Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 06.05.2013, 13:21   #1
zazfan
 
mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? - Standard

mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?



Hallo liebe Helfer,

ich versuche grade den Laptop meiner Schwester "aufzuräumen", dabei sind mir die MapsGalaxy Toolbar und MindSpark Toolbar Platform Plugin Stub aufgefallen.

Habe versucht mit Avast- MapsGalaxy zu entfernen. Es wird zwar deaktiviert, aber ist trotzdem noch auf dem System und lässt sich nicht entfernen.

Ausserdem kommt mir die Toolbar MindSpark komisch vor? Laut Google ist diese Datei eine Dynamic Link Library. Aber da stand für Windows XP und hier läuft und lief immer nur Windows Vista? Ist diese Datei verdächtig? ich konnte hierzu keine klare Antwort finden.

Bitte könnt Ihr mir helfen da reinezumachen? Was kann ich machen um die loszuwerden?

Ich hab nach Anweisung die Logs erstellt. Ich hoffe ich habe alles richtig gemacht...

mfg zazfan

defogger:

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:37 on 06/05/2013 (strasseb)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
OTL - Extra.txt

Code:
ATTFilter
OTL Extras logfile created on: 03.05.2013 17:43:46 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\strasseb\Downloads\trojaner board software
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,33% Memory free
6,21 Gb Paging File | 5,04 Gb Available in Paging File | 81,21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221,39 Gb Total Space | 140,09 Gb Free Space | 63,28% Space Free | Partition Type: NTFS
Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS
 
Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [CEWE FOTOSCHAU] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoinsight Designer] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\Fotoinsight Designer.exe" "%1" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{45FFEE7D-0120-4F38-95F6-F91CB8CF9AE1}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{47C65F07-722E-49B6-9553-E1871BF7DDE6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0ABD473A-563E-4D59-95AC-6FB1A875D5E6}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | 
"{1C1F131D-4C66-48E7-8027-9851A20084BF}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | 
"{58615DF2-ACB5-4609-9859-79BC4DE59A55}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | 
"{7A03F58B-9268-4269-89B6-8F5AC62334CC}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | 
"{9C76BF88-E56E-4846-A14A-734DBD2951B9}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | 
"{C6D71A7F-BB66-4A96-9724-1547186EEF06}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | 
"{C813D1AB-D3AE-434A-9C42-74A3C4FF9C8C}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | 
"{D2F1696C-6C59-40A5-9DF5-A1F50C8146E2}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | 
"{D7A157D1-1D38-4F46-8D92-7BE40B0DF574}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | 
"{E09688CC-B538-4FCE-B497-4CE29F5B72C4}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | 
"{F84D72E3-511C-4D04-9B42-F73564A8C861}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | 
"TCP Query User{8CC8D391-B9FF-4613-ABD5-2DB665FBA891}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"UDP Query User{5472B74D-F329-4AF7-B8F1-3BE60259BE06}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{09F25F86-F957-4051-8AB2-0E0D948BBB5D}" = 1310
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{207E9B74-F4D3-4FD7-8142-16FF41825BC4}_is1" = Secure Banking Version 1.5.1
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1" = System Explorer 4.1.1
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65AA10FF-6F32-48AE-881F-FC96E7BF3A5E}" = ESU for Microsoft Vista
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6D4553DF-2095-4D10-92C0-17934733B51D}" = 1310_Help
"{6D7E031C-4C05-4265-854A-FE9FDEA9984D}" = 1310Trb
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software  1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E728E952-DD4F-4BCD-A5C8-40FBFEFF91FE}" = OpenOffice.org Installer 1.0
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v.10.0.15
"Ashampoo Slideshow Studio Elements_is1" = Ashampoo Slideshow Studio Elements 2.0.1
"Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60
"avast" = avast! Free Antivirus
"AviSynth" = AviSynth 2.6
"AvsP_is1" = AvsP
"BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1" = DVD slideshow GUI 0.9.5.4
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Fotoinsight Designer" = Fotoinsight Designer
"GnuPG" = GNU Privacy Guard
"Google Chrome" = Google Chrome
"GUI for dvdauthor" = GUI for dvdauthor 1.07
"HaaliMkx" = Haali Media Splitter
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HelixYUVCodecs" = Helix YUV Codecs (remove only)
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"ImgBurn" = ImgBurn
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de)
"Mozilla Thunderbird 17.0.5 (x86 de)" = Mozilla Thunderbird 17.0.5 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 8" = TeamViewer 8
"VLC media player" = VLC media player 2.0.6
"WildTangent hp Master Uninstall" = My HP Games
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Spotify" = Spotify
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 15.09.2011 21:30:22 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:30:23 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:30:34 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:30:35 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:30:38 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:30:39 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:34:59 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:35:00 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
[ System Events ]
Error - 03.05.2013 09:41:49 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 03.05.2013 10:20:00 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 03.05.2013 10:21:57 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022
Description = 
 
