Hallo, mich hat es heute erwischt, AVG Antivirus war wohl zu langsam. In meinem eingeschränkten Konto (WIN7 Ultimate) hat sich ein Virus eingenistet, sieht aus wie etwas von der Bundesregierung, ich soll angeblich irgendwas illegales gemacht haben .. Ich weiß garnicht wie dieser Plagegeist heißt . Ich habe auf mein nicht befallenes Admin Konto gewechselt um das hier schreiben zu können.. notfalls hätte ich noch ein Netbook. Habe schon mal Malwarebytes runtergeladen.. Habe mit AVG den kompletten Rechner gescannt, der hat wohl auch was gefunden und angeblich bereinigt, aber wenn ich wieder in mein Konto mit eingeschränkten Rechten gehe, legt sich die Seite wieder über den kpl.Bildschirm ..da hatte er wohl noch was anderes gefunden. Bitte um Eure Hilfe, danke!
Hi,
mal mit FRST reinschauen: Schritt 1 Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere diese auf einen USB Stick (nicht in einen Unterordner!). Schliesse den USB Stick an den infizierten Rechner an. Du musst das System nun in die System Reparatur Option booten: Variante 1 - Über den Boot Manager Wenn du jetzt in den Reparaturoptionen bist, wähle Eingabeaufforderung.
Bitte poste in deiner nächsten Antwort:
Danke!
leider ist F8 mit meiner USB Tastatur nicht machbar, ich versuche das booten von CD! Hier das FRST Log:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-04-2013 02 Ran by SYSTEM on 29-04-2013 15:40:14 Running from L:\ Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet001 ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe [37888 2010-10-21] (Hewlett-Packard ) HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-10] (IDT, Inc.) HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [415752 2009-08-13] (Logitech Inc.) HKLM\...\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2093064 2009-08-13] (Logitech Inc.) HKLM\...\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE [4195848 2009-08-13] (Logitech Inc.) HKLM\...\Run: [PrintDisp] C:\Windows\system32\PrintDisp.exe [828416 2011-08-08] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard) HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-05-17] (EasyBits Software AS) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1686528 2012-03-27] (Wondershare) HKLM-x32\...\Run: [PE2CKFNT SE] C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe [25088 1998-07-03] () HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-24] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2254768 2012-12-10] (LogMeIn Inc.) HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4394032 2013-03-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe" -osboot [295072 2013-01-19] (RealNetworks, Inc.) HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [Iminent] C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C" [1074736 2013-01-25] (Iminent) HKLM-x32\...\Run: [IminentMessenger] C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884784 2013-01-25] (Iminent) HKLM-x32\...\Run: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [210472 2006-10-24] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PaperPort PTD] "C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe" [29984 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] "C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe" [46368 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PPort11reminder] "C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" [328992 2007-08-30] (Nuance Communications, Inc.) HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1163264 2011-04-01] () HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.) HKU\Hermann\...\Run: [DymoQuickPrint] "C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe" /startup [1825360 2011-01-28] (Sanford, L.P.) HKU\Hermann\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [x] HKU\Hermann\...\Run: [WebCamRT.exe] C:\Program Files (x86)\Philips ToUcam Camera\SpotLife\WebCamRT.exe /WinStart /regkey=Software\Spotlife\Spotlife.5\WebCamSettings [x] HKU\Hermann\...\Run: [TrafficTravisv4] C:\Users\Hermann\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe [x] HKU\Hermann\...\Policies\system: [DisableLockWorkstation] 0 HKU\Hermann\...\Policies\system: [DisableChangePassword] 0 HKU\Hermann\...\Policies\system: [LogonHoursAction] 2 HKU\Hermann\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Hermann Neuer ADMIN\...\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus Photo PX730" [283232 2012-11-05] (SEIKO EPSON CORPORATION) HKU\Hermann Neuer ADMIN\...\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [1098072 2013-03-27] (Garmin Ltd or its subsidiaries) HKU\Hermann Neuer ADMIN\...\Policies\system: [LogonHoursAction] 2 HKU\Hermann Neuer ADMIN\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Hermann Surf\...\Run: [Epson Stylus Photo PX730(Netzwerk)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /FU "C:\Users\HERMAN~1\AppData\Local\Temp\E_SAF32.tmp" /EF "HKCU" [x] HKU\Hermann Surf\...\Run: [DymoQuickPrint] "C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe" /startup [1825360 2011-01-28] (Sanford, L.P.) HKU\Hermann Surf\...\Run: [TrafficTravisv4] C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe [17953280 2013-04-29] () HKU\Hermann Surf\...\Run: [ctfmon.exe] C:\PROGRA~3\rundll32.exe C:\PROGRA~3\8bzd6z.dat,FG00 [127488 2013-04-29] (?????????? ??????????2) HKU\Hermann Surf\...\Policies\system: [LogonHoursAction] 2 HKU\Hermann Surf\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Jessi\...\Run: [Epson Stylus Photo PX730(Netzwerk)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /FU "C:\Users\Jessi\AppData\Local\Temp\E_SB99F.tmp" /EF "HKCU" [x] HKU\Jessi\...\Run: [DymoQuickPrint] "C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe" /startup [1825360 2011-01-28] (Sanford, L.P.) HKU\Jessi\...\Run: [ICQ] "C:\Users\Jessi\AppData\Roaming\ICQ\Application\ICQ7M\ICQ.exe" silent loginmode=4 [127040 2012-11-22] (ICQ, LLC.) HKU\Jessi\...\Policies\system: [LogonHoursAction] 2 HKU\Jessi\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:ProgramData\Start Menu\Programs\Startup\Photo Express Calendar Checker SE.lnk ShortcutTarget: Photo Express Calendar Checker SE.lnk -> C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe (Ulead Systems, Inc.) Startup: C:ProgramData\Start Menu\Programs\Startup\Reality Fusion GameCam SE.lnk ShortcutTarget: Reality Fusion GameCam SE.lnk -> C:\Program Files (x86)\Philips ToUcam Camera\GameCam SE\Program\RFTray.exe () Startup: C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) Startup: C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk ShortcutTarget: msconfig.lnk -> C:\PROGRA~3\8bzd6z.dat (?????????? ??????????2) Startup: C:\Users\Jessi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Services (Whitelisted) ================= S2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-02-27] (AVG Technologies CZ, s.r.o.) S2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [282624 2013-02-18] (AVG Technologies CZ, s.r.o.) S2 BRA_Scheduler; C:\Program Files (x86)\Brother\bratimer.exe [98304 2012-12-11] () S2 CLKMSVC10_38F51D56; c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-24] (CyberLink) S2 DymoPnpService; C:\Program Files (x86)\DYMO\DYMO Label Software\DymoPnpService.exe [32336 2011-01-28] (Sanford, L.P.) S2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [610944 2012-07-28] (SEIKO EPSON CORPORATION) S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-27] (Garmin Ltd or its subsidiaries) S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () S2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [2795048 