows "{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3 "{5511C07D-A83C-45AD-92B6-42DF99729A3C}" = Adobe Photoshop Elements 7.0 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress "{5DE11949-2B11-4F13-BAD5-1C237122CFDB}" = Lumac "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{67E4EE98-59F4-4220-89A6-A20AF5BEC689}" = Microsoft AutoRoute 2005 "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6E36A172-06FB-4BC8-B7FC-D30D219E6776}" = Tom Clancy's H.A.W.X "{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic "{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart "{7CDC26F7-D6BF-442A-B599-0075A48310F7}" = SA32xx Device Manager "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115208410}" = First Class Flurry "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2 "{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help "{85734060-4F8B-477D-9FBD-44DEAC824BE2}" = SlimDrivers "{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{88D68A69-D247-466B-90DD-575F6BE16230}_is1" = CardRecovery 5.30 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX "{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007 "{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0015-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}_STANDARD_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0017-0407-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (German) 2007 "{90120000-0017-0407-0000-0000000FF1CE}_OMUI.de-de_{2733AA87-26FC-41B0-9D2F-3092345BC370}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}_STANDARD_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}_STANDARD_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}_STANDARD_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}_OMUI.de-de_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}_STANDARD_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_OMUI.de-de_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_OMUI.de-de_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}_STANDARD_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}_OMUI.de-de_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}_STANDARD_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_STANDARD_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0407-1000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0407-1000-0000000FF1CE}_OMUI.de-de_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0407-1000-0000000FF1CE}_STANDARD_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}_OMUI.de-de_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}_STANDARD_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0100-0407-0000-0000000FF1CE}" = Microsoft Office O MUI (German) 2007 "{90120000-0100-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0101-0407-0000-0000000FF1CE}" = Microsoft Office X MUI (German) 2007 "{90120000-0101-0407-0000-0000000FF1CE}_OMUI.de-de_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{911B0407-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002 "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A66C4716-7E10-4A53-8101-00C3C11D6A9C}" = Kane and Lynch: Dead Men "{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}" = PixiePack Codec Pack "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5 "{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI "{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin "{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars "{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287 "{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}" = Need for Speed™ SHIFT "{BCB52F35-4C56-49F2-A3D6-FDED54B01847}" = pdfforge Toolbar v4.4 "{BD136CE7-6666-4273-A056-8D92F8625AAB}" = Sun ODF Plugin for Microsoft Office 3.2 "{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C2524280-A5CF-4458-B809-167F13FAB56D}" = F4200 "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C438DF2B-C5DF-4783-9CA5-9B89E501FA62}" = Works Update "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup "{C6A12D9B-D86A-4ee6-B980-95E4B26A2E13}" = Microsoft Works Suite-Add-Ins für Microsoft Word "{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0 "{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential "{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM) "{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade "{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help "{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer "{E8F5F4AB-512F-44EB-9018-3C527AF6A717}" = Irodio Photo & Video Studio "{E9A6A5CA-3F4B-4F78-BC30-9DF815367FA0}" = Primary Classroom English "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "7-Zip" = 7-Zip 9.20 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0 "Ashampoo ClipFinder HD_is1" = Ashampoo ClipFinder HD 2.11 "Ashampoo Music Studio 3_is1" = Ashampoo Music Studio 3.50 "Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60 "AVMFBox" = AVM FRITZ!Box Dokumentation "AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss "Card Reader Driver and USIM Editor Program_is1" = USIM Editor 1.0.33.0 "Castrol Honda Superbike World Champions" = Castrol Honda Superbike World Champions "CCleaner" = CCleaner (remove only) "ClickPotatoLiteSA" = ClickPotato "conduitEngine" = Conduit Engine "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Elf_1.12 Toolbar" = Elf 1.12 Toolbar "ENTERPRISE" = Microsoft Office Enterprise 2007 "Firstload" = Firstload "Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7 "Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 7.2 "Free YouTube Download_is1" = Free YouTube Download version 3.0.13.815 "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.32.918 "Freemake Video Downloader_is1" = Freemake Video Downloader "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "Identity Card" = Identity Card "InstallShield_{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "InstallShield_{5DE11949-2B11-4F13-BAD5-1C237122CFDB}" = Lumac "InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Packard Bell MyBackup "InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM) "KaloMa_is1" = KaloMa 4.93 "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 2.1.0 "LimeWire" = LimeWire 5.5.10 "LManager" = Launch Manager "Metaboli" = Metaboli "Mit Erfolg bewerben" = Mit Erfolg bewerben v1.0 "Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MyAshampoo Toolbar" = MyAshampoo Toolbar "OMUI.de-de" = Microsoft Office Language Pack 2007 - German/Deutsch "OpenAL" = OpenAL "Packard Bell InfoCentre" = Packard Bell InfoCentre "Packard Bell Registration" = Packard Bell Registration "Packard Bell Welcome Center" = Welcome Center "PackardBell Screensaver" = PackardBell ScreenSaver "PunkBusterSvc" = PunkBuster Services "Red Alert 2" = Command & Conquer Alarmstufe Rot 2 "Shockwave" = Shockwave "STANDARD" = Microsoft Office Standard 2007 "SystemRequirementsLab" = System Requirements Lab "Uninstall_is1" = Uninstall 1.0.0.1 "UseNeXT_is1" = UseNeXT "VLC media player" = VLC media player 2.0.3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinPcapInst" = WinPcap 4.1.2 "Works2005Setup" = Setup-Start von Microsoft Works 2005 "Yahoo! Companion" = Yahoo! Toolbar ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2259796694-2473700428-155409205-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Amazon Kindle" = Amazon Kindle "pdfsam" = pdfsam ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 12.04.2013 04:15:26 | Computer Name = Benjamin-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16421, Zeitstempel: 0x4d76255d Name des fehlerhaften Moduls: urlmon.dll, Version: 9.0.8112.16441, Zeitstempel: 0x4ee810a7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000346c7 ID des fehlerhaften Prozesses: 0x7a8 Startzeit der fehlerhaften Anwendung: 0x01ce374a3c4729d8 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\iexplore.exe Pfad des fehlerhaften Moduls: C:\Windows\syswow64\urlmon.dll Berichtskennung: 212a9d2d-a349-11e2-b793-bfca376b27eb Error - 12.04.2013 04:25:30 | Computer Name = Benjamin-PC | Source = RasClient | ID = 20227 Description = Error - 12.04.2013 04:25:30 | Computer Name = Benjamin-PC | Source = RasClient | ID = 20227 Description = Error - 12.04.2013 13:17:13 | Computer Name = Benjamin-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16421, Zeitstempel: 0x4d76255d Name des fehlerhaften Moduls: MSONSEXT.DLL, Version: 10.145.7329.0, Zeitstempel: 0x4019138d Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004f8b5 ID des fehlerhaften Prozesses: 0x1968 Startzeit der fehlerhaften Anwendung: 0x01ce37a1774c73f9 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\iexplore.exe Pfad des fehlerhaften Moduls: C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL Berichtskennung: d06831ff-a394-11e2-9ebe-e4fb5f25ce94 Error - 13.04.2013 11:52:53 | Computer Name = Benjamin-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 13.04.2013 11:52:54 | Computer Name = Benjamin-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error - 13.04.2013 11:52:54 | Computer Name = Benjamin-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error - 13.04.2013 12:14:05 | Computer Name = Benjamin-PC | Source = Google Update | ID = 20 Description = Error - 13.04.2013 13:07:16 | Computer Name = Benjamin-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: gmer.exe, Version: 2.1.19163.0, Zeitstempel: 0x515d31f0 Name des fehlerhaften Moduls: MSONSEXT.DLL, Version: 10.145.7329.0, Zeitstempel: 0x4019138d Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004f8b5 ID des fehlerhaften Prozesses: 0x73c Startzeit der fehlerhaften Anwendung: 0x01ce38601d7cd878 Pfad der fehlerhaften Anwendung: C:\Users\Benjasmin\Desktop\gmer.exe Pfad des fehlerhaften Moduls: C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL Berichtskennung: 9764bb5b-a45c-11e2-b9f1-986af6ef8fe2 Error - 13.04.2013 14:54:53 | Computer Name = Benjamin-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: gmer.exe, Version: 2.1.19163.0, Zeitstempel: 0x515d31f0 Name des fehlerhaften Moduls: MSONSEXT.DLL, Version: 10.145.7329.0, Zeitstempel: 0x4019138d Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004f8b5 ID des fehlerhaften Prozesses: 0x1374 Startzeit der fehlerhaften Anwendung: 0x01ce386c469ad216 Pfad der fehlerhaften Anwendung: C:\Users\Benjasmin\Desktop\gmer.exe Pfad des fehlerhaften Moduls: C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL Berichtskennung: a0040201-a46b-11e2-b9f1-986af6ef8fe2 Error - 13.04.2013 15:14:05 | Computer Name = Benjamin-PC | Source = Google Update | ID = 20 Description = [ OSession Events ] Error - 01.07.2012 14:27:16 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1218 seconds with 0 seconds of active time. This session ended with a crash. Error - 01.07.2012 15:04:56 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2232 seconds with 120 seconds of active time. This session ended with a crash. Error - 01.07.2012 15:05:59 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 37 seconds with 0 seconds of active time. This session ended with a crash. Error - 01.07.2012 15:06:32 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5 seconds with 0 seconds of active time. This session ended with a crash. Error - 05.09.2012 03:30:25 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 4933 seconds with 3840 seconds of active time. This session ended with a crash. Error - 08.10.2012 15:46:43 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 934 seconds with 180 seconds of active time. This session ended with a crash. Error - 06.03.2013 16:27:28 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 29 seconds with 0 seconds of active time. This session ended with a crash. Error - 06.03.2013 16:31:02 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 7 seconds with 0 seconds of active time. This session ended with a crash. Error - 01.04.2013 04:48:14 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 24 seconds with 0 seconds of active time. This session ended with a crash. Error - 01.04.2013 04:49:40 | Computer Name = Benjamin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 14.04.2013 13:16:39 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:17:09 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:17:39 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:18:09 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:18:39 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:19:30 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:20:00 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:20:30 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:21:00 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 Error - 14.04.2013 13:21:30 | Computer Name = Benjamin-PC | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%126 < End of report > |
14.04.2013, 18:49 | #10 | ||
/// TB-Ausbilder | BKA Trojaner weißer Desktop Hi, Zitat:
Zu den Programmen, die direkt nach Schadsoftware suchen, kommen wir dann später noch. Schritt 1 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 2 Warnung für Mitleser: Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix.
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
Schritt 3 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
14.04.2013, 20:19 | #11 | ||
| BKA Trojaner weißer DesktopZitat:
Ich habe Combofix laufen lassen. Der PC hat sich auch von allein neugestartet. Ich bin mir jetzt nicht sicher ob es korrekt durchgelaufen ist, denn es gab folgende Meldung welche ca. 10-15min dort stand ohne das etwas weiter ging. Zitat:
Ich weiß nicht ob mein Virenprogramm das Problem war. Ich benutze AVG 2013 als kostenlose Version. Diese ist nur vorrübergehend zu deaktivieren. D.h. für 15min oder bis zum nächsten Neustart. Oder es war mein Fehler da ich zu spät das Programm deaktiviert habe sodsas mir Combofix die Fehlermeldung angezeigt hat AVG zu deaktivieren. Sollte ich es nochmal durchaufen lassen? Oder mit Schritt 3 fortfahren? AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.200 - Datei am 14/04/2013 um 20:19:14 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Benjasmin - BENJAMIN-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Benjasmin\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : Application Updater ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml Gelöscht mit Neustart : C:\Program Files (x86)\Common Files\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\Application Updater Ordner Gelöscht : C:\Program Files (x86)\Ask.com Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\clickpotatolite Ordner Gelöscht : C:\Program Files (x86)\Common Files\spigot Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\ConduitEngine Ordner Gelöscht : C:\Program Files (x86)\DAEMON Tools Toolbar Ordner Gelöscht : C:\Program Files (x86)\Elf_1.12 Ordner Gelöscht : C:\Program Files (x86)\MyAshampoo Ordner Gelöscht : C:\Program Files (x86)\pdfforge Toolbar Ordner Gelöscht : C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar Ordner Gelöscht : C:\ProgramData\ClickPotatoLiteSA Ordner Gelöscht : C:\ProgramData\InstallMate Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clickpotato Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Users\BENJAS~1\AppData\Local\Temp\boost_interprocess Ordner Gelöscht : C:\Users\Benjasmin\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\AVG Secure Search Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\AVG Security Toolbar Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\ConduitEngine Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\Elf_1.12 Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\MyAshampoo Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\pdfforge Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Benjasmin\AppData\LocalLow\Search Settings Ordner Gelöscht : C:\Users\Benjasmin\AppData\Roaming\clickpotatolite Ordner Gelöscht : C:\Users\Benjasmin\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Benjasmin\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\Benjasmin\AppData\Roaming\vghd Ordner Gelöscht : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\AppDataLow\AskToolbarInfo Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\conduitEngine Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Elf_1.12 Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\MyAshampoo Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\pdfforge Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Search Settings Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\AVG Security Toolbar Schlüssel Gelöscht : HKCU\Software\clickpotatolitesa Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{38542454-DFB6-44F5-B052-D4E071A3D073} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38542454-DFB6-44F5-B052-D4E071A3D073} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\Software\Application Updater Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D2083641-E57F-4EAB-BB85-0582424F4A29} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\MenuButtonIE.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ClickPotatoLiteAx.Info Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ClickPotatoLiteAx.Info.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ClickPotatoLiteAX.UserProfiles Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ClickPotatoLiteAX.UserProfiles.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MenuButtonIE.ButtonIE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MenuButtonIE.ButtonIE.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2475029 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2857572 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{814BAA91-DC22-4350-87D6-0C86E93F7F08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C55CA95C-324B-451C-B2D2-6E895AA75FEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gelöscht : HKLM\Software\ClickPotatoLite Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\conduitEngine Schlüssel Gelöscht : HKLM\Software\Elf_1.12 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{15297264-D90A-493D-8A5E-DF58E1A1DCA9} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{418294C2-4FFE-4D5C-8D22-F991F48F8E61} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-CD68-4F36-8D02-8C43722EE5DA} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\Software\MyAshampoo Schlüssel Gelöscht : HKLM\Software\pdfforge Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\Search Settings Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{15297264-D90A-493D-8A5E-DF58E1A1DCA9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{38542454-DFB6-44F5-B052-D4E071A3D073} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{418294C2-4FFE-4D5C-8D22-F991F48F8E61} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7A3D6D17-9DD5-4C60-8076-D1784DABAF8C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{06923ABA-01F4-4652-A38F-92658CCEAA57} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B7FBF993-696A-4CE4-BAC8-9600295A2A0A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D99A738A-D92F-4E12-9D3F-B2A6DDA77163} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38542454-DFB6-44F5-B052-D4E071A3D073} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\clickpotatolitesa Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Elf_1.12 Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MyAshampoo Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{38542454-DFB6-44F5-B052-D4E071A3D073}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{38542454-DFB6-44F5-B052-D4E071A3D073}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{38542454-DFB6-44F5-B052-D4E071A3D073}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [clickpotatolitesa] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ClickPotatoLite@ClickPotatoLite.com] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{38542454-DFB6-44F5-B052-D4E071A3D073}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v15.0.1 (de) Datei : C:\Users\Benjasmin\AppData\Roaming\Mozilla\Firefox\Profiles\d3d3hsr5.default\prefs.js Gelöscht : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\FireFoxExt\\14.2.0.1"); ************************* AdwCleaner[S1].txt - [22720 octets] - [14/04/2013 20:19:14] ########## EOF - C:\AdwCleaner[S1].txt - [22781 octets] ########## Combofix Logfile: Code:
ATTFilter ComboFix 13-04-14.01 - Benjasmin 14.04.2013 20:33:11.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4091.2502 [GMT 2:00] ausgeführt von:: c:\users\Benjasmin\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\program files (x86)\Common Files\packardbell.ico c:\program files (x86)\Downloaded Installers c:\program files (x86)\Downloaded Installers\{85734060-4F8B-477D-9FBD-44DEAC824BE2}\setup.msi c:\programdata\FullRemove.exe c:\users\Benjasmin\4.0 c:\users\Benjasmin\AppData\Roaming\.# c:\users\Benjasmin\Documents\~WRL0005.tmp c:\users\Benjasmin\Documents\~WRL0006.tmp c:\users\Benjasmin\Documents\~WRL0311.tmp c:\users\Benjasmin\Documents\~WRL0948.tmp c:\users\Benjasmin\Documents\~WRL1118.tmp c:\users\Benjasmin\Documents\~WRL1201.tmp c:\users\Benjasmin\Documents\~WRL1397.tmp c:\users\Benjasmin\Documents\~WRL1398.tmp c:\users\Benjasmin\Documents\~WRL1719.tmp c:\users\Benjasmin\Documents\~WRL1938.tmp c:\users\Benjasmin\Documents\~WRL2302.tmp c:\users\Benjasmin\Documents\~WRL2590.tmp c:\users\Benjasmin\Documents\~WRL2893.tmp c:\windows\IsUn0407.exe c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . ((((((((((((((((((((((( Dateien erstellt von 2013-03-14 bis 2013-04-14 )))))))))))))))))))))))))))))) . . 2013-04-14 18:49 . 2013-04-14 18:49 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-04-13 22:01 . 2013-04-13 22:01 -------- d-----w- C:\FRST 2013-04-12 08:40 . 2013-04-12 08:40 -------- d-----w- c:\users\Benjasmin\AppData\Roaming\LumacDaemon 2013-04-12 08:40 . 2013-04-12 08:40 -------- d-----w- c:\users\Benjasmin\AppData\Local\Firstload 2013-04-12 08:39 . 2013-04-12 08:39 -------- d-----w- c:\program files (x86)\Lumac 2013-04-10 21:27 . 2013-04-12 19:40 -------- d-----w- c:\users\Benjasmin\dwhelper 2013-04-01 08:35 . 2013-04-01 08:36 -------- d-----w- c:\users\Benjasmin\AppData\Roaming\Umox 2013-04-01 08:35 . 2013-04-01 08:36 -------- d-----w- c:\users\Benjasmin\AppData\Roaming\Apoz 2013-04-01 08:35 . 2013-04-01 08:35 -------- d-----w- c:\users\Benjasmin\AppData\Roaming\Ocbyo . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-14 18:54 . 2011-12-16 07:49 15672 ----a-w- c:\windows\system32\drivers\SWDUMon.sys 2013-04-12 06:40 . 2012-07-27 11:08 39768 ----a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-02-26 21:40 . 2013-02-26 21:40 246072 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys 2013-02-14 01:52 . 2013-02-14 01:52 239416 ----a-w- c:\windows\system32\drivers\avgtdia.sys 2013-02-08 02:37 . 2013-02-08 02:37 116536 ----a-w- c:\windows\system32\drivers\avgmfx64.sys 2013-02-08 02:37 . 2013-02-08 02:37 311096 ----a-w- c:\windows\system32\drivers\avgloga.sys 2013-02-08 02:37 . 2013-02-08 02:37 71480 ----a-w- c:\windows\system32\drivers\avgidsha.sys 2013-02-08 02:37 . 2013-02-08 02:37 206136 ----a-w- c:\windows\system32\drivers\avgldx64.sys 2013-02-08 02:37 . 2013-02-08 02:37 45880 ----a-w- c:\windows\system32\drivers\avgrkx64.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2}] 2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-11-18 16:29 120104 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll . c:\users\Benjasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files (x86)\LimeWire\LimeWire.exe [2010-6-22 503808] OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ DL-10.lnk - c:\program files (x86)\DC Software\DL10XP.exe [2011-6-5 380928] HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Philips Device Manager.lnk - c:\philips\SA32xx Device Manager\SA32xx_DeviceManager.exe [2012-8-13 1615216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) . R2 AfaService;Afa Card Reader Service;c:\windows\system32\afasrv64.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe [x] R3 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 544768] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\DRIVERS\massfilter.sys [2009-04-09 11776] R3 MHIKEY10;MHIKEY10;c:\windows\system32\Drivers\MHIKEY10x64.sys [2010-04-09 59392] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-05 216064] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [2013-04-14 15672] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-09 1255736] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-03-08 834544] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2013-02-08 71480] S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2013-02-08 311096] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2013-02-08 116536] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2013-02-08 45880] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2013-02-26 246072] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2013-02-08 206136] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2013-02-14 239416] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2013-04-12 39768] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464] S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2013-02-27 4937264] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-02-19 282624] S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2009-09-30 844320] S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe [2013-02-25 9216] S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-08-28 1150496] S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-11-18 305448] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2009-08-21 62720] S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-08-29 44312] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160] S2 vToolbarUpdater15.0.0;vToolbarUpdater15.0.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe [2013-04-12 990896] S3 InputFilter_Hid_FlexDef2c;Siliten HID Devices(FlexDef2c) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2c.sys [2010-08-06 19968] S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-20 317480] S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}] 2010-02-16 17:02 114688 ----a-w- c:\program files (x86)\PixiePack Codec Pack\InstallerHelper.exe . Inhalt des "geplante Tasks" Ordners . 2013-04-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000Core.job - c:\users\Benjasmin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-28 16:09] . 2013-04-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2259796694-2473700428-155409205-1000UA.job - c:\users\Benjasmin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-28 16:09] . 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-06 14:04] . 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-06 14:04] . 2013-04-14 c:\windows\Tasks\SlimDrivers Startup.job - c:\program files (x86)\SlimDrivers\SlimDrivers.exe [2011-05-10 09:44] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-11-18 16:31 137512 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-10-09 508472] "PLFSetI"="c:\windows\PLFSetI.exe" [2009-11-20 200704] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-22 295936] "Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2009-09-30 823840] "mwlDaemon"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-11-18 349480] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.finanzen.net/devisen/dollarkurs uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=easynote_tj65&r=27360110i7b6l0300z1m5f49i1u628 mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=easynote_tj65&r=27360110i7b6l0300z1m5f49i1u628 mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Free YouTube Download - c:\users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to Mp3 Converter - c:\users\Benjasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: Interfaces\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}\25557455543545: DhcpNameServer = 172.26.253.113 172.26.253.25 208.67.220.220 208.67.222.222 TCP: Interfaces\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}\6496C6D6071627B6: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}\84F6C69646169702D2022457370213: DhcpNameServer = 192.168.7.1 TCP: Interfaces\{A9BA50EF-97C8-4C30-AF96-1E571E0DB1CE}: NameServer = 208.67.222.222 208.67.220.220 FF - ProfilePath - c:\users\Benjasmin\AppData\Roaming\Mozilla\Firefox\Profiles\d3d3hsr5.default\ FF - ExtSQL: 2013-03-12 16:23; fmdownloader@gmail.com; c:\program files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com FF - ExtSQL: 2013-03-12 16:23; ytfmdownloader@gmail.com; c:\program files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com FF - ExtSQL: 2013-04-10 23:20; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; c:\users\Benjasmin\AppData\Roaming\Mozilla\Firefox\Profiles\d3d3hsr5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF - ExtSQL: !HIDDEN! 2011-05-04 21:47; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) Toolbar-Locked - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Toolbar-Locked - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) AddRemove-Castrol Honda Superbike World Champions - c:\windows\IsUn0407.exe AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe AddRemove-Shockwave - c:\windows\System32\Macromed\Shockwave 8\UNWISE.EXE . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Data] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Networking] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET CLR Networking 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET Data Provider for Oracle] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NET Data Provider for SqlServer] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\.NETFramework] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\1394ohci] "ImagePath"="\SystemRoot\system32\drivers\1394ohci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ACPI] "ImagePath"="system32\drivers\ACPI.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AcpiPmi] "ImagePath"="\SystemRoot\system32\drivers\acpipmi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AdobeActiveFileMonitor7.0] "ImagePath"="c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adp94xx] "ImagePath"="\SystemRoot\system32\DRIVERS\adp94xx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adpahci] "ImagePath"="\SystemRoot\system32\DRIVERS\adpahci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adpu320] "ImagePath"="\SystemRoot\system32\DRIVERS\adpu320.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\adsi] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AeLookupSvc] "ServiceDll"="%SystemRoot%\System32\aelupsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AfaService] "ImagePath"="c:\windows\system32\afasrv64.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AFD] "ImagePath"="\SystemRoot\system32\drivers\afd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\agp440] "ImagePath"="\SystemRoot\system32\drivers\agp440.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ALG] "ImagePath"="%SystemRoot%\System32\alg.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\aliide] "ImagePath"="\SystemRoot\system32\drivers\aliide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdide] "ImagePath"="\SystemRoot\system32\drivers\amdide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AmdK8] "ImagePath"="\SystemRoot\system32\DRIVERS\amdk8.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AmdPPM] "ImagePath"="\SystemRoot\system32\DRIVERS\amdppm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdsata] "ImagePath"="\SystemRoot\system32\drivers\amdsata.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdsbs] "ImagePath"="\SystemRoot\system32\DRIVERS\amdsbs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\amdxata] "ImagePath"="system32\drivers\amdxata.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ApfiltrService] "ImagePath"="system32\DRIVERS\Apfiltr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppID] "ImagePath"="\SystemRoot\system32\drivers\appid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppIDSvc] "ServiceDll"="%SystemRoot%\System32\appidsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Appinfo] "ServiceDll"="%SystemRoot%\System32\appinfo.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AppMgmt] "ServiceDll"="%SystemRoot%\System32\appmgmts.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\arc] "ImagePath"="\SystemRoot\system32\DRIVERS\arc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\arcsas] "ImagePath"="\SystemRoot\system32\DRIVERS\arcsas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AsyncMac] "ImagePath"="system32\DRIVERS\asyncmac.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\atapi] "ImagePath"="system32\drivers\atapi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AudioEndpointBuilder] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AudioSrv] "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avg] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVG Security Toolbar Service] "ImagePath"="c:\program files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSAgent] "ImagePath"="\"c:\program files (x86)\AVG\AVG2013\avgidsagent.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSDriver] "ImagePath"="system32\DRIVERS\avgidsdrivera.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AVGIDSHA] "ImagePath"="system32\DRIVERS\avgidsha.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgldx64] "ImagePath"="system32\DRIVERS\avgldx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgloga] "ImagePath"="system32\DRIVERS\avgloga.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgmfx64] "ImagePath"="system32\DRIVERS\avgmfx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgrkx64] "ImagePath"="system32\DRIVERS\avgrkx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Avgtdia] "ImagePath"="system32\DRIVERS\avgtdia.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\avgtp] "ImagePath"="\??\c:\windows\system32\drivers\avgtpx64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\avgwd] "ImagePath"="\"c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\AxInstSV] "ServiceDll"="%SystemRoot%\System32\AxInstSV.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\b06bdrv] "ImagePath"="\SystemRoot\system32\DRIVERS\bxvbda.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\b57nd60a] "ImagePath"="system32\DRIVERS\b57nd60a.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BattC] "MofImagePath"="system32\drivers\battc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BCM43XX] "ImagePath"="system32\DRIVERS\bcmwl664.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BDESVC] "ServiceDll"="%SystemRoot%\System32\bdesvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Beep] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BFE] "ServiceDll"="%SystemRoot%\System32\bfe.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BITS] "ServiceDll"="%systemroot%\system32\qmgr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\blbdrive] "ImagePath"="\SystemRoot\system32\DRIVERS\blbdrive.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\bowser] "ImagePath"="system32\DRIVERS\bowser.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrFiltLo] "ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltLo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrFiltUp] "ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltUp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BridgeMP] "ImagePath"="system32\DRIVERS\bridge.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Browser] "ServiceDll"="%SystemRoot%\System32\browser.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Brserid] "ImagePath"="\SystemRoot\System32\Drivers\Brserid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrSerWdm] "ImagePath"="\SystemRoot\System32\Drivers\BrSerWdm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrUsbMdm] "ImagePath"="\SystemRoot\System32\Drivers\BrUsbMdm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BrUsbSer] "ImagePath"="\SystemRoot\System32\Drivers\BrUsbSer.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BTHMODEM] "ImagePath"="\SystemRoot\system32\DRIVERS\bthmodem.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\BTHPORT] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\bthserv] "ServiceDll"="%SystemRoot%\system32\bthserv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\catchme] "ImagePath"="\??\c:\combofix\catchme.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cdfs] "ImagePath"="system32\DRIVERS\cdfs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cdrom] "ImagePath"="\SystemRoot\system32\drivers\cdrom.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CertPropSvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\circlass] "ImagePath"="\SystemRoot\system32\DRIVERS\circlass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CLFS] "ImagePath"="System32\CLFS.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v2.0.50727_32] "ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v2.0.50727_64] "ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v4.0.30319_32] "ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\clr_optimization_v4.0.30319_64] "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CmBatt] "ImagePath"="system32\DRIVERS\CmBatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\cmdide] "ImagePath"="\SystemRoot\system32\drivers\cmdide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CNG] "ImagePath"="System32\Drivers\cng.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CnxtHdAudService] "ImagePath"="system32\drivers\CHDRT64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Compbatt] "ImagePath"="system32\DRIVERS\compbatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CompositeBus] "ImagePath"="\SystemRoot\system32\drivers\CompositeBus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\COMSysApp] "ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\crcdisk] "ImagePath"="\SystemRoot\system32\DRIVERS\crcdisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\crypt32] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\CryptSvc] "ServiceDll"="%SystemRoot%\system32\cryptsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DCLocator] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DcomLaunch] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\defragsvc] "ServiceDll"="%Systemroot%\System32\defragsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DfsC] "ImagePath"="System32\Drivers\dfsc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DfSdkS] "ImagePath"="\"c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dhcp] "ServiceDll"="%SystemRoot%\system32\dhcpcore.dll" -- . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\discache] "ImagePath"="System32\drivers\discache.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Disk] "ImagePath"="system32\DRIVERS\disk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dnscache] "ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\dot3svc] "ServiceDll"="%SystemRoot%\System32\dot3svc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dot4] "ImagePath"="system32\DRIVERS\Dot4.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Dot4Print] "ImagePath"="\SystemRoot\system32\drivers\Dot4Prt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\dot4usb] "ImagePath"="system32\DRIVERS\dot4usb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DPS] "ServiceDll"="%SystemRoot%\system32\dps.