![]() |
|
Plagegeister aller Art und deren Bekämpfung: Delta Search komplett entfernt?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() Delta Search komplett entfernt? Hallo, ich bin nicht sicher ob Delta Search komplett entfernt wurde. Hier die bisherigen Dateien: Gmer: GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-06-05 00:09:51 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEVS-60UST0 rev.01.01A01 232,89GB Running: gmer_2.1.19163.exe; Driver: C:\Users\tanja\AppData\Local\Temp\ugloipow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwAdjustPrivilegesToken [0x9E625BDC] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwAlpcConnectPort [0x9E627538] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwAlpcCreatePort [0x9E62778E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwAlpcSendWaitReceivePort [0x9E627A08] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwClose [0x9E62645C] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwConnectPort [0x9E626B3E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateEvent [0x9E626F48] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateFile [0x9E626604] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateMutant [0x9E626E20] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateNamedPipeFile [0x9E6257E2] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreatePort [0x9E626CDC] SSDT 8B6347DE ZwCreateSection SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateSemaphore [0x9E62707A] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateSymbolicLinkObject [0x9E628CBC] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateThread [0x9E6260FA] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateWaitablePort [0x9E626D7E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDebugActiveProcess [0x9E6286AE] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwDuplicateObject [0x9E62967E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwFsControlFile [0x9E62675E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwLoadDriver [0x9E628740] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwMapViewOfSection [0x9E628D70] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenEvent [0x9E626FEA] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenFile [0x9E6264DE] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenMutant [0x9E626EB8] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenProcess [0x9E625DE2] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenSection [0x9E628CE6] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenSemaphore [0x9E62711C] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwOpenThread [0x9E625D06] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueryDirectoryObject [0x9E627C4A] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQuerySection [0x9E629088] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwQueueApcThread [0x9E6289D6] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwReplyPort [0x9E6274A6] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwReplyWaitReceivePort [0x9E62736C] SSDT 8B6347E8 ZwRequestWaitReplyPort SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwResumeThread [0x9E629560] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSecureConnectPort [0x9E626878] SSDT 8B6347E3 ZwSetContextThread SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetInformationToken [0x9E627CFE] SSDT 8B6347ED ZwSetSecurityObject SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSetSystemInformation [0x9E6291C8] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSuspendProcess [0x9E6292AC] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwSuspendThread [0x9E6293D4] SSDT 8B6347F2 ZwSystemDebugControl SSDT 8B63477F ZwTerminateProcess SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwTerminateThread [0x9E625EB0] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwUnmapViewOfSection [0x9E628F3E] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwWriteVirtualMemory [0x9E62603A] SSDT \SystemRoot\system32\DRIVERS\klif.sys ZwCreateThreadEx [0x9E6261FA] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeSetEvent + 119 82CE685C 4 Bytes [DC, 5B, 62, 9E] {FCOMP QWORD [EBX+0x62]; SAHF } .text ntkrnlpa.exe!KeSetEvent + 13D 82CE6880 8 Bytes [38, 75, 62, 9E, 8E, 77, 62, ...] .text ntkrnlpa.exe!KeSetEvent + 181 82CE68C4 4 Bytes [08, 7A, 62, 9E] {OR [EDX+0x62], BH; SAHF } .text ntkrnlpa.exe!KeSetEvent + 1A9 82CE68EC 4 Bytes [5C, 64, 62, 9E] .text ntkrnlpa.exe!KeSetEvent + 1C1 82CE6904 4 Bytes CALL E539A78B .text ... .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9D40E000, 0x391095, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtCreateFile + 6 7740424A 4 Bytes [28, 0C, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtCreateFile + B 7740424F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtMapViewOfSection + 6 7740499A 4 Bytes [28, 0F, 7C, 00] {SUB [EDI], CL; JL 0x4} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtMapViewOfSection + B 7740499F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenFile + 6 77404A2A 4 Bytes [68, 0C, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenFile + B 77404A2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcess + 6 77404AAA 4 Bytes [A8, 0D, 7C, 00] {TEST AL, 0xd; JL 0x4} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcess + B 77404AAF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcessToken + 6 77404ABA 4 Bytes CALL 7640C6CC C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcessToken + B 77404ABF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcessTokenEx + 6 77404ACA 4 Bytes [A8, 0E, 7C, 00] {TEST AL, 0xe; JL 0x4} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenProcessTokenEx + B 