|
Plagegeister aller Art und deren Bekämpfung: Externe Festplatte infiziert? wscript.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.08.2013, 18:57 | #1 |
| Externe Festplatte infiziert? wscript.exe Liebe Community, ich habe mir wohl einen Virus auf meiner externen Festplatte eingefangen. Das befürchte ich zumindest. Meine Ordner werden alle als Verknüpfungen dargestellt. Verkünpfungsziel ist eine Datei im "system32"-Ordner - wscript.exe. Mein Virenscanner (avast) bestätigt auch, dass er einen solchen Trojaner gefunden hätte. Trotz Löschung des Trojaners mit dem Scanner ändert sich das Problem nicht. Ein Scan mit Anti-Malwarebytes ergab einige Treffer, darunter aber nicht den. Ich habe alle Treffer beseitigt. Das Problem existiert weiter. Ich bin ratlos... Danke schonmal! |
24.08.2013, 19:01 | #2 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Hallo,
__________________kannst du bitte die genaue Fundmeldung von avast posten? Steck die externe Festplatte bitte an und teile mir ihren Laufwerksbuchstaben mit. Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
__________________ |
24.08.2013, 19:12 | #3 |
| Externe Festplatte infiziert? wscript.exe Die Benachrichtigung von avast hab ich leider nicht mehr.
__________________Meine Festplatte ist angeschlossen, Laufwerk E:! Scan mit OTL läuft. OTL-Logfile OTL.txt Code:
ATTFilter OTL logfile created on: 24.08.2013 20:04:02 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matthias\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,02 Gb Available Physical Memory | 34,92% Memory free 11,57 Gb Paging File | 7,55 Gb Available in Paging File | 65,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 318,92 Gb Free Space | 71,97% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 437,63 Gb Free Space | 46,99% Space Free | Partition Type: FAT32 Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.08.24 20:02:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Matthias\Downloads\OTL.exe PRC - [2013.08.17 15:14:18 | 000,276,376 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013.08.06 01:30:06 | 000,164,816 | ---- | M] (APN LLC.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe PRC - [2013.08.06 01:29:59 | 001,601,488 | ---- | M] (APN) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe PRC - [2013.07.25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe PRC - [2013.07.21 13:52:03 | 001,861,512 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe PRC - [2013.05.16 10:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe PRC - [2013.05.16 10:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe PRC - [2013.05.15 13:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2013.04.04 14:50:32 | 000,887,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe PRC - [2012.05.30 13:55:26 | 001,112,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe PRC - [2012.05.02 01:03:44 | 002,279,304 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe PRC - [2012.04.25 06:18:10 | 000,784,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe PRC - [2012.04.06 12:17:04 | 002,796,112 | ---- | M] (Samsung Electronics CO., LTD.) -- C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe PRC - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () -- C:\Program Files (x86)\XSManager\WTGService.exe PRC - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe PRC - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe PRC - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe PRC - [2012.02.21 12:55:16 | 000,936,272 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe PRC - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe PRC - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe PRC - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe PRC - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\irstrtsv.exe PRC - [2012.01.31 08:56:48 | 001,640,328 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe PRC - [2012.01.28 07:38:52 | 004,466,256 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe PRC - [2012.01.04 20:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe PRC - [2010.07.08 23:05:12 | 000,160,992 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\starter4g.exe PRC - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\service4g.exe ========== Modules (No Company Name) ========== MOD - [2013.08.17 15:14:17 | 003,551,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013.07.21 13:52:02 | 016,166,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll MOD - [2013.05.16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl MOD - [2013.05.16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl MOD - [2013.04.21 21:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2013.04.21 21:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011.09.08 12:40:10 | 001,645,056 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll MOD - [2011.02.16 18:03:20 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll ========== Services (SafeList) ========== SRV:64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV:64bit: - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:64bit: - [2012.03.30 05:54:10 | 000,079,664 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe -- (ExpressCache) SRV:64bit: - [2012.02.02 15:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV:64bit: - [2011.12.08 03:44:04 | 000,594,704 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) SRV:64bit: - [2011.12.08 03:43:56 | 000,273,168 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2011.12.08 03:43:48 | 000,618,256 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2011.12.08 03:43:44 | 000,148,752 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2011.12.05 02:30:50 | 000,659,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV:64bit: - [2011.12.05 01:55:36 | 000,135,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) SRV - [2013.08.22 21:53:23 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.08.17 15:14:17 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.08.06 01:30:06 | 000,164,816 | ---- | M] (APN LLC.) [Auto | Running] -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe -- (APNMCP) SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.23 10:20:45 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer) SRV - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\XSManager\WTGService.exe -- (WTGService) SRV - [2012.03.12 01:46:40 | 000,274,200 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs) SRV - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service) SRV - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor) SRV - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe -- (SamsungDeviceConfigurationWinService) SRV - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R) SRV - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service) SRV - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysWOW64\irstrtsv.exe -- (irstrtsv) SRV - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\Windows\service4g.exe -- (XS Stick Service) SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2013.06.28 00:54:02 | 001,030,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2013.06.28 00:54:02 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2013.06.28 00:54:02 | 000,189,936 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm) DRV:64bit: - [2013.05.09 10:59:07 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:64bit: - [2013.05.09 10:59:07 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt) DRV:64bit: - [2013.05.09 10:59:07 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:64bit: - [2013.05.09 10:59:06 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2013.05.09 10:59:06 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2013.01.22 22:32:33 | 000,117,888 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmnsusbser.sys -- (cmnsusbser) DRV:64bit: - [2012.12.13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012.03.30 05:54:16 | 000,095,024 | ---- | M] (Diskeeper Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\excsd.sys -- (excsd) DRV:64bit: - [2012.03.30 05:54:16 | 000,023,344 | ---- | M] (Diskeeper Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\excfs.sys -- (excfs) DRV:64bit: - [2012.03.14 12:49:20 | 000,242,512 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD) DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.02.16 15:08:26 | 000,031,216 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd) DRV:64bit: - [2012.02.14 05:38:56 | 000,060,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (ibtfltcoex) DRV:64bit: - [2012.02.07 02:49:04 | 000,026,504 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irstrtdv.sys -- (irstrtdv) DRV:64bit: - [2012.01.09 12:49:26 | 000,225,920 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UBDA.sys -- (RTL2832UBDA) DRV:64bit: - [2012.01.09 12:49:26 | 000,049,152 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832U_IRHID.sys -- (RTL2832U_IRHID) DRV:64bit: - [2012.01.09 12:49:26 | 000,039,680 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UUSB.sys -- (RTL2832UUSB) DRV:64bit: - [2012.01.05 13:36:54 | 014,652,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2012.01.04 20:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc) DRV:64bit: - [2012.01.04 20:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub) DRV:64bit: - [2012.01.04 20:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs) DRV:64bit: - [2011.12.20 10:38:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd) DRV:64bit: - [2011.12.20 10:38:36 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible) DRV:64bit: - [2011.12.20 10:38:36 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus) DRV:64bit: - [2011.12.05 21:23:08 | 000,331,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP) DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL) DRV:64bit: - [2011.12.01 15:51:00 | 011,417,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) DRV:64bit: - [2011.11.30 04:19:48 | 000,747,008 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf) DRV:64bit: - [2011.11.30 04:19:46 | 000,094,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux) DRV:64bit: - [2011.11.29 12:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2011.11.23 16:02:20 | 000,648,808 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.11.10 11:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009.11.05 14:04:42 | 000,513,600 | ---- | M] (ITETech ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF15BDA.sys -- (AF9035BDA) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.28 08:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=119816&tt=gc_&babsrc=HP_ss&mntrId=4CA7C48508CCFD54 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_din2g&mntrId=4CA7C48508CCFD54&affID=119357&tt=180613_ndt6&tsp=4921 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms} IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com.anonymize-me.de/?anonymto=687474703A2F2F6D7973746172742E696E63726564696261722E636F6D2F6D623230312F3F7365617263683D7B7365617263685465726D737D266C6F633D49425F445326613D3650515178665374586A26693D3236&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Ask Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: "false" FF - prefs.js..browser.startup.homepage: "hxxp://www.domradio.de/" FF - prefs.js..extensions.enabledAddons: gmailwatcher%40sonthakit:1.61 FF - prefs.js..extensions.enabledAddons: addon%40codecs.com:1.0 FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17 FF - prefs.js..extensions.enabledAddons: toolbar_ORJ-V7%40apn.ask.com:21.51433 FF - prefs.js..extensions.enabledAddons: %7B74fa6b20-2ae6-4584-a4fd-4ac734f8d210%7D:3.3 FF - prefs.js..extensions.enabledAddons: ffxtlbr%40delta.com:1.5.0 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.18 21:40:21 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\ht66y4t0.default\extensions\firejump@firejump.net FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.06.04 01:49:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\Extensions [2013.08.24 19:46:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions [2013.08.23 19:16:57 | 000,000,000 | ---D | M] (BargainJoy) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210} [2013.07.20 10:34:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013.06.22 12:22:49 | 000,000,000 | ---D | M] ("Safe ads") -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\addon@codecs.com [2013.08.24 19:38:25 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\ffxtlbr@delta.com [2013.06.22 12:21:23 | 000,000,000 | ---D | M] (WebCake) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\plugin@getwebcake.com [2013.03.21 10:23:42 | 000,226,606 | ---- | M] () (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\gmailwatcher@sonthakit.xpi [2013.08.12 02:31:09 | 000,454,970 | ---- | M] () (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\toolbar_ORJ-V7@apn.ask.com.xpi [2013.07.13 08:41:45 | 000,002,545 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\ask-search.xml [2013.03.21 13:05:26 | 000,002,308 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\askcom.xml [2013.06.22 12:21:24 | 000,006,546 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\babylon.xml [2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\BrowserProtect.xml [2013.06.22 12:21:39 | 000,001,294 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\delta.xml [2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\googlede.xml [2013.05.27 15:56:30 | 000,001,304 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\holasearch.xml [2013.04.02 21:54:32 | 000,002,683 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\Search_Results.xml [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (Recorder Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{10743931-94DF-476f-A987-4391233C17A2} [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions [2013.08.17 15:14:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2013.04.02 21:54:32 | 000,002,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\windows\SysWOW64\npDeployJava1.