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\drmkaud] "ImagePath"="system32\drivers\drmkaud.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\DXGKrnl] "ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EapHost] "ServiceDll"="%SystemRoot%\System32\eapsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ebdrv] "ImagePath"="\SystemRoot\system32\DRIVERS\evbda.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EFS] "ImagePath"="%SystemRoot%\System32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ehRecvr] "ImagePath"="%systemroot%\ehome\ehRecvr.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ehSched] "ImagePath"="%systemroot%\ehome\ehsched.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\elxstor] "ImagePath"="\SystemRoot\system32\DRIVERS\elxstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ePowerSvc] "ImagePath"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ErrDev] "ImagePath"="\SystemRoot\system32\drivers\errdev.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ESENT] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\eventlog] "ServiceDll"="%SystemRoot%\System32\wevtsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EventSystem] "ServiceDll"="%systemroot%\system32\es.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\exfat] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fastfat] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Fax] "ImagePath"="%systemroot%\system32\fxssvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fdc] "ImagePath"="\SystemRoot\system32\DRIVERS\fdc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fdPHost] "ServiceDll"="%SystemRoot%\system32\fdPHost.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FDResPub] "ServiceDll"="%SystemRoot%\system32\fdrespub.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FileInfo] "ImagePath"="system32\drivers\fileinfo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Filetrace] "ImagePath"="system32\drivers\filetrace.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FLEXnet Licensing Service] "ImagePath"="\"c:\program files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\flpydisk] "ImagePath"="\SystemRoot\system32\DRIVERS\flpydisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FltMgr] "ImagePath"="system32\drivers\fltmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FontCache] "ServiceDll"="%SystemRoot%\system32\FntCache.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FontCache3.0.0.0] "ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FreemakeVideoCapture] "ImagePath"="\"c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\FsDepends] "ImagePath"="System32\drivers\FsDepends.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Fs_Rec] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\fvevol] "ImagePath"="System32\DRIVERS\fvevol.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gagp30kx] "ImagePath"="\SystemRoot\system32\DRIVERS\gagp30kx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gpsvc] "ServiceDll"="%SystemRoot%\System32\gpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Greg_Service] "ImagePath"="c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gupdate] "ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gupdatem] "ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\gusvc] "ImagePath"="\"c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hcw85cir] "ImagePath"="\SystemRoot\system32\drivers\hcw85cir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HdAudAddService] "ImagePath"="\SystemRoot\system32\drivers\HdAudio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HDAudBus] "ImagePath"="\SystemRoot\system32\drivers\HDAudBus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidBatt] "ImagePath"="\SystemRoot\system32\DRIVERS\HidBatt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidBth] "ImagePath"="\SystemRoot\system32\DRIVERS\hidbth.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidIr] "ImagePath"="\SystemRoot\system32\DRIVERS\hidir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hidserv] "ServiceDll"="%SystemRoot%\System32\hidserv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HidUsb] "ImagePath"="system32\DRIVERS\hidusb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hkmsvc] "ServiceDLL"="%SystemRoot%\system32\kmsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HomeGroupListener] "ServiceDll"="%SystemRoot%\system32\ListSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HomeGroupProvider] "ServiceDll"="%SystemRoot%\system32\provsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hpqcxs08] "ServiceDll"="c:\program files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hpqddsvc] "ServiceDll"="c:\program files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HpSAMD] "ImagePath"="\SystemRoot\system32\drivers\HpSAMD.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\HTTP] "ImagePath"="system32\drivers\HTTP.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\hwpolicy] "ImagePath"="System32\drivers\hwpolicy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\i8042prt] "ImagePath"="\SystemRoot\system32\drivers\i8042prt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IAANTMON] "ImagePath"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iaStor] "ImagePath"="system32\DRIVERS\iaStor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iaStorV] "ImagePath"="\SystemRoot\system32\drivers\iaStorV.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\idsvc] "ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\igfx] "ImagePath"="system32\DRIVERS\igdkmd64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iirsp] "ImagePath"="\SystemRoot\system32\DRIVERS\iirsp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IKEEXT] "ServiceDll"="%SystemRoot%\System32\ikeext.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\inetaccs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\InputFilter_Hid_FlexDef2c] "ImagePath"="system32\DRIVERS\InputFilter_FlexDef2c.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\intelide] "ImagePath"="\SystemRoot\system32\drivers\intelide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\intelppm] "ImagePath"="system32\DRIVERS\intelppm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPBusEnum] "ServiceDll"="%SystemRoot%\system32\ipbusenum.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IpFilterDriver] "ImagePath"="system32\DRIVERS\ipfltdrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iphlpsvc] "ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPMIDRV] "ImagePath"="\SystemRoot\system32\drivers\IPMIDrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IPNAT] "ImagePath"="System32\drivers\ipnat.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\IRENUM] "ImagePath"="system32\drivers\irenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\isapnp] "ImagePath"="\SystemRoot\system32\drivers\isapnp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\iScsiPrt] "ImagePath"="\SystemRoot\system32\drivers\msiscsi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\k57nd60a] "ImagePath"="system32\DRIVERS\k57nd60a.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\kbdclass] "ImagePath"="\SystemRoot\system32\drivers\kbdclass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\kbdhid] "ImagePath"="\SystemRoot\system32\drivers\kbdhid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KeyIso] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KSecDD] "ImagePath"="System32\Drivers\ksecdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KSecPkg] "ImagePath"="System32\Drivers\ksecpkg.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ksthunk] "ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\KtmRm] "ServiceDll"="%systemroot%\system32\msdtckrm.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\L1E] "ImagePath"="system32\DRIVERS\L1E62x64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LanmanServer] "ServiceDll"="%SystemRoot%\System32\srvsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LanmanWorkstation] "ServiceDll"="%SystemRoot%\System32\wkssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ldap] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lltdio] "ImagePath"="system32\DRIVERS\lltdio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lltdsvc] "ServiceDll"="%SystemRoot%\System32\lltdsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\lmhosts] "ServiceDll"="%SystemRoot%\System32\lmhsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Lsa] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_FC] "ImagePath"="\SystemRoot\system32\DRIVERS\lsi_fc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SAS] "ImagePath"="\SystemRoot\system32\DRIVERS\lsi_sas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SAS2] "ImagePath"="\SystemRoot\system32\DRIVERS\lsi_sas2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\LSI_SCSI] "ImagePath"="\SystemRoot\system32\DRIVERS\lsi_scsi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\luafv] "ImagePath"="\SystemRoot\system32\drivers\luafv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\massfilter] "ImagePath"="system32\DRIVERS\massfilter.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Mcx2Svc] "ServiceDll"="%SystemRoot%\system32\Mcx2Svc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\megasas] "ImagePath"="\SystemRoot\system32\DRIVERS\megasas.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MegaSR] "ImagePath"="\SystemRoot\system32\DRIVERS\MegaSR.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MHIKEY10] "ImagePath"="System32\Drivers\MHIKEY10x64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Microsoft Office Groove Audit Service] "ImagePath"="\"c:\program files (x86)\Microsoft Office\Office12\GrooveAuditService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MMCSS] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Modem] "ImagePath"="system32\drivers\modem.