77404ACF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThread + 6 77404B1A 4 Bytes [68, 0D, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThread + B 77404B1F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThreadToken + 6 77404B2A 4 Bytes [68, 0E, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThreadToken + B 77404B2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThreadTokenEx + 6 77404B3A 4 Bytes CALL 7640C74D C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtOpenThreadTokenEx + B 77404B3F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtQueryAttributesFile + 6 77404BCA 4 Bytes [A8, 0C, 7C, 00] {TEST AL, 0xc; JL 0x4} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtQueryAttributesFile + B 77404BCF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtQueryFullAttributesFile + 6 77404C7A 4 Bytes CALL 7640C88B C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtQueryFullAttributesFile + B 77404C7F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtSetInformationFile + 6 7740515A 4 Bytes [28, 0D, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtSetInformationFile + B 7740515F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtSetInformationThread + 6 774051AA 4 Bytes [28, 0E, 7C, 00] {SUB [ESI], CL; JL 0x4} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtSetInformationThread + B 774051AF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtUnmapViewOfSection + 6 7740544A 4 Bytes [68, 0F, 7C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[3368] ntdll.dll!NtUnmapViewOfSection + B 7740544F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtCreateFile + 6 7740424A 4 Bytes [28, 18, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtCreateFile + B 7740424F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtMapViewOfSection + 6 7740499A 4 Bytes [28, 1B, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtMapViewOfSection + B 7740499F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenFile + 6 77404A2A 4 Bytes [68, 18, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenFile + B 77404A2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcess + 6 77404AAA 4 Bytes [A8, 19, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcess + B 77404AAF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcessToken + 6 77404ABA 4 Bytes CALL 76413BD8 C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcessToken + B 77404ABF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcessTokenEx + 6 77404ACA 4 Bytes [A8, 1A, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenProcessTokenEx + B 77404ACF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThread + 6 77404B1A 4 Bytes [68, 19, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThread + B 77404B1F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThreadToken + 6 77404B2A 4 Bytes [68, 1A, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThreadToken + B 77404B2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThreadTokenEx + 6 77404B3A 4 Bytes CALL 76413C59 C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtOpenThreadTokenEx + B 77404B3F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtQueryAttributesFile + 6 77404BCA 4 Bytes [A8, 18, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtQueryAttributesFile + B 77404BCF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtQueryFullAttributesFile + 6 77404C7A 4 Bytes CALL 76413D97 C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtQueryFullAttributesFile + B 77404C7F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtSetInformationFile + 6 7740515A 4 Bytes [28, 19, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtSetInformationFile + B 7740515F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtSetInformationThread + 6 774051AA 4 Bytes [28, 1A, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtSetInformationThread + B 774051AF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtUnmapViewOfSection + 6 7740544A 4 Bytes [68, 1B, F1, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5028] ntdll.dll!NtUnmapViewOfSection + B 7740544F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtCreateFile + 6 7740424A 4 Bytes [28, 20, 2C, 00] {SUB [EAX], AH; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtCreateFile + B 7740424F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtMapViewOfSection + 6 7740499A 4 Bytes [28, 23, 2C, 00] {SUB [EBX], AH; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtMapViewOfSection + B 7740499F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenFile + 6 77404A2A 4 Bytes [68, 20, 2C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenFile + B 77404A2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcess + 6 77404AAA 4 Bytes [A8, 21, 2C, 00] {TEST AL, 0x21; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcess + B 77404AAF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcessToken + 6 77404ABA 4 Bytes CALL 764076E0 C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcessToken + B 77404ABF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcessTokenEx + 6 77404ACA 4 Bytes [A8, 22, 2C, 00] {TEST AL, 0x22; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenProcessTokenEx + B 77404ACF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThread + 6 77404B1A 4 Bytes [68, 21, 2C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThread + B 77404B1F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThreadToken + 6 77404B2A 4 Bytes [68, 22, 2C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThreadToken + B 77404B2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThreadTokenEx + 6 77404B3A 4 Bytes CALL 76407761 C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtOpenThreadTokenEx + B 77404B3F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtQueryAttributesFile + 6 77404BCA 4 Bytes [A8, 20, 2C, 00] {TEST AL, 0x20; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtQueryAttributesFile + B 77404BCF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtQueryFullAttributesFile + 6 77404C7A 4 Bytes CALL 7640789F C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtQueryFullAttributesFile + B 77404C7F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtSetInformationFile + 6 7740515A 4 Bytes [28, 21, 2C, 00] {SUB [ECX], AH; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtSetInformationFile + B 7740515F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtSetInformationThread + 6 774051AA 4 Bytes [28, 22, 2C, 00] {SUB [EDX], AH; SUB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtSetInformationThread + B 774051AF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtUnmapViewOfSection + 6 7740544A 4 Bytes [68, 23, 2C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5200] ntdll.dll!NtUnmapViewOfSection + B 7740544F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtCreateFile + 6 7740424A 4 Bytes [28, BC, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtCreateFile + B 7740424F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtMapViewOfSection + 6 7740499A 4 Bytes [28, BF, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtMapViewOfSection + B 7740499F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenFile + 6 77404A2A 4 Bytes [68, BC, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenFile + B 77404A2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcess + 6 77404AAA 4 Bytes [A8, BD, 1C, 00] {TEST AL, 0xbd; SBB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcess + B 77404AAF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcessToken + 6 77404ABA 4 Bytes CALL 7640677C C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcessToken + B 77404ABF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcessTokenEx + 6 77404ACA 4 Bytes [A8, BE, 1C, 00] {TEST AL, 0xbe; SBB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenProcessTokenEx + B 77404ACF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThread + 6 77404B1A 4 Bytes [68, BD, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThread + B 77404B1F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThreadToken + 6 77404B2A 4 Bytes [68, BE, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThreadToken + B 77404B2F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThreadTokenEx + 6 77404B3A 4 Bytes CALL 764067FD C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtOpenThreadTokenEx + B 77404B3F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtQueryAttributesFile + 6 77404BCA 4 Bytes [A8, BC, 1C, 00] {TEST AL, 0xbc; SBB AL, 0x0} .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtQueryAttributesFile + B 77404BCF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtQueryFullAttributesFile + 6 77404C7A 4 Bytes CALL 7640693B C:\Windows\system32\SHELL32.dll .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtQueryFullAttributesFile + B 77404C7F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtSetInformationFile + 6 7740515A 4 Bytes [28, BD, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtSetInformationFile + B 7740515F 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtSetInformationThread + 6 774051AA 4 Bytes [28, BE, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtSetInformationThread + B 774051AF 1 Byte [E2] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtUnmapViewOfSection + 6 7740544A 4 Bytes [68, BF, 1C, 00] .text C:\Users\tanja\AppData\Local\Google\Chrome\Application\chrome.exe[5524] ntdll.dll!NtUnmapViewOfSection + B 7740544F 1 Byte [E2] OTL:OTL Logfile: Code:
ATTFilter OTL logfile created on: 04.06.2013 20:49:15 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tanja\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 0,87 Gb Available Physical Memory | 43,55% Memory free 4,23 Gb Paging File | 2,78 Gb Available in Paging File | 65,60% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 147,94 Gb Free Space | 63,53% Space Free | Partition Type: NTFS Drive D: | 5,95 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: TANJA-PC | User Name: tanja | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\tanja\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\WINDOWS\System32\atieclxx.exe (AMD) PRC - C:\WINDOWS\System32\atiesrxx.exe (AMD) PRC - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.) PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\conime.exe (Microsoft Corporation) PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_030ac640\stacsv.exe (IDT, Inc.) PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe (Andrea Electronics Corporation) PRC - C:\WINDOWS\WindowsMobile\wmdSync.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\agrsmsvc.exe (Agere Systems) ========== Modules (No Company Name) ========== MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll () MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll () MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\pdf.dll () MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\libglesv2.dll () MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\libegl.dll () MOD - C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\2bc38488f9988db801a844e2590294a3\System.Security.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3da65115bf9debbf564861f6b123a2e4\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e9ea3e70247b4aa4a8b260426db3aa6b\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\15e2d7f51f15830591727d6d6a1e4032\System.ServiceProcess.