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (no name) - {120A8821-2BEE-4C29-BCDA-62C577781992} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found. O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL File not found O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.5\bh\delta.dll (Delta-search.com) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.5\deltaTlbr.dll (Delta-search.com) O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found. O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software) O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS) O4 - HKLM..\Run: [ApnTBMon] C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (APN) O4 - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files (x86)\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKLM..\Run: [starter4g] C:\Windows\starter4g.exe (4G Systems GmbH & Co. KG) O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DelayedDesktopSwitchTimeout = 0 O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4750731-9CEA-48CB-B383-6C430621A66D}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\ms-help - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN64C~1.DLL) - C:\ProgramData\Wincert\win64cert.dll () O20 - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN32C~1.DLL) - C:\ProgramData\Wincert\win32cert.dll () O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{98c6118b-3358-11e2-9bc4-c48508ccfd57}\Shell - "" = AutoRun O33 - MountPoints2\{98c6118b-3358-11e2-9bc4-c48508ccfd57}\Shell\AutoRun\command - "" = D:\Setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.08.24 19:38:29 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\BabSolution [2013.08.24 19:38:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta [2013.08.24 19:38:23 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Delta [2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Simply Super Software [2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Simply Super Software [2013.08.24 19:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover [2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover [2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software [2013.08.24 18:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2013.08.24 18:58:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 [2013.08.24 18:58:27 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\windows\SysNative\sdnclean64.exe [2013.08.24 18:58:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2 [2013.08.24 18:17:01 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Malwarebytes [2013.08.24 18:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.08.24 18:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.08.24 18:16:38 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2013.08.24 18:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.08.24 13:34:32 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle [2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services [2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services [2013.08.22 21:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2013.08.22 21:49:57 | 000,000,000 | -HSD | C] -- C:\Users\Matthias\AppData\Roaming\750 [2013.08.22 21:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [2013.08.22 21:47:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2013.08.22 21:45:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2013.08.22 21:45:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2013.08.22 21:45:20 | 000,000,000 | RH-D | C] -- C:\MSOCache [2013.08.22 21:43:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys [2013.08.22 19:38:33 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\DAEMON Tools Lite [2013.08.22 19:38:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite [2013.08.22 19:37:53 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2013.08.22 19:22:30 | 000,000,000 | -HSD | C] -- C:\74b36 [2013.08.17 15:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.08.12 22:21:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ [2013.08.11 22:10:35 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Schlag den Raab - Das 3. Spiel [2013.08.11 22:10:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer [2013.08.11 22:10:19 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\ProtectDISC [2013.08.11 22:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games [2013.08.11 22:02:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bitComposer Games [2013.08.04 07:23:18 | 000,000,000 | ---D | C] -- C:\windows\SysNative\MRT [2013.07.31 16:32:59 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Desktop\Libori-Dienstag ========== Files - Modified Within 30 Days ========== [2013.08.24 19:53:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job [2013.08.24 19:48:51 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.08.24 19:48:51 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.08.24 19:48:09 | 001,498,742 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2013.08.24 19:48:09 | 000,654,400 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2013.08.24 19:48:09 | 000,616,242 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2013.08.24 19:48:09 | 000,130,240 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2013.08.24 19:48:09 | 000,106,622 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2013.08.24 19:43:52 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job [2013.08.24 19:43:51 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2013.08.24 19:41:34 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2013.08.24 19:32:00 | 000,001,114 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2013.08.24 19:21:00 | 000,000,298 | ---- | M] () -- C:\windows\tasks\DSite.job [2013.08.24 19:14:11 | 000,462,896 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2013.08.24 18:37:59 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI [2013.08.24 17:47:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job [2013.08.24 10:48:39 | 000,000,320 | ---- | M] () -- C:\windows\tasks\MT66 Software Update.job [2013.08.23 19:16:42 | 000,000,005 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\WBPU-TTL.DAT [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys [2013.08.22 21:35:21 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt [2013.08.20 22:24:25 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00003553.LCS [2013.07.31 17:01:43 | 000,000,072 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\WB.CFG ========== Files Created - No Company Name ========== [2013.08.24 18:58:38 | 000,001,355 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk [2013.08.24 13:34:32 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI [2013.08.11 22:10:22 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00003553.LCS [2013.07.27 00:21:11 | 000,000,072 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WB.CFG [2013.07.22 21:20:00 | 000,010,455 | ---- | C] () -- C:\Users\Matthias\Friebe_elster_2048.pfx [2013.06.28 11:27:50 | 000,000,005 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WBPU-Q2-TTL.DAT [2013.06.22 13:21:04 | 000,000,005 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WBPU-TTL.DAT [2013.06.22 12:22:31 | 000,079,360 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll [2013.06.22 12:22:17 | 000,645,632 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll [2013.06.22 12:22:17 | 000,240,640 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll [2013.06.22 12:22:06 | 000,715,038 | ---- | C] () -- C:\windows\unins000.exe [2013.06.22 12:22:06 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll [2013.06.22 12:22:06 | 000,002,000 | ---- | C] () -- C:\windows\unins000.dat [2013.06.22 12:16:53 | 000,376,832 | ---- | C] () -- C:\windows\SysWow64\xvid.dll [2013.06.21 22:56:26 | 000,000,218 | ---- | C] () -- C:\Users\Matthias\.recently-used.xbel [2013.05.27 15:54:57 | 000,178,688 | ---- | C] () -- C:\windows\SysWow64\unrar.dll [2013.03.04 20:08:50 | 000,007,168 | ---- | C] () -- C:\Users\Matthias\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.12.01 00:42:45 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll [2012.11.23 10:20:48 | 000,338,432 | ---- | C] () -- C:\windows\SysWow64\sqlite36_engine.dll [2012.06.30 13:44:34 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe [2012.06.30 12:37:45 | 000,003,586 | ---- | C] () -- C:\windows\HotFixList.ini [2012.03.13 04:59:22 | 000,963,912 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin [2012.03.13 04:59:22 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin [2012.03.13 04:59:19 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin [2012.03.13 04:59:19 | 000,261,208 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin [2012.03.13 04:59:16 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll [2012.03.13 04:59:14 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll [2012.03.13 04:59:14 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin [2012.03.13 04:59:13 | 013,184,512 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll [2012.02.02 15:08:26 | 000,001,536 | ---- | C] () -- C:\windows\SysWow64\IusEventLog.dll ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.08.22 21:49:57 | 000,000,000 | -HSD | M] -- C:\Users\Matthias\AppData\Roaming\750 [2013.07.07 21:38:34 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Audacity [2013.03.05 00:52:41 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\avidemux [2013.08.24 19:38:29 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\BabSolution [2013.03.04 23:49:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Babylon [2013.04.02 21:47:05 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Canneverbe Limited [2013.06.22 12:22:09 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\CDXReader [2013.08.22 21:44:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DAEMON Tools Lite [2013.06.22 12:21:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DealPly [2013.08.24 19:38:23 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Delta [2013.03.04 23:49:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DesktopIconForAmazon [2013.08.24 19:15:14 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Dropbox [2013.06.22 12:21:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DSite [2013.04.02 22:38:01 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DVDVideoSoft [2013.04.02 22:27:41 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DVDVideoSoftIEHelpers [2013.03.09 01:42:25 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\elsterformular [2012.11.23 09:59:39 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Engelmann Media [2013.07.30 16:07:03 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FileZilla [2012.12.01 00:42:56 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FreeAudioPack [2013.04.02 21:54:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FreeFLVConverter [2013.06.21 22:56:26 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Gaupol [2013.06.21 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\gtk-2.0 [2013.07.20 00:59:27 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\ICQ [2013.08.22 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\IrfanView [2013.06.22 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\LavFilters [2013.01.09 16:51:45 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\MAY Computer [2013.05.11 19:55:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\MusE [2012.11.23 10:20:45 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\OCS [2013.03.24 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\OpenOffice.org [2012.11.23 10:20:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Opera [2013.01.12 15:40:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Origin [2013.05.27 15:59:34 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\PerformerSoft [2013.08.11 22:10:19 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\ProtectDISC [2013.01.18 16:33:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Scribus [2013.08.24 19:06:20 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Simply Super Software [2013.07.01 20:29:04 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Subtitle Edit [2012.12.28 01:03:59 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\TerraTec [2013.06.22 12:22:15 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Ultimate Codec Packages [2013.04.02 22:22:35 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Video DVD Maker FREE [2012.11.17 22:09:46 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Visan [2013.03.01 10:17:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\XSManager ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:CB0AACC9 < End of report > Code:
ATTFilter OTL Extras logfile created on: 24.08.2013 20:04:02 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matthias\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,02 Gb Available Physical Memory | 34,92% Memory free 11,57 Gb Paging File | 7,55 Gb Available in Paging File | 65,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 318,92 Gb Free Space | 71,97% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 437,63 Gb Free Space | 46,99% Space Free | Partition Type: FAT32 Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0436CEA9-698E-430E-BB1F-09C80EC35353}" = rport=445 | protocol=6 | dir=out | app=system | "{2223CF43-4B6C-464E-95D5-87BD29B7BD99}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{241D0DCC-2DDF-419B-8BE3-BB38F3116349}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2E3C6DD4-847E-4FED-BA6C-FC9ADDB6A283}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{387AA4CE-D36B-4095-8E21-0EE33291AE69}" = rport=139 | protocol=6 | dir=out | app=system | "{4563C9C8-F97B-44C2-9C72-0ECDECD44806}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{4E104AC3-404C-4FE7-BAD4-534AD76A327E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{57DDE9F5-0E20-4066-8D5E-87E7219E7CE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{58229A73-E337-47EF-8DFB-4D2394B740B9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{586B5219-FA5E-48A8-B7D2-5E8569AF6828}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{73A80D95-D754-471F-B96B-A447112F05CB}" = lport=10243 | protocol=6 | dir=in | app=system | "{779648A7-8399-4D24-9244-A1E83021E7E0}" = rport=137 | protocol=17 | dir=out | app=system | "{78C841EF-F0C0-42D5-8013-75FCEF706F71}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{7D7B7F00-C187-40C7-9018-041EE1028310}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7E47EF18-E911-444D-AA49-339B68BB6AA6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8A98285A-CDDE-425A-966D-4D4B314CBED4}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{930D0493-BCFB-4EEE-AF4C-3D216119D30A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{93A83531-FDD6-4584-AC3A-3A11D9170305}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{9BD29CBC-0ACB-49A4-9ECD-FC798377B76A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9E88BC59-8DB5-4920-A329-5EEC34462AAA}" = lport=138 | protocol=17 | dir=in | app=system | "{9EFC8579-2987-4E44-820C-AE17499A5C3A}" = lport=137 | protocol=17 | dir=in | app=system | "{AD768F5D-B99C-4CEC-BB46-9AAE7FDCCE79}" = lport=2869 | protocol=6 | dir=in | app=system | "{B1744E19-BE6C-4CF0-A48D-D5F299233371}" = lport=139 | protocol=6 | dir=in | app=system | "{B6C64B38-9574-488E-B6B5-169DDBCC822E}" = rport=10243 | protocol=6 | dir=out | app=system | "{B87E108D-46A8-4D4A-8BB8-7ED899FB4800}" = lport=445 | protocol=6 | dir=in | app=system | "{C1675484-5844-40DF-8CE9-ED048B4EC999}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C287B71D-60A8-4136-A44C-3DB32AC18009}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C2EBCC5B-7A36-4B70-AB77-658A409599F3}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{CF50AD87-6DD7-496E-8836-5C7A82B929DF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F17A45E0-B598-4C3D-AC77-9F45A3FF97B7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{F2882A53-5A64-443D-84F8-C4F66CF5A83B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F3312CE5-78E4-4186-A6AC-4403312B87C2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F521DB80-92E7-4261-B7A8-B0866A409782}" = rport=138 | protocol=17 | dir=out | app=system | "{FF8B6CEE-7C21-4173-8A4E-75F3C11D307C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01641C9D-49C5-4FDE-B1B4-475B3C231116}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{06AD03B2-E7C3-4DF6-9485-F5E1B73B3B07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{0FB3C0B7-A94A-486A-AA6E-9DC0E21BE9CA}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | "{19AAC066-F4BF-40E9-8381-A311040607DE}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{1EAFC354-C540-4593-8176-686CD1F16040}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{233491A6-87B6-4ACD-883D-585AC173F445}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{240AFACA-886B-4369-A43D-31C36D6E4B35}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{24F33176-70B0-47E8-968E-9FBA6925D002}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{264EE886-100A-46EA-AA21-9F9968300A20}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe | "{28197DE6-8E5E-4B6E-AA3D-E088A8EC07EF}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{33F5B46E-D0F7-4631-82A9-C1965BF1DE6F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{347EDD06-238D-4147-B351-118BA3E622A3}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{3496B250-99E7-4043-B5E3-CA98D7A57000}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{378356E6-85AE-48C8-92A7-6A03C9B46F7D}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | "{3A2D54B9-1180-4929-BC7F-530D13FED6C3}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | "{3C27AD16-779C-4CAE-89B2-C939400A896F}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | "{401EA2B1-0323-45BF-9BDB-68CF4FB608A2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{460297C1-3816-4B33-A5C1-3AA01F6B77D0}" = protocol=6 | dir=out | app=system | "{4B3DAEE9-7164-4459-B7D9-B852F79178AD}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | "{544750CB-19C4-4508-BDDF-20FE8A8D0D57}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{599FFCA2-1F30-44DA-8CD7-2DA8634D64AE}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | "{5E858310-0E4A-4628-922B-78B0C2E6AAC9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{63170B9B-C412-43E6-B9C6-1BDB4C64FA30}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{6341CDE1-DDF0-4322-960B-6B2C6D2F19A1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{65B9BD46-F9C5-4755-B839-3D7AF1872101}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{674E1A3A-0FE8-4F3D-A678-8780C1994485}" = protocol=6 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | "{6761AD54-38A7-4F93-80BB-7DEFC3D8B394}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{756EFEE2-BEBC-4F44-A064-2D0D99295DF0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7AD77024-60F2-4216-913F-AEFC8FC944FA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{84B97CEE-C7C6-46D4-AB7A-E50A077AF052}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{855637EF-E060-430A-AB73-36512B38B93C}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{88B16A89-57F7-4F39-9F5F-99DEB1D90397}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{99215DB0-E3EF-4A08-B0C9-E10648EB17EC}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{A0E448D2-620A-42EB-BC45-980FD520F178}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{A3DDED73-CD7E-491F-BEFC-4D0AEC69C18B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BBB76FB6-0A16-46AF-9ACA-68FDB78D753E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{C03A4322-16D7-470C-9318-334E0A28155B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C0FB93F2-E787-469F-8F09-FAB16C3B31E6}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{C56AB1E6-C319-4241-9761-80666D2510DE}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | "{C9CC4DC7-73A2-4E4D-8151-4F7F9986A749}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | "{D601ECD8-BED2-492F-9967-E177D7044DBB}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{D9135861-BC13-4453-BF8B-0A3D1EE6B203}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{DA7B6BCF-AEE0-4A14-90CD-EA7B55D1153E}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe | "{DD02B452-C91B-47C5-9562-E85E14B9F310}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | "{DD8E06E0-2832-480A-8DFE-19857E416C84}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{DDBD7845-C6DD-48B2-8731-601F03419C87}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | "{E0FFCA86-31D7-47F0-99C1-BFDC4A29DC36}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\insttool.exe | "{E10CEE13-CEB5-44E0-8021-09E6FCDE89F3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E3E98352-A3C7-440C-952A-581FFD71396B}" = protocol=17 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | "{E55E3451-BAFC-4076-9C6C-BA7EB806C269}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe | "{E6418CE4-8820-4EB7-89EF-51D09F6A6764}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{E6461C57-A902-4519-AB8E-60996004BDFF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E90254D6-94F5-4D30-AC92-672AB2BB75B8}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe | "{EAAE70F4-723F-47EA-8CB0-D775C93289E8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{EB7EC6C7-544C-4A35-9E36-AB1363D4C5AD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{EF409194-6CBE-4535-A5F0-1CAEAD0DB336}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe | "{FE4B1515-F2F3-4809-95B0-5EB4450DD4C3}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\insttool.exe | "{FED98362-9B95-4659-8CF9-4B8B59DF2023}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{33F7A501-8820-4A41-8EC1-0476E68FF8C9}C:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{6280D4BC-5F2C-4B10-B398-A2938BB36E10}C:\program files (x86)\origin games\fifa 12\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "TCP Query User{75274A09-3E10-4C7E-8672-B6E184938F22}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | "TCP Query User{A1BA3AD1-0BD6-45EA-A854-57BBF45CE1C1}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | "UDP Query User{6D93E194-5F39-4467-9399-B966897609EB}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | "UDP Query User{D43E0A68-C01B-44BF-9AE3-16F98CCD6678}C:\program files (x86)\origin games\fifa 12\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "UDP Query User{D6DC1BF3-C301-403B-9855-77B2F6007C1B}C:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{F8EEF5E8-3AAC-4BEE-AE7F-3A6F40B5AF41}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}" = Easy Support Center "{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display "{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}" = Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed "{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}" = ExpressCache "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{3C28BFD4-90C7-3138-87EF-418DC16E9598}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4ED70939-4D42-48E4-B573-13E3B8B13ADF}" = gs_x64 "{520C4DD4-2BC7-409B-BA48-E1A4F832662D}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10 "{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64) "{76FF0F03-B707-4332-B5D1-A56C8303514E}" = iTunes "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0017-0407-1000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (German) 2010 "{90140000-0017-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{D3646908-5C00-4C50-B9A5-9F1D1A83B452}" = Microsoft SharePoint Designer 2010 Service Pack 1 (SP1) "{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0000-1000-0000000FF1CE}" = Microsoft Office Publisher 2010 "{90140000-0019-0000-1000-0000000FF1CE}_Office14.PUBLISHER_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-0019-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-1000-0000000FF1CE}_Office14.OMUI.de-de_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-1000-0000000FF1CE}_Office14.OMUI.de-de_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-1000-0000000FF1CE}_Office14.PUBLISHER_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-1000-0000000FF1CE}_Office14.OMUI.de-de_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PUBLISHER_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-002C-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PUBLISHER_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010 "{90140000-0043-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010 "{90140000-0043-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-006E-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0100-0407-1000-0000000FF1CE}" = Microsoft Office O MUI (German) 2010 "{90140000-0100-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{E2D2FA5C-6353-4F7B-9ABF-F548759A5D35}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1) "{90140000-0101-0407-1000-0000000FF1CE}" = Microsoft Office X MUI (German) 2010 "{90140000-0101-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{EA7ED796-796A-4C86-8BCB-88A55C89E32C}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1) "{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0115-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}" = WebCake 3.00 "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF7756DD-656A-45C3-BA71-74673E8259A9}" = Intel® PROSet/Wireless WiFi Software "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F76C9B9E-8F61-461D-B4AE-EC926C3A8D46}" = eDocPrintPro "DesktopIconAmazon" = Desktop Icon für Amazon "Elantech" = ETDWare PS/2-X64 10.7.13.1_WHQL "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Office14.OMUI.de-de" = Microsoft Office Language Pack 2010 - German/Deutsch "Office14.PUBLISHER" = Microsoft Publisher 2010 "ProInst" = Intel PROSet Wireless "Scribus 1.4.2" = Scribus 1.4.2 (64bit) "SearchAnonymizer" = SearchAnonymizer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{03CC9D58-B132-4CC0-A521-4F3660AA43C7}" = Movie Maker "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{12F81925-F3C1-40DB-91F7-777817974319}" = Easy File Share "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5 "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Settings "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9.6 