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\monitor] "ImagePath"="system32\DRIVERS\monitor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mouclass] "ImagePath"="\SystemRoot\system32\drivers\mouclass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mouhid] "ImagePath"="system32\DRIVERS\mouhid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mountmgr] "ImagePath"="System32\drivers\mountmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MozillaMaintenance] "ImagePath"="\"c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mpio] "ImagePath"="\SystemRoot\system32\drivers\mpio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mpsdrv] "ImagePath"="System32\drivers\mpsdrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MpsSvc] "ServiceDll"="%SystemRoot%\system32\mpssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MRxDAV] "ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb] "ImagePath"="system32\DRIVERS\mrxsmb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb10] "ImagePath"="system32\DRIVERS\mrxsmb10.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mrxsmb20] "ImagePath"="system32\DRIVERS\mrxsmb20.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msahci] "ImagePath"="\SystemRoot\system32\drivers\msahci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msdsm] "ImagePath"="\SystemRoot\system32\drivers\msdsm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC] "ImagePath"="%SystemRoot%\System32\msdtc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC Bridge 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSDTC Bridge 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Msfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mshidkmdf] "ImagePath"="\SystemRoot\System32\drivers\mshidkmdf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msisadrv] "ImagePath"="system32\drivers\msisadrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSiSCSI] "ServiceDll"="%systemroot%\system32\iscsiexe.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\msiserver] "ImagePath"="%systemroot%\system32\msiexec.exe /V" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSKSSRV] "ImagePath"="system32\drivers\MSKSSRV.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSPCLOCK] "ImagePath"="system32\drivers\MSPCLOCK.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSPQM] "ImagePath"="system32\drivers\MSPQM.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsRPC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSSCNTRS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mssmbios] "ImagePath"="\SystemRoot\system32\drivers\mssmbios.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MSTEE] "ImagePath"="system32\drivers\MSTEE.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MTConfig] "ImagePath"="\SystemRoot\system32\DRIVERS\MTConfig.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Mup] "ImagePath"="System32\Drivers\mup.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mwlPSDFilter] "ImagePath"="system32\DRIVERS\mwlPSDFilter.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mwlPSDNServ] "ImagePath"="system32\DRIVERS\mwlPSDNServ.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\mwlPSDVDisk] "ImagePath"="system32\DRIVERS\mwlPSDVDisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MWLService] "ImagePath"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\napagent] "ServiceDLL"="%SystemRoot%\system32\qagentRT.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NativeWifiP] "ImagePath"="system32\DRIVERS\nwifi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NDIS] "ImagePath"="system32\drivers\ndis.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisCap] "ImagePath"="system32\DRIVERS\ndiscap.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisTapi] "ImagePath"="system32\DRIVERS\ndistapi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Ndisuio] "ImagePath"="system32\DRIVERS\ndisuio.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NdisWan] "ImagePath"="system32\DRIVERS\ndiswan.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NDProxy] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Nero BackItUp Scheduler 4.0] "ImagePath"="c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Net Driver HPZ12] "ServiceDll"="c:\windows\system32\HPZinw12.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetBIOS] "ImagePath"="system32\DRIVERS\netbios.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetBT] "ImagePath"="System32\DRIVERS\netbt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Netlogon] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Netman] "ServiceDll"="%SystemRoot%\System32\netman.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\netprofm] "ServiceDll"="%SystemRoot%\System32\netprofm.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NetTcpPortSharing] "ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NETw5s64] "ImagePath"="system32\DRIVERS\NETw5s64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\netw5v64] "ImagePath"="system32\DRIVERS\netw5v64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nfrd960] "ImagePath"="\SystemRoot\system32\DRIVERS\nfrd960.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NlaSvc] "ServiceDll"="%SystemRoot%\System32\nlasvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Npfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nsi] "ServiceDll"="%systemroot%\system32\nsisvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nsiproxy] "ImagePath"="system32\drivers\nsiproxy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTDS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Ntfs] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTI IScheduleSvc] "ImagePath"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTIDrvr] "ImagePath"="\??\c:\windows\system32\drivers\NTIDrvr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Null] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NVHDA] "ImagePath"="system32\drivers\nvhda64v.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nvlddmkm] "ImagePath"="system32\DRIVERS\nvlddmkm.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nvraid] "ImagePath"="\SystemRoot\system32\drivers\nvraid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nvstor] "ImagePath"="\SystemRoot\system32\drivers\nvstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NVSvc] "ImagePath"="%SystemRoot%\system32\nvvsvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\nv_agp] "ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\OberonGameConsoleService] "ImagePath"="\"c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\odserv] "ImagePath"="\"c:\program files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ohci1394] "ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ose] "ImagePath"="\"c:\program files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Outlook] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\p2pimsvc] "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\p2psvc] "ServiceDll"="%SystemRoot%\system32\p2psvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Parport] "ImagePath"="\SystemRoot\system32\DRIVERS\parport.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\partmgr] "ImagePath"="System32\drivers\partmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PcaSvc] "ServiceDll"="%SystemRoot%\System32\pcasvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pci] "ImagePath"="system32\drivers\pci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pciide] "ImagePath"="\SystemRoot\system32\drivers\pciide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pcmcia] "ImagePath"="\SystemRoot\system32\DRIVERS\pcmcia.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pcw] "ImagePath"="System32\drivers\pcw.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PEAUTH] "ImagePath"="system32\drivers\peauth.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfDisk] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfHost] "ImagePath"="%SystemRoot%\SysWow64\perfhost.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfNet] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfOS] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PerfProc] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pla] "ServiceDll"="%systemroot%\system32\pla.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PlugPlay] "ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Pml Driver HPZ12] "ServiceDll"="c:\windows\system32\HPZipm12.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PnkBstrA] "ImagePath"="c:\windows\system32\PnkBstrA.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PNRPAutoReg] "ServiceDll"="%SystemRoot%\system32\pnrpauto.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PNRPsvc] "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PolicyAgent] "ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PortProxy] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Power] "ServiceDll"="%SystemRoot%\system32\umpo.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PptpMiniport] "ImagePath"="system32\DRIVERS\raspptp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Processor] "ImagePath"="\SystemRoot\system32\DRIVERS\processr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ProfSvc] "ServiceDll"="%systemroot%\system32\profsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ProtectedStorage] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Psched] "ImagePath"="system32\DRIVERS\pacer.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PxHlpa64] "ImagePath"="System32\Drivers\PxHlpa64.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ql2300] "ImagePath"="\SystemRoot\system32\DRIVERS\ql2300.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ql40xx] "ImagePath"="\SystemRoot\system32\DRIVERS\ql40xx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\QWAVE] "ServiceDll"="%windir%\system32\qwave.