2013-04-03] (Iminent) S2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [327392 2012-01-13] () S3 DATEV Update-Service; "J:\DATEV\PROGRAMM\INSTALL\DvInesASDSvc.Exe" [x] ==================== Drivers (Whitelisted) ==================== S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-02-26] (AVG Technologies CZ, s.r.o.) S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-07] (AVG Technologies CZ, s.r.o.) S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-07] (AVG Technologies CZ, s.r.o.) S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-07] (AVG Technologies CZ, s.r.o.) S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-07] (AVG Technologies CZ, s.r.o.) S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-07] (AVG Technologies CZ, s.r.o.) S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [239416 2013-02-13] (AVG Technologies CZ, s.r.o.) S3 cmntnet; C:\Windows\System32\DRIVERS\cmntnet.sys [141824 2013-02-13] (Wireless Data Device) S3 cmnuusbser; C:\Windows\System32\DRIVERS\cmnuusbser.sys [123904 2013-02-13] (Wireless Device) S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-11-23] () S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S0 dmboot; S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-04-29 15:40 - 2013-04-29 15:40 - 00000000 ____D C:\FRST 2013-04-29 02:41 - 2013-04-29 02:41 - 00002632 ____A C:ProgramData\z6dzb8.js 2013-04-29 02:26 - 2013-04-29 02:26 - 00000000 ____D C:\Windows\pss 2013-04-29 02:21 - 2013-04-29 02:21 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\AuthenTec 2013-04-29 02:20 - 2013-04-29 02:20 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Symantec 2013-04-29 02:02 - 2013-04-29 02:02 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Hermann Neuer ADMIN\Downloads\mbam-setup- 2013-04-29 01:53 - 2013-04-29 02:00 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\vlc 2013-04-29 01:31 - 2013-04-29 01:31 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\Scansoft 2013-04-29 01:31 - 2013-04-29 01:31 - 00000000 ____A C:\Users\Hermann Neuer ADMIN\Sti_Trace.log 2013-04-29 01:27 - 2013-04-29 02:41 - 95023320 ___AT C:ProgramData\z6dzb8.pad 2013-04-29 01:27 - 2013-04-29 02:41 - 00000000 ____A C:ProgramData\as98213.txt 2013-04-29 01:27 - 2013-04-29 01:27 - 95023320 ___AT C:ProgramData\dzrol7.pad 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\8bzd6z.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\7lorzd.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00044544 ____A (Microsoft Corporation) C:ProgramData\rundll32.exe 2013-04-29 01:27 - 2013-04-29 01:27 - 00000152 ____A C:ProgramData\z6dzb8.reg 2013-04-29 01:27 - 2013-04-29 01:27 - 00000056 ____A C:ProgramData\z6dzb8.bat 2013-04-29 00:23 - 2013-04-29 00:23 - 00000094 ____A C:\Users\Hermann Surf\Documents\Seriennummer ScanSoft.txt 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\Documents\Eigene PaperPort-Dokumente 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\Zeon 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\ScanSoft 2013-04-29 00:07 - 2013-04-29 00:07 - 00000000 ___RD C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Brother 2013-04-28 23:56 - 2013-04-28 23:56 - 00002151 ____A C:\Users\Hermann Surf\Desktop\ControlCenter3.lnk 2013-04-25 02:02 - 2013-04-25 02:02 - 00055220 ____A C:\Users\Hermann Surf\Downloads\mod_flexytalk_1.0.zip 2013-04-25 00:33 - 2013-04-12 06:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-04-21 05:17 - 2013-04-21 05:25 - 00000000 __RAD C:\Jessis iPod 2013-04-19 00:07 - 2013-04-19 00:48 - 246370077 ____A C:\Users\Hermann Surf\Downloads\G-Queen.11.04.08.Anna.Shimizu.And.Azusa.Onodera.Vivente.1.JAP.XXX.720p.WMV-OHRLY_mov-world.net.rar 2013-04-16 00:34 - 2013-04-16 00:34 - 00586059 ____A C:\Users\Hermann Surf\Downloads\vertragsverlngerungenmai.zip 2013-04-15 06:41 - 2013-04-15 06:41 - 00005120 ____A C:\Users\Hermann Surf\Documents\Dokument1.zdl 2013-04-15 06:02 - 2013-04-15 06:41 - 00006144 ____A C:\Users\Hermann Surf\Documents\Buchstaben_mybetreuung.zdl 2013-04-15 05:33 - 2013-04-15 06:06 - 00010730 ____A C:\Users\Hermann Surf\Documents\wwwmybetreuung_AufklebeBuchstaben.odt 2013-04-15 05:27 - 2013-04-15 05:27 - 00001114 ____A C:\Users\Hermann Surf\Desktop\LibreOffice.lnk 2013-04-15 02:48 - 2013-04-15 02:48 - 00000000 ___RD C:\Users\Hermann Surf\AppData\Roaming\Brother 2013-04-13 04:21 - 2013-04-13 04:21 - 00000000 ____D C:\Users\Jessi\AppData\Local\Scansoft 2013-04-13 04:21 - 2013-04-13 04:21 - 00000000 ____A C:\Users\Jessi\Sti_Trace.log 2013-04-12 13:23 - 2013-04-12 13:23 - 00000000 ____D C:\Users\Hermann Surf\AppData\Local\Scansoft 2013-04-12 13:23 - 2013-04-12 13:23 - 00000000 ____A C:\Users\Hermann Surf\Sti_Trace.log 2013-04-12 13:20 - 2013-04-21 04:43 - 00000432 ____A C:\Windows\BRWMARK.INI 2013-04-12 13:20 - 2013-04-12 13:20 - 00000256 ____A C:\Windows\Brpfx04a.ini 2013-04-12 13:20 - 2013-04-12 13:20 - 00000093 ____A C:\Windows\brpcfx.ini 2013-04-12 13:19 - 2013-04-12 13:19 - 00000066 ____A C:\Windows\Brfaxrx.ini 2013-04-12 13:19 - 2013-04-12 13:19 - 00000050 ____A C:\Windows\System32\BD9320CW.DAT 2013-04-12 13:19 - 2013-04-12 13:19 - 00000000 ____D C:\Users\Public\Documents\BrFaxRx 2013-04-12 13:19 - 2011-03-01 08:53 - 00118784 ____N (Brother Industries,LTD.) C:\Windows\SysWOW64\BrMfNt.dll 2013-04-12 13:19 - 2010-02-09 07:22 - 00255488 ____N (brother) C:\Windows\System32\NSSRH64.dll 2013-04-12 13:19 - 2009-10-26 00:34 - 00059392 ____N (Brother Industries,Ltd.) C:\Windows\System32\BrWiaNCp.dll 2013-04-12 13:19 - 2009-10-26 00:34 - 00048640 ____N (Brother Industries,Ltd) C:\Windows\System32\Brnsplg.dll 2013-04-12 13:19 - 2009-08-18 09:38 - 00083968 ____N (Brother Industries, Ltd.) C:\Windows\System32\BrNetSti.dll 2013-04-12 13:19 - 2008-10-17 10:04 - 00179712 ____N (Brother Industries, Ltd.) C:\Windows\System32\BrfxDA5b.dll 2013-04-12 13:19 - 2008-06-17 05:33 - 00167936 ____N (brother) C:\Windows\SysWOW64\NSSearch.dll 2013-04-12 13:19 - 2007-12-13 12:16 - 00005632 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2L.dll 2013-04-12 13:19 - 2006-07-07 02:40 - 00073728 ____N (Brother Industories Ltd. P&S Company) C:\Windows\SysWOW64\BRCrypt.dll 2013-04-12 13:19 - 2005-04-22 03:36 - 00143360 ____N C:\Windows\System32\BrSNMP64.dll 2013-04-12 13:19 - 2003-11-28 08:57 - 00000000 ____A C:\Windows\brdfxspd.dat 2013-04-12 13:19 - 2002-11-26 03:43 - 00106496 ____N C:\Windows\SysWOW64\BrMuSNMP.dll 2013-04-12 13:16 - 2010-05-10 07:45 - 00103736 ____A (Brother Industries Ltd) C:\Windows\SysWOW64\BRRBTOOL.EXE 2013-04-12 13:16 - 2010-04-02 04:33 - 00025299 ____A (Brother Industries, Ltd) C:\Windows\SysWOW64\BRLM03A.DLL 2013-04-12 13:16 - 2010-01-12 01:02 - 01560576 ____A (Brother Industries, Ltd.) C:\Windows\System32\BrWi209c.dll 2013-04-12 13:16 - 2009-01-15 09:20 - 00003072 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2S.dll 2013-04-12 13:16 - 2007-12-13 12:16 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2.dll 2013-04-12 13:16 - 2006-12-21 01:23 - 00176128 ____A (Brother Industries, Ltd.) C:\Windows\SysWOW64\BROSNMP.DLL 2013-04-12 13:16 - 2005-01-17 06:10 - 00045056 ____A C:\Windows\SysWOW64\BRTCPCON.DLL 2013-04-12 13:16 - 2004-08-09 06:00 - 00000114 ____A C:\Windows\SysWOW64\BRLMW03A.INI 2013-04-12 13:16 - 2004-08-09 05:42 - 00077824 ____A (Brother Industries, Ltd.) C:\Windows\SysWOW64\BRLMW03A.DLL 2013-04-12 13:16 - 1999-10-26 15:00 - 00000050 ____A C:\Windows\System32\BRADC08A.DAT 2013-04-12 13:13 - 2013-04-12 13:21 - 00000000 ____D C:ProgramData\InstallShield 2013-04-12 13:13 - 2013-04-12 13:13 - 00000000 ____D C:\Program Files\Nuance 2013-04-12 13:13 - 2008-03-28 03:24 - 00031864 ____A C:\Windows\maxlink.ini 2013-04-12 