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20B1B020-DEAE-48D1-9960-D4C3185D758B}" = Phase 5 HTML-Editor "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25 "{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery "{3CBD94C1-BA15-488C-888B-D8DD296CC6DC}" = Fotogalerie "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40F4FF7A-B214-4453-B973-080B09CED019}" = Absolute Reminder "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5 "{4F524A2D-5637-006A-76A7-A758B70C0300}" = Ask Toolbar "{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support "{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74D5F45B-EC9F-4083-9493-364D159FFFBE}_is1" = DivXLand Media Subtitler 2.1.0 "{770103E9-E1C3-48C9-812B-2982C7070575}_is1" = Pazera Free MOV to AVI Converter 1.4 "{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}" = ICQ7M "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{93F34C5C-ACAA-48F3-9B26-70359A117F12}" = Intel(R) WiDi "{94CDEFC5-D87D-4122-8F06-275AC30B1314}" = Fast Flash Sleep Resume "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Deutsch "{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy "{B654E683-93ED-4B4F-BED8-4CE9C0B8D3ED}" = Multimedia POP "{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack "{B750B5C2-CC17-4967-905B-29F4EB986131}" = Software Launcher "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{cb41fc68-4442-4f7f-b22f-8f31c74897ac}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 "{D848E062-BA12-4855-0001-E7C196D614BE}" = MyTube Bigpack HD Free "{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1" = FireJump "{DE256D8B-D971-456D-BC02-CB64DA24F115}" = Easy Software Manager "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common "{E630D30A-79EE-407A-8F51-9D57D1F45230}" = gs_x86 "{EA8ADAA9-6671-4839-A51E-0C6792B78F3E}" = FIFA 12 "{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker "{EDE7A262-DB20-4432-A630-2ACEE186C416}" = Easy Migration "{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}" = E-POP "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5212949-60B3-43FC-A178-4A7B0BEDAD69}" = eDocPrintPro v3.17.0 "{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27) "{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171 "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) OpenCL CPU Runtime "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin "3D073343-CEEB-4ce7-85AC-A69A7631B5D6" = Intel(R) Rapid Start Technology "7-Zip" = 7-Zip 9.20 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ANSTOSS 3_is1" = ANSTOSS 3 "Audacity_is1" = Audacity 2.0.2 "avast" = avast! Free Antivirus "Cinergy T Stick RC" = Cinergy T Stick RC V86.001.1129.2011 "Cinergy T-Stick MKII" = Cinergy T-Stick MKII V9.06.3.01 "codecs" = codecs "DAEMON Tools Lite" = DAEMON Tools Lite "DC-Bass Source" = DC-Bass Source 1.3.0 "delta" = Delta toolbar "Disketch" = Disketch Disc Label Software "Doxillion" = Doxillion Document Converter "EasyCash&Tax_is1" = EasyCash&Tax 1.57 "ECTPlugAnlagenverzeichnis_is1" = ECTPlugAnlagenverzeichnis 1.5 "Elster-Export Plugin für EasyCash&Tax_is1" = Elster-Export 1.13 "ElsterFormular" = ElsterFormular "ffdshow_is1" = ffdshow v1.1.4399 [2012-03-22] "FileZilla Client" = FileZilla Client 3.6.0.1 "Free FLV Converter_is1" = Free FLV Converter V 7.5.0 "Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 7.2 "Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2 "Freemake Video Converter_is1" = Freemake Video Converter Version 4.0.1 "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "IrfanView" = IrfanView (remove only) "KLiteCodecPack_is1" = K-Lite Codec Pack 9.9.0 (Standard) "LAME_is1" = LAME v3.99.3 (for Windows) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300 "Mozilla Firefox 23.0.1 (x86 de)" = Mozilla Firefox 23.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "MuseScore" = MuseScore 1.3 "OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5 "Origin" = Origin "Passbild-Generator_is1" = Bewerbungsfoto-/Passbild-Generator v3.5a "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "SDR3" = Schlag den Raab - Das 3. Spiel "Searchqu Toolbar" = Windows Searchqu Toolbar "SubtitleCreator" = SubtitleCreator "SubtitleEdit_is1" = Subtitle Edit 3.3.6 "Trojan Remover_is1" = Trojan Remover 6.8.8 "VLC media player" = VLC media player 2.0.6 "WinLiveSuite" = Windows Live Essentials "XSManager" = XSManager "Xvid Video Codec 1.3.2" = Xvid Video Codec ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "DSite" = Update for Ultimate Codec "Ultimate Codec Packages" = Ultimate Codec Packages ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 03.08.2013 16:26:21 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 2059 Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6383514 Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6383514 Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6384513 Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6384513 Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6385527 Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6385527 [ System Events ] Error - 24.06.2013 14:26:38 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003 Description = Error - 25.06.2013 12:28:39 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003 Description = Error - 25.06.2013 13:35:07 | Computer Name = Matthias_Friebe | Source = DCOM | ID = 10010 Description = Error - 25.06.2013 13:37:02 | Computer Name = Matthias_Friebe | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 25.06.2013 13:43:47 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003 Description = Error - 25.06.2013 18:28:37 | Computer Name = Matthias_Friebe | Source = DCOM | ID = 10005 Description = Error - 25.06.2013 18:28:37 | Computer Name = Matthias_Friebe | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%109 Error - 25.06.2013 18:59:17 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003 Description = Error - 26.06.2013 17:04:58 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003 Description = Error - 26.06.2013 19:30:31 | Computer Name = Matthias_Friebe | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR6 gefunden. < End of report > |
24.08.2013, 19:33 | #4 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Ok, Platte angesteckt lassen. Schritt 1 Scan mit Combofix
Schritt 2
Code:
ATTFilter dir /a /b "E:\" /c
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
24.08.2013, 20:14 | #5 |
| Externe Festplatte infiziert? wscript.exe Combofix Combofix Logfile: Code:
ATTFilter ComboFix 13-08-22.01 - Matthias 24.08.2013 20:43:31.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.5926.2861 [GMT 2:00] ausgeführt von:: c:\users\Matthias\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Delta\delta\1.8.24.5\deltaApp.dll c:\program files (x86)\Delta\delta\1.8.24.5\deltaEng.dll c:\program files (x86)\Windows Searchqu Toolbar c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\BrowserConnection.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\css\new-tab.css c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_amazon.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ebay.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_facebook.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_fantastigames.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ftalk.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_youtube.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\IDR_WEBSTORE_ICON.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png__ c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\new-tab.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\analytics.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\constant.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config - Copy.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\jquery.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\localStorage.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\new-tab.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\preferences.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\manifest.json c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\OurLocalPage.html c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngr.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\DnsBHO.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest.alt c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlp.xpt c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF10.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF11.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF12.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF13.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF14.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF15.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF3.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF4.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF5.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF6.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF7.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF8.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF9.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DataMngr.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DnsBHO.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Error404BHO.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\NewTabBHO.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.xul c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RelatedSearch.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RequestPreserver.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SearchBHO.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SettingManager.js c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Settings.xml c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\install.rdf c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\IEBHO.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\installhelper.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngr.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngrUI.exe c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\DnsBHO.dll c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\IEBHO.dll c:\program files (x86)\Windows Searchqu Toolbar\sysid.ini c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe c:\programdata\BrowserDefender c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings c:\programdata\Roaming c:\programdata\Wincert\WIN32C~1.DLL c:\users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage c:\users\Matthias\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E76258EF-35BE-48ED-890A-B5D99C1B8BFC}.xps c:\users\Matthias\AppData\Roaming\750 c:\users\Matthias\AppData\Roaming\750\6312.js c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-24 bis 2013-08-24 )))))))))))))))))))))))))))))) . . 2013-08-24 18:57 . 2013-08-24 18:57 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-24 18:46 . 2013-08-24 18:46 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\offreg.dll 2013-08-24 17:38 . 2013-08-24 17:38 -------- d-----w- c:\users\Matthias\AppData\Roaming\BabSolution 2013-08-24 17:38 . 2013-08-24 17:38 -------- d-----w- c:\program files (x86)\Delta 2013-08-24 17:38 . 2013-08-24 17:38 -------- d-----w- c:\users\Matthias\AppData\Roaming\Delta 2013-08-24 17:06 . 2013-08-24 17:06 -------- d-----w- c:\users\Matthias\AppData\Roaming\Simply Super Software 2013-08-24 17:06 . 2013-08-24 17:06 -------- d-----w- c:\program files (x86)\Trojan Remover 2013-08-24 17:06 . 2013-08-24 17:06 -------- d-----w- c:\programdata\Simply Super Software 2013-08-24 16:58 . 2013-08-24 17:03 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-08-24 16:58 . 2013-08-24 18:42 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2013-08-24 16:17 . 2013-08-24 16:17 -------- d-----w- c:\users\Matthias\AppData\Roaming\Malwarebytes 2013-08-24 16:16 . 2013-08-24 16:16 -------- d-----w- c:\programdata\Malwarebytes 2013-08-24 16:16 . 2013-08-24 16:16 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-08-24 16:16 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-08-24 14:20 . 2013-08-24 14:20 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2013-08-23 17:30 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\mpengine.dll 2013-08-22 19:54 . 2013-08-22 19:54 -------- d-----w- c:\program files\Microsoft Analysis Services 2013-08-22 19:54 . 2013-08-22 19:54 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services 2013-08-22 19:54 . 2013-08-22 19:55 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8 2013-08-22 19:47 . 2013-08-22 19:47 -------- d-----w- c:\program files\Common Files\DESIGNER 2013-08-22 19:45 . 2013-08-22 19:55 -------- d-----w- c:\program files\Microsoft Office 2013-08-22 19:45 . 2013-08-22 19:45 -------- d-----r- C:\MSOCache 2013-08-22 19:43 . 2013-08-22 19:43 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2013-08-22 17:38 . 2013-08-22 19:44 -------- d-----w- c:\users\Matthias\AppData\Roaming\DAEMON Tools Lite 2013-08-22 17:38 . 2013-08-22 19:43 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite 2013-08-22 17:37 . 2013-08-22 19:44 -------- d-----w- c:\programdata\DAEMON Tools Lite 2013-08-22 17:22 . 2013-08-22 17:22 -------- d-----w- C:\74b36 2013-08-15 06:10 . 2013-07-26 03:35 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-08-15 06:10 . 2013-07-26 02:49 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-08-14 15:17 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-08-12 20:21 . 