![]() |
| |||||||
Log-Analyse und Auswertung: snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #3 |
| | snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen Super, vielen Dank!
__________________Firefox und IE haben jetzt keine snap.do Toolbar und Starseite mehr! Aber ist es damit vollständig behoben? adwCleaner: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.200 - Datei am 15/04/2013 um 21:30:42 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzer : **NAME** - **NAME**-PC
# Bootmodus : Normal
# Ausgef¸hrt unter : C:\Users\**NAME**\Desktop\adwcleaner.exe
# Option [Lˆschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelˆscht : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\searchplugins\Web Search.xml
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\extensions\staged
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\OpenCandy
Ordner Gelˆscht : C:\Users\**NAME**\AppData\Roaming\pdfforge
***** [Registrierungsdatenbank] *****
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schl¸ssel Gelˆscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKCU\Software\SmartBar
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schl¸ssel Gelˆscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Wert Gelˆscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16537
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=hp&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=68158704-666d-4655-a66f-e1a1a3aa6ac2&searchtype=ds&q={searchTerms}&installDate=14/04/2013 --> hxxp://www.google.com
-\\ Mozilla Firefox v20.0.1 (de)
Datei : C:\Users\**NAME**\AppData\Roaming\Mozilla\Firefox\Profiles\89exxq82.default\prefs.js
Gelˆscht : user_pref("browser.search.selectedEngine", "Web Search");
Gelˆscht : user_pref("browser.startup.homepage", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=[...]
Gelˆscht : user_pref("extensions.helperbar.SmartbarDisabled", true);
Gelˆscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Gelˆscht : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=681[...]
*************************
AdwCleaner[S1].txt - [4391 octets] - [15/04/2013 21:30:42]
########## EOF - C:\AdwCleaner[S1].txt - [4451 octets] ##########
OTL: OTL Logfile: Code:
ATTFilter OTL logfile created on: 15.04.2013 22:18:06 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\**NAME**\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,58% Memory free 5,98 Gb Paging File | 4,81 Gb Available in Paging File | 80,41% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 144,17 Gb Total Space | 96,18 Gb Free Space | 66,71% Space Free | Partition Type: NTFS Drive D: | 144,15 Gb Total Space | 11,23 Gb Free Space | 7,79% Space Free | Partition Type: NTFS Drive F: | 14,83 Gb Total Space | 1,17 Gb Free Space | 7,88% Space Free | Partition Type: FAT32 Computer Name: **NAME**-PC | User Name: **NAME** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.15 13:46:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe PRC - [2013.03.07 00:32:44 | 004,767,304 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2013.03.07 00:32:44 | 000,045,248 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.01.29 21:08:04 | 002,447,888 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\vsmon.exe PRC - [2013.01.29 20:35:36 | 000,073,832 | ---- | M] (Check Point Software Technologies LTD) -- C:\Programme\CheckPoint\ZoneAlarm\zatray.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2012.11.22 16:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe PRC - [2012.11.22 16:32:54 | 000,738,984 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ForceField.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.10.08 14:15:40 | 000,167,936 | ---- | M] (Mediafour Corporation) -- C:\Programme\Mediafour\MacDrive 8\MacDrive.exe PRC - [2010.10.08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) -- C:\Programme\Mediafour\MacDrive 8\MacDrive8Service.exe ========== Modules (No Company Name) ========== ========== Services (SafeList) ========== SRV - [2013.04.10 08:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.03.07 00:32:44 | 000,045,248 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2013.03.06 17:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.02.28 19:09:08 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013.01.29 21:08:04 | 002,447,888 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Programme\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon) SRV - [2012.11.22 16:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.10.08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) [Auto | Running] -- C:\Programme\Mediafour\MacDrive 8\MacDrive8Service.exe -- (MacDrive8Service) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006.10.26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - [2013.03.07 00:33:24 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013.03.07 00:33:24 | 000,368,176 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013.03.07 00:33:24 | 000,164,736 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013.03.07 00:33:24 | 000,062,376 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013.03.07 00:33:24 | 000,049,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013.03.07 00:33:23 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013.03.07 00:33:23 | 000,060,656 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr) DRV - [2013.03.07 00:33:22 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012.12.13 11:49:38 | 000,454,744 