13:12 - 2013-04-12 13:13 - 00000000 ____D C:ProgramData\ScanSoft 2013-04-12 13:12 - 2013-04-12 13:12 - 00000000 ____D C:\Program Files (x86)\ScanSoft 2013-04-12 13:11 - 2013-04-12 13:20 - 00000000 ____D C:ProgramData\Brother 2013-04-12 11:08 - 2013-04-12 11:08 - 00000000 ____D C:\Users\Jessi\AppData\Roaming\ExpressDownloader 2013-04-12 11:07 - 2013-04-12 11:07 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl64_01009.Wdf 2013-04-12 03:08 - 2013-04-12 03:09 - 17881976 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite.eps 2013-04-12 03:02 - 2013-04-12 03:09 - 00000132 ____A C:\Users\Hermann Surf\AppData\Roaming\Adobe PNG Format CS5 Prefs 2013-04-12 03:02 - 2013-04-12 03:02 - 01754178 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite copy.psd 2013-04-12 02:56 - 2013-04-12 03:08 - 11371143 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite.psd 2013-04-10 09:32 - 2013-04-21 05:05 - 11657101 ____A C:\Users\Hermann Surf\Documents\Flyer A4 Balikbayan Rückseite.psd 2013-04-10 09:00 - 2013-02-21 02:30 - 01766912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-04-10 09:00 - 2013-02-21 02:30 - 01129984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 14323200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 13761024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 02046464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-04-10 09:00 - 2013-02-21 02:29 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-04-10 09:00 - 2013-02-21 02:15 - 02240512 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-04-10 09:00 - 2013-02-21 02:15 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-04-10 09:00 - 2013-02-21 02:14 - 19230208 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 02647040 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-04-10 09:00 - 2013-02-21 02:14 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-04-10 09:00 - 2013-02-19 04:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-04-10 09:00 - 2013-02-19 03:42 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-04-10 09:00 - 2013-02-19 03:10 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-04-10 09:00 - 2013-02-19 02:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-04-10 04:42 - 2013-04-10 04:42 - 00000000 ____D C:\Users\Public\Documents\sun 2013-04-10 04:42 - 2013-04-10 04:42 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\LibreOffice 2013-04-10 01:21 - 2013-04-10 01:21 - 00001096 ____A C:\Users\Public\Desktop\LibreOffice 4.0.lnk 2013-04-10 01:20 - 2013-04-10 01:21 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4.0 2013-04-10 01:10 - 2013-04-10 01:12 - 193572864 ____A C:\Users\Hermann Surf\Downloads\LibreOffice_4.0.2_Win_x86.msi 2013-04-10 00:59 - 2013-03-18 22:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-04-10 00:59 - 2013-03-18 21:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2013-04-10 00:59 - 2013-03-18 21:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-04-10 00:59 - 2013-03-18 21:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-04-10 00:59 - 2013-03-18 20:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-04-10 00:59 - 2013-03-18 19:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe 2013-04-10 00:59 - 2013-02-28 19:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-04-10 00:59 - 2013-02-14 22:08 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2013-04-10 00:59 - 2013-02-14 22:06 - 03717632 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2013-04-10 00:59 - 2013-02-14 22:02 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll 2013-04-10 00:59 - 2013-02-14 20:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-04-10 00:59 - 2013-02-14 20:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-04-10 00:59 - 2013-02-14 19:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-04-10 00:59 - 2013-01-23 22:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys 2013-04-06 09:56 - 2013-04-06 09:56 - 00000579 ____A C:\Users\Hermann Surf\Documents\AdobePhotoshop_CS5_Serials.txt 2013-04-04 10:16 - 2013-04-04 10:16 - 04889704 ____A (TeamViewer GmbH) C:\Users\Jessi\Downloads\TeamViewer_Setup_de_8.0.1739.exe 2013-04-04 10:16 - 2013-04-04 10:16 - 00000000 ____D C:\Users\Jessi\AppData\Roaming\TeamViewer 2013-04-04 09:51 - 2013-04-04 09:52 - 24842968 ____A (DVDVideoSoft Ltd. ) C:\Users\Jessi\Downloads\FreeYouTubeToMP3Converter_3.12.1.320.exe 2013-04-04 06:54 - 2013-04-04 06:54 - 00005185 ____A C:\Users\Hermann Surf\AppData\Local\recently-used.xbel 2013-04-04 00:41 - 2013-04-04 00:41 - 00001890 ____A C:\Users\Public\Desktop\Garmin Express.lnk 2013-04-04 00:41 - 2013-04-04 00:41 - 00000000 ____D C:ProgramData\Package Cache 2013-04-04 00:41 - 2013-04-04 00:41 - 00000000 ____D C:ProgramData\Garmin 2013-04-04 00:38 - 2013-04-04 00:38 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Iminent 2013-03-31 00:38 - 2013-03-31 00:38 - 00211898 ____A C:\Users\Hermann Surf\Downloads\DLV_B_Schorn.tif ==================== One Month Modified Files and Folders ======= 2013-04-29 15:40 - 2013-04-29 15:40 - 00000000 ____D C:\FRST 2013-04-29 04:36 - 2011-11-23 18:59 - 00000000 ____D C:ProgramData\NVIDIA 2013-04-29 04:36 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-29 04:36 - 2009-07-13 20:51 - 00001682 ____A C:\Windows\setupact.log 2013-04-29 04:21 - 2012-04-24 15:01 - 01193058 ____A C:\Windows\WindowsUpdate.log 2013-04-29 04:19 - 2012-04-26 23:52 - 00001908 ____A C:\Windows\diagwrn.xml 2013-04-29 04:19 - 2012-04-26 23:52 - 00001908 ____A C:\Windows\diagerr.xml 2013-04-29 04:15 - 2009-07-13 20:45 - 00030208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-29 04:15 - 2009-07-13 20:45 - 00030208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-29 04:14 - 2009-07-13 20:51 - 00000000 ____A C:\Windows\setuperr.log 2013-04-29 04:08 - 2012-11-05 01:09 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\LogMeIn Hamachi 2013-04-29 04:08 - 2012-05-03 02:39 - 00001108 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-04-29 04:04 - 2012-05-03 02:39 - 00001112 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-04-29 04:03 - 2011-11-23 18:47 - 00698514 ____A C:\Windows\System32\perfh007.dat 2013-04-29 04:03 - 2011-11-23 18:47 - 00148570 ____A C:\Windows\System32\perfc007.dat 2013-04-29 04:03 - 2009-07-13 21:13 - 01612484 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-29 03:28 - 2012-04-24 21:38 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-04-29 02:42 - 2012-10-18 22:40 - 00000000 ___RD C:\Users\Hermann Surf\Dropbox 2013-04-29 02:42 - 2012-10-18 22:38 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\Dropbox 2013-04-29 02:41 - 2013-04-29 02:41 - 00002632 ____A C:ProgramData\z6dzb8.js 2013-04-29 02:41 - 2013-04-29 01:27 - 95023320 ___AT C:ProgramData\z6dzb8.pad 2013-04-29 02:41 - 2013-04-29 01:27 - 00000000 ____A C:ProgramData\as98213.txt 2013-04-29 02:41 - 2012-10-30 07:54 - 00000000 ____D C:\Users\Hermann Surf\AppData\Local\LogMeIn Hamachi 2013-04-29 02:26 - 2013-04-29 02:26 - 00000000 ____D C:\Windows\pss 2013-04-29 02:21 - 2013-04-29 02:21 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\AuthenTec 2013-04-29 02:20 - 2013-04-29 02:20 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Symantec 2013-04-29 02:02 - 2013-04-29 02:02 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Hermann Neuer ADMIN\Downloads\mbam-setup- 2013-04-29 02:00 - 2013-04-29 01:53 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\vlc 2013-04-29 01:32 - 2012-12-12 06:20 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\Avg2013 2013-04-29 01:32 - 2012-10-29 08:33 - 00132344 ____A C:\Users\Hermann Neuer ADMIN\AppData\Local\GDIPFONTCACHEV1.DAT 2013-04-29 01:31 - 2013-04-29 01:31 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Local\Scansoft 2013-04-29 01:31 - 2013-04-29 01:31 - 00000000 ____A C:\Users\Hermann Neuer ADMIN\Sti_Trace.log 2013-04-29 01:31 - 2012-10-29 08:32 - 00000000 ____D C:\users\Hermann Neuer ADMIN 2013-04-29 01:27 - 2013-04-29 01:27 - 95023320 ___AT C:ProgramData\dzrol7.pad 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\8bzd6z.