|
Log-Analyse und Auswertung: mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.05.2013, 13:21 | #1 |
| mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo liebe Helfer, ich versuche grade den Laptop meiner Schwester "aufzuräumen", dabei sind mir die MapsGalaxy Toolbar und MindSpark Toolbar Platform Plugin Stub aufgefallen. Habe versucht mit Avast- MapsGalaxy zu entfernen. Es wird zwar deaktiviert, aber ist trotzdem noch auf dem System und lässt sich nicht entfernen. Ausserdem kommt mir die Toolbar MindSpark komisch vor? Laut Google ist diese Datei eine Dynamic Link Library. Aber da stand für Windows XP und hier läuft und lief immer nur Windows Vista? Ist diese Datei verdächtig? ich konnte hierzu keine klare Antwort finden. Bitte könnt Ihr mir helfen da reinezumachen? Was kann ich machen um die loszuwerden? Ich hab nach Anweisung die Logs erstellt. Ich hoffe ich habe alles richtig gemacht... mfg zazfan defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:37 on 06/05/2013 (strasseb) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter OTL Extras logfile created on: 03.05.2013 17:43:46 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\strasseb\Downloads\trojaner board software Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,33% Memory free 6,21 Gb Paging File | 5,04 Gb Available in Paging File | 81,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 221,39 Gb Total Space | 140,09 Gb Free Space | 63,28% Space Free | Partition Type: NTFS Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [CEWE FOTOSCHAU] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\CEWE FOTOSCHAU.exe" -d "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Fotoinsight Designer] -- "C:\Program Files\Fotoinsight\Fotoinsight Designer\Fotoinsight Designer.exe" "%1" () Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{45FFEE7D-0120-4F38-95F6-F91CB8CF9AE1}" = lport=2869 | protocol=6 | dir=in | app=system | "{47C65F07-722E-49B6-9553-E1871BF7DDE6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0ABD473A-563E-4D59-95AC-6FB1A875D5E6}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{1C1F131D-4C66-48E7-8027-9851A20084BF}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{58615DF2-ACB5-4609-9859-79BC4DE59A55}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{7A03F58B-9268-4269-89B6-8F5AC62334CC}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{9C76BF88-E56E-4846-A14A-734DBD2951B9}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{C6D71A7F-BB66-4A96-9724-1547186EEF06}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{C813D1AB-D3AE-434A-9C42-74A3C4FF9C8C}" = protocol=6 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "{D2F1696C-6C59-40A5-9DF5-A1F50C8146E2}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{D7A157D1-1D38-4F46-8D92-7BE40B0DF574}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{E09688CC-B538-4FCE-B497-4CE29F5B72C4}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{F84D72E3-511C-4D04-9B42-F73564A8C861}" = protocol=17 | dir=in | app=c:\users\strasseb\appdata\roaming\spotify\spotify.exe | "TCP Query User{8CC8D391-B9FF-4613-ABD5-2DB665FBA891}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{5472B74D-F329-4AF7-B8F1-3BE60259BE06}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{09F25F86-F957-4051-8AB2-0E0D948BBB5D}" = 1310 "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{207E9B74-F4D3-4FD7-8142-16FF41825BC4}_is1" = Secure Banking Version 1.5.1 "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program "{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper "{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1 "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant "{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1" = System Explorer 4.1.1 "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6 "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087 "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{65AA10FF-6F32-48AE-881F-FC96E7BF3A5E}" = ESU for Microsoft Vista "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6D4553DF-2095-4D10-92C0-17934733B51D}" = 1310_Help "{6D7E031C-4C05-4265-854A-FE9FDEA9984D}" = 1310Trb "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4 "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch "{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C716522C-3731-4667-8579-40B098294500}" = Toolbox "{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport "{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext "{E728E952-DD4F-4BCD-A5C8-40FBFEFF91FE}" = OpenOffice.org Installer 1.0 "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply "{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax "{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "7-Zip" = 7-Zip 9.20 "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v.10.0.15 "Ashampoo Slideshow Studio Elements_is1" = Ashampoo Slideshow Studio Elements 2.0.1 "Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60 "avast" = avast! Free Antivirus "AviSynth" = AviSynth 2.6 "AvsP_is1" = AvsP "BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1" = DVD slideshow GUI 0.9.5.4 "CCleaner" = CCleaner "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "Fotoinsight Designer" = Fotoinsight Designer "GnuPG" = GNU Privacy Guard "Google Chrome" = Google Chrome "GUI for dvdauthor" = GUI for dvdauthor 1.07 "HaaliMkx" = Haali Media Splitter "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149) "HelixYUVCodecs" = Helix YUV Codecs (remove only) "HP Imaging Device Functions" = HP Imaging Device Functions 8.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0 "HPExtendedCapabilities" = HP Customer Participation Program 8.0 "HPOCR" = HP OCR Software 8.0 "ImgBurn" = ImgBurn "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "IrfanView" = IrfanView (remove only) "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "Mozilla Thunderbird 17.0.5 (x86 de)" = Mozilla Thunderbird 17.0.5 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIA Drivers" = NVIDIA Drivers "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4 "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0 "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamViewer 8" = TeamViewer 8 "VLC media player" = VLC media player 2.0.6 "WildTangent hp Master Uninstall" = My HP Games ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 15.09.2011 21:30:22 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:23 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:34 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:35 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:38 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:30:39 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:34:59 