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\vsdatant.sys -- (Vsdatant) DRV - [2012.11.22 16:33:30 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - [2012.11.15 21:06:10 | 000,587,096 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.10.07 15:36:04 | 000,234,160 | ---- | M] (Mediafour Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\MDFSYSNT.SYS -- (MDFSYSNT) DRV - [2010.05.12 14:51:34 | 000,029,792 | ---- | M] (Mediafour Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\MDPMGRNT.SYS -- (MDPMGRNT) DRV - [2010.05.12 14:42:50 | 000,057,800 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\CBDisk.sys -- (CBDisk) DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5C E3 10 E7 C4 36 CE 01 [binary data] IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: {68158704-666d-4655-a66f-e1a1a3aa6ac2}:1.0 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1483 FF - prefs.js..extensions.enabledAddons: %7B68158704-666d-4655-a66f-e1a1a3aa6ac2%7D:1.1 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll () FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.04.11 22:24:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013.04.12 18:59:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 00:21:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.11 22:50:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\**NAME**\AppData\Roaming\mozilla\Extensions [2013.04.15 21:30:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\**NAME**\AppData\Roaming\mozilla\Firefox\Profiles\89exxq82.default\extensions [2013.04.11 22:50:16 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.11 22:24:55 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF File not found (No name found) -- C:\USERS\**NAME**\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\89EXXQ82.DEFAULT\EXTENSIONS\{68158704-666D-4655-A66F-E1A1A3AA6AC2} [2013.04.10 08:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.04.10 10:18:46 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.04.10 10:18:46 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.04.10 10:18:46 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.04.10 10:18:46 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.04.10 10:18:46 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.04.10 10:18:46 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKU\S-1-5-21-2252076472-839911540-1304659702-1000\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Getting started with MacDrive 8] C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe (Mediafour Corporation) O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) O4 - HKLM..\Run: [MacDrive 8 application] C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe (Mediafour Corporation) O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD) O4 - HKU\.DEFAULT..\RunOnce: [SPReview] C:\Windows\System32\SPReview\SPReview.exe (Microsoft Corporation) O4 - HKU\S-1-5-18..\RunOnce: [SPReview] C:\Windows\System32\SPReview\SPReview.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71DB1997-A1B9-4F5C-BD32-383F1BED20D2}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e63082c5-a2f8-11e2-93f3-001d72e49611}\Shell - "" = AutoRun O33 - MountPoints2\{e63082c5-a2f8-11e2-93f3-001d72e49611}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.15 21:15:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt [2013.04.15 14:09:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe [2013.04.14 10:54:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator [2013.04.14 10:54:41 | 000,088,576 | ---- | C] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll [2013.04.14 10:54:38 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator [2013.04.14 10:53:04 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Programs [2013.04.13 13:59:01 | 000,000,000 | ---D | C] -- C:\Vegas_Prerender [2013.04.13 13:58:12 | 000,000,000 | ---D | C] -- C:\Vegas_Data [2013.04.13 13:32:50 | 000,000,000 | ---D | C] -- C:\Acer [2013.04.13 13:31:06 | 000,000,000 | ---D | C] -- C:\Book [2013.04.13 13:30:15 | 000,000,000 | ---D | C] -- C:\Treiber [2013.04.13 13:25:11 | 000,000,000 | --SD | C] -- C:\Dropbox [2013.04.13 13:20:50 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\irgendwas [2013.04.13 13:20:47 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\DRUCK 29.8.12 [2013.04.13 13:20:32 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\DriveNavi_for_HD-HSQ [2013.04.13 13:20:31 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Desktop\BORKUM [2013.04.12 23:56:01 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\MAXON [2013.04.12 19:10:10 | 000,000,000 | ---D | C] -- C:\Installationen [2013.04.12 18:59:59 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Documents\ForceField Shared Files [2013.04.12 18:59:59 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\CheckPoint [2013.04.12 18:59:38 | 000,587,096 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys [2013.04.12 18:59:38 | 000,075,096 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klflt.sys [2013.04.12 18:59:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE [2013.04.12 18:59:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point [2013.04.12 18:56:32 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint [2013.04.12 18:55:04 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint [2013.04.12 18:50:11 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2013.04.12 18:49:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2013.04.12 18:48:31 