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\7lorzd.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00044544 ____A (Microsoft Corporation) C:ProgramData\rundll32.exe 2013-04-29 01:27 - 2013-04-29 01:27 - 00000152 ____A C:ProgramData\z6dzb8.reg 2013-04-29 01:27 - 2013-04-29 01:27 - 00000056 ____A C:ProgramData\z6dzb8.bat 2013-04-29 00:27 - 2012-10-30 08:07 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4 2013-04-29 00:25 - 2012-10-11 03:08 - 00000000 ____D C:\Users\Hermann Surf\Documents\DYMO Label 2013-04-29 00:23 - 2013-04-29 00:23 - 00000094 ____A C:\Users\Hermann Surf\Documents\Seriennummer ScanSoft.txt 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\Documents\Eigene PaperPort-Dokumente 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\Zeon 2013-04-29 00:20 - 2013-04-29 00:20 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\ScanSoft 2013-04-29 00:07 - 2013-04-29 00:07 - 00000000 ___RD C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Brother 2013-04-28 23:56 - 2013-04-28 23:56 - 00002151 ____A C:\Users\Hermann Surf\Desktop\ControlCenter3.lnk 2013-04-28 23:52 - 2012-04-24 14:12 - 00000000 ____D C:ProgramData\MFAData 2013-04-28 23:46 - 2011-11-23 19:16 - 00000000 ____D C:ProgramData\truesuite 2013-04-26 09:26 - 2012-10-29 14:29 - 00000000 ____D C:\Users\Jessi\AppData\Local\LogMeIn Hamachi 2013-04-25 02:02 - 2013-04-25 02:02 - 00055220 ____A C:\Users\Hermann Surf\Downloads\mod_flexytalk_1.0.zip 2013-04-23 23:39 - 2012-09-24 00:38 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\vlc 2013-04-21 05:25 - 2013-04-21 05:17 - 00000000 __RAD C:\Jessis iPod 2013-04-21 05:05 - 2013-04-10 09:32 - 11657101 ____A C:\Users\Hermann Surf\Documents\Flyer A4 Balikbayan Rückseite.psd 2013-04-21 04:43 - 2013-04-12 13:20 - 00000432 ____A C:\Windows\BRWMARK.INI 2013-04-19 11:29 - 2012-05-04 12:24 - 00000000 ____D C:\Users\Jessi\AppData\Roaming\Skype 2013-04-19 00:48 - 2013-04-19 00:07 - 246370077 ____A C:\Users\Hermann Surf\Downloads\G-Queen.11.04.08.Anna.Shimizu.And.Azusa.Onodera.Vivente.1.JAP.XXX.720p.WMV-OHRLY_mov-world.net.rar 2013-04-16 00:34 - 2013-04-16 00:34 - 00586059 ____A C:\Users\Hermann Surf\Downloads\vertragsverlngerungenmai.zip 2013-04-15 06:41 - 2013-04-15 06:41 - 00005120 ____A C:\Users\Hermann Surf\Documents\Dokument1.zdl 2013-04-15 06:41 - 2013-04-15 06:02 - 00006144 ____A C:\Users\Hermann Surf\Documents\Buchstaben_mybetreuung.zdl 2013-04-15 06:06 - 2013-04-15 05:33 - 00010730 ____A C:\Users\Hermann Surf\Documents\wwwmybetreuung_AufklebeBuchstaben.odt 2013-04-15 05:27 - 2013-04-15 05:27 - 00001114 ____A C:\Users\Hermann Surf\Desktop\LibreOffice.lnk 2013-04-15 02:48 - 2013-04-15 02:48 - 00000000 ___RD C:\Users\Hermann Surf\AppData\Roaming\Brother 2013-04-15 02:22 - 2012-07-16 00:19 - 00000000 ____D C:ProgramData\Adobe 2013-04-15 02:21 - 2012-04-24 21:38 - 00691592 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-04-15 02:21 - 2011-11-23 19:08 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-04-13 04:21 - 2013-04-13 04:21 - 00000000 ____D C:\Users\Jessi\AppData\Local\Scansoft 2013-04-13 04:21 - 2013-04-13 04:21 - 00000000 ____A C:\Users\Jessi\Sti_Trace.log 2013-04-13 04:21 - 2012-04-30 08:54 - 00132344 ____A C:\Users\Jessi\AppData\Local\GDIPFONTCACHEV1.DAT 2013-04-13 04:21 - 2012-04-30 08:26 - 00000000 ____D C:\users\Jessi 2013-04-12 13:24 - 2009-07-13 20:45 - 05060032 ____A C:\Windows\System32\FNTCACHE.DAT 2013-04-12 13:23 - 2013-04-12 13:23 - 00000000 ____D C:\Users\Hermann Surf\AppData\Local\Scansoft 2013-04-12 13:23 - 2013-04-12 13:23 - 00000000 ____A C:\Users\Hermann Surf\Sti_Trace.log 2013-04-12 13:23 - 2012-09-23 23:14 - 00132344 ____A C:\Users\Hermann Surf\AppData\Local\GDIPFONTCACHEV1.DAT 2013-04-12 13:23 - 2012-09-23 23:12 - 00000000 ____D C:\users\Hermann Surf 2013-04-12 13:22 - 2010-11-20 19:47 - 00724412 ____A C:\Windows\PFRO.log 2013-04-12 13:21 - 2013-04-12 13:13 - 00000000 ____D C:ProgramData\InstallShield 2013-04-12 13:20 - 2013-04-12 13:20 - 00000256 ____A C:\Windows\Brpfx04a.ini 2013-04-12 13:20 - 2013-04-12 13:20 - 00000093 ____A C:\Windows\brpcfx.ini 2013-04-12 13:20 - 2013-04-12 13:11 - 00000000 ____D C:ProgramData\Brother 2013-04-12 13:19 - 2013-04-12 13:19 - 00000066 ____A C:\Windows\Brfaxrx.ini 2013-04-12 13:19 - 2013-04-12 13:19 - 00000050 ____A C:\Windows\System32\BD9320CW.DAT 2013-04-12 13:19 - 2013-04-12 13:19 - 00000000 ____D C:\Users\Public\Documents\BrFaxRx 2013-04-12 13:19 - 2013-03-25 03:12 - 00000000 ____D C:\Program Files (x86)\Brother 2013-04-12 13:16 - 2011-11-23 19:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-04-12 13:13 - 2013-04-12 13:13 - 00000000 ____D C:\Program Files\Nuance 2013-04-12 13:13 - 2013-04-12 13:12 - 00000000 ____D C:ProgramData\ScanSoft 2013-04-12 13:12 - 2013-04-12 13:12 - 00000000 ____D C:\Program Files (x86)\ScanSoft 2013-04-12 11:08 - 2013-04-12 11:08 - 00000000 ____D C:\Users\Jessi\AppData\Roaming\ExpressDownloader 2013-04-12 11:07 - 2013-04-12 11:07 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl64_01009.Wdf 2013-04-12 06:45 - 2013-04-25 00:33 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-04-12 03:09 - 2013-04-12 03:08 - 17881976 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite.eps 2013-04-12 03:09 - 2013-04-12 03:02 - 00000132 ____A C:\Users\Hermann Surf\AppData\Roaming\Adobe PNG Format CS5 Prefs 2013-04-12 03:08 - 2013-04-12 02:56 - 11371143 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite.psd 2013-04-12 03:02 - 2013-04-12 03:02 - 01754178 ____A C:\Users\Hermann Surf\Documents\Flyer halb A4 Balikbayan Rückseite copy.psd 2013-04-12 02:47 - 2012-05-03 02:40 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-04-10 09:24 - 2012-11-05 09:53 - 00000000 ____D C:\Users\Hermann Surf\AppData\Local\CrashDumps 2013-04-10 09:01 - 2012-04-24 21:41 - 72702784 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-04-10 09:01 - 2009-07-13 18:34 - 00000650 ____A C:\Windows\win.ini 2013-04-10 04:42 - 2013-04-10 04:42 - 00000000 ____D C:\Users\Public\Documents\sun 2013-04-10 04:42 - 2013-04-10 04:42 - 00000000 ____D C:\Users\Hermann Surf\AppData\Roaming\LibreOffice 2013-04-10 01:21 - 2013-04-10 01:21 - 00001096 ____A C:\Users\Public\Desktop\LibreOffice 4.0.lnk 2013-04-10 01:21 - 2013-04-10 01:20 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4.0 2013-04-10 01:12 - 2013-04-10 01:10 - 193572864 ____A C:\Users\Hermann Surf\Downloads\LibreOffice_4.0.2_Win_x86.msi 2013-04-10 00:56 - 2012-10-16 07:22 - 00000000 ____D C:\Users\Hermann Surf\Documents\Steuerfälle 2013-04-08 01:44 - 2012-12-12 06:49 - 00000983 ____A C:\Users\Public\Desktop\AVG 2013.lnk 2013-04-06 09:56 - 2013-04-06 09:56 - 00000579 ____A C:\Users\Hermann Surf\Documents\AdobePhotoshop_CS5_Serials.txt 2013-04-04 10:16 - 2013-04-04 10:16 - 04889704 ____A (TeamViewer GmbH) C:\Users\Jessi\Downloads\TeamViewer_Setup_de_8.0.1739.exe 2013-04-04 10:16 - 2013-04-04 10:16 - 00000000 ____D C:\Users\Jessi\AppData\Roaming\TeamViewer 2013-04-04 09:52 - 2013-04-04 09:51 - 24842968 ____A (DVDVideoSoft Ltd. ) C:\Users\Jessi\Downloads\FreeYouTubeToMP3Converter_3.12.1.320.exe 2013-04-04 06:55 - 2013-01-08 02:29 - 00002301 ____A C:\Users\Public\Desktop\Steuer-Spar- Erklärung