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:35:00 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 15.09.2011 21:47:48 | Computer Name = Oskar | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = [ System Events ] Error - 03.05.2013 09:41:49 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 10:20:00 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000 Description = Error - 03.05.2013 10:21:57 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 10:21:59 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 10:59:25 | Computer Name = Oskar | Source = Service Control Manager | ID = 7000 Description = Error - 03.05.2013 11:00:28 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7022 Description = Error - 03.05.2013 11:00:30 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 11:00:39 | Computer Name = Oskar | Source = Service Control Manager | ID = 7001 Description = Error - 03.05.2013 11:01:24 | Computer Name = Oskar | Source = Service Control Manager | ID = 7011 Description = < End of report > Code:
ATTFilter OTL logfile created on: 06.05.2013 12:59:09 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\strasseb\Downloads\trojaner board software Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 68,89% Memory free 6,20 Gb Paging File | 5,32 Gb Available in Paging File | 85,93% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 221,39 Gb Total Space | 140,12 Gb Free Space | 63,29% Space Free | Partition Type: NTFS Drive D: | 11,49 Gb Total Space | 1,53 Gb Free Space | 13,32% Space Free | Partition Type: NTFS Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.03 17:31:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\strasseb\Downloads\trojaner board software\OTL.exe PRC - [2013.05.02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.04.09 11:57:52 | 002,853,320 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\SystemExplorer.exe PRC - [2013.03.14 04:40:22 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) -- C:\Programme\System Explorer\service\SystemExplorerService.exe PRC - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.05.02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPoint\SetPoint.exe PRC - [2008.05.02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL2\KHALMNPR.exe PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynTPStart.exe PRC - [2007.09.05 13:09:54 | 001,620,520 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2007.09.05 13:09:54 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe ========== Modules (No Company Name) ========== MOD - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe MOD - [2012.09.07 17:30:22 | 000,016,384 | ---- | M] () -- C:\Programme\Secure Banking\SecureBanking.dll MOD - [2012.09.05 20:49:54 | 000,008,704 | ---- | M] () -- C:\Programme\Secure Banking\funcs.dll MOD - [2010.02.12 10:37:50 | 000,633,696 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll MOD - [2007.09.30 19:34:52 | 000,345,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll MOD - [2007.09.30 19:34:42 | 000,255,384 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll MOD - [2007.09.30 19:34:42 | 000,120,208 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll MOD - [2007.09.30 19:34:42 | 000,038,184 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll MOD - [2007.09.30 19:33:32 | 000,066,856 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll MOD - [2007.09.05 12:52:04 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll MOD - [2007.08.14 15:43:46 | 006,365,184 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtGui4.dll MOD - [2007.07.12 13:55:52 | 000,131,072 | ---- | M] () -- C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll MOD - [2007.07.12 13:55:28 | 001,581,056 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtCore4.dll ========== Services (SafeList) ========== SRV - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.04.20 15:10:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.12 18:45:36 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) [On_Demand | Running] -- C:\Programme\System Explorer\service\SystemExplorerService.exe -- (SystemExplorerHelpService) SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS) SRV - [2008.05.02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2007.03.05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\D91F.tmp -- (MEMSWEEP2) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2013.03.07 01:33:22 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2012.11.28 19:49:00 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.09.05 16:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008.03.04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService) DRV - [2008.02.29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV - [2008.02.29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2008.02.29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2007.10.18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2007.09.10 00:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService) DRV - [2007.07.11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2007.06.18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007.03.07 04:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD) DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007.02.16 23:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKLM\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKLM\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803} IE - HKCU\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF IE - HKCU\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKCU\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox" FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.2 FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68 FF - prefs.js..extensions.enabledAddons: %7B6bdc61ae-7b80-44a3-9476-e1d121ec2238%7D:0.85 FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.5.4 FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.5.2 FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8 FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.31 FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=" FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF - prefs.js..network.proxy.type: 2 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll (MindSpark) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin [2013.05.01 23:18:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.03 15:47:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 18:45:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.03 11:13:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.04 21:08:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.29 