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Macromedia [2013.04.12 18:48:03 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Adobe [2013.04.12 14:13:09 | 000,000,000 | ---D | C] -- C:\Program Files\Tipp10 [2013.04.12 14:06:51 | 000,057,800 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\drivers\CBDisk.sys [2013.04.12 14:06:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MacDrive 8 [2013.04.12 14:06:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Mediafour [2013.04.12 14:06:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mediafour [2013.04.12 14:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\Mediafour [2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\Documents\Ableton [2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Ableton [2013.04.12 01:25:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton [2013.04.12 01:24:20 | 000,233,472 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\REX Shared Library.dll [2013.04.12 01:24:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton [2013.04.12 01:24:19 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\ReWire.dll [2013.04.12 01:21:52 | 000,000,000 | ---D | C] -- C:\Program Files\Ableton [2013.04.12 00:48:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Publish Providers [2013.04.12 00:33:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony [2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Sony [2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony [2013.04.12 00:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2013.04.12 00:31:51 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Sony [2013.04.12 00:29:46 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Apple Computer [2013.04.12 00:23:42 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Apple Computer [2013.04.12 00:21:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2013.04.12 00:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime [2013.04.12 00:21:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2013.04.12 00:18:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2013.04.12 00:18:51 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Apple [2013.04.12 00:18:49 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update [2013.04.12 00:18:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2013.04.12 00:09:25 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Diagnostics [2013.04.11 23:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [2013.04.11 23:57:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works [2013.04.11 23:57:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2013.04.11 23:57:07 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2013.04.11 23:57:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET [2013.04.11 23:54:54 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Microsoft Help [2013.04.11 23:54:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2013.04.11 23:54:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help [2013.04.11 23:54:22 | 000,000,000 | RH-D | C] -- C:\MSOCache [2013.04.11 23:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.11 23:38:42 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Skype [2013.04.11 23:38:35 | 000,000,000 | R--D | C] -- C:\Program Files\Skype [2013.04.11 23:38:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2013.04.11 23:38:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2013.04.11 23:38:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype [2013.04.11 23:36:53 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\JAM Software [2013.04.11 23:36:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free [2013.04.11 23:36:51 | 000,000,000 | ---D | C] -- C:\Program Files\JAM Software [2013.04.11 23:33:38 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\REAPER [2013.04.11 23:33:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REAPER [2013.04.11 23:33:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software [2013.04.11 23:33:09 | 000,000,000 | ---D | C] -- C:\Program Files\REAPER [2013.04.11 23:30:33 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\vlc [2013.04.11 23:16:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.11 23:16:09 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.11 23:15:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.11 23:15:15 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.11 23:02:47 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2 [2013.04.11 23:02:47 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2 [2013.04.11 22:50:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Mozilla [2013.04.11 22:50:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Mozilla [2013.04.11 22:50:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2013.04.11 22:50:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013.04.11 22:50:14 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.11 22:26:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.04.11 22:26:02 | 000,368,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.04.11 22:26:02 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.04.11 22:26:00 | 000,060,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2013.04.11 22:25:59 | 000,062,376 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.04.11 22:25:58 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.04.11 22:25:54 | 000,228,600 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.11 22:25:54 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.04.11 