Selbstständige 2013.lnk 2013-04-04 06:54 - 2013-04-04 06:54 - 00005185 ____A C:\Users\Hermann Surf\AppData\Local\recently-used.xbel 2013-04-04 00:41 - 2013-04-04 00:41 - 00001890 ____A C:\Users\Public\Desktop\Garmin Express.lnk 2013-04-04 00:41 - 2013-04-04 00:41 - 00000000 ____D C:ProgramData\Package Cache 2013-04-04 00:41 - 2013-04-04 00:41 - 00000000 ____D C:ProgramData\Garmin 2013-04-04 00:41 - 2012-10-29 08:33 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Garmin 2013-04-04 00:41 - 2012-06-27 04:39 - 00000000 ____D C:\Program Files (x86)\Garmin 2013-04-04 00:40 - 2012-08-20 12:43 - 00000000 ____D C:\Program Files (x86)\Philips ToUcam Camera 2013-04-04 00:38 - 2013-04-04 00:38 - 00000000 ____D C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Iminent 2013-04-02 04:19 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache 2013-03-31 00:51 - 2012-10-18 22:40 - 00001044 ____A C:\Users\Hermann Surf\Desktop\Dropbox.lnk 2013-03-31 00:38 - 2013-03-31 00:38 - 00211898 ____A C:\Users\Hermann Surf\Downloads\DLV_B_Schorn.tif Other Malware: =========== C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\\msconfig.lnk ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-04-10 01:20:13 Restore point made on: 2013-04-10 09:00:17 Restore point made on: 2013-04-12 13:12:00 Restore point made on: 2013-04-12 13:13:30 Restore point made on: 2013-04-12 13:15:59 Restore point made on: 2013-04-12 13:19:36 Restore point made on: 2013-04-12 13:20:12 Restore point made on: 2013-04-14 09:13:43 Restore point made on: 2013-04-22 11:28:41 Restore point made on: 2013-04-25 07:01:58 Restore point made on: 2013-04-28 23:57:46 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 12268.32 MB Available physical RAM: 11072.77 MB Total Pagefile: 12266.52 MB Available Pagefile: 11062.7 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:926.94 GB) (Free:771.73 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Datenpartition) (Fixed) (Total:922.84 GB) (Free:796.15 GB) NTFS (Disk=0 Partition=4) Drive f: (HP_RECOVERY) (Fixed) (Total:13.13 GB) (Free:1.62 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)] Drive g: (W7SP1_ULTIMATE) (CDROM) (Total:5.23 GB) (Free:0 GB) UDF Drive l: (FREI8GB) (Removable) (Total:7.46 GB) (Free:7.46 GB) FAT32 (Disk=5 Partition=1) Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 1863 GB 1024 KB Datentr„ger 1 Kein Medium 0 B 0 B Datentr„ger 2 Kein Medium 0 B 0 B Datentr„ger 3 Kein Medium 0 B 0 B Datentr„ger 4 Kein Medium 0 B 0 B Datentr„ger 5 Online 7656 MB 0 B Partitions of Disk 0: =============== Datentr„ger-ID: 40DB00A1 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 100 MB 1024 KB Partition 2 Prim„r 926 GB 101 MB Partition 0 Erweitert 922 GB 927 GB Partition 4 Logisch 922 GB 927 GB Partition 3 Prim„r 13 GB 1849 GB ================================================================================== Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 Y SYSTEM NTFS Partition 100 MB Fehlerfre ========================================================= Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C OS NTFS Partition 926 GB Fehlerfre ========================================================= Disk: 0 Partition 4 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 D Datenpartit NTFS Partition 922 GB Fehlerfre ========================================================= Disk: 0 Partition 3 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 F HP_RECOVERY NTFS Partition 13 GB Fehlerfre ========================================================= Partitions of Disk 5: =============== Datentr„ger-ID: C3072E18 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 7652 MB 4032 KB ================================================================================== Disk: 5 Partition 1 Typ : 0B Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 9 L FREI8GB FAT32 Wechselmed 7652 MB Fehlerfre ========================================================= ============================== MBR & Partition Table ================== ==================================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 40DB00A1) Partition 1: (Active) - (Size=100 MB) - (Type=07) (NTFS) Partition 2: (Not Active) - (Size=927 GB) - (Type=07) (NTFS) Partition 3: (Not Active) - (Size=923 GB) - (Type=OF) (Extended) Partition 4: (Not Active) - (Size=13 GB) - (Type=07) (NTFS) ==================================================================== Disk: 5 (MBR Code: Windows XP) (Size: 7 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=7 GB) - (Type=0B) Last Boot: 2013-04-23 23:58 ==================== End Of Log ============================ Geändert von hardyxy9 (29.04.2013 um 13:26 Uhr) |
Hi, kannst du nach folgendem Fix wieder normal in das befallene Benutzerkonto starten? Schritt 1 Drücke auf einem Zweitrechner bitte die
ATTFilter HKU\Hermann Surf\...\Run: [ctfmon.exe] C:\PROGRA~3\rundll32.exe C:\PROGRA~3\8bzd6z.dat,FG00 [127488 2013-04-29] (?????????? ??????????2) Startup: C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk 2013-04-29 02:41 - 2013-04-29 02:41 - 00002632 ____A C:ProgramData\z6dzb8.js 2013-04-29 01:27 - 2013-04-29 02:41 - 95023320 ___AT C:ProgramData\z6dzb8.pad 2013-04-29 01:27 - 2013-04-29 02:41 - 00000000 ____A C:ProgramData\as98213.txt 2013-04-29 01:27 - 2013-04-29 01:27 - 95023320 ___AT C:ProgramData\dzrol7.pad 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\8bzd6z.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\7lorzd.dat 2013-04-29 01:27 - 2013-04-29 01:27 - 00044544 ____A (Microsoft Corporation) C:ProgramData\rundll32.exe 2013-04-29 01:27 - 2013-04-29 01:27 - 00000152 ____A C:ProgramData\z6dzb8.reg 2013-04-29 01:27 - 2013-04-29 01:27 - 00000056 ____A C:ProgramData\z6dzb8.bat
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
Ich habe hoffentlich alles richtig gemacht: FIXLOG
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-04-2013 02 Ran by SYSTEM at 2013-04-29 16:58:38 Run:1 Running from L:\ Boot Mode: Recovery ============================================== HKEY_USERS\Hermann Surf\Software\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe value not found. C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk moved successfully. 2013-04-29 02:41 - 2013-04-29 02:41 - 00002632 ____A C:ProgramData\z6dzb8.js => File not found. 2013-04-29 01:27 - 2013-04-29 02:41 - 95023320 ___AT C:ProgramData\z6dzb8.pad => File not found. 2013-04-29 01:27 - 2013-04-29 02:41 - 00000000 ____A C:ProgramData\as98213.txt => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 95023320 ___AT C:ProgramData\dzrol7.pad => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\8bzd6z.dat => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 00127488 ____A (?????????? ??????????2) C:ProgramData\7lorzd.dat => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 00044544 ____A (Microsoft Corporation) C:ProgramData\rundll32.exe => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 00000152 ____A C:ProgramData\z6dzb8.reg => File not found. 2013-04-29 01:27 - 2013-04-29 01:27 - 00000056 ____A C:ProgramData\z6dzb8.bat => File not found. ==== End of Fixlog ==== Die Antwort ist: JA, die Seite taucht nicht mehr auf. Danke, Du bist einfach spitze! Kommt jetzt noch was ..? |
Ok, dann mach in diesem Konto bitte einen OTL-Scan: Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
__________________ --> WIN7 eingeschränktes Konto nicht nutzbar / soll 100€ zahlen ? |
[AVG AntiVirus hat dabei angeschlagen und das gemeldet (warum erst jetzt...?): "";"Virus identifiziert: JS/Agent.Z, c:\ProgramData\z6dzb8.js";"Infiziert" | Ich habe auf 'entfernen' geklickt.]