09:12:45 | 000,000,000 | ---D | M] [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.05.03 15:34:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions [2012.10.09 08:16:54 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013.04.28 18:23:12 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2013.04.28 18:23:06 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2013.05.01 01:39:19 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\https-everywhere@eff(86).org [2008.09.07 17:25:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Sunbird\Profiles\1mckrlaz.default\extensions [2013.04.28 18:23:14 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\isreaditlater@ideashower.com.xpi [2013.04.28 16:40:49 | 000,262,896 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2013.04.28 16:52:25 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013.04.28 16:50:56 | 000,581,999 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\uriloader@pdf.js.xpi [2013.04.28 18:23:04 | 000,350,097 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2013.04.28 18:23:03 | 000,087,920 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013.04.28 18:23:03 | 000,073,384 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi [2013.04.28 18:23:03 | 000,532,430 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013.04.28 16:43:14 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.28 18:23:02 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012.05.04 15:40:46 | 000,002,333 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\askcom.xml [2013.04.29 13:09:11 | 000,002,402 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\bingp.xml [2012.12.02 14:41:43 | 000,009,650 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\my-web-search.xml [2013.04.29 10:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 18:45:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013.05.03 15:47:41 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009.09.05 11:29:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2013.04.12 18:45:37 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.18 17:18:29 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.08 08:33:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.18 17:18:29 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.18 17:18:29 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.18 17:18:29 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.18 17:18:29 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://mega.co.nz/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2012.05.04 18:52:50 | 000,442,787 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 15216 more lines... O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found. O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking) O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template [2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0) [2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase [2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager [2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager [2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter [2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc [2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI [2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor [2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP [2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP [2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn [2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI [2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen [2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU [2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys [2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker [2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine [2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger [2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking [2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking [2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer [2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer [2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.05.06 12:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.06 12:45:48 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.06 12:45:48 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.06 12:45:48 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.06 12:45:48 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.06 12:42:13 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.05.06 12:41:29 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001 [2013.05.06 12:41:14 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:44 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.06 12:40:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.06 12:40:26 | 3220,144,128 | -HS- | M] () -- C:\hiberfil.sys [2013.05.06 12:39:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:33 | 005,243,208 | ---- | M] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk ========== Files Created - No Company Name ========== [2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 13:59:46 | 3220,144,128 | -HS- | C] () -- C:\hiberfil.sys [2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:23 | 005,243,208 | ---- | C] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001 [2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk [2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin [2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm [2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat [2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo [2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements [2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC [2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg [2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express [2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache [2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify [2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template [2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird [2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report > Geändert von zazfan (06.05.2013 um 14:05 Uhr) Grund: logs einfügen |
06.05.2013, 13:24 | #2 |
/// TB-Ausbilder | mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo,
__________________Kannst du die Logfiles bitte nicht anhängen (das erschwert mir das Auswerten massiv), sondern deren Inhalt direkt innerhalb von Codetags einfügen: [code]Inhalt Logfile[/code]. Falls die Logs zu gross sind, dann (und nur dann) in ein zip-Archiv (nicht *.7z) packen und anhängen. Danke.