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\QWAVEdrv] "ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAcd] "ImagePath"="System32\DRIVERS\rasacd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAgileVpn] "ImagePath"="system32\DRIVERS\AgileVpn.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasAuto] "ServiceDll"="%SystemRoot%\System32\rasauto.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Rasl2tp] "ImagePath"="system32\DRIVERS\rasl2tp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasMan] "ServiceDll"="%SystemRoot%\System32\rasmans.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasPppoe] "ImagePath"="system32\DRIVERS\raspppoe.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RasSstp] "ImagePath"="system32\DRIVERS\rassstp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdbss] "ImagePath"="system32\DRIVERS\rdbss.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdpbus] "ImagePath"="\SystemRoot\system32\DRIVERS\rdpbus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPCDD] "ImagePath"="System32\DRIVERS\RDPCDD.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPDD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPENCDD] "ImagePath"="system32\drivers\rdpencdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPNP] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPREFMP] "ImagePath"="system32\drivers\rdprefmp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RDPWD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rdyboost] "ImagePath"="System32\drivers\rdyboost.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RemoteAccess] "ServiceDLL"="%SystemRoot%\System32\mprdim.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RemoteRegistry] "ServiceDll"="%SystemRoot%\system32\regsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcEptMapper] "ServiceDll"="%SystemRoot%\System32\RpcEpMap.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcLocator] "ImagePath"="%SystemRoot%\system32\locator.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RpcSs] "ServiceDll"="%SystemRoot%\system32\rpcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\rspndr] "ImagePath"="system32\DRIVERS\rspndr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RSUSBSTOR] "ImagePath"="System32\Drivers\RtsUStor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\RtsUIR] "ImagePath"="system32\DRIVERS\Rts516xIR.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SamSs] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sbp2port] "ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SCardSvr] "ServiceDll"="%SystemRoot%\System32\SCardSvr.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\scfilter] "ImagePath"="System32\DRIVERS\scfilter.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Schedule] "ServiceDll"="%systemroot%\system32\schedsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SCPolicySvc] "ServiceDll"="%SystemRoot%\System32\certprop.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SDRSVC] "ServiceDll"="%Systemroot%\System32\SDRSVC.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\secdrv] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\seclogon] "ServiceDll"="%windir%\system32\seclogon.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SENS] "ServiceDll"="%SystemRoot%\system32\sens.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SensrSvc] "ServiceDll"="%SystemRoot%\system32\sensrsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Serenum] "ImagePath"="\SystemRoot\system32\DRIVERS\serenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Serial] "ImagePath"="\SystemRoot\system32\DRIVERS\serial.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sermouse] "ImagePath"="\SystemRoot\system32\DRIVERS\sermouse.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelEndpoint 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelOperation 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ServiceModelService 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SessionEnv] "ServiceDLL"="%SystemRoot%\system32\sessenv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffdisk] "ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffp_mmc] "ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sffp_sd] "ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sfloppy] "ImagePath"="\SystemRoot\system32\DRIVERS\sfloppy.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SharedAccess] "ServiceDll"="%SystemRoot%\System32\ipnathlp.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ShellHWDetection] "ServiceDll"="%SystemRoot%\System32\shsvcs.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SiSRaid2] "ImagePath"="\SystemRoot\system32\DRIVERS\SiSRaid2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SiSRaid4] "ImagePath"="\SystemRoot\system32\DRIVERS\sisraid4.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Smb] "ImagePath"="system32\DRIVERS\smb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SMSvcHost 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SMSvcHost 4.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SNMPTRAP] "ImagePath"="%SystemRoot%\System32\snmptrap.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\spldr] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Spooler] "ImagePath"="%SystemRoot%\System32\spoolsv.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sppsvc] "ImagePath"="%SystemRoot%\system32\sppsvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sppuinotify] "ServiceDll"="%SystemRoot%\system32\sppuinotify.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sptd] "ImagePath"="\SystemRoot\System32\Drivers\sptd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\sr] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srv] "ImagePath"="System32\DRIVERS\srv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srv2] "ImagePath"="System32\DRIVERS\srv2.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfHDA] "ImagePath"="system32\DRIVERS\VSTAZL6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfV92] "ImagePath"="system32\DRIVERS\VSTDPV6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SrvHsfWinac] "ImagePath"="system32\DRIVERS\VSTCNXT6.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\srvnet] "ImagePath"="System32\DRIVERS\srvnet.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SSDPSRV] "ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SstpSvc] "ServiceDll"="%SystemRoot%\system32\sstpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\stexstor] "ImagePath"="\SystemRoot\system32\DRIVERS\stexstor.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\stisvc] "ServiceDll"="%SystemRoot%\System32\wiaservc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SWDUMon] "ImagePath"="system32\DRIVERS\SWDUMon.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\swenum] "ImagePath"="\SystemRoot\system32\drivers\swenum.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\swprv] "ServiceDll"="%Systemroot%\System32\swprv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SysMain] "ServiceDll"="%systemroot%\system32\sysmain.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TabletInputService] "ServiceDll"="%SystemRoot%\System32\TabSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TapiSrv] "ServiceDll"="%SystemRoot%\System32\tapisrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TBS] "ServiceDll"="%SystemRoot%\System32\tbssvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Tcpip] "ImagePath"="System32\drivers\tcpip.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIP6] "ImagePath"="system32\DRIVERS\tcpip.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIP6TUNNEL] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tcpipreg] "ImagePath"="System32\drivers\tcpipreg.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TCPIPTUNNEL] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TDPIPE] "ImagePath"="system32\drivers\tdpipe.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TDTCP] "ImagePath"="system32\drivers\tdtcp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tdx] "ImagePath"="system32\DRIVERS\tdx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TermDD] "ImagePath"="\SystemRoot\system32\drivers\termdd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TermService] "ServiceDll"="%SystemRoot%\System32\termsrv.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Themes] "ServiceDll"="%SystemRoot%\system32\themeservice.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\THREADORDER] "ServiceDll"="%SystemRoot%\system32\mmcss.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TrkWks] "ServiceDll"="%SystemRoot%\System32\trkwks.dll" -- . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TrustedInstaller] "ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TSDDD] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tssecsrv] "ImagePath"="System32\DRIVERS\tssecsrv.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\TsUsbFlt] "ImagePath"="system32\drivers\tsusbflt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\tunnel] "ImagePath"="system32\DRIVERS\tunnel.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\uagp35] "ImagePath"="\SystemRoot\system32\DRIVERS\uagp35.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UBHelper] "ImagePath"="\??\c:\windows\system32\drivers\UBHelper.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\udfs] "ImagePath"="system32\DRIVERS\udfs.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UGatherer] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UGTHRSVC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UI0Detect] "ImagePath"="%SystemRoot%\system32\UI0Detect.