2013-08-12 20:21 -------- d--h--w- c:\programdata\CanonBJ 2013-08-12 20:21 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL 2013-08-11 20:10 . 2013-08-11 20:10 -------- d-----w- c:\program files (x86)\ProtectDisc Driver Installer 2013-08-11 20:10 . 2013-08-11 20:10 -------- d-----w- c:\users\Matthias\AppData\Roaming\ProtectDISC 2013-08-11 20:02 . 2013-08-11 20:02 -------- d-----w- c:\program files (x86)\bitComposer Games 2013-08-04 05:23 . 2013-08-15 06:06 -------- d-----w- c:\windows\system32\MRT . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-22 19:53 . 2012-11-17 16:09 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-08-22 19:53 . 2012-11-17 16:09 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-08-15 06:04 . 2012-11-30 07:34 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-07-12 18:48 . 2013-07-12 18:48 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-07-12 18:48 . 2012-11-22 22:28 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-07-12 18:48 . 2012-11-22 22:28 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-07-09 04:45 . 2013-08-14 15:17 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-06-27 22:54 . 2013-03-22 18:33 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-06-27 22:54 . 2012-11-19 23:20 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-06-27 22:54 . 2012-11-19 23:20 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-06-22 10:22 . 2013-06-22 10:22 715038 ----a-w- c:\windows\unins000.exe 2013-06-22 10:16 . 2013-06-22 10:16 376832 ----a-w- c:\windows\SysWow64\xvid.dll 2013-06-05 03:34 . 2013-07-11 19:23 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-11 19:23 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-11 19:23 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-06-04 01:11 . 2013-06-04 01:11 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-06-04 01:11 . 2013-06-04 01:11 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-06-04 01:11 . 2013-06-04 01:11 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-06-04 01:11 . 2013-06-04 01:11 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-06-04 01:11 . 2013-06-04 01:11 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-06-04 01:11 . 2013-06-04 01:11 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-06-04 01:11 . 2013-06-04 01:11 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-06-04 01:11 . 2013-06-04 01:11 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-06-04 01:11 . 2013-06-04 01:11 81408 ----a-w- c:\windows\system32\icardie.dll 2013-06-04 01:11 . 2013-06-04 01:11 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-06-04 01:11 . 2013-06-04 01:11 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-06-04 01:11 . 2013-06-04 01:11 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-06-04 01:11 . 2013-06-04 01:11 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-06-04 01:11 . 2013-06-04 01:11 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-06-04 01:11 . 2013-06-04 01:11 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-06-04 01:11 . 2013-06-04 01:11 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-06-04 01:11 . 2013-06-04 01:11 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-06-04 01:11 . 2013-06-04 01:11 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-06-04 01:11 . 2013-06-04 01:11 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-06-04 01:11 . 2013-06-04 01:11 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-06-04 01:11 . 2013-06-04 01:11 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-06-04 01:11 . 2013-06-04 01:11 441856 ----a-w- c:\windows\system32\html.iec 2013-06-04 01:11 . 2013-06-04 01:11 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-06-04 01:11 . 2013-06-04 01:11 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-06-04 01:11 . 2013-06-04 01:11 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-06-04 01:11 . 2013-06-04 01:11 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-06-04 01:11 . 2013-06-04 01:11 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-06-04 01:11 . 2013-06-04 01:11 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-06-04 01:11 . 2013-06-04 01:11 235008 ----a-w- c:\windows\system32\url.dll 2013-06-04 01:11 . 2013-06-04 01:11 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-06-04 01:11 . 2013-06-04 01:11 216064 ----a-w- c:\windows\system32\msls31.dll 2013-06-04 01:11 . 2013-06-04 01:11 197120 ----a-w- c:\windows\system32\msrating.dll 2013-06-04 01:11 . 2013-06-04 01:11 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-06-04 01:11 . 2013-06-04 01:11 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-06-04 01:11 . 2013-06-04 01:11 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-06-04 01:11 . 2013-06-04 01:11 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-06-04 01:11 . 2013-06-04 01:11 149504 ----a-w- c:\windows\system32\occache.dll 2013-06-04 01:11 . 2013-06-04 01:11 144896 ----a-w- c:\windows\system32\wextract.exe 2013-06-04 01:11 . 2013-06-04 01:11 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-06-04 01:11 . 2013-06-04 01:11 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-06-04 01:11 . 2013-06-04 01:11 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-06-04 01:11 . 2013-06-04 01:11 13824 ----a-w- c:\windows\system32\mshta.exe 2013-06-04 01:11 . 2013-06-04 01:11 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-06-04 01:11 . 2013-06-04 01:11 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-06-04 01:11 . 2013-06-04 01:11 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-06-04 01:11 . 2013-06-04 01:11 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-06-04 01:11 . 2013-06-04 01:11 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-06-04 01:11 . 2013-06-04 01:11 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-06-04 01:11 . 2013-06-04 01:11 102912 ----a-w- c:\windows\system32\inseng.dll 2013-06-04 01:02 . 2013-06-04 01:02 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-06-04 01:02 . 2013-06-04 01:02 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-06-04 01:02 . 2013-06-04 01:02 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-06-04 01:02 . 2013-06-04 01:02 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-06-04 01:02 . 2013-06-04 01:02 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-06-04 01:02 . 2013-06-04 01:02 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-06-04 01:02 . 2013-06-04 01:02 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-06-04 01:02 . 2013-06-04 01:02 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-06-04 01:02 . 2013-06-04 01:02 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-06-04 01:02 . 2013-06-04 01:02 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-06-04 01:02 . 2013-06-04 01:02 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-06-04 01:02 . 2013-06-04 01:02 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2013-06-04 01:02 . 2013-06-04 01:02 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-06-04 01:02 . 2013-06-04 01:02 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-06-04 01:02 . 2013-06-04 01:02 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-04 01:02 . 2013-06-04 01:02 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-06-04 01:02 . 2013-06-04 01:02 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-06-04 01:02 . 2013-06-04 01:02 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-06-04 01:02 . 2013-06-04 01:02 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-06-04 01:02 . 2013-06-04 01:02 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-06-04 01:02 . 2013-06-04 01:02 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "starter4g"="c:\windows\starter4g.exe" [2010-07-08 160992] "ApplyEsf-eDocPrintPro"="c:\program files (x86)\Common Files\MAYComputer\eDocPrintPro\\ApplyEsf.exe" [2010-11-25 315392] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-08-05 1601488] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] "TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-07-19 1655568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "DelayedDesktopSwitchTimeout"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AF9035BDA;Cinergy T-Stick service;c:\windows\system32\DRIVERS\AF15BDA.sys;c:\windows\SYSNATIVE\DRIVERS\AF15BDA.sys [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmnsusbser.sys [x] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 RTL2832U_IRHID;Cinergy T Stick HID;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys;c:\windows\SYSNATIVE\DRIVERS\RTL2832U_IRHID.sys [x] R3 RTL2832UBDA;Cinergy T Stick RC BDA service;c:\windows\system32\drivers\RTL2832UBDA.sys;c:\windows\SYSNATIVE\drivers\RTL2832UBDA.sys [x] R3 RTL2832UUSB;Cinergy T Stick RC USB service;c:\windows\system32\Drivers\RTL2832UUSB.sys;c:\windows\SYSNATIVE\Drivers\RTL2832UUSB.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 excsd;ExpressCache Storage Filter Driver;c:\windows\system32\DRIVERS\excsd.sys;c:\windows\SYSNATIVE\DRIVERS\excsd.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 excfs;ExpressCache File System Filter Driver;c:\windows\system32\DRIVERS\excfs.sys;c:\windows\SYSNATIVE\DRIVERS\excfs.sys [x] S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 ExpressCache;ExpressCache;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] S2 irstrtsv;Intel(R) Rapid Start Technology Service;c:\windows\SysWOW64\irstrtsv.exe;c:\windows\SysWOW64\irstrtsv.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 SamsungDeviceConfigurationWinService;SamsungDeviceConfiguration;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [x] S2 SearchAnonymizer;SearchAnonymizer;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 WTGService;WTGService;c:\program files (x86)\XSManager\WTGService.exe;c:\program files (x86)\XSManager\WTGService.exe [x] S2 XS Stick Service;XS Stick Service;c:\windows\service4g.exe;c:\windows\service4g.exe [x] S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 irstrtdv;Intel(R) Rapid Start Technology Driver;c:\windows\system32\DRIVERS\irstrtdv.sys;c:\windows\SYSNATIVE\DRIVERS\irstrtdv.sys [x] S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-08-01 20:22 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-17 19:53] . 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20] . 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20] . 2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41] . 2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Ocs_SM"="c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-11-23 106496] "ApplyEsf-eDocPrintPro"="c:\program files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe" [2013-01-03 443392] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.domradio.de/ FF - ExtSQL: 2013-08-23 19:16; {74fa6b20-2ae6-4584-a4fd-4ac734f8d210}; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210} FF - ExtSQL: 2013-08-24 19:38; ffxtlbr@delta.com; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\ffxtlbr@delta.com FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true FF - user.js: extentions.webcake.installId - 6af63b99-f003-4ded-9bce-6c00089258b8 FF - user.js: extentions.webcake.defaultEnableAppsList - layers,brain/features,newOffers/wc FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - 4ca70e72000000000000c48508ccfd54 FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15941 FF - user.js: extensions.delta.vrsn - 1.8.24.5 FF - user.js: extensions.delta.vrsni - 1.8.24.5 FF - user.js: extensions.delta.vrsnTs - 1.8.24.519:38 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - orgnl FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - de FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.ffxUnstlRst - true FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta_i.babTrack - affID=121115&tt=200813_245&tsp=4984 srcExt=def FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) Toolbar-10 - (no file) AddRemove-Searchqu Toolbar - c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-24 21:10:29 ComboFix-quarantined-files.txt 2013-08-24 19:10 . Vor Suchlauf: 9 Verzeichnis(se), 342.258.233.344 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 342.203.432.960 Bytes frei . - - End Of File - - 77EE78F3313385B4E95767CBFADB502C OTL Code:
ATTFilter OTL logfile created on: 24.08.2013 21:13:21 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matthias\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,59 Gb Available Physical Memory | 44,79% Memory free 11,57 Gb Paging File | 8,37 Gb Available in Paging File | 72,29% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 318,80 Gb Free Space | 71,94% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32 Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: VIDC.LAGS - lagarith.dll ( ) Drivers32:64bit: vidc.XVID - xvidvfw.dll () Drivers32: msacm.l3acm - C:\windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FFDS - C:\windows\SysWow64\ff_vfw.dll () Drivers32: VIDC.LAGS - C:\windows\SysWow64\lagarith.dll ( ) Drivers32: vidc.mjpg - C:\windows\SysWow64\pvmjpg30.dll (Pegasus Imaging Corporation) Drivers32: vidc.XVID - C:\windows\SysWow64\xvidvfw.dll () ========== Custom Scans ========== <Combofix Logfile: |
24.08.2013, 20:31 | #6 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Das sieht irgendwie so aus, als hättest du das Combofix-Logfile bei OTL in die Textbox eingegeben... Kannst du den Schritt 2 (OTL) bitte nochmals wiederholen, so wie er angegeben ist?