__________________ |
06.05.2013, 14:10 | #3 |
/// TB-Ausbilder | mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Ok, dann versuch mal das:
__________________Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ |
07.05.2013, 11:28 | #4 |
| mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo Leo, danke für die schnelle Hilfe. Anbei die angeforderten Logs: AdwCleaner: Code:
ATTFilter # AdwCleaner v2.300 - Datei am 07/05/2013 um 11:01:43 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : strasseb - OSKAR # Bootmodus : Normal # Ausgeführt unter : C:\Users\strasseb\Downloads\trojaner board software\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk Datei Gelöscht : C:\Users\strasseb\AppData\Roaming\Mozilla\Firefox\Profiles\dlj3bm0d.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\strasseb\AppData\Roaming\Mozilla\Firefox\Profiles\dlj3bm0d.default\searchplugins\my-web-search.xml Ordner Gelöscht : C:\Program Files\MapsGalaxy_39 Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\Users\strasseb\AppData\Local\MapsGalaxy_39 Ordner Gelöscht : C:\Users\strasseb\AppData\LocalLow\MapsGalaxy_39 Ordner Gelöscht : C:\Users\strasseb\AppData\Roaming\Mozilla\Firefox\Profiles\dlj3bm0d.default\jetpack ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\strasseb\AppData\Roaming\Mozilla\Firefox\Profiles\dlj3bm0d.default\prefs.js C:\Users\strasseb\AppData\Roaming\Mozilla\Firefox\Profiles\dlj3bm0d.default\user.js ... Gelöscht ! Gelöscht : user_pref("extensions.mywebsearch.prevDefaultEngine", "Ask.com"); Gelöscht : user_pref("extensions.mywebsearch.prevKwdEnabled", true); Gelöscht : user_pref("extensions.mywebsearch.prevSelectedEngine", "Ask.com"); Gelöscht : user_pref("extensions.toolbar.mindspark._39Members_.homepage", "hxxp://home.mywebsearch.com/index.jh[...] -\\ Google Chrome v26.0.1410.64 Datei : C:\Users\strasseb\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [3586 octets] - [07/05/2013 11:01:43] ########## EOF - C:\AdwCleaner[S1].txt - [3646 octets] ########## Otl.txt Code:
ATTFilter OTL logfile created on: 07.05.2013 11:30:45 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\strasseb\Downloads\trojaner board software Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 70,05% Memory free 6,21 Gb Paging File | 5,29 Gb Available in Paging File | 85,17% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 221,39 Gb Total Space | 140,52 Gb Free Space | 63,47% Space Free | Partition Type: NTFS Drive D: | 11,49 Gb Total Space | 1,51 Gb Free Space | 13,15% Space Free | Partition Type: NTFS Computer Name: OSKAR | User Name: strasseb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.03 17:31:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\strasseb\Downloads\trojaner board software\OTL.exe PRC - [2013.05.02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2013.03.14 04:40:22 | 001,103,768 | ---- | M] (Spotify Ltd) -- C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.09.10 16:06:26 | 000,372,736 | ---- | M] (Secure Banking) -- C:\Programme\Secure Banking\SecureBanking.exe PRC - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.05.02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPoint\SetPoint.exe PRC - [2008.05.02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\KHAL2\KHALMNPR.exe PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2007.09.15 10:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynTPStart.exe PRC - [2007.09.05 13:09:54 | 001,620,520 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2007.09.05 13:09:54 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe ========== Modules (No Company Name) ========== MOD - [2012.09.07 17:30:34 | 000,002,560 | ---- | M] () -- C:\Programme\Secure Banking\sbservice.exe MOD - [2012.09.07 17:30:22 | 000,016,384 | ---- | M] () -- C:\Programme\Secure Banking\SecureBanking.dll MOD - [2012.09.05 20:49:54 | 000,008,704 | ---- | M] () -- C:\Programme\Secure Banking\funcs.dll MOD - [2010.02.12 10:37:50 | 000,633,696 | ---- | M] () -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll MOD - [2007.09.30 19:33:32 | 000,066,856 | ---- | M] () -- C:\Programme\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll MOD - [2007.09.05 12:52:04 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll MOD - [2007.08.14 15:43:46 | 006,365,184 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtGui4.dll MOD - [2007.07.12 13:55:52 | 000,131,072 | ---- | M] () -- C:\Programme\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll MOD - [2007.07.12 13:55:28 | 001,581,056 | ---- | M] () -- C:\Programme\Common Files\LightScribe\QtCore4.dll ========== Services (SafeList) ========== SRV - [2013.05.02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2013.04.23 09:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2013.04.20 15:10:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.12 18:45:36 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.25 06:13:10 | 000,567,256 | ---- | M] (Mister Group) [On_Demand | Stopped] -- C:\Programme\System Explorer\service\SystemExplorerService.exe -- (SystemExplorerHelpService) SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Programme\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe -- (DfSdkS) SRV - [2008.05.02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2007.03.05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\D91F.tmp -- (MEMSWEEP2) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2013.03.07 01:33:22 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2012.11.28 19:49:00 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.09.05 16:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008.03.04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService) DRV - [2008.02.29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV - [2008.02.29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2008.02.29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2007.10.18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2007.09.10 00:12:28 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService) DRV - [2007.07.11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2007.06.18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007.03.07 04:15:58 | 001,059,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD) DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007.02.16 23:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKLM\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{ABB9D7E1-CFEE-4A67-92A8-B5964E5B4803}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{F91A88AB-7B29-4D0B-A874-A26BC37F3536}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox" FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.2 FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68 FF - prefs.js..extensions.enabledAddons: %7B6bdc61ae-7b80-44a3-9476-e1d121ec2238%7D:0.85 FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.5.4 FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.5.2 FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8 FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.31 FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.1 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=" FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF - prefs.js..network.proxy.type: 2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.03 15:47:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 18:45:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.05.03 11:13:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.04.04 21:08:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.04.29 09:12:45 | 000,000,000 | ---D | M] [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions [2010.09.02 21:06:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2013.05.06 14:55:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions [2012.10.09 08:16:54 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013.04.28 18:23:12 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2013.04.28 18:23:06 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2013.05.01 01:39:19 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Users\strasseb\AppData\Roaming\mozilla\Firefox\Profiles\dlj3bm0d.default\extensions\https-everywhere@eff(86).org [2008.09.07 17:25:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\Sunbird\Profiles\1mckrlaz.default\extensions [2013.04.28 18:23:14 | 000,223,719 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\isreaditlater@ideashower.com.xpi [2013.04.28 16:40:49 | 000,262,896 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2013.04.28 16:52:25 | 000,370,423 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013.04.28 16:50:56 | 000,581,999 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\uriloader@pdf.js.xpi [2013.04.28 18:23:04 | 000,350,097 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2013.04.28 18:23:03 | 000,087,920 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013.04.28 18:23:03 | 000,073,384 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi [2013.05.06 14:55:20 | 000,534,214 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013.04.28 16:43:14 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.28 18:23:02 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013.04.29 13:09:11 | 000,002,402 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\mozilla\firefox\profiles\dlj3bm0d.default\searchplugins\bingp.xml [2013.04.29 10:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 18:45:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013.05.03 15:47:41 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2009.09.05 11:29:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2013.04.12 18:45:37 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.03.18 17:18:29 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.08 08:33:12 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.03.18 17:18:29 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.03.18 17:18:29 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.18 17:18:29 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.18 17:18:29 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://mega.co.nz/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2012.05.04 18:52:50 | 000,442,787 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 15216 more lines... O2 - BHO: (no name) - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - No CLSID value found. O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [SecureBanking] C:\Programme\Secure Banking\SecureBanking.exe (Secure Banking) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [Spotify Web Helper] C:\Users\strasseb\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O7 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data] O8 - Extra context menu item: Alles mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlall.htm File not found O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlselected.htm File not found O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dllink.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet) O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet) O15 - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CC7C804-C27F-46A2-861A-AAF879867857}: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005.09.11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.05.03 17:21:40 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Template [2013.05.03 16:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013.05.03 16:11:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2013.05.03 16:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013.05.03 15:48:13 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.03 15:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.05.03 15:48:12 | 000,368,944 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.03 15:48:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.03 15:48:07 | 000,056,080 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.03 15:48:06 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.03 15:48:03 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.03 15:46:59 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.03 14:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software(0) [2013.05.01 01:32:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Documents\wichtige thunderbird passphrase [2013.04.29 14:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Backup Manager [2013.04.29 13:59:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.04.29 13:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Password Protection Manager [2013.04.29 13:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\FAT32 Formatter [2013.04.29 03:44:31 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 03:20:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:18:29 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\vlc [2013.04.29 03:15:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013.04.29 03:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2013.04.29 03:12:03 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2013.04.29 03:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013.04.29 03:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013.04.29 02:51:52 | 000,000,000 | ---D | C] -- C:\Users\strasseb\.DVDslideshowGUI [2013.04.29 02:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter [2013.04.29 02:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Haali [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GUI for dvdauthor [2013.04.29 02:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\GUI for dvdauthor [2013.04.29 02:50:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AvsP [2013.04.29 02:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\AvsP [2013.04.29 02:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn [2013.04.29 02:49:49 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn [2013.04.29 02:49:04 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013.04.29 02:49:00 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2013.04.29 02:47:45 | 000,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI [2013.04.29 02:47:33 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:11 | 005,514,668 | ---- | C] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:46:51 | 005,082,084 | ---- | C] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 00:48:35 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\Tools für überprüfungen [2013.04.29 00:15:22 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\gnupg [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNU Privacy Guard [2013.04.29 00:07:39 | 000,000,000 | ---D | C] -- C:\Program Files\GNU [2013.04.28 23:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.28 18:50:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled [2013.04.28 18:09:02 | 000,025,088 | ---- | C] (TeamViewer GmbH) -- C:\Windows\System32\drivers\teamviewervpn.sys [2013.04.28 18:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013.04.28 17:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2013.04.28 17:52:29 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2013.04.28 17:33:06 | 000,000,000 | ---D | C] -- C:\Users\strasseb\Desktop\HP Drucker [2013.04.28 16:17:00 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine [2013.04.28 16:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\stinger [2013.04.28 16:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking [2013.04.28 16:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Secure Banking [2013.04.28 16:08:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.04.28 16:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.04.28 15:25:27 | 000,000,000 | ---D | C] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.04.28 15:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer [2013.04.28 15:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [2013.04.28 15:10:02 | 000,000,000 | ---D | C] -- C:\Program Files\System Explorer [2013.04.12 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2013.05.07 11:51:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.07 11:19:20 | 000,632,530 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.07 11:19:20 | 000,599,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.07 11:19:20 | 000,127,566 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.07 11:19:20 | 000,105,202 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.07 11:14:04 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.dat [2013.05.07 11:14:03 | 000,032,156 | ---- | M] () -- C:\ProgramData\nvModes.001 [2013.05.07 11:13:39 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.05.07 11:12:21 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.07 11:12:21 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.07 11:12:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.07 11:12:08 | 3220,103,168 | -HS- | M] () -- C:\hiberfil.sys [2013.05.07 11:11:13 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.05.07 11:00:56 | 000,000,791 | ---- | M] () -- C:\Users\strasseb\Desktop\adwcleaner.exe - Verknüpfung.lnk [2013.05.06 14:59:56 | 000,014,624 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.zip [2013.05.06 14:59:43 | 000,009,932 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer.zip [2013.05.03 17:39:43 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:39:06 | 000,000,795 | ---- | M] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:38:05 | 000,000,811 | ---- | M] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | M] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | M] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | M] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:58:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.05.03 15:48:13 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:31:24 | 000,000,762 | ---- | M] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 15:16:16 | 000,350,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.05.03 13:49:11 | 000,008,268 | ---- | M] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2013.05.02 16:52:41 | 000,174,664 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.05.02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.05.02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.05.02 01:34:09 | 000,049,376 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.05.02 01:34:08 | 000,049,760 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2013.05.02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.05.02 01:33:35 | 000,041,664 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013.05.02 01:33:27 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013.04.29 03:15:02 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:41 | 000,034,936 | ---- | M] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:48:31 | 000,000,902 | ---- | M] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:45 | 007,760,687 | ---- | M] (Boraxsoft) -- C:\Users\strasseb\AppData\Roaming\SetupGFD.exe [2013.04.29 02:47:33 | 005,243,208 | ---- | M] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:23 | 001,357,348 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:20 | 000,117,723 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:47:19 | 005,514,668 | ---- | M] (LIGHTNING UK!) -- C:\Users\strasseb\AppData\Roaming\Imgburn.exe [2013.04.29 02:47:11 | 005,082,084 | ---- | M] (The Public) -- C:\Users\strasseb\AppData\Roaming\Avisynth.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | M] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013.04.28 21:10:55 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.04.28 21:10:55 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.04.28 18:09:08 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | M] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:27:35 | 000,027,620 | ---- | M] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2013.04.10 20:19:30 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk ========== Files Created - No Company Name ========== [2013.05.07 11:00:56 | 000,000,791 | ---- | C] () -- C:\Users\strasseb\Desktop\adwcleaner.exe - Verknüpfung.lnk [2013.05.06 14:59:55 | 000,014,624 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.zip [2013.05.06 14:59:42 | 000,009,932 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer.zip [2013.05.03 17:39:43 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\defogger_reenable [2013.05.03 17:38:05 | 000,000,811 | ---- | C] () -- C:\Users\strasseb\Desktop\gmer_2.1.19163.exe - Verknüpfung.lnk [2013.05.03 17:37:35 | 000,000,750 | ---- | C] () -- C:\Users\strasseb\Desktop\OTL.exe - Verknüpfung.lnk [2013.05.03 17:36:42 | 000,000,795 | ---- | C] () -- C:\Users\strasseb\Desktop\Defogger.exe - Verknüpfung.lnk [2013.05.03 17:21:56 | 000,002,653 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Tabellenkalkulation.lnk [2013.05.03 17:21:37 | 000,000,000 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\wklnhst.dat [2013.05.03 17:21:26 | 000,002,032 | ---- | C] () -- C:\Users\strasseb\Desktop\Microsoft Works-Textverarbeitung.lnk [2013.05.03 17:10:02 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.05.03 16:50:49 | 000,000,373 | ---- | C] () -- C:\Users\strasseb\Desktop\Bilder - Verknüpfung.lnk [2013.05.03 16:10:52 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf [2013.05.03 15:48:13 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.05.03 15:48:05 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.05.03 15:48:04 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.05.03 15:31:24 | 000,000,762 | ---- | C] () -- C:\Users\strasseb\Documents\Meine freigegebenen Ordner.lnk [2013.05.03 13:59:46 | 3220,103,168 | -HS- | C] () -- C:\hiberfil.sys [2013.04.29 04:10:41 | 000,350,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.29 03:15:02 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2013.04.29 03:12:08 | 000,000,807 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk [2013.04.29 03:03:07 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013.04.29 03:03:07 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013.04.29 02:51:40 | 000,034,936 | ---- | C] () -- C:\Windows\System32\uninstHelixYUV.exe [2013.04.29 02:49:52 | 000,001,662 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk [2013.04.29 02:48:31 | 000,000,902 | ---- | C] () -- C:\Users\strasseb\Desktop\DVD slideshow GUI.lnk [2013.04.29 02:47:23 | 005,243,208 | ---- | C] ( ) -- C:\Users\strasseb\AppData\Roaming\AvsP.exe [2013.04.29 02:47:20 | 001,357,348 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\MatroskaSplitter.exe [2013.04.29 02:47:19 | 000,117,723 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\yuvcodecs-1.3.exe [2013.04.29 02:45:06 | 000,000,671 | ---- | C] () -- C:\Users\strasseb\Desktop\Download - Verknüpfung.lnk [2013.04.28 22:16:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013.04.28 18:09:08 | 000,000,967 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013.04.28 18:09:08 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013.04.28 16:34:11 | 002,335,270 | ---- | C] () -- C:\Windows\System32\85636D9.mht [2013.04.28 16:33:26 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a0687E5.mht [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.dat [2013.04.28 14:50:53 | 000,032,156 | ---- | C] () -- C:\ProgramData\nvModes.001 [2013.01.11 22:13:51 | 000,000,104 | ---- | C] () -- C:\Users\strasseb\Internet - Verknüpfung.lnk [2011.09.15 02:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin [2008.10.27 18:56:57 | 000,008,268 | ---- | C] () -- C:\Users\strasseb\AppData\Local\d3d9caps.dat [2008.10.27 14:01:05 | 000,004,096 | -H-- | C] () -- C:\Users\strasseb\AppData\Local\keyfile3.drm [2008.08.17 09:41:40 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.001 [2008.08.16 15:10:56 | 000,027,620 | ---- | C] () -- C:\Users\strasseb\AppData\Roaming\nvModes.dat [2008.08.15 20:00:51 | 000,008,192 | ---- | C] () -- C:\Users\strasseb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.07.25 18:15:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo [2012.07.25 17:16:31 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Ashampoo Slideshow Studio Elements [2012.06.02 16:17:20 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\EAC [2013.04.29 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\FNET [2013.05.03 12:25:59 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Free Download Manager [2013.04.29 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\gnupg [2010.08.20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Image Zone Express [2013.04.29 03:20:04 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\ImgBurn [2013.04.29 03:12:03 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\IrfanView [2008.09.07 19:00:01 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Printer Info Cache [2013.04.28 15:38:51 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Spotify [2013.04.29 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\TeamViewer [2013.05.03 17:21:40 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Template [2010.09.02 21:06:21 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\Thunderbird [2008.09.07 16:09:44 | 000,000,000 | ---D | M] -- C:\Users\strasseb\AppData\Roaming\WildTangent ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report > |
07.05.2013, 11:40 | #5 |
/// TB-Ausbilder | mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hey, wie läuft der Rechner denn jetzt? Schritt 1 Fixen mit OTL
Code:
ATTFilter :OTL @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com: C:\Program Files\MapsGalaxy_39\bar\1.bin FF - HKLM\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin: C:\Program Files\MapsGalaxy_39\bar\1.bin\NP39Stub.dll File not found IE - HKU\S-1-5-21-1888165910-1750397384-2113425497-1000\..\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=E90B559C-A755-4EC7-AF6F-B80BF6701273&apn_sauid=2E1EB563-DCD3-4CA3-925E-73B9F7DA0BDF :commands [emptytemp]
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck und:
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
08.05.2013, 07:51 | #6 |
| mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo Leo, der Rechner läuft wunderbar, nur bis er hochgefahren ist und alles geladen hat dauert noch ziemlich lange... Hier meine logs: Otl: Code:
ATTFilter All processes killed ========== OTL ========== Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 . Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\39ffxtbr@MapsGalaxy_39.com not found. File C:\Program Files\MapsGalaxy_39\bar\1.bin not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@MapsGalaxy_39.com/Plugin\ not found. Registry key HKEY_USERS\S-1-5-21-1888165910-1750397384-2113425497-1000\Software\Microsoft\Internet Explorer\SearchScopes\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29E9DFA0-F97D-4A9F-A8CE-E6F3784FBCCE}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: strasseb ->Temp folder emptied: 53593653 bytes ->Temporary Internet Files folder emptied: 6436036 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 69696436 bytes ->Google Chrome cache emptied: 11337943 bytes ->Flash cache emptied: 492 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1711027 bytes RecycleBin emptied: 1326995410 bytes Total Files Cleaned = 1.402,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05072013_134321 Files\Folders moved on Reboot... C:\Users\strasseb\AppData\Local\Temp\ehmsas.txt moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.05.07.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 strasseb :: OSKAR [Administrator] Schutz: Aktiviert 07.05.2013 14:02:04 mbam-log-2013-05-07 (14-02-04).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 201364 Laufzeit: 11 Minute(n), 43 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a71aaf9315904146939e8fb51d373ccf # engine=13775 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-07 05:24:07 # local_time=2013-05-07 07:24:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=774 16777213 85 91 357971 144657319 0 0 # compatibility_mode=5892 16776574 100 100 359893 205480175 0 0 # scanned=100469 # found=0 # cleaned=0 # scan_time=17671 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a71aaf9315904146939e8fb51d373ccf # engine=13779 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-08 05:02:46 # local_time=2013-05-08 07:02:46 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=774 16777213 85 91 399890 144699238 0 0 # compatibility_mode=5892 16776574 100 100 401812 205522094 0 0 # scanned=203084 # found=0 # cleaned=0 # scan_time=13974 Code:
ATTFilter Results of screen317's Security Check version 0.99.63 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Sophos Anti-Rootkit 1.5.0 Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 21 Adobe Flash Player 11.7.700.169 Adobe Reader 10.1.6 Adobe Reader out of Date! Mozilla Firefox (20.0.1) Mozilla Thunderbird (17.0.5) Google Chrome 26.0.1410.43 Google Chrome 26.0.1410.64 Google Chrome Plugins... ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
08.05.2013, 11:27 | #7 |
/// TB-Ausbilder | mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo, sieht gut aus. Und auch die Software ist schon alle aktuell. Wegen des langsamen Aufstartens: Vielleicht findest du hier eine Möglichkeit, das ein wenig zu beschleunigen: http://www.trojaner-board.de/71631-p...samer-tun.html Hier müssen wir nur noch aufräumen: Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
08.05.2013, 20:33 | #8 |
| mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Hallo Leo/Aharonov, vielen Dank für die schnelle und kompetente Hilfe Läuft alles wunderbar und habe auch noch richtig viel gelernt dabei lG zazfan |
08.05.2013, 20:45 | #9 |
/// TB-Ausbilder | mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? Danke für die Rückmeldung. Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu mapsgalaxy toolbar und mindspark toolbar platform plugin stub - wie entfernen? |
32 bit, 7-zip, antwort, anweisung, aswrvrt.sys, datei, deaktiviert, dynamic, entferne, entfernen, erstell, free download, google, hoffe, install.exe, intranet, komisch, konnte, laptop, launch, lightning, link, microsoft office 2003, mindspark, mindspark toolbar, officejet, plug-in, plugin, richtig, s3.amazonaws.com, spotify web helper, system, toolbar, verdächtig, versuche, versucht, vista, wie entfernen, wie entfernen?, windows, windows vista, windows xp |