Error - 03.05.2013 10:21:59 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 03.05.2013 10:59:25 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 03.05.2013 11:00:28 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022
Description = 
 
Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022
Description = 
 
Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 03.05.2013 11:00:39 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 03.05.2013 11:01:24 | Computer Name = Oskar | Source = Service Control Manager | ID = 7011
Description = 
 
 
< End of report >
         
OTL - OTL.txt
Code:
ATTFilter
OTL logfile created on: 06.05.2013 12:59:09 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\strasseb\Downloads\trojaner board software
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 68,89% Memory free
6,20 Gb Paging File | 5,32 Gb Available in Paging File | 85,93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221,39 Gb Total Space | 140,12 Gb Free Space | 63,29% Space Free | Partition Type: NTFS
Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS
 
Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.05.03 17:31:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\strasseb\Downloads\trojaner board software\OTL.exe
PRC - [2013.05.02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2013.04.09 11:57:52 | 002,853,320 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\SystemExplorer.exe
PRC - [2013.03.14 04:40:22 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\service\SystemExplorerService.exe
PRC - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.05.02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPoint\SetPoint.exe
PRC - [2008.05.02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynTPStart.exe
PRC - [2007.09.05 13:09:54 | 001,620,520 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2007.09.05 13:09:54 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe
MOD - [2012.09.07 17:30:22 | 000,016,384 | ---- | M] () -- C:\Programme\Secure Banking\SecureBanking.dll
MOD - [2012.09.05 20:49:54 | 000,008,704 | ---- | M] () -- C:\Programme\Secure Banking\funcs.dll
MOD - [2010.02.12 10:37:50 | 000,633,696 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll
MOD - [2007.09.30 19:34:52 | 000,345,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007.09.30 19:34:42 | 000,255,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007.09.30 19:34:42 | 000,120,208 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007.09.30 19:34:42 | 000,038,184 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007.09.30 19:33:32 | 000,066,856 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007.09.05 12:52:04 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll
MOD - [2007.08.14 15:43:46 | 006,365,184 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtGui4.dll
MOD - [2007.07.12 13:55:52 | 000,131,072 | ---- | M] () -- C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2007.07.12 13:55:28 | 001,581,056 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtCore4.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013.04.20 15:10:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.04.12 18:45:36 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) [On_Demand | Running] -- C:\Programme\System Explorer\service\SystemExplorerService.exe -- (SystemExplorerHelpService)
SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS)
SRV - [2008.05.02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.03.05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\D91F.tmp -- (MEMSWEEP2)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2013.03.07 01:33:22 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2012.11.28 19:49:00 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.09.05 16:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.03.04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008.02.29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2008.02.29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007.10.18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007.09.10 00:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007.07.11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007.06.18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.03.07 04:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.02.16 23:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}
IE - HKLM\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}
IE - HKCU\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF
IE - HKCU\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKCU\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.2
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7B6bdc61ae-7b80-44a3-9476-e1d121ec2238%7D:0.85
FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.5.4
FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.5.2
FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8
FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.31
FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q="
FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF - prefs.js..network.proxy.type: 2
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin [2013.05.01 23:18:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.03 15:47:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 18:45:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.03 11:13:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.04 21:08:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.29 09:12:45 | 000,000,000 | ---D | M]
 