__________________ --> Externe Festplatte infiziert? wscript.exe |
24.08.2013, 20:33 | #7 |
| Externe Festplatte infiziert? wscript.exe Verzeihung, mein Fehler. hier das neue OTL-File Code:
ATTFilter OTL logfile created on: 24.08.2013 21:33:02 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\*****\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 43,18% Memory free 11,57 Gb Paging File | 8,24 Gb Available in Paging File | 71,18% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 317,48 Gb Free Space | 71,65% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32 Computer Name: ***** | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days ========== Custom Scans ========== < dir /a /b "E:\" /c > FOUND.000 Medien System Volume Information Recycled Daten Programme $RECYCLE.BIN 202 Medien.lnk Daten.lnk Programme.lnk 7575 < End of report > Geändert von PKos (24.08.2013 um 21:18 Uhr) |
24.08.2013, 20:37 | #8 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Ok, und grad nochmals:
Code:
ATTFilter dir /a/s/b "E:\Recycled" /c dir /a/s/b "E:\202" /c dir /a/s/b "E:\7575" /c
__________________ cheers, Leo |
24.08.2013, 20:40 | #9 |
| Externe Festplatte infiziert? wscript.exe Neues OTL-File Code:
ATTFilter OTL logfile created on: 24.08.2013 21:39:51 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\****\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 40,71% Memory free 11,57 Gb Paging File | 8,04 Gb Available in Paging File | 69,52% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 317,48 Gb Free Space | 71,65% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32 Computer Name: ***** | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days ========== Custom Scans ========== < dir /a/s/b "E:\Recycled" /c > < dir /a/s/b "E:\202" /c > E:\202\i3d3.js E:\202\g31.js < dir /a/s/b "E:\7575" /c > E:\7575\i686.js E:\7575\g64106.js < End of report > Geändert von PKos (24.08.2013 um 21:17 Uhr) |
24.08.2013, 20:57 | #10 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Ok, dann mach bitte diesen Fix. Wie ist der Zustand danach auf der externen Platte? Fixen mit OTL
Code:
ATTFilter :files C:\74b36 E:\202 E:\Medien.lnk E:\Daten.lnk E:\Programme.lnk E:\7575 dir /a/b "C:\" /c attrib -h -s "E:\*" /s /d /c :commands [emptytemp]
__________________ cheers, Leo |
24.08.2013, 21:11 | #11 |
| Externe Festplatte infiziert? wscript.exe Die Verknüpfungen sind alle weg, die Dateiordner wieder ganz normal da. Dafür noch neue Ordner: "Found.000", "Recycled", "System Volume Information" Code:
ATTFilter All processes killed ========== FILES ========== File\Folder C:\74b36 not found. File\Folder E:\202 not found. File\Folder E:\Medien.lnk not found. File\Folder E:\Daten.lnk not found. File\Folder E:\Programme.lnk not found. File\Folder E:\7575 not found. < dir /a/b "C:\" /c > $RECYCLE.BIN 30d7a25614e5d95791 ComboFix.txt Cyanide Documents and Settings hiberfil.sys Intel msdia80.dll MSOCache pagefile.sys PerfLogs Program Files Program Files (x86) ProgramData Qoobox Recovery RHDSetup.log setup.log System Volume Information user.js Users Windows _OTL C:\Users\*****\Downloads\cmd.bat deleted successfully. C:\Users\*****\Downloads\cmd.txt deleted successfully. < attrib -h -s "E:\*" /s /d /c > C:\Users\*****\Downloads\cmd.bat deleted successfully. C:\Users\*****\Downloads\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: ***** ->Temp folder emptied: 1125 bytes ->Temporary Internet Files folder emptied: 55170 bytes ->Java cache emptied: 4758840 bytes ->FireFox cache emptied: 6371899 bytes ->Google Chrome cache emptied: 447051005 bytes ->Flash cache emptied: 64497 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2682 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42304315 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 477,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 08242013_220612 Files\Folders moved on Reboot... C:\Users\*****\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Geändert von PKos (24.08.2013 um 21:19 Uhr) |
25.08.2013, 01:52 | #12 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Gut. Bei diesen 3 neuen Ordnern kannst du das Attribut "versteckt" wieder aktivieren, denn dieses hab ich im Fix für alle rausgenommen (denn die Malware hat deine bestehenden Ordner versteckt und Verknüpfungen gleichen Namens erstellt, welche auf Malwarefiles gezeigt haben). Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
25.08.2013, 08:12 | #13 |
| Externe Festplatte infiziert? wscript.exe AdwCleaner Code:
ATTFilter # AdwCleaner v3.001 - Report created 25/08/2013 at 08:34:11 # Updated 24/08/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : ***** - ***** # Running from : C:\Users\*****\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : APNMCP Service Deleted : SearchAnonymizer ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\apn Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\AskPartnerNetwork Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\boost_interprocess Folder Deleted : C:\ProgramData\Browser Manager Folder Deleted : C:\ProgramData\IBUpdaterService Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork Folder Deleted : C:\Program Files (x86)\delta Folder Deleted : C:\Program Files (x86)\Iminent Folder Deleted : C:\Users\*****\AppData\Local\Temp\apn Folder Deleted : C:\Users\*****\AppData\Roaming\BabSolution Folder Deleted : C:\Users\*****\AppData\Roaming\Babylon Folder Deleted : C:\Users\*****\AppData\Roaming\DealPly Folder Deleted : C:\Users\*****\AppData\Roaming\delta Folder Deleted : C:\Users\*****\AppData\Roaming\DesktopIconForAmazon Folder Deleted : C:\Users\*****\AppData\Roaming\DSite Folder Deleted : C:\Users\*****\AppData\Roaming\dvdvideosoftiehelpers Folder Deleted : C:\Users\*****\AppData\Roaming\OCS Folder Deleted : C:\Users\*****\AppData\Roaming\PerformerSoft Folder Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\ffxtlbr@delta.com Folder Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\plugin@getwebcake.com File Deleted : C:\windows\System32\roboot64.exe File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Askcom.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\ask-search.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Babylon.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\BrowserProtect.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\delta.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\holasearch.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Search_Results.xml File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\\invalidprefs.js File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\user.js File Deleted : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage File Deleted : C:\windows\System32\Tasks\Dealply File Deleted : C:\windows\System32\Tasks\EPUpdater File Deleted : C:\windows\System32\Tasks\QtraxPlayer ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Deleted : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Key Deleted : HKCU\Software\5f558fdeb469eb43 Key Deleted : HKLM\SOFTWARE\5f558fdeb469eb43 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_k-lite-codec-pack_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_k-lite-codec-pack_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} Key Deleted : HKCU\Software\APN PIP Key Deleted : HKCU\Software\AskPartnerNetwork Key Deleted : HKCU\Software\BI Key Deleted : HKCU\Software\Conduit [#] Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\delta LTD Key Deleted : HKCU\Software\Delta Key Deleted : HKCU\Software\dsiteproducts Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\Iminent Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\OCS Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\AppDataLow\Software\XingHaoLyrics Key Deleted : HKLM\Software\AskPartnerNetwork Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\BabylonToolbar Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Delta Key Deleted : HKLM\Software\IB Updater Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\Software\SearchquSRTB Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Key Deleted : [x64] HKLM\SOFTWARE\IB Updater Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\prefs.js ] Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", true); Line Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119828&babsrc=NT_ss&mntrId=4ca70e72000000000000c48508ccfd54"); Line Deleted : user_pref("extensions.ORJ-V7.domain", "\"www.search.ask.com\""); Line Deleted : user_pref("extensions.delta.admin", false); Line Deleted : user_pref("extensions.delta.aflt", "orgnl"); Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Line Deleted : user_pref("extensions.delta.autoRvrt", "false"); Line Deleted : user_pref("extensions.delta.bbDpng", "25"); Line Deleted : user_pref("extensions.delta.cntry", "DE"); Line Deleted : user_pref("extensions.delta.dfltLng", "de"); Line Deleted : user_pref("extensions.delta.excTlbr", false); Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true); Line Deleted : user_pref("extensions.delta.hdrMd5", "9809EBCE858AC573C1E1811A43119C3C"); Line Deleted : user_pref("extensions.delta.id", "4ca70e72000000000000c48508ccfd54"); Line Deleted : user_pref("extensions.delta.instlDay", "15941"); Line Deleted : user_pref("extensions.delta.instlRef", "sst"); Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.24.519:38:25"); Line Deleted : user_pref("extensions.delta.newTab", false); Line Deleted : user_pref("extensions.delta.prdct", "delta"); Line Deleted : user_pref("extensions.delta.prtnrId", "delta"); Line Deleted : user_pref("extensions.delta.rvrt", "false"); Line Deleted : user_pref("extensions.delta.sg", "azb"); Line Deleted : user_pref("extensions.delta.smplGrp", "azb"); Line Deleted : user_pref("extensions.delta.tlbrId", "base"); Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", ""); Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.5"); Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.519:38:25"); Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.5"); Line Deleted : user_pref("extensions.delta_i.babExt", ""); Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=180613_ndt6&tsp=4921"); Line Deleted : user_pref("extensions.delta_i.srcExt", "ss"); Line Deleted : user_pref("extensions.enabledAddons", "gmailwatcher%40sonthakit:1.61,addon%40codecs.com:1.0,%7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17,toolbar_ORJ-V7%40apn.ask.com:21.51433,%7B74fa6b20-2ae6-458[...] Line Deleted : user_pref("extensions.holasearch.admin", false); Line Deleted : user_pref("extensions.holasearch.aflt", "babsst"); Line Deleted : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}"); Line Deleted : user_pref("extensions.holasearch.autoRvrt", "false"); Line Deleted : user_pref("extensions.holasearch.dfltLng", "en"); Line Deleted : user_pref("extensions.holasearch.excTlbr", false); Line Deleted : user_pref("extensions.holasearch.ffxUnstlRst", false); Line Deleted : user_pref("extensions.holasearch.id", "4ca70e72000000000000c48508ccfd54"); Line Deleted : user_pref("extensions.holasearch.instlDay", "15852"); Line Deleted : user_pref("extensions.holasearch.instlRef", "sst"); Line Deleted : user_pref("extensions.holasearch.newTab", false); Line Deleted : user_pref("extensions.holasearch.prdct", "holasearch"); Line Deleted : user_pref("extensions.holasearch.prtnrId", "holasearch"); Line Deleted : user_pref("extensions.holasearch.rvrt", "false"); Line Deleted : user_pref("extensions.holasearch.smplGrp", "none"); Line Deleted : user_pref("extensions.holasearch.tlbrId", "base"); Line Deleted : user_pref("extensions.holasearch.tlbrSrchUrl", ""); Line Deleted : user_pref("extensions.holasearch.vrsn", "1.8.16.16"); Line Deleted : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1615:56:28"); Line Deleted : user_pref("extensions.holasearch.vrsni", "1.8.16.16"); Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":136890[...] Line Deleted : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc"); Line Deleted : user_pref("extentions.webcake.installId", "6af63b99-f003-4ded-9bce-6c00089258b8"); -\\ Google Chrome v28.0.1500.95 [ File : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [22858 octets] - [25/08/2013 08:30:44] AdwCleaner[S0].txt - [22292 octets] - [25/08/2013 08:34:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [22353 octets] ########## Code:
ATTFilter OTL logfile created on: 25.08.2013 08:41:11 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\*****\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,79 Gb Total Physical Memory | 2,77 Gb Available Physical Memory | 47,83% Memory free 11,57 Gb Paging File | 8,45 Gb Available in Paging File | 73,03% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 443,13 Gb Total Space | 318,52 Gb Free Space | 71,88% Space Free | Partition Type: NTFS Drive E: | 931,28 Gb Total Space | 443,37 Gb Free Space | 47,61% Space Free | Partition Type: FAT32 Computer Name: ***** | User Name: ***** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.08.24 20:02:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe PRC - [2013.08.17 15:14:18 | 000,276,376 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013.07.21 13:52:03 | 001,861,512 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe PRC - [2013.07.19 17:42:26 | 001,655,568 | ---- | M] (Simply Super Software) -- C:\Program Files (x86)\Trojan Remover\Trjscan.exe PRC - [2013.05.25 02:47:30 | 027,776,968 | ---- | M] (Dropbox, Inc.) -- C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012.05.30 13:55:26 | 001,112,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe PRC - [2012.05.02 01:03:44 | 002,279,304 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe PRC - [2012.04.25 06:18:10 | 000,784,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe PRC - [2012.04.06 12:17:04 | 002,796,112 | ---- | M] (Samsung Electronics CO., LTD.) -- C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe PRC - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () -- C:\Program Files (x86)\XSManager\WTGService.exe PRC - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe PRC - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe PRC - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe PRC - [2012.02.21 12:55:16 | 000,936,272 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe PRC - [2012.02.16 15:08:06 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe PRC - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe PRC - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe PRC - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe PRC - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\irstrtsv.exe PRC - [2012.01.31 08:56:48 | 001,640,328 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe PRC - [2012.01.28 07:38:52 | 004,466,256 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe PRC - [2012.01.04 20:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe PRC - [2010.07.08 23:05:12 | 000,160,992 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\starter4g.exe PRC - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\service4g.exe ========== Modules (No Company Name) ========== MOD - [2013.08.17 15:14:17 | 003,551,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2013.07.21 13:52:02 | 016,166,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll MOD - [2013.04.21 21:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2013.04.21 21:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2013.03.13 22:48:52 | 024,978,944 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Dropbox\bin\libcef.dll MOD - [2012.11.14 01:32:50 | 003,558,400 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll MOD - [2011.09.08 12:40:10 | 001,645,056 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll MOD - [2011.02.16 18:03:20 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll ========== Services (SafeList) ========== SRV:64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV:64bit: - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:64bit: - [2012.03.30 05:54:10 | 000,079,664 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe -- (ExpressCache) SRV:64bit: - [2012.02.02 15:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV:64bit: - [2011.12.08 03:44:04 | 000,594,704 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService) SRV:64bit: - [2011.12.08 03:43:56 | 000,273,168 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2011.12.08 03:43:48 | 000,618,256 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2011.12.08 03:43:44 | 000,148,752 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2011.12.05 02:30:50 | 000,659,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3) SRV:64bit: - [2011.12.05 01:55:36 | 000,135,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr) SRV - [2013.08.22 21:53:23 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.08.17 15:14:17 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\XSManager\WTGService.exe -- (WTGService) SRV - [2012.03.12 01:46:40 | 000,274,200 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs) SRV - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service) SRV - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor) SRV - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe -- (SamsungDeviceConfigurationWinService) SRV - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R) SRV - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service) SRV - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysWOW64\irstrtsv.exe -- (irstrtsv) SRV - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\Windows\service4g.exe -- (XS Stick Service) SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2013.06.28 00:54:02 | 001,030,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2013.06.28 00:54:02 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2013.06.28 00:54:02 | 000,189,936 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm) DRV:64bit: - [2013.05.09 10:59:07 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:64bit: - [2013.05.09 10:59:07 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt) DRV:64bit: - [2013.05.09 10:59:07 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:64bit: - [2013.05.09 10:59:06 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2013.05.09 10:59:06 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2013.01.22 22:32:33 | 000,117,888 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmnsusbser.sys -- (cmnsusbser) DRV:64bit: - [2012.12.13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012.03.30 05:54:16 | 000,095,024 | ---- | M] (Diskeeper Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\excsd.sys -- (excsd) DRV:64bit: - [2012.03.30 05:54:16 | 000,023,344 | ---- | M] (Diskeeper Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\excfs.sys -- (excfs) DRV:64bit: - [2012.03.14 12:49:20 | 000,242,512 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD) DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.02.16 15:08:26 | 000,031,216 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd) DRV:64bit: - [2012.02.14 05:38:56 | 000,060,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (ibtfltcoex) DRV:64bit: - [2012.02.07 02:49:04 | 000,026,504 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irstrtdv.sys -- (irstrtdv) DRV:64bit: - [2012.01.09 12:49:26 | 000,225,920 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UBDA.sys -- (RTL2832UBDA) DRV:64bit: - [2012.01.09 12:49:26 | 000,049,152 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832U_IRHID.sys -- (RTL2832U_IRHID) DRV:64bit: - [2012.01.09 12:49:26 | 000,039,680 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UUSB.sys -- (RTL2832UUSB) DRV:64bit: - [2012.01.05 13:36:54 | 014,652,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2012.01.04 20:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc) DRV:64bit: - [2012.01.04 20:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub) DRV:64bit: - [2012.01.04 20:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs) DRV:64bit: - [2011.12.20 10:38:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd) DRV:64bit: - [2011.12.20 10:38:36 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible) DRV:64bit: - [2011.12.20 10:38:36 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus) DRV:64bit: - [2011.12.05 21:23:08 | 000,331,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP) DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL) DRV:64bit: - [2011.12.01 15:51:00 | 011,417,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) DRV:64bit: - [2011.11.30 04:19:48 | 000,747,008 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf) DRV:64bit: - [2011.11.30 04:19:46 | 000,094,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux) DRV:64bit: - [2011.11.29 12:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2011.11.23 16:02:20 | 000,648,808 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.11.10 11:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11) DRV:64bit: - [2009.11.05 14:04:42 | 000,513,600 | ---- | M] (ITETech ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF15BDA.sys -- (AF9035BDA) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.28 08:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Ask Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: "false" FF - prefs.js..browser.startup.homepage: "hxxp://www.domradio.de/" FF - prefs.js..extensions.enabledAddons: gmailwatcher%40sonthakit:1.61 FF - prefs.js..extensions.enabledAddons: addon%40codecs.com:1.0 FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17 FF - prefs.js..extensions.enabledAddons: toolbar_ORJ-V7%40apn.ask.com:21.51433 FF - prefs.js..extensions.enabledAddons: %7B74fa6b20-2ae6-4584-a4fd-4ac734f8d210%7D:3.3 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.18 21:40:21 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.06.04 01:49:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions [2013.08.25 08:34:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions [2013.08.23 19:16:57 | 000,000,000 | ---D | M] (BargainJoy) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210} [2013.07.20 10:34:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013.06.22 12:22:49 | 000,000,000 | ---D | M] ("Safe ads") -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\addon@codecs.com [2013.03.21 10:23:42 | 000,226,606 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\gmailwatcher@sonthakit.xpi [2013.08.12 02:31:09 | 000,454,970 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\toolbar_ORJ-V7@apn.ask.com.xpi [2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\googlede.xml [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (Recorder Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{10743931-94DF-476f-A987-4391233C17A2} [2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions [2013.08.17 15:14:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\windows\SysWOW64\npDeployJava1.