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\d995a0e7d64a874cddea6294caaa2539\System.Transactions.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\0f5a23bb73681b6388daccd8e250ba66\System.Data.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll () MOD - C:\WINDOWS\System32\atitmpxx.dll () MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll () MOD - C:\WINDOWS\System32\msjetoledb40.dll () MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll () MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll () MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll () MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll () MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll () MOD - C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll () MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll () MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll () MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll () ========== Services (SafeList) ========== SRV - (Recovery Service for Windows) -- C:\Windows\SMINST\BLService.exe File not found SRV - (FreemakeVideoCapture) -- C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe File not found SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (AMD External Events Utility) -- C:\WINDOWS\System32\atiesrxx.exe (AMD) SRV - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.) SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab) SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) SRV - (STacSV) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_030ac640\stacsv.exe (IDT, Inc.) SRV - (IAANTMON) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) SRV - (AESTFilters) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe (Andrea Electronics Corporation) SRV - (ezSharedSvc) -- C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS) SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (WcesComm) -- C:\WINDOWS\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\WINDOWS\WindowsMobile\rapimgr.dll (Microsoft Corporation) SRV - (AgereModemAudio) -- C:\WINDOWS\System32\agrsmsvc.exe (Agere Systems) ========== Driver Services (SafeList) ========== DRV - (UIUSys) -- system32\DRIVERS\UIUSYS.SYS File not found DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found DRV - (catchme) -- C:\Users\tanja\AppData\Local\Temp\catchme.sys File not found DRV - (MBAMSwissArmy) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) DRV - (avipbb) -- C:\WINDOWS\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV - (avgntflt) -- C:\WINDOWS\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV - (avkmgr) -- C:\WINDOWS\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV - (ssmdrv) -- C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (KLIF) -- C:\WINDOWS\System32\drivers\klif.sys (Kaspersky Lab) DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdap) -- C:\WINDOWS\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV - (AtiHDAudioService) -- C:\WINDOWS\System32\drivers\AtihdLH3.sys (Advanced Micro Devices) DRV - (amdiox86) -- C:\WINDOWS\System32\drivers\amdiox86.sys (Advanced Micro Devices) DRV - (winusb) -- C:\WINDOWS\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s1018mdm) -- C:\WINDOWS\System32\drivers\s1018mdm.sys (MCCI Corporation) DRV - (s1018mgmt) -- C:\WINDOWS\System32\drivers\s1018mgmt.sys (MCCI Corporation) DRV - (s1018bus) -- C:\WINDOWS\System32\drivers\s1018bus.sys (MCCI Corporation) DRV - (s1018nd5) -- C:\WINDOWS\System32\drivers\s1018nd5.sys (MCCI Corporation) DRV - (s1018mdfl) -- C:\WINDOWS\System32\drivers\s1018mdfl.sys (MCCI Corporation) DRV - (s1018unic) -- C:\WINDOWS\System32\drivers\s1018unic.sys (MCCI Corporation) DRV - (s1018obex) -- C:\WINDOWS\System32\drivers\s1018obex.sys (MCCI Corporation) DRV - (RTL8169) -- C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation ) DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (AtiPcie) -- C:\WINDOWS\System32\drivers\AtiPcie.sys (ATI Technologies Inc.) DRV - (athr) -- C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (STHDA) -- C:\WINDOWS\System32\drivers\stwrt.sys (IDT, Inc.) DRV - (JMCR) -- C:\WINDOWS\System32\drivers\jmcr.sys (JMicron Technology Corp.) DRV - (hpdskflt) -- C:\WINDOWS\System32\drivers\hpdskflt.sys (Hewlett-Packard Corporation) DRV - (Accelerometer) -- C:\WINDOWS\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation) DRV - (hwdatacard) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV - (AgereSoftModem) -- C:\WINDOWS\System32\drivers\AGRSM.sys (Agere Systems) DRV - (enecir) -- C:\WINDOWS\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.) DRV - (seehcri) -- C:\WINDOWS\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications) DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.) DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.) DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvm60x32.sys (NVIDIA Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4 IE - HKLM\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 IE - HKLM\..\SearchScopes\{D9A80BB3-B0E4-4B4D-93DF-67B60F57DAC5}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKLM\..\SearchScopes\{DE9FEAA3-5CD2-4DC3-A08D-D2562FDD252F}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {6ECF98C8-BFCA-4547-ACEF-8D6F006B502A} IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = hxxp://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4 IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.delta-search.com/?q={searchTerms}&affID=119357&tt=gc_&babsrc=SP_ss&mntrId=EC27002186AC455A IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=PV&apn_dtid=YYYYYYYYDE&apn_uid=737A2F37-8F9E-4FF8-895E-2AD2D4F41253&apn_sauid=D2D14019-853C-4B39-A28E-9C12A3559DD3 IE - HKCU\..