![]() |
|
Log-Analyse und Auswertung: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo liebe Helfer, ich versuche grade den Laptop meiner Schwester "aufzuräumen", dabei sind mir die MapsGalaxy Toolbar und MindSpark Toolbar Platform Plugin Stub aufgefallen. Habe versucht mit Avast- MapsGalaxy zu entfernen. Es wird zwar deaktiviert, aber ist trotzdem noch auf dem System und lässt sich nicht entfernen. Ausserdem kommt mir die Toolbar MindSpark komisch vor? Laut Google ist diese Datei eine Dynamic Link Library. Aber da stand für Windows XP und hier läuft und lief immer nur Windows Vista? Ist diese Datei verdächtig? ich konnte hierzu keine klare Antwort finden. Bitte könnt Ihr mir helfen da reinezumachen? Was kann ich machen um die loszuwerden? Ich hab nach Anweisung die Logs erstellt. Ich hoffe ich habe alles richtig gemacht... mfg zazfan defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:37 on 06/05/2013 (strasseb) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter OTL Extras logfile created on: 03.05.2013 17:43:46 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\strasseb\Downloads\trojaner board software Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,33% Memory free 6,21 Gb Paging File | 5,04 Gb Available in Paging File | 81,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 221,39 Gb Total Space | 140,09 Gb Free Space | 63,28% Space Free | Partition Type: NTFS Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [CEWE FOTOSCHAU] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\CEWE FOTOSCHAU.exe" -d "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Fotoinsight Designer] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\Fotoinsight Designer.exe" "%1" () Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{45FFEE7D-0120-4F38-95F6-F91CB8CF9AE1}" = lport=2869 | protocol=6 | dir=in | app=system | "{47C65F07-722E-49B6-9553-E1871BF7DDE6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0ABD473A-563E-4D59-95AC-6FB1A875D5E6}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{1C1F131D-4C66-48E7-8027-9851A20084BF}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{58615DF2-ACB5-4609-9859-79BC4DE59A55}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{7A03F58B-9268-4269-89B6-8F5AC62334CC}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{9C76BF88-E56E-4846-A14A-734DBD2951B9}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{C6D71A7F-BB66-4A96-9724-1547186EEF06}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{C813D1AB-D3AE-434A-9C42-74A3C4FF9C8C}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{D2F1696C-6C59-40A5-9DF5-A1F50C8146E2}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{D7A157D1-1D38-4F46-8D92-7BE40B0DF574}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{E09688CC-B538-4FCE-B497-4CE29F5B72C4}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{F84D72E3-511C-4D04-9B42-F73564A8C861}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "TCP Query User{8CC8D391-B9FF-4613-ABD5-2DB665FBA891}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{5472B74D-F329-4AF7-B8F1-3BE60259BE06}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{09F25F86-F957-4051-8AB2-0E0D948BBB5D}" = 1310 "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{207E9B74-F4D3-4FD7-8142-16FF41825BC4}_is1" = Secure Banking Version 1.5.1 "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program "{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper "{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1 "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant "{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1" = System Explorer 4.1.1 "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6 "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087 "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{65AA10FF-6F32-48AE-881F-FC96E7BF3A5E}" = ESU for Microsoft Vista "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6D4553DF-2095-4D10-92C0-17934733B51D}" = 1310_Help "{6D7E031C-4C05-4265-854A-FE9FDEA9984D}" = 1310Trb "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4 "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch "{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C716522C-3731-4667-8579-40B098294500}" = Toolbox "{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport "{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext "{E728E952-DD4F-4BCD-A5C8-40FBFEFF91FE}" = OpenOffice.org Installer 1.0 "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply "{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax "{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "7-Zip" = 7-Zip 9.20 "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v.10.0.15 "Ashampoo Slideshow Studio Elements_is1" = Ashampoo Slideshow Studio Elements 2.0.1 "Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60 "avast" = avast! Free Antivirus "AviSynth" = AviSynth 2.6 "AvsP_is1" = AvsP "BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1" = DVD slideshow GUI 0.9.5.4 "CCleaner" = CCleaner "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "Fotoinsight Designer" = Fotoinsight Designer "GnuPG" = GNU Privacy Guard "Google Chrome" = Google Chrome "GUI for dvdauthor" = GUI for dvdauthor 1.07 "HaaliMkx" = Haali Media Splitter "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149) "HelixYUVCodecs" = Helix YUV Codecs (remove only) "HP Imaging Device Functions" = HP Imaging Device Functions 8.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0 "HPExtendedCapabilities" = HP Customer Participation Program 8.0 "HPOCR" = HP OCR Software 8.0 "ImgBurn" = ImgBurn "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "IrfanView" = IrfanView (remove only) "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "Mozilla Thunderbird 17.0.5 (x86 de)" = Mozilla Thunderbird 17.0.5 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIA Drivers" = NVIDIA Drivers "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4 "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0 "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamViewer 8" = TeamViewer 8 "VLC media player" = VLC media player 2.0.6 "WildTangent hp Master Uninstall" = My HP Games ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 15.09.2011 21:30:22 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:23 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:34 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:35 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:38 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:39 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:34:59 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:35:00 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = [ System Events ] Error - 03.05.2013 09:41:49 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 10:20:00 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000 Description = Error - 03.05.2013 10:21:57 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 10:21:59 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 10:59:25 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000 Description = Error - 03.05.2013 11:00:28 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 11:00:39 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 11:01:24 | Computer Name = Oskar | Source = Service Control Manager | ID = 7011 Description = < End of report > Code:
ATTFilter OTL logfile created on: 06.05.2013 12:59:09 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\strasseb\Downloads\trojaner board software Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 68,89% Memory free 6,20 Gb Paging File | 5,32 Gb Available in Paging File | 85,93% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 221,39 Gb Total Space | 140,12 Gb Free Space | 63,29% Space Free | Partition Type: NTFS Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.03 17:31:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\strasseb\Downloads\trojaner board software\OTL.exe PRC - [2013.05.02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.04.09 11:57:52 | 002,853,320 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\SystemExplorer.exe PRC - [2013.03.14 04:40:22 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\service\SystemExplorerService.exe PRC - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.05.02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPoint\SetPoint.exe PRC - [2008.05.02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL2\KHALMNPR.exe PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynTPStart.exe PRC - [2007.09.05 13:09:54 | 001,620,520 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2007.09.05 13:09:54 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe ========== Modules (No Company Name) ========== MOD - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe MOD - [2012.09.07 17:30:22 | 000,016,384 | ---- | M] () -- C:\Programme\Secure Banking\SecureBanking.dll MOD - [2012.09.05 20:49:54 | 000,008,704 | ---- | M] () -- C:\Programme\Secure Banking\funcs.dll MOD - [2010.02.12 10:37:50 | 000,633,696 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll MOD - [2007.09.30 19:34:52 | 000,345,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll MOD - [2007.09.30 19:34:42 | 000,255,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll MOD - [2007.09.30 19:34:42 | 000,120,208 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll MOD - [2007.09.30 19:34:42 | 000,038,184 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll MOD - [2007.09.30 19:33:32 | 000,066,856 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll MOD - [2007.09.05 12:52:04 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll MOD - [2007.08.14 15:43:46 | 006,365,184 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtGui4.dll MOD - [2007.07.12 13:55:52 | 000,131,072 | ---- | M] () -- C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll MOD - [2007.07.12 13:55:28 | 001,581,056 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtCore4.dll ========== Services (SafeList) ========== SRV - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.04.20 15:10:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.12 18:45:36 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) [On_Demand | Running] -- C:\Programme\System Explorer\service\SystemExplorerService.exe -- (SystemExplorerHelpService) SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS) SRV - [2008.05.02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2007.03.05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\D91F.tmp -- (MEMSWEEP2) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2013.03.07 01:33:22 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2012.11.28 19:49:00 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.09.05 16:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008.03.04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService) DRV - [2008.02.29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV - [2008.02.29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2008.02.29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2007.10.18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2007.09.10 00:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService) DRV - [2007.07.11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2007.06.18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007.03.07 04:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD) DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007.02.16 23:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKLM\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKLM\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKCU\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF IE - HKCU\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKCU\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox" FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.2 FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68 FF - prefs.js..extensions.enabledAddons: %7B6bdc61ae-7b80-44a3-9476-e1d121ec2238%7D:0.85 FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.5.4 FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.5.2 FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8 FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.31 FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=" FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF - prefs.js..network.proxy.type: 2 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll (MindSpark) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin [2013.05.01 23:18:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.03 15:47:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 18:45:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.03 11:13:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.04 21:08:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.29 09:12:45 | 000,000,000 | ---D | M] [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.05.03 15:34:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions [2012.10.09 08:16:54 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013.04.28 18:23:12 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2013.04.28 18:23:06 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2013.05.01 01:39:19 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\https-everywhere@eff(86).org [2008.09.07 17:25:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Sunbird\Profiles\1mckrlaz.default\extensions [2013.04.28 18:23:14 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\isreaditlater@ideashower.com.xpi [2013.04.28 16:40:49 | 000,262,896 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2013.04.28 16:52:25 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013.04.28 16:50:56 | 000,581,999 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\uriloader@pdf.js.xpi [2013.04.28 18:23:04 | 000,350,097 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2013.04.28 18:23:03 | 000,087,920 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013.04.28 18:23:03 | 000,073,384 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi [2013.04.28 18:23:03 | 000,532,430 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013.04.28 16:43:14 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.28 18:23:02 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012.05.04 15:40:46 | 000,002,333 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\askcom.xml [2013.04.29 13:09:11 | 000,002,402 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\bingp.xml [2012.12.02 14:41:43 | 000,009,650 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\my-web-search.xml [2013.04.29 10:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 18:45:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013.05.03 15:47:41 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009.09.05 11:29:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2013.04.12 18:45:37 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.18 17:18:29 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.08 08:33:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.18 17:18:29 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.18 17:18:29 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.18 17:18:29 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.18 17:18:29 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://mega.co.nz/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2012.05.04 18:52:50 | 000,442,787 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 15216 more lines... O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found. O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking) O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template [2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0) [2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase [2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager [2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager [2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter [2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc [2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI [2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor [2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP [2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP [2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn [2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI [2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen [2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU [2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys [2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker [2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine [2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger [2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking [2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking [2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer [2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer [2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.05.06 12:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.06 12:45:48 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.06 12:45:48 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.06 12:45:48 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.06 12:45:48 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.06 12:42:13 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.05.06 12:41:29 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001 [2013.05.06 12:41:14 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.06 12:40:26 | 3220,144,128 | -HS- | M] () -- C:\hiberfil.sys [2013.05.06 12:39:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:33 | 005,243,208 | ---- | M] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk ========== Files Created - No Company Name ========== [2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 13:59:46 | 3220,144,128 | -HS- | C] () -- C:\hiberfil.sys [2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:23 | 005,243,208 | ---- | C] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001 [2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk [2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin [2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm [2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat [2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo [2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements [2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC [2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg [2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express [2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache [2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify [2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template [2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird [2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report > Geändert von zazfan (06.05.2013 um 14:05 Uhr) Grund: logs einfügen |
Themen zu mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? |
32 bit, 7-zip, antwort, anweisung, aswrvrt.sys, datei, deaktiviert, dynamic, entferne, entfernen, erstell, free download, google, hoffe, install.exe, intranet, komisch, konnte, laptop, launch, lightning, link, microsoft office 2003, mindspark, mindspark toolbar, officejet, plug-in, plugin, richtig, s3.amazonaws.com, spotify web helper, system, toolbar, verdächtig, versuche, versucht, vista, wie entfernen, wie entfernen?, windows, windows vista, windows xp |