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\uliagpkx] "ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\umbus] "ImagePath"="\SystemRoot\system32\drivers\umbus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UmPass] "ImagePath"="\SystemRoot\system32\DRIVERS\umpass.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Updater Service] "ImagePath"="c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\upnphost] "ServiceDll"="%SystemRoot%\System32\upnphost.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbbus] "ImagePath"="system32\DRIVERS\lgx64bus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbccgp] "ImagePath"="system32\DRIVERS\usbccgp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\USBCCID] "ImagePath"="system32\DRIVERS\RtsUCcid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbcir] "ImagePath"="\SystemRoot\system32\drivers\usbcir.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UsbDiag] "ImagePath"="system32\DRIVERS\lgx64diag.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbehci] "ImagePath"="system32\DRIVERS\usbehci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbhub] "ImagePath"="system32\DRIVERS\usbhub.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\USBModem] "ImagePath"="system32\DRIVERS\lgx64modem.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbohci] "ImagePath"="\SystemRoot\system32\drivers\usbohci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbprint] "ImagePath"="system32\DRIVERS\usbprint.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbscan] "ImagePath"="system32\DRIVERS\usbscan.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\USBSTOR] "ImagePath"="system32\DRIVERS\USBSTOR.SYS" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbuhci] "ImagePath"="system32\DRIVERS\usbuhci.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\usbvideo] "ImagePath"="\SystemRoot\System32\Drivers\usbvideo.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\UxSms] "ServiceDll"="%SystemRoot%\System32\uxsms.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VaultSvc] "ImagePath"="%SystemRoot%\system32\lsass.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vdrvroot] "ImagePath"="system32\drivers\vdrvroot.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vds] "ImagePath"="%SystemRoot%\System32\vds.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vga] "ImagePath"="system32\DRIVERS\vgapnp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VgaSave] "ImagePath"="\SystemRoot\System32\drivers\vga.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vhdmp] "ImagePath"="\SystemRoot\system32\drivers\vhdmp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\viaide] "ImagePath"="\SystemRoot\system32\drivers\viaide.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volmgr] "ImagePath"="system32\drivers\volmgr.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volmgrx] "ImagePath"="System32\drivers\volmgrx.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volsnap] "ImagePath"="system32\drivers\volsnap.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vsmraid] "ImagePath"="\SystemRoot\system32\DRIVERS\vsmraid.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\VSS] "ImagePath"="%systemroot%\system32\vssvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vToolbarUpdater15.0.0] "ImagePath"="c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vwifibus] "ImagePath"="system32\DRIVERS\vwifibus.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vwififlt] "ImagePath"="system32\DRIVERS\vwififlt.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\vwifimp] "ImagePath"="system32\DRIVERS\vwifimp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\W32Time] "ServiceDll"="%systemroot%\system32\w32time.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\W3SVC] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WacomPen] "ImagePath"="\SystemRoot\system32\DRIVERS\wacompen.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WANARP] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wanarpv6] "ImagePath"="system32\DRIVERS\wanarp.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WatAdminSvc] "ImagePath"="%SystemRoot%\system32\Wat\WatAdminSvc.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wbengine] "ImagePath"="\"%systemroot%\system32\wbengine.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WbioSrvc] "ServiceDll"="%SystemRoot%\System32\wbiosrvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wcncsvc] "ServiceDll"="%SystemRoot%\System32\wcncsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WcsPlugInService] "ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wd] "ImagePath"="\SystemRoot\system32\DRIVERS\wd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wdf01000] "ImagePath"="system32\drivers\Wdf01000.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WdiServiceHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WdiSystemHost] "ServiceDll"="%SystemRoot%\system32\wdi.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WebClient] "ServiceDll"="%SystemRoot%\System32\webclnt.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wecsvc] "ServiceDll"="%SystemRoot%\system32\wecsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wercplsupport] "ServiceDll"="%SystemRoot%\System32\wercplsupport.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WerSvc] "ServiceDll"="%SystemRoot%\System32\WerSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WfpLwf] "ImagePath"="system32\DRIVERS\wfplwf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WIMMount] "ImagePath"="system32\drivers\wimmount.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinDefend] "ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Windows Workflow Foundation 3.0.0.0] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinHttpAutoProxySvc] "ServiceDll"="winhttp.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Winmgmt] "ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinRM] "ServiceDll"="%SystemRoot%\system32\WsmSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Winsock] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinSock2] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WinUsb] "ImagePath"="system32\DRIVERS\WinUsb.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Wlansvc] "ServiceDll"="%SystemRoot%\System32\wlansvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wlidsvc] "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WmiAcpi] "ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WmiApRpl] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wmiApSrv] "ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WMPNetworkSvc] "ImagePath"="\"%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WPCSvc] "ServiceDll"="%SystemRoot%\System32\wpcsvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WPDBusEnum] "ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ws2ifsl] "ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WSearch] "ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WSearchIdxPi] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wuauserv] "ServiceDll"="%systemroot%\system32\wuaueng.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WudfPf] "ImagePath"="system32\drivers\WudfPf.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WUDFRd] "ImagePath"="system32\DRIVERS\WUDFRd.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\wudfsvc] "ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\WwanSvc] "ServiceDll"="%SystemRoot%\System32\wwansvc.dll" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\xmlprov] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ZTEusbmdm6k] "ImagePath"="system32\DRIVERS\ZTEusbmdm6k.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ZTEusbnet] "ImagePath"="system32\DRIVERS\ZTEusbnet.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ZTEusbnmea] "ImagePath"="system32\DRIVERS\ZTEusbnmea.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ZTEusbser6k] "ImagePath"="system32\DRIVERS\ZTEusbser6k.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\ZTEusbvoice] "ImagePath"="system32\DRIVERS\ZTEusbvoice.sys" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{288748E4-5952-4616-BD83-90FD1282BFC4}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{867F18B4-90FB-4472-ADFE-74E4F0AC7B49}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{92A79336-6ACC-4FB0-820D-1B35FE3F9AA2}] . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{A9303A6B-F7AB-451D-9EE9-52E0EA50BBF0}] . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2259796694-2473700428-155409205-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*0*0*0*¬ \OpenWithList] @Class="Shell" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-04-14 21:10:51 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-04-14 19:10 . Vor Suchlauf: 22 Verzeichnis(se), 295.853.195.264 Bytes frei Nach Suchlauf: 34 Verzeichnis(se), 296.670.904.320 Bytes frei . - - End Of File - - 50C73BA273C2915C76EEE1610BF5C6E2 Geändert von Brock88 (14.04.2013 um 20:26 Uhr) |
14.04.2013, 20:28 | #12 | |
/// TB-Ausbilder | BKA Trojaner weißer DesktopZitat:
__________________ cheers, Leo |
14.04.2013, 20:45 | #13 | ||
| BKA Trojaner weißer Desktop Bei mir ist von dir folgender, von dir vorher beschriebener, Fall eingetreten. Zitat:
Ist dies irgendwie zu berücksichtigen? |
14.04.2013, 20:47 | #14 |
| BKA Trojaner weißer Desktop Anhang |
14.04.2013, 20:55 | #15 |
/// TB-Ausbilder | BKA Trojaner weißer Desktop Wenn das ein Programm ist, welches du kennst und nutzt, dann ist alles ok. Combofix wird etwas in der Firewall zurückgesetzt haben.
__________________ cheers, Leo |
Themen zu BKA Trojaner weißer Desktop |
abbild, anmelden, ausdrucksweise, besten, bka - trojaner, desktop, eingabe, eingabeaufforderung, erschein, erscheint, fehler, interne, internetverbindung, melde, melden, otl ! was soll ich jetzt tun?, passwort, scan, sonstiges, starte, subsystem, taskmanager, troja, trojaner, verbindung, weiße, weißer, weißer bildschirm, weißer desktop |