\SearchScopes\{46EC9B81-47EC-48A1-A269-47ED20F0A29D}: "URL" = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKCU\..\SearchScopes\{6ECF98C8-BFCA-4547-ACEF-8D6F006B502A}: "URL" = hxxp://start.funmoods.com/results.php?f=4&a=make&q={searchTerms} IE - HKCU\..\SearchScopes\{821BFD3B-AF05-4E82-A498-7759F19A3E57}: "URL" = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{AA69D842-11F4-425A-A485-5B3BF09B35B0}: "URL" = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 IE - HKCU\..\SearchScopes\{D9A80BB3-B0E4-4B4D-93DF-67B60F57DAC5}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933 IE - HKCU\..\SearchScopes\{DE5AE17E-2CE1-4989-990D-50470E22E90E}: "URL" = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{DE9FEAA3-5CD2-4DC3-A08D-D2562FDD252F}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\tanja\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll ( ) FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\tanja\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( ) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\tanja\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\tanja\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2013.05.02 09:58:55 | 000,000,000 | ---D | M] [2012.01.31 18:30:47 | 000,002,047 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}, CHR - homepage: hxxp://www.delta-search.com/?affID=119357&tt=gc_&babsrc=HP_ss&mntrId=EC27002186AC455A CHR - plugin: Shockwave Flash (Enabled) = C:\Users\tanja\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\tanja\AppData\Local\Google\Chrome\Application\27.0.1453.94\pdf.dll CHR - plugin: Freemake np-plugin for google chrome (Enabled) = C:\Users\tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\npFreemake.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 6 U33 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll CHR - plugin: Java Deployment Toolkit 6.0.330.3 (Enabled) = C:\Windows\system32\npdeployJava1.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Facebook Plugin (Enabled) = C:\Users\tanja\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll CHR - plugin: Facebook Plugin (Enabled) = C:\Users\tanja\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2011.05.01 19:07:38 | 000,000,098 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {120A8821-2BEE-4C29-BCDA-62C577781992} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\WINDOWS\WindowsMobile\wmdSync.exe (Microsoft Corporation) O4 - HKCU..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe File not found O4 - HKCU..\Run: [PCSpeedUp] C:\Program Files\PC Beschleunigen\PCSpeedUp.lnk () O4 - Startup: C:\Users\tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Inhaltsverzeichnis.onetoc2 () O4 - Startup: C:\Users\tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O15 - HKCU\..Trusted Domains: com ([www.msi] http in Trusted sites) O15 - HKCU\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites) O15 - HKCU\..Trusted Domains: com.tw ([global.msi] http in Trusted sites) O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA) O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan.cab (JordanUploader Class) O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/RELEASECAB/install.cab (WebSDev Control) O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab (CeWe Color AG & Co. OHG Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab (EPUImageControl Class) O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab (IPSUploader4 Control) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.13.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C75A6B42-3CEA-4248-95CE-CD403A440A60}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\vsharechrome - No CLSID value found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\tanja\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\tanja\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013.06.03 21:59:12 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.06.03 22:23:10 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2013.06.03 22:23:09 | 000,000,000 | ---D | C] -- C:\Users\tanja\AppData\Roaming\Malwarebytes [2013.06.03 21:58:22 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013.06.03 21:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013.06.03 21:11:56 | 000,000,000 | ---D | C] -- C:\Users\tanja\AppData\Roaming\DealPly [2013.06.03 21:11:41 | 000,000,000 | ---D | C] -- C:\Users\tanja\AppData\Roaming\DSite [2013.06.03 21:11:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon [2013.06.03 21:11:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2013.06.03 21:11:28 | 000,000,000 | ---D | C] -- C:\Users\tanja\AppData\Roaming\Babylon [2013.05.15 20:37:59 | 000,000,000 | ---D | C] -- C:\Users\tanja\AppData\Roaming\GTek [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.06.04 20:45:09 | 000,000,000 | ---- | M] () -- C:\Users\tanja\defogger_reenable [2013.06.04 20:33:05 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.06.04 20:31:38 | 000,000,277 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2013.06.04 20:31:10 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.06.04 20:28:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2163405644-2042700254-2785213940-1004UA.job [2013.06.04 20:27:21 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.06.04 20:25:41 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.06.04 20:25:41 | 000,003,216 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.06.04 20:25:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.06.04 20:25:24 | 2145,214,464 | -HS- | M] () -- C:\hiberfil.sys [2013.06.04 10:47:17 | 000,008,331 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.06.03 22:23:41 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2013.06.03 