[2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions
[2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.05.03 15:34:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions
[2012.10.09 08:16:54 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2013.04.28 18:23:12 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2013.04.28 18:23:06 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2013.05.01 01:39:19 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\https-everywhere@eff(86).org
[2008.09.07 17:25:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Sunbird\Profiles\1mckrlaz.default\extensions
[2013.04.28 18:23:14 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\isreaditlater@ideashower.com.xpi
[2013.04.28 16:40:49 | 000,262,896 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi
[2013.04.28 16:52:25 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
[2013.04.28 16:50:56 | 000,581,999 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\uriloader@pdf.js.xpi
[2013.04.28 18:23:04 | 000,350,097 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2013.04.28 18:23:03 | 000,087,920 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
[2013.04.28 18:23:03 | 000,073,384 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi
[2013.04.28 18:23:03 | 000,532,430 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013.04.28 16:43:14 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.04.28 18:23:02 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2012.05.04 15:40:46 | 000,002,333 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\askcom.xml
[2013.04.29 13:09:11 | 000,002,402 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\bingp.xml
[2012.12.02 14:41:43 | 000,009,650 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\my-web-search.xml
[2013.04.29 10:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.04.12 18:45:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.05.03 15:47:41 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009.09.05 11:29:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2013.04.12 18:45:37 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.03.18 17:18:29 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.08 08:33:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.03.18 17:18:29 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.03.18 17:18:29 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.03.18 17:18:29 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.03.18 17:18:29 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://mega.co.nz/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
 
O1 HOSTS File: ([2012.05.04 18:52:50 | 000,442,787 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O1 - Hosts: 127.0.0.1	www.007guard.com
O1 - Hosts: 127.0.0.1	007guard.com
O1 - Hosts: 127.0.0.1	008i.com
O1 - Hosts: 127.0.0.1	www.008k.com
O1 - Hosts: 127.0.0.1	008k.com
O1 - Hosts: 127.0.0.1	www.00hq.com
O1 - Hosts: 127.0.0.1	00hq.com
O1 - Hosts: 127.0.0.1	010402.com
O1 - Hosts: 127.0.0.1	www.032439.com
O1 - Hosts: 127.0.0.1	032439.com
O1 - Hosts: 127.0.0.1	www.0scan.com
O1 - Hosts: 127.0.0.1	0scan.com
O1 - Hosts: 127.0.0.1	1000gratisproben.com
O1 - Hosts: 127.0.0.1	www.1000gratisproben.com
O1 - Hosts: 127.0.0.1	1001namen.com
O1 - Hosts: 127.0.0.1	www.1001namen.com
O1 - Hosts: 127.0.0.1	www.100888290cs.com
O1 - Hosts: 127.0.0.1	100888290cs.com
O1 - Hosts: 127.0.0.1	100sexlinks.com
O1 - Hosts: 127.0.0.1	www.100sexlinks.com
O1 - Hosts: 127.0.0.1	www.10sek.com
O1 - Hosts: 127.0.0.1	10sek.com
O1 - Hosts: 127.0.0.1	1-2005-search.com
O1 - Hosts: 15216 more lines...
O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found.
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00  [binary data]
O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found
O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template
[2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0)
[2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase
[2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager
[2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET
[2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager
[2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter
[2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager
[2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn
[2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc
[2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView
[2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI
[2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali
[2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor
[2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor
[2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor
[2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP
[2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP
[2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI
[2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe
[2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe
[2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe
[2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen
[2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg
[2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard
[2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard
[2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU
[2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled
[2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys
[2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker
[2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine
[2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger
[2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking
[2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking
[2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer
[2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer
[2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer
[2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer
[2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
 
========== Files - Modified Within 30 Days ==========
 
[2013.05.06 12:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.06 12:45:48 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.05.06 12:45:48 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.05.06 12:45:48 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.05.06 12:45:48 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.05.06 12:42:13 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2013.05.06 12:41:29 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013.05.06 12:41:14 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.06 12:40:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.06 12:40:26 | 3220,144,128 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.06 12:39:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable
[2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk
[2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk
[2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk
[2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk
[2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat
[2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk
[2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk
[2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk
[2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat
[2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk
[2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe
[2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk
[2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe
[2013.04.29 02:47:33 | 005,243,208 | ---- | M] (                                                            ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe
[2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe
[2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe
[2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe
[2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe
[2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk
[2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk
[2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht
[2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht
[2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001
[2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
 