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll O1 HOSTS File: ([2013.08.24 20:57:40 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (no name) - {120A8821-2BEE-4C29-BCDA-62C577781992} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software) O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found O4 - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files (x86)\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [starter4g] C:\Windows\starter4g.exe (4G Systems GmbH & Co. KG) O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software) O4 - Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DelayedDesktopSwitchTimeout = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4750731-9CEA-48CB-B383-6C430621A66D}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\ms-help - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.08.25 08:30:42 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2013.08.24 21:58:38 | 000,000,000 | ---D | C] -- C:\_OTL [2013.08.24 21:11:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.08.24 21:10:59 | 000,000,000 | ---D | C] -- C:\windows\temp [2013.08.24 20:39:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe [2013.08.24 20:39:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe [2013.08.24 20:39:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe [2013.08.24 20:38:55 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.08.24 20:38:44 | 000,000,000 | ---D | C] -- C:\windows\erdnt [2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\Simply Super Software [2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Simply Super Software [2013.08.24 19:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover [2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover [2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software [2013.08.24 18:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2013.08.24 18:17:01 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Malwarebytes [2013.08.24 18:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.08.24 18:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.08.24 18:16:38 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2013.08.24 18:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.08.24 13:34:32 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle [2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services [2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services [2013.08.22 21:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2013.08.22 21:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [2013.08.22 21:47:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2013.08.22 21:45:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2013.08.22 21:45:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2013.08.22 21:45:20 | 000,000,000 | R--D | C] -- C:\MSOCache [2013.08.22 21:43:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys [2013.08.22 19:38:33 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite [2013.08.22 19:38:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite [2013.08.22 19:37:53 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2013.08.17 15:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.08.12 22:21:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ [2013.08.11 22:10:35 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Schlag den Raab - Das 3. Spiel [2013.08.11 22:10:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer [2013.08.11 22:10:19 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\ProtectDISC [2013.08.11 22:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games [2013.08.11 22:02:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bitComposer Games [2013.08.04 07:23:18 | 000,000,000 | ---D | C] -- C:\windows\SysNative\MRT [2013.07.31 16:32:59 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\Libori-Dienstag ========== Files - Modified Within 30 Days ========== [2013.08.25 08:42:44 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.08.25 08:42:44 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.08.25 08:41:40 | 001,498,742 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2013.08.25 08:41:40 | 000,654,400 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2013.08.25 08:41:40 | 000,616,242 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2013.08.25 08:41:40 | 000,130,240 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2013.08.25 08:41:40 | 000,106,622 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2013.08.25 08:35:49 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job [2013.08.25 08:35:48 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2013.08.25 08:35:25 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2013.08.25 08:32:00 | 000,001,114 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2013.08.25 08:05:25 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job [2013.08.24 22:05:49 | 000,001,059 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013.08.24 20:57:40 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts [2013.08.24 19:14:11 | 000,462,896 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2013.08.24 18:37:59 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI [2013.08.24 17:47:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job [2013.08.23 19:16:42 | 000,000,005 | ---- | M] () -- C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys [2013.08.22 21:35:21 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt [2013.08.20 22:24:25 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00003553.LCS [2013.07.31 17:01:43 | 000,000,072 | ---- | M] () -- C:\Users\*****\AppData\Roaming\WB.CFG ========== Files Created - No Company Name ========== [2013.08.24 22:05:49 | 000,001,059 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013.08.24 20:39:43 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe [2013.08.24 20:39:43 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe [2013.08.24 20:39:43 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe [2013.08.24 20:39:43 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe [2013.08.24 20:39:43 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe [2013.08.24 13:34:32 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI [2013.08.11 22:10:22 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00003553.LCS [2013.07.27 00:21:11 | 000,000,072 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WB.CFG [2013.07.22 21:20:00 | 000,010,455 | ---- | C] () -- C:\Users\*****\Friebe_elster_2048.pfx [2013.06.28 11:27:50 | 000,000,005 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT [2013.06.22 13:21:04 | 000,000,005 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT [2013.06.22 12:22:31 | 000,079,360 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll [2013.06.22 12:22:17 | 000,645,632 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll [2013.06.22 12:22:17 | 000,240,640 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll [2013.06.22 12:22:06 | 000,715,038 | ---- | C] () -- C:\windows\unins000.exe [2013.06.22 12:22:06 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll [2013.06.22 12:22:06 | 000,002,000 | ---- | C] () -- C:\windows\unins000.dat [2013.06.22 12:16:53 | 000,376,832 | ---- | C] () -- C:\windows\SysWow64\xvid.dll [2013.06.21 22:56:26 | 000,000,218 | ---- | C] () -- C:\Users\*****\.recently-used.xbel [2013.05.27 15:54:57 | 000,178,688 | ---- | C] () -- C:\windows\SysWow64\unrar.dll [2013.03.04 20:08:50 | 000,007,168 | ---- | C] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.12.01 00:42:45 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll [2012.11.23 10:20:48 | 000,338,432 | ---- | C] () -- C:\windows\SysWow64\sqlite36_engine.dll [2012.06.30 13:44:34 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe [2012.06.30 12:37:45 | 000,003,586 | ---- | C] () -- C:\windows\HotFixList.ini [2012.03.13 04:59:22 | 000,963,912 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin [2012.03.13 04:59:22 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin [2012.03.13 04:59:19 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin [2012.03.13 04:59:19 | 000,261,208 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin [2012.03.13 04:59:16 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll [2012.03.13 04:59:14 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll [2012.03.13 04:59:14 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin [2012.03.13 04:59:13 | 013,184,512 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll [2012.02.02 15:08:26 | 000,001,536 | ---- | C] () -- C:\windows\SysWow64\IusEventLog.dll ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.07.07 21:38:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Audacity [2013.03.05 00:52:41 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\avidemux [2013.04.02 21:47:05 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Canneverbe Limited [2013.06.22 12:22:09 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\CDXReader [2013.08.22 21:44:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite [2013.08.25 08:35:58 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Dropbox [2013.04.02 22:38:01 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DVDVideoSoft [2013.03.09 01:42:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\elsterformular [2012.11.23 09:59:39 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Engelmann Media [2013.07.30 16:07:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FileZilla [2012.12.01 00:42:56 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FreeAudioPack [2013.04.02 21:54:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FreeFLVConverter [2013.06.21 22:56:26 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Gaupol [2013.06.21 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\gtk-2.0 [2013.07.20 00:59:27 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\ICQ [2013.08.22 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\IrfanView [2013.06.22 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LavFilters [2013.01.09 16:51:45 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\MAY Computer [2013.05.11 19:55:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\MusE [2013.03.24 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\OpenOffice.org [2012.11.23 10:20:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Opera [2013.01.12 15:40:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Origin [2013.08.11 22:10:19 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\ProtectDISC [2013.01.18 16:33:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Scribus [2013.08.24 19:06:20 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Simply Super Software [2013.07.01 20:29:04 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Subtitle Edit [2012.12.28 01:03:59 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\TerraTec [2013.06.22 12:22:15 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Ultimate Codec Packages [2013.04.02 22:22:35 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Video DVD Maker FREE [2012.11.17 22:09:46 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Visan [2013.03.01 10:17:13 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\XSManager ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:CB0AACC9 < End of report > |
25.08.2013, 10:47 | #14 |
/// TB-Ausbilder | Externe Festplatte infiziert? wscript.exe Wie läuft der Rechner? Alles in Ordnung? Schritt 1 Fixen mit OTL
Code:
ATTFilter :OTL IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B FF - prefs.js..browser.search.order.1: "Ask Search" O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found :commands [emptytemp]
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
25.08.2013, 23:53 | #15 |
| Externe Festplatte infiziert? wscript.exe OTL: Code:
ATTFilter All processes killed ========== OTL ========== Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1113C54B-0A97-4487-B3A5-D9C3130418EC}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1263E943-A411-4127-91C8-579383726819}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1263E943-A411-4127-91C8-579383726819}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E8595F0-B862-45FC-A057-3284126557BC}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3E73719-337B-46B6-848C-0F584E2BDAF2}\ not found. Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}\ not found. Prefs.js: "Ask Search" removed from browser.search.order.1 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Matthias ->Temp folder emptied: 3275 bytes ->Temporary Internet Files folder emptied: 7179 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 6236383 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 602 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3290 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 6,00 mb Error: Unable to interpret < Solltest du d> in the current context! OTL by OldTimer - Version 3.2.69.0 log created on 08252013_233857 Files\Folders moved on Reboot... C:\Users\*****\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3414e2cbed009342b50f2ba92d1c401e # engine=14899 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-25 10:42:57 # local_time=2013-08-26 12:42:57 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 3913914 154180449 0 0 # compatibility_mode=5893 16776573 100 94 95926 129100427 0 0 # scanned=237310 # found=2 # cleaned=0 # scan_time=3524 sh=529F1CB730B133C2264E3451DCCC7DEEB179C135 ft=1 fh=2c963b952ca2f278 vn="probably a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\_Setupx.dll.vir" sh=9B7AFC05F48AE3F56DBE1A2114F8FDF50067A187 ft=0 fh=0000000000000000 vn="JS/Adware.Yontoo.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\plugin@getwebcake.com\content\overlay.js.vir" Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Trojan Remover 6.8.8 Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Adobe Flash Player 11.8.800.94 Adobe Reader XI Mozilla Firefox (23.0.1) Google Chrome 28.0.1500.72 Google Chrome 28.0.1500.95 Google Chrome 29.0.1547.