22:24:42 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.04.11 22:24:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2013.04.11 22:22:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2013.04.11 21:44:24 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Adobe [2013.04.11 18:56:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview [2013.04.11 18:55:56 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders [2013.04.11 18:53:59 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\fms.dll [2013.04.11 17:21:29 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2013.04.11 17:21:14 | 000,000,000 | -HSD | C] -- C:\Boot [2013.04.11 17:04:54 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2013.04.11 16:53:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang [2013.04.11 16:53:57 | 000,000,000 | ---D | C] -- C:\Program Files\Intel [2013.04.11 16:49:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\x64 [2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Searches [2013.04.11 16:30:56 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2013.04.11 16:30:44 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Identities [2013.04.11 16:30:42 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Contacts [2013.04.11 16:30:34 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\VirtualStore [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Vorlagen [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Verlauf [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Temporary Internet Files [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Startmenü [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\SendTo [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Recent [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Netzwerkumgebung [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Lokale Einstellungen [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Videos [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Musik [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Eigene Dateien [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Documents\Eigene Bilder [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Druckumgebung [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Cookies [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\AppData\Local\Anwendungsdaten [2013.04.11 16:30:30 | 000,000,000 | -HSD | C] -- C:\Users\**NAME**\Anwendungsdaten [2013.04.11 16:30:29 | 000,000,000 | --SD | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Videos [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Saved Games [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Pictures [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Music [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Links [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Favorites [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Downloads [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Documents [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\Desktop [2013.04.11 16:30:29 | 000,000,000 | R--D | C] -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2013.04.11 16:30:29 | 000,000,000 | -H-D | C] -- C:\Users\**NAME**\AppData [2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Temp [2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Local\Microsoft [2013.04.11 16:30:29 | 000,000,000 | ---D | C] -- C:\Users\**NAME**\AppData\Roaming\Media Center Programs [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Recovery [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Programme [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2013.04.11 16:30:20 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2013.04.11 16:25:27 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2013.04.11 16:22:52 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2013.04.11 16:22:31 | 000,000,000 | -HSD | C] -- C:\System Volume Information ========== Files - Modified Within 30 Days ========== [2013.04.15 22:09:10 | 000,021,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 22:09:10 | 000,021,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.15 22:01:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.15 22:01:36 | 2408,390,656 | -HS- | M] () -- C:\hiberfil.sys [2013.04.15 16:56:46 | 000,613,083 | ---- | M] () -- C:\Users\**NAME**\Desktop\adwcleaner.exe [2013.04.15 15:38:10 | 000,001,129 | -H-- | M] () -- C:\Windows\System32\BTImages.dat [2013.04.15 14:10:10 | 000,000,000 | ---- | M] () -- C:\Users\**NAME**\defogger_reenable [2013.04.15 14:09:18 | 000,643,866 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.15 14:09:18 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.15 14:09:18 | 000,126,394 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.15 14:09:18 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.15 13:58:28 | 000,377,856 | ---- | M] () -- C:\Users\**NAME**\Desktop\gmer_2.1.19163.exe [2013.04.15 13:51:54 | 000,050,477 | ---- | M] () -- C:\Users\**NAME**\Desktop\Defogger.exe [2013.04.15 13:46:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\**NAME**\Desktop\OTL.exe [2013.04.14 10:54:45 | 000,000,989 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk [2013.04.12 19:02:34 | 000,417,507 | ---- | M] () -- C:\Windows\System32\drivers\vsconfig.xml [2013.04.12 14:00:25 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf [2013.04.12 00:47:28 | 000,002,540 | ---- | M] () -- C:\Users\**NAME**\Documents\Vegas Pro registrieren.htm [2013.04.12 00:00:06 | 000,301,088 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.11 23:46:42 | 000,007,597 | ---- | M] () -- C:\Users\**NAME**\AppData\Local\Resmon.ResmonCfg [2013.04.11 23:02:47 | 000,001,096 | ---- | M] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Instruction Manual.lnk [2013.04.11 22:25:54 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.04.11 21:06:29 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2013.04.11 17:48:58 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Browserwahl.lnk [2013.04.11 17:21:16 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2013.04.11 16:26:16 | 000,057,035 | ---- | M] () -- C:\Windows\System32\license.rtf [2013.03.30 14:58:42 | 001,321,553 | ---- | M] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Gesangskurs_Borkum.jpg [2013.03.30 14:58:42 | 001,304,191 | ---- | M] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Borkum_Doku.jpg ========== Files Created - No Company Name ========== [2013.04.15 21:22:29 | 000,001,118 | ---- | C] () -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.04.15 21:13:30 | 000,613,083 | ---- | C] () -- C:\Users\**NAME**\Desktop\adwcleaner.exe [2013.04.15 15:37:19 | 000,001,129 | -H-- | C] () -- C:\Windows\System32\BTImages.dat [2013.04.15 14:10:10 | 000,000,000 | ---- | C] () -- C:\Users\**NAME**\defogger_reenable [2013.04.15 14:09:14 | 000,377,856 | ---- | C] () -- C:\Users\**NAME**\Desktop\gmer_2.1.19163.exe [2013.04.15 14:08:59 | 000,050,477 | ---- | C] () -- C:\Users\**NAME**\Desktop\Defogger.exe [2013.04.14 10:54:45 | 000,000,989 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk [2013.04.13 13:20:54 | 001,499,884 | ---- | C] () -- C:\Users\**NAME**\Desktop\02 Spur 2.wma [2013.04.13 13:20:54 | 001,321,553 | ---- | C] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Gesangskurs_Borkum.jpg [2013.04.13 13:20:54 | 001,304,191 | ---- | C] () -- C:\Users\**NAME**\Desktop\Projektanmeldung_Protokoll_Borkum_Doku.jpg [2013.04.13 13:20:54 | 000,229,613 | ---- | C] () -- C:\Users\**NAME**\Desktop\zeiten.pdf [2013.04.13 13:20:54 | 000,057,176 | ---- | C] () -- C:\Users\**NAME**\Desktop\NINA_Exposé_290113.pdf [2013.04.13 13:20:54 | 000,000,894 | ---- | C] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Anleitung.lnk [2013.04.12 19:00:01 | 000,417,507 | ---- | C] () -- C:\Windows\System32\drivers\vsconfig.xml [2013.04.12 14:00:25 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf [2013.04.12 00:47:28 | 000,002,540 | ---- | C] () -- C:\Users\**NAME**\Documents\Vegas Pro registrieren.htm [2013.04.12 00:18:50 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2013.04.11 23:46:42 | 000,007,597 | ---- | C] () -- C:\Users\**NAME**\AppData\Local\Resmon.ResmonCfg [2013.04.11 23:41:23 | 000,001,132 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.11 23:02:47 | 000,001,096 | ---- | C] () -- C:\Users\**NAME**\Desktop\ASIO4ALL v2 Instruction Manual.lnk [2013.04.11 22:50:19 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.04.11 22:25:58 | 000,164,736 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.04.11 22:25:57 | 000,049,248 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.04.11 21:06:29 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2013.04.11 18:54:37 | 000,146,852 | ---- | C] () -- C:\Windows\System32\systemsf.ebd [2013.04.11 18:53:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2013.04.11 18:53:47 | 000,010,429 | ---- | C] () -- C:\Windows\System32\ScavengeSpace.xml [2013.04.11 18:53:44 | 000,105,559 | ---- | C] () -- C:\Windows\System32\RacRules.xml [2013.04.11 17:48:58 | 000,001,750 | ---- | C] () -- C:\Users\Public\Desktop\Browserwahl.lnk [2013.04.11 17:21:16 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK [2013.04.11 17:21:15 | 000,383,786 | RHS- | C] () -- C:\bootmgr [2013.04.11 16:53:57 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll [2013.04.11 16:53:57 | 000,121,232 | ---- | C] () -- C:\Windows\System32\IScrNB.bmp [2013.04.11 16:30:58 | 000,001,409 | ---- | C] () -- C:\Users\**NAME**\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2013.04.11 16:26:12 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2013.04.11 16:26:01 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2013.04.11 16:22:32 | 2408,390,656 | -HS- | C] () -- C:\hiberfil.sys ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2013.04.12 01:25:57 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Ableton [2013.04.12 18:59:59 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\CheckPoint [2013.04.12 18:50:11 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2013.04.13 00:00:20 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\JAM Software [2013.04.12 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\MAXON [2013.04.12 00:48:24 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Publish Providers [2013.04.11 23:36:11 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\REAPER [2013.04.12 01:03:17 | 000,000,000 | ---D | M] -- C:\Users\**NAME**\AppData\Roaming\Sony ========== Purity Check ========== < End of report > |
| Themen zu snap.do Startseite und Browserleiste (Firefox/Win7-32Bit) entfernen |
| antivirus, aswrvrt.sys, autorun, avast, awdcleaner, bho, chip.de, defender, entfernen, error, explorer, fehler, format, helper, install.exe, installation, kaspersky, logfile, mozilla, msvcrt, nicht möglich, ntdll.dll, problem, registry, rundll, scan, security, senden, services.exe, smartbar, snap do, svchost.exe, udp, windows internet |