========== Files Created - No Company Name ==========
 
[2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable
[2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk
[2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk
[2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk
[2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk
[2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat
[2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk
[2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk
[2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk
[2013.05.03 13:59:46 | 3220,144,128 | -HS- | C] () -- C:\hiberfil.sys
[2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk
[2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe
[2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
[2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk
[2013.04.29 02:47:23 | 005,243,208 | ---- | C] (                                                            ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe
[2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe
[2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe
[2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk
[2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk
[2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht
[2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht
[2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001
[2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk
[2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin
[2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat
[2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm
[2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001
[2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat
[2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo
[2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements
[2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC
[2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET
[2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager
[2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg
[2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express
[2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn
[2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView
[2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache
[2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify
[2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer
[2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template
[2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird
[2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
         

Geändert von zazfan (06.05.2013 um 14:05 Uhr) Grund: logs einfügen

 

Themen zu mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?
32 bit, 7-zip, antwort, anweisung, aswrvrt.sys, datei, deaktiviert, dynamic, entferne, entfernen, erstell, free download, google, hoffe, install.exe, intranet, komisch, konnte, laptop, launch, lightning, link, microsoft office 2003, mindspark, mindspark toolbar, officejet, plug-in, plugin, richtig, s3.amazonaws.com, spotify web helper, system, toolbar, verdächtig, versuche, versucht, vista, wie entfernen, wie entfernen?, windows, windows vista, windows xp




Ähnliche Themen: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?


  1. Yahoo Toolbar drängelt vor, AVG Securtiy Toolbar nicht löschbar, Werbung poppt auf trotz Firewall
    Plagegeister aller Art und deren Bekämpfung - 23.09.2015 (31)
  2. Lottery Stream toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 24.08.2015 (2)
  3. RecipeSearch toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 19.08.2015 (2)
  4. UnzipApp toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 16.08.2015 (2)
  5. InboxNow toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 14.08.2015 (2)
  6. Metro Hotspot toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 14.08.2015 (2)
  7. DownSpeedTest Toolbar by Mindspark entfernen
    Anleitungen, FAQs & Links - 13.08.2015 (2)
  8. Windows Vista: Mindspark Toolbar Plattform funktioniert nicht mehr
    Alles rund um Windows - 26.03.2015 (15)
  9. Babylon toolbar entfernen, BrowserCompanion entfernen, DealPly entfernen, GinyasBrowserCompanions entfernen
    Log-Analyse und Auswertung - 17.12.2014 (9)
  10. MapsGalaxy Toolbar entfernen
    Anleitungen, FAQs & Links - 13.11.2014 (2)
  11. DLSecure Toolbar entfernen
    Anleitungen, FAQs & Links - 21.09.2014 (2)
  12. Mindspark Toolbar Platform Plugin Stub for 32-bit Windows bei Add-ons-Manager gefunden
    Log-Analyse und Auswertung - 17.09.2014 (11)
  13. Max-Toolbar entfernen
    Anleitungen, FAQs & Links - 01.08.2014 (2)
  14. Mapsgalaxy-Toolbar und /-Service
    Log-Analyse und Auswertung - 26.05.2014 (11)
  15. Windows 7 "PUP Babylon Toolbar" und "a variant of Win32/Bundled.Toolbar.Ask.D" gefunden
    Log-Analyse und Auswertung - 26.09.2013 (9)
  16. Mywebsearch und MapsGalaxy Toolbar - wie entfernen?
    Log-Analyse und Auswertung - 17.04.2013 (5)
  17. Entrusted Toolbar und DVDVideoSoftTB Toolbar lassen sich nicht deinstaliern
    Plagegeister aller Art und deren Bekämpfung - 24.03.2013 (4)

Zum Thema mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? - Hallo liebe Helfer, ich versuche grade den Laptop meiner Schwester "aufzuräumen", dabei sind mir die MapsGalaxy Toolbar und MindSpark Toolbar Platform Plugin Stub aufgefallen. Habe versucht mit Avast- MapsGalaxy zu - mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?...
Archiv
Du betrachtest: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.