ATTFilter OTL logfile created on: 4/29/2013 5:11:06 PM - Run 1 OTL by OldTimer - Version Folder = C:\Users\Hermann Surf\Downloads 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 11.98 Gb Total Physical Memory | 9.48 Gb Available Physical Memory | 79.11% Memory free 23.96 Gb Paging File | 21.21 Gb Available in Paging File | 88.52% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 926.94 Gb Total Space | 771.71 Gb Free Space | 83.25% Space Free | Partition Type: NTFS Drive D: | 13.13 Gb Total Space | 1.62 Gb Free Space | 12.31% Space Free | Partition Type: NTFS Drive J: | 922.84 Gb Total Space | 796.15 Gb Free Space | 86.27% Space Free | Partition Type: NTFS Computer Name: HERMANN-HP | User Name: Hermann Neuer ADMIN | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - File not found -- PRC - [2013/04/29 17:09:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hermann Surf\Downloads\OTL.exe PRC - [2013/04/29 10:27:23 | 017,953,280 | ---- | M] () -- C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe PRC - [2013/04/15 12:21:49 | 001,855,880 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe PRC - [2013/04/03 16:05:21 | 002,795,048 | ---- | M] (Iminent) -- C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe PRC - [2013/03/27 16:17:42 | 000,185,688 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe PRC - [2013/03/13 17:15:00 | 004,394,032 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe PRC - [2013/03/12 09:05:50 | 029,106,336 | ---- | M] (Dropbox, Inc.) -- C:\Users\Hermann Surf\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2013/02/27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe PRC - [2013/02/19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe PRC - [2013/01/25 14:47:00 | 001,074,736 | ---- | M] (Iminent) -- C:\Program Files (x86)\Iminent\Iminent.exe PRC - [2013/01/25 14:47:00 | 000,884,784 | ---- | M] (Iminent) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe PRC - [2013/01/19 16:32:58 | 000,295,072 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\real\realplayer\Update\realsched.exe PRC - [2012/12/18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/12/11 11:02:40 | 000,098,304 | ---- | M] () -- C:\Program Files (x86)\Brother\bratimer.exe PRC - [2012/12/10 18:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe PRC - [2012/11/05 12:31:52 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012/06/11 17:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe PRC - [2012/01/14 08:26:31 | 000,327,392 | ---- | M] () -- C:\Program Files (x86)\XSManager\WTGService.exe PRC - [2011/06/09 15:37:00 | 000,653,128 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe PRC - [2011/06/09 15:36:34 | 000,142,664 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe PRC - [2011/03/30 10:41:10 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2011/03/29 03:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe PRC - [2011/02/24 10:10:24 | 000,212,944 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe PRC - [2011/02/01 09:41:24 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011/02/01 09:41:20 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2011/01/28 21:32:40 | 001,825,360 | ---- | M] (Sanford, L.P.) -- C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe PRC - [2010/11/21 05:25:10 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe PRC - [2010/10/12 13:56:40 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe PRC - [2010/04/23 22:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe PRC - [2009/08/13 17:37:44 | 000,522,760 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe PRC - [2009/02/24 15:47:06 | 000,143,360 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe PRC - [2008/11/20 20:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe PRC - [2008/10/24 16:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe PRC - [2000/08/17 17:40:20 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\Philips ToUcam Camera\GameCam SE\Program\RFTray.exe PRC - [1998/09/17 16:34:26 | 000,055,296 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe ========== Modules (No Company Name) ========== MOD - [2013/04/29 10:27:23 | 017,953,280 | ---- | M] () -- C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe MOD - [2013/04/15 12:21:49 | 016,032,648 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll MOD - [2013/02/14 18:20:33 | 000,148,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\12630df9abc4ebf7ff67de989b8e8123\System.Configuration.Install.ni.dll MOD - [2013/02/13 20:04:07 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\39f4c7717661667c68f9af8c4f6402b9\System.Windows.Forms.ni.dll MOD - [2013/01/10 20:45:41 | 001,078,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\c1b67737c13c99776cde5989ec2885c8\System.IdentityModel.ni.dll MOD - [2013/01/10 20:45:40 | 018,080,256 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a0445401f2473a1aa4b66c9c0791c7f6\System.ServiceModel.ni.dll MOD - [2013/01/10 20:44:35 | 001,925,632 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\da5ccd3bc4583fb68696cb0c8209daf4\System.Web.Services.ni.dll MOD - [2013/01/10 20:44:27 | 000,787,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\1d254fbc811d0de6c54a9d9c428c4497\System.EnterpriseServices.ni.dll MOD - [2013/01/10 20:44:27 | 000,649,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dcb0e7d56ffca14d7c483103235b11ad\System.Transactions.ni.dll MOD - [2013/01/10 20:44:27 | 000,236,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\1d254fbc811d0de6c54a9d9c428c4497\System.EnterpriseServices.Wrapper.dll MOD - [2013/01/10 20:44:26 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\e7b4706dfe18f29486dbaf5d35e01765\System.Runtime.DurableInstancing.ni.dll MOD - [2013/01/10 20:44:26 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll MOD - [2013/01/10 20:44:25 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\910fe53ec2122cf3a2ad11c2b2f5cbfd\System.Runtime.Serialization.ni.dll MOD - [2013/01/10 20:44:07 | 001,801,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll MOD - [2013/01/10 20:08:21 | 018,002,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\14f511c47523f19ca591eb207e9e2084\PresentationFramework.ni.dll MOD - [2013/01/10 20:08:12 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e10fd15441d278c04a03302880a3e231\PresentationCore.ni.dll MOD - [2013/01/10 20:08:10 | 006,815,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\9071f089ab65d518d1bd7e8fa857a95f\System.Data.ni.dll MOD - [2013/01/10 20:08:06 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\27dcf04ed7a3506045597c02a5a1fc31\System.Core.ni.dll MOD - [2013/01/10 20:08:05 | 003,858,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\7a9ff5ce3a909d075179a2ac70d8f388\WindowsBase.ni.dll MOD - [2013/01/10 20:08:03 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll MOD - [2013/01/10 20:08:02 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll MOD - [2013/01/10 20:08:01 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll MOD - [2013/01/10 20:08:01 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5de5d8c1c02e33789e3cf7e3f54c0ec9\System.Configuration.ni.dll MOD - [2013/01/10 20:07:57 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll MOD - [2012/12/12 07:32:26 | 005,025,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\\System.Windows.Forms.dll MOD - [2012/11/05 12:31:52 | 002,295,264 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012/10/05 12:53:24 | 003,198,976 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\\System.dll MOD - [2012/10/05 12:53:24 | 000,630,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Drawing\\System.Drawing.dll MOD - [2012/08/31 12:59:19 | 004,550,656 | ---- | M] () -- C:\Windows\assembly\GAC_32\mscorlib\\mscorlib.dll MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2012/02/11 01:31:42 | 001,253,376 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\WindowsBase\\WindowsBase.dll MOD - [2012/02/11 01:31:41 | 005,283,840 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework\\PresentationFramework.dll MOD - [2012/02/11 01:31:40 | 004,218,880 | ---- | M] () -- C:\Windows\assembly\GAC_32\PresentationCore\\PresentationCore.dll MOD - [2011/08/09 11:37:16 | 001,571,817 | ---- | M] () -- C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\libeay32.dll MOD - [2011/08/09 11:37:16 | 000,331,742 | ---- | M] () -- C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\ssleay32.dll MOD - [2011/03/30 10:40:56 | 000,237,160 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll MOD - [2011/01/28 21:14:54 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\DYMO\DYMO Label Software\DYMO.Common.dll MOD - [2010/11/21 05:25:01 | 000,667,648 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Core\\System.Core.dll MOD - [2010/11/21 05:24:32 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\\System.Configuration.dll MOD - [2010/11/21 05:23:48 | 002,048,000 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\\System.Xml.dll MOD - [2010/11/13 01:26:08 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll MOD - [2009/06/10 23:22:40 | 000,010,752 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Accessibility\\Accessibility.dll MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll MOD - [2003/07/11 02:09:28 | 000,048,192 | ---- | M] () -- C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\1031\nsextint.dll MOD - [2000/08/17 18:02:36 | 000,086,016 | ---- | M] () -- C:\Program Files (x86)\Philips ToUcam Camera\GameCam SE\Program\RFTrayRes.dll MOD - [2000/08/17 17:40:20 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\Philips ToUcam Camera\GameCam SE\Program\RFTray.exe MOD - [2000/08/17 17:40:14 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Philips ToUcam Camera\GameCam SE\Program\RfDownload.dll MOD - [1998/11/30 18:34:06 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\U32MISC.dll MOD - [1998/07/22 17:33:02 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\u32Spy.dll ========== Services (SafeList) ========== SRV:64bit: - [2012/11/05 15:17:46 | 000,151,648 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE -- (EPSON_PM_RPCV4_04) SRV:64bit: - [2012/07/28 13:32:43 | 000,610,944 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe -- (EpsonCustomerResearchParticipation) SRV:64bit: - [2011/06/10 12:35:04 | 000,302,592 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\STacSV64.exe -- (STacSV) SRV:64bit: - [2010/10/11 12:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc) SRV:64bit: - [2010/09/23 04:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/05/07 05:16:22 | 000,078,848 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\SysNative\PrintCtrl.exe -- (Printer Control) SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2009/03/03 12:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters) SRV - [2013/04/15 12:21:49 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/04/03 16:05:21 | 002,795,048 | ---- | M] (Iminent) [Auto | Running] -- C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe -- (SProtection) SRV - [2013/03/27 16:17:42 | 000,185,688 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service) SRV - [2013/02/27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) SRV - [2013/02/19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2013/01/08 13:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/12/18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/12/11 11:02:40 | 000,098,304 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Brother\bratimer.exe -- (BRA_Scheduler) SRV - [2012/12/10 18:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service) SRV - [2012/11/05 12:31:52 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/06/11 17:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe -- (BBUpdate) SRV - [2012/06/11 17:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe -- (BBSvc) SRV - [2012/01/14 08:26:31 | 000,327,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\XSManager\WTGService.exe -- (WTGService) SRV - [2011/06/09 21:23:58 | 000,085,560 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe -- (HP Support Assistant Service) SRV - [2011/06/09 15:37:18 | 000,264,008 | ---- | M] (HP) [Auto | Stopped] -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe -- (FPLService) SRV - [2011/03/30 10:41:10 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011/03/29 03:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe) SRV - [2011/02/25 07:34:42 | 000,241,648 | ---- | M] (CyberLink) [Auto | Stopped] -- c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe -- (CLKMSVC10_38F51D56) SRV - [2011/02/24 10:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service) SRV - [2011/02/21 02:48:00 | 000,155,232 | ---- | M] (DATEV eG) [On_Demand | Stopped] -- J:\DATEV\PROGRAMM\Install\DvInesASDSvc.Exe -- (DATEV Update-Service) SRV - [2011/02/01 09:41:24 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011/02/01 09:41:20 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2011/01/28 21:34:52 | 000,032,336 | ---- | M] (Sanford, L.P.) [Auto | Running] -- C:\Program Files (x86)\DYMO\DYMO Label Software\DymoPnpService.exe -- (DymoPnpService) SRV - [2010/10/12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService) SRV - [2010/03/18 23:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0) SRV - [2008/10/24 16:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe -- (EpsonBidirectionalService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013/02/26 23:40:46 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver) DRV:64bit: - [2013/02/14 03:52:46 | 000,239,416 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia) DRV:64bit: - [2013/02/13 14:15:32 | 000,141,824 | ---- | M] (Wireless Data Device) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmntnet.sys -- (cmntnet) DRV:64bit: - [2013/02/13 14:15:32 | 000,123,904 | ---- | M] (Wireless Device) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmnuusbser.sys -- (cmnuusbser) DRV:64bit: - [2013/02/08 04:37:56 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64) DRV:64bit: - [2013/02/08 04:37:54 | 000,311,096 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga) DRV:64bit: - [2013/02/08 04:37:50 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA) DRV:64bit: - [2013/02/08 04:37:42 | 000,206,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64) DRV:64bit: - [2013/02/08 04:37:40 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64) DRV:64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012/04/18 15:05:16 | 000,019,304 | ---- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\grmnusb.sys -- (grmnusb) DRV:64bit: - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011/11/24 05:15:39 | 000,031,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmxdrv.sys -- (pmxdrv) DRV:64bit: - [2011/11/24 04:55:44 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/11/24 04:55:44 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011/08/02 16:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl) DRV:64bit: - [2011/06/10 12:35:04 | 000,528,384 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA) DRV:64bit: - [2011/04/26 21:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2011/04/22 12:17:04 | 000,471,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011/04/21 01:07:22 | 000,399,944 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tixhci.sys -- (tixhci) DRV:64bit: - [2011/04/21 01:07:22 | 000,131,656 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tihub3.sys -- (tihub3) DRV:64bit: - [2011/03/03 19:59:20 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010/10/19 13:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2009/09/23 03:46:18 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr) DRV:64bit: - [2009/09/23 03:46:17 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm) DRV:64bit: - [2009/09/23 03:32:39 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2009/09/23 03:32:33 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2009/07/14 15:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum) DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/07/14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam) DRV:64bit: - [2009/06/10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV:64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64) DRV:64bit: - [2008/07/26 15:25:48 | 000,790,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64) DRV:64bit: - [2008/07/26 15:22:34 | 002,624,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LV302V64.SYS -- (PID_PEPI) DRV:64bit: - [2008/07/26 15:22:22 | 000,015,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lv302a64.sys -- (lvpepf64) DRV:64bit: - [2008/07/24 13:04:34 | 000,115,328 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2007/05/14 17:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb) DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE:64bit: - HKLM\..\SearchScopes\{136E043D-39D8-4884-88F7-B47A3B070908}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKLM\..\SearchScopes\{1}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} IE - HKLM\..\SearchScopes\{136E043D-39D8-4884-88F7-B47A3B070908}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4 IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4 IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..\SearchScopes\{136E043D-39D8-4884-88F7-B47A3B070908}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4 IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.chatzum.com/?orig=HP&affid=62&cztbid=394286201 IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.) IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.chatzum.com/?orig=DS&affid=62&cztbid=394286201&q={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes\{1}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes\{136E043D-39D8-4884-88F7-B47A3B070908}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} IE - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4 IE - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\TS_KeyLodaded\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found IE - HKU\TS_KeyLodaded\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\TS_KeyLodaded\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox IE - HKU\TS_KeyLodaded\..