21:59:12 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013.06.03 21:28:01 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2163405644-2042700254-2785213940-1004Core.job [2013.06.03 21:11:51 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\DSite.job [2013.05.31 21:25:20 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.31 21:25:20 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.31 21:25:20 | 000,126,704 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.31 21:25:20 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.30 13:11:01 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\MT66 Software Update.job [2013.05.26 16:29:41 | 000,002,080 | ---- | M] () -- C:\Users\tanja\Desktop\Google Chrome.lnk [2013.05.19 15:10:52 | 000,327,296 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.06.04 20:45:09 | 000,000,000 | ---- | C] () -- C:\Users\tanja\defogger_reenable [2013.06.03 21:59:12 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013.06.03 21:11:50 | 000,000,286 | ---- | C] () -- C:\Windows\tasks\DSite.job [2012.11.20 21:41:08 | 000,108,650 | ---- | C] () -- C:\Users\tanja\CIMG2560.jpg [2012.11.20 21:40:51 | 000,103,376 | ---- | C] () -- C:\Users\tanja\CIMG2559.jpg [2012.11.20 21:40:34 | 000,089,780 | ---- | C] () -- C:\Users\tanja\CIMG2558.jpg [2012.11.20 21:40:16 | 000,078,283 | ---- | C] () -- C:\Users\tanja\CIMG2556.jpg [2012.11.20 21:39:57 | 000,108,160 | ---- | C] () -- C:\Users\tanja\CIMG2553.jpg [2012.11.20 21:39:41 | 000,103,018 | ---- | C] () -- C:\Users\tanja\CIMG2551.jpg [2012.11.20 21:39:25 | 000,098,300 | ---- | C] () -- C:\Users\tanja\CIMG2549.jpg [2012.11.20 21:38:23 | 000,107,270 | ---- | C] () -- C:\Users\tanja\CIMG2561.jpg [2012.08.28 10:04:34 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.08.28 10:04:34 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.08.28 10:04:34 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2012.08.28 10:04:32 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.01.31 18:16:37 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2012.01.31 18:16:36 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2012.01.31 18:16:31 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2012.01.31 18:16:31 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2012.01.31 18:16:29 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011.12.10 14:57:34 | 000,000,040 | ---- | C] () -- C:\Users\tanja\AppData\Roaming\cdr.ini [2011.04.28 17:30:38 | 000,000,552 | ---- | C] () -- C:\Users\tanja\AppData\Local\d3d8caps.dat [2010.09.18 20:31:25 | 000,006,116 | ---- | C] () -- C:\Users\tanja\.recently-used.xbel [2010.06.26 07:17:35 | 000,001,356 | ---- | C] () -- C:\Users\tanja\AppData\Local\d3d9caps.dat [2009.06.16 21:53:05 | 000,000,098 | ---- | C] () -- C:\Users\tanja\AppData\Roaming\wklnhst.dat [2009.06.14 13:56:19 | 000,015,360 | ---- | C] () -- C:\Users\tanja\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.01.27 13:53:51 | 000,028,599 | ---- | C] () -- C:\ProgramData\nvModes.dat [2009.01.27 13:53:51 | 000,028,599 | ---- | C] () -- C:\ProgramData\nvModes.001 [2008.06.23 13:02:02 | 000,097,410 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 [2008.05.23 17:48:50 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.11.21 15:16:57 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\AnvSoft [2011.04.28 21:49:26 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Ashampoo [2013.06.03 21:11:28 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Babylon [2011.03.31 21:47:53 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Canneverbe Limited [2012.01.19 18:37:52 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Clone2Go Audio Converter Free Version [2013.06.03 21:11:56 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\DealPly [2012.12.03 22:12:52 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\DesktopIconForAmazon [2013.06.03 21:11:41 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\DSite [2012.07.29 21:41:38 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\DVDVideoSoft [2012.01.20 18:27:10 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\DVDVideoSoftIEHelpers [2010.03.01 21:18:09 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Facebook [2010.09.11 07:09:19 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\gtk-2.0 [2011.11.21 15:16:35 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\OpenCandy [2011.03.20 21:38:05 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\OpenOffice.org [2009.06.13 06:49:13 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Opera [2013.06.03 21:43:57 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Philipp Winterberg [2013.04.12 20:59:37 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Samsung [2009.06.16 21:53:18 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Template [2011.04.28 14:02:54 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\TrojanHunter [2012.01.31 18:18:09 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Video DVD Maker FREE [2011.08.20 21:31:01 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Vodafone [2012.06.03 12:14:46 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\XnView [2009.06.26 21:02:24 | 000,000,000 | ---D | M] -- C:\Users\tanja\AppData\Roaming\Zylom ========== Purity Check ========== < End of report > OTL Extras:OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 29.04.2011 19:36:08 - Run 2 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\tanja\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 44,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 73,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 195,86 Gb Free Space | 84,10% Space Free | Partition Type: NTFS Computer Name: TANJA-PC | User Name: tanja | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .bat [@ = batfile] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [CEWE FOTOSCHAU] -- "C:\Program Files\dm\dm-Fotowelt\CEWE FOTOSCHAU.exe" -d "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [dm-Fotowelt] -- "C:\Program Files\dm\dm-Fotowelt\dm-Fotowelt.