\SearchScopes\{136E043D-39D8-4884-88F7-B47A3B070908}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKU\TS_KeyLodaded\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF IE - HKU\TS_KeyLodaded\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} IE - HKU\TS_KeyLodaded\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} IE - HKU\TS_KeyLodaded\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\TS_KeyLodaded\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..CT2851647.browser.search.defaultthis.engineName: true FF - prefs.js..browser.search.defaultenginename: "ChatZumSearch" FF - prefs.js..browser.search.order.1: "ChatZumSearch" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: "false" FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT2851647&SearchSource=13&CUI=SB_CUI" FF - prefs.js..extensions.enabledAddons: webbooster@iminent.com: FF - prefs.js..extensions.enabledAddons: {ADFA33FD-16F5-4355-8504-DF4D664CFE83}:1.0.20 FF - prefs.js..extensions.enabledAddons: {c840e246-6b95-475e-9bd7-caa1c7eca9f2}: FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2851647&SearchSource=2&CUI=UN09309758555980696&UM=&q=" FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@dymo.com/DymoLabelFramework: C:\Program Files (x86)\DYMO\DYMO Label Software\Framework\npDYMOLabelFramework.dll ( Sanford L.P.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version= c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\TEMP.Hermann-HP\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/01/19 16:33:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/01/19 16:33:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\webbooster@iminent.com: C:\Program Files (x86)\Iminent\webbooster@iminent.com [2013/03/09 15:10:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/12 17:53:33 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/12 17:53:33 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/10/29 19:04:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\Extensions [2013/04/29 12:24:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\Firefox\Profiles\qxs2ikp0.default\extensions [2013/04/29 11:39:26 | 000,000,000 | ---D | M] (ChatZum Toolbar) -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\Firefox\Profiles\qxs2ikp0.default\extensions\{ADFA33FD-16F5-4355-8504-DF4D664CFE83} [2013/04/29 12:24:49 | 000,000,000 | ---D | M] (uTorrentBar_DE) -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\Firefox\Profiles\qxs2ikp0.default\extensions\{c840e246-6b95-475e-9bd7-caa1c7eca9f2} [2013/03/09 15:10:47 | 000,001,609 | ---- | M] () -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\firefox\profiles\qxs2ikp0.default\searchplugins\ChatZumSearch.xml [2013/04/29 11:39:58 | 000,001,058 | ---- | M] () -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\mozilla\firefox\profiles\qxs2ikp0.default\searchplugins\utorrentbarde-customized-web-search.xml [2013/04/29 17:03:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012/11/05 12:31:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013/04/29 17:03:26 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\mozilla firefox\extensions\websitelogon@truesuite.com [2012/12/03 12:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\updated\extensions [2012/12/03 12:01:12 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2012/12/03 12:01:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012/12/03 12:01:09 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\websitelogon@truesuite.com [2013/03/09 15:10:14 | 000,000,000 | ---D | M] ("Iminent Minibar") -- C:\PROGRAM FILES (X86)\IMINENT\WEBBOOSTER@IMINENT.COM [2012/11/05 12:31:52 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/04/21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/09/12 16:59:18 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012/04/21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012/04/21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012/04/21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012/04/21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent) O2 - BHO: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.) O2 - BHO: (IEHlprObj Class) - {DA5A2A9E-DF07-4a8e-B423-BC5CD4D1880C} - C:\Program Files\WebBoomerang\IEHelper.dll () O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\ChatZum Toolbar\tbunsj9FD8.tmp\tbcore3.dll () O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (ChatZum Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files (x86)\ChatZum Toolbar\tbunsj9FD8.tmp\tbcore3.dll () O3 - HKLM\..\Toolbar: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe (Hewlett-Packard ) O4:64bit: - HKLM..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe (Hewlett-Packard) O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [PrintDisp] C:\Windows\SysNative\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS) O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [Iminent] C:\Program Files (x86)\Iminent\Iminent.exe (Iminent) O4 - HKLM..\Run: [IminentMessenger] C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (Iminent) O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [PE2CKFNT SE] C:\Program Files (x86)\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe () O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\real\realplayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Wondershare) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003..\Run: [ctfmon.exe] C:\ProgramData\8bzd6z.dat (Корпорация Майкрософт2) O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003..\Run: [DymoQuickPrint] C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe (Sanford, L.P.) O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003..\Run: [Epson Stylus Photo PX730(Netzwerk)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /FU "C:\Users\HERMAN~1\AppData\Local\Temp\E_SAF32.tmp" /EF "HKCU" File not found O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003..\Run: [TrafficTravisv4] C:\Users\Hermann Surf\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe () O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus Photo PX730" File not found O4 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries) O4 - HKU\TS_KeyLodaded..\Run: [DymoQuickPrint] C:\Program Files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe (Sanford, L.P.) O4 - HKU\TS_KeyLodaded..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found O4 - HKU\TS_KeyLodaded..\Run: [TrafficTravisv4] C:\Users\Hermann\AppData\Roaming\Traffic Travis v4\TrafficTravisV4.exe File not found O4 - HKU\TS_KeyLodaded..\Run: [WebCamRT.exe] C:\Program Files (x86)\Philips ToUcam Camera\SpotLife\WebCamRT.exe /WinStart /regkey=Software\Spotlife\Spotlife.5\WebCamSettings File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Hermann Surf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = File not found O4 - Startup: C:\Users\Jessi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O7 - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0 O7 - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\TS_KeyLodaded\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found O9:64bit: - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~2\VideoGet\VideoGet\Plugins\VIDEOG~2.DLL () O9:64bit: - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~2\VideoGet\VideoGet\Plugins\VIDEOG~2.DLL () O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~2\VideoGet\VideoGet\Plugins\VIDEOG~1.DLL () O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~2\VideoGet\VideoGet\Plugins\VIDEOG~1.DLL () O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-2928652112-3187983571-3213460233-1003\..Trusted Domains: netzaehler.de ([]https in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/ (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7DC02DD9-EAAF-4808-9CC8-A515805F5335}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D955C847-13C9-4AE2-A9D9-B6218CB8759A}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F40FCA03-8D20-441F-BCF5-08EF17DC8385}: DhcpNameServer = O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18:64bit: - Protocol\Filter\text/xml - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{2198e1bf-8eac-11e1-83e1-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{2198e1bf-8eac-11e1-83e1-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/04/30 01:40:05 | 000,000,000 | ---D | C] -- C:\FRST [2013/04/29 12:26:53 | 000,000,000 | ---D | C] -- C:\Windows\pss [2013/04/29 12:21:13 | 000,000,000 | ---D | C] -- C:\Users\Hermann Neuer ADMIN\AppData\Local\AuthenTec [2013/04/29 12:20:36 | 000,000,000 | ---D | C] -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Symantec [2013/04/29 11:53:01 | 000,000,000 | ---D | C] -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\vlc [2013/04/29 11:31:56 | 000,000,000 | ---D | C] -- C:\Users\Hermann Neuer ADMIN\AppData\Local\Scansoft [2013/04/29 11:27:49 | 000,127,488 | ---- | C] (Корпорация Майкрософт2) -- C:\ProgramData\8bzd6z.dat [2013/04/29 11:27:49 | 000,127,488 | ---- | C] (Корпорация Майкрософт2) -- C:\ProgramData\7lorzd.dat [2013/04/29 11:27:48 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\rundll32.exe [2013/04/29 10:07:33 | 000,000,000 | R--D | C] -- C:\Users\Hermann Neuer ADMIN\AppData\Roaming\Brother [2013/04/21 15:17:09 | 000,000,000 | R--D | C] -- C:\Jessis iPod [2013/04/12 23:20:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother [2013/04/12 23:19:22 | 000,073,728 | ---- | C] (Brother Industories Ltd. 