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0E4080A2-4DFE-447A-89C5-294B5F8AFC54}" = lport=2869 | protocol=6 | dir=in | app=system | "{0EDDA007-FD65-46AF-89F4-1AC92E83C30A}" = lport=445 | protocol=6 | dir=in | app=system | "{18DF71C7-942F-4188-8C99-17D015E86AE3}" = rport=139 | protocol=6 | dir=out | app=system | "{3A8669AD-2D6D-4B6E-AB10-19B3568625EF}" = lport=137 | protocol=17 | dir=in | app=system | "{533FF4FC-3380-4738-BD98-C17E686D3521}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{53CEAAB8-4874-4D71-B2F7-4AF629F1A105}" = lport=138 | protocol=17 | dir=in | app=system | "{71BFB6E2-3E93-4926-A84B-03AA555B5B9D}" = rport=445 | protocol=6 | dir=out | app=system | "{AEFD7D35-41B2-4898-B80B-F3495412F5DF}" = rport=137 | protocol=17 | dir=out | app=system | "{B2087C5F-4404-4F8C-8729-DF144A316DA9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{B44CB042-F8EF-4E5A-9370-EB16A8CC5617}" = lport=139 | protocol=6 | dir=in | app=system | "{DB0A47E9-0590-4F3F-8286-293B08AEE3F8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{FCD16410-4192-4F98-A64C-C7BE1BFC825E}" = rport=138 | protocol=17 | dir=out | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{21E66A03-70A0-4BF0-BE99-F75012840F1E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{2FC616A3-0BCD-4071-B8AB-185F7E742DB1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{370DAC5C-E88E-4629-8864-875264EA4438}" = dir=in | app=c:\program files\itunes\itunes.exe | "{503906D1-11BB-48E4-B1A5-49F8B83B71D9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{5375EF57-FA49-46D2-8D26-8AEFF09C4A04}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{57BAE173-1FA5-418A-95D3-4EC98114C574}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5F777A5C-DAF8-4DC3-A382-69CE3D9608E7}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{6DD883D7-6C64-48E2-9420-193E37B16C08}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{72CB9BCF-EE32-4B0E-AB33-D7E4CB50587B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{7389CCD4-CDF6-44CA-9CCE-BB46741CBEE1}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{816C9D53-7382-473F-AF53-232AB9F734D2}" = dir=in | app=c:\program files\finalmediaplayer\fmpcheckforupdates.exe | "{A619F510-808A-4100-B717-241278A59F9A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{B2489612-AB6D-4B8B-B6E8-D3AA5838CD1B}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{C217537B-B728-4A63-AF21-D8BBEDD0A6D6}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{CCE364AA-E71D-413D-A5F6-781B9BE085FB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{DEC51382-E5B5-4F03-B708-FE7F975C5C17}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{F3429D8E-2F33-4643-83F3-498279262998}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "TCP Query User{2E41DDC9-C91C-4AEE-B767-725D2A912AD6}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "TCP Query User{4077F823-CE28-48BA-9269-7729D806AB8D}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "TCP Query User{56301984-0906-404C-8B33-B9BAB7738144}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{855256BC-1F13-48A8-9EC4-D3824A02DEED}C:\program files\tvants\tvants.exe" = protocol=6 | dir=in | app=c:\program files\tvants\tvants.exe | "TCP Query User{9E34CA35-2476-4E2F-874D-56D2462641E2}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{AA3C790B-AFB0-42AA-845D-948A260A36E3}C:\program files\tvuplayer\tvuplayer.exe" = protocol=6 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe | "TCP Query User{E4F2FF89-DFD7-441A-B687-88CAB02E9F42}C:\program files\wolfenstein - enemy territory\et.exe" = protocol=6 | dir=in | app=c:\program files\wolfenstein - enemy territory\et.exe | "TCP Query User{EC7AA552-11F2-4E73-92E6-15C6968666D3}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | "UDP Query User{18B7BD88-C625-4729-8B9A-057AE3DDD519}C:\program files\tvuplayer\tvuplayer.exe" = protocol=17 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe | "UDP Query User{265B3848-9370-4FA4-A6DB-77F338615A25}C:\program files\wolfenstein - enemy territory\et.exe" = protocol=17 | dir=in | app=c:\program files\wolfenstein - enemy territory\et.exe | "UDP Query User{301E8F78-56EC-4B3E-88C9-BC613AAC57F5}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "UDP Query User{455DC5BC-FBEC-4F2E-A99C-385F2C2C7D38}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{5FB79144-A7FA-4625-8AD1-FBF9A98BEFCD}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "UDP Query User{672E29E8-A0F8-45F0-84FF-E65598988693}C:\program files\tvants\tvants.exe" = protocol=17 | dir=in | app=c:\program files\tvants\tvants.exe | "UDP Query User{C7F213A2-6D72-464A-B112-95F4956E9C59}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | "UDP Query User{D9C3F28A-A41C-4E26-8F70-68A32427DCFB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1C34CDB8-113E-1075-2689-286A54CF50AD}" = Catalyst Control Center Graphics Full Existing "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 24 "{26B318E5-56E1-02AD-0005-868DD19E8B4A}" = Catalyst Control Center Localization German "{28C3E5E6-5ACA-408D-9A46-089C5334EC97}" = HP Help and Support "{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{2BEA657F-D1A0-5978-D8FA-E4541E2717FB}" = Catalyst Control Center Graphics Full New "{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support "{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}" = HP QuickTouch 1.00 D2 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2 "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module "{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7 "{48142A2C-F339-A6D4-D485-7D82C6E829F8}" = ccc-utility "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update "{51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A}" = HP Easy Setup - Frontend "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{52CC81B2-19E8-E159-EF1C-F737762D99D2}" = Catalyst Control Center Graphics Previews Vista "{558FF444-F562-4E4C-98BD-7B20EE184D2E}" = Catalyst Control Center - Branding "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{582287DA-0806-4AC0-BF19-C15E3A466034}" = LightScribe System Software 1.12.33.2 "{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{619B5360-FB03-D666-6C84-7982E1B1EE63}" = ccc-core-static "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73224864-7DAB-305E-2705-85109D8D4C7C}" = Skins "{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module "{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger "{83B41111-C648-3AF1-CB40-38BFBDDA445F}" = Catalyst Control Center Core Implementation "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver "{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91E04CA7-0B13-4F8C-AA4D-2A573AC96D19}" = Windows Live Essentials "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9F238A60-C445-4B81-8EDE-07DC924E98F8}" = HP MULTIPLE MODEM INSTALLER for VISTA "{A1399B3E-93A8-E865-EC9B-6B452E3094E5}" = Catalyst Control Center InstallProxy "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A5CE7175-080D-49AC-B5A3-E7E3502428F5}" = HP Wireless Assistant "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.3 - Deutsch "{B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21}" = HP Customer Experience Enhancements "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B95197E0-3A42-8935-8CC8-86E2238B62D2}" = CCC Help English "{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update "{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CB71A20E-B1B4-4562-81FA-33E1DBD0342F}" = ProtectSmart Hard Drive Protection "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{E3778D3F-0038-F606-CE2A-C82B4398B05A}" = Catalyst Control Center Graphics Previews Common "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor "{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}" = HP User Guides 0102 "{F4FF044B-D02A-FFA9-0F7D-3EE46B788A42}" = Catalyst Control Center Graphics Light "{F5EE4ED1-E6E8-A5F0-A95D-A20FF0767345}" = ATI Catalyst Install Manager "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FEA65C4D-382F-D881-D29E-E5FDD76DDD7F}" = CCC Help German "7-Zip" = 7-Zip 4.65 "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Agere Systems Soft Modem" = Agere Systems HDA Modem "AOL Toolbar" = AOL Toolbar 5.0 "Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.80 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0 "Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter "conduitEngine" = Conduit Engine "dm-Fotowelt" = dm-Fotowelt "FinalMediaPlayer_is1" = Final Media Player 2011 "Free RAR Extract Frog" = Free RAR Extract Frog "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "MyAshampoo Toolbar" = MyAshampoo Toolbar "NVIDIA Drivers" = NVIDIA Drivers "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6 "Stellar Phoenix Windows Data Recovery-Home_is1" = Stellar Phoenix Windows Data Recovery-Home "SynTPDeinstKey" = Synaptics Pointing Device Driver "Trusted Software Assistant_is1" = File Type Assistant "TuneUpMedia" = TuneUp Companion 1.9.0 "WinGimp-2.0_is1" = GIMP 2.6.10 "WinLiveSuite_Wave3" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Facebook Plug-In" = Facebook Plug-In ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.10.2010 14:07:03 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 00:17:57 | Computer Name = tanja-PC | Source = WinMgmt | ID = 10 Description = Error - 24.10.2010 00:18:11 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 00:18:11 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 12:50:09 | Computer Name = tanja-PC | Source = WinMgmt | ID = 10 Description = Error - 24.10.2010 12:50:19 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 12:50:19 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 14:34:54 | Computer Name = tanja-PC | Source = WinMgmt | ID = 10 Description = Error - 24.10.2010 14:35:04 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 24.10.2010 14:35:04 | Computer Name = tanja-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = [ System Events ] Error - 29.04.2011 02:56:33 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 02:56:33 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 02:56:33 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 02:57:08 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7022 Description = Error - 29.04.2011 11:35:57 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 11:35:57 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7009 Description = Error - 29.04.2011 11:35:57 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 11:35:57 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 11:35:57 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.04.2011 11:36:00 | Computer Name = tanja-PC | Source = Service Control Manager | ID = 7022 Description = < End of report > |
Themen zu Delta Search komplett entfernt? |
7-zip, antivir, avira, avp, bho, bonjour, desktop, error, excel, firefox, flash player, google, helper, home, homepage, iexplore.exe, installation, intranet, kaspersky, launch, logfile, nodrives, ntdll.dll, origin, plug-in, realtek, registry, scan, software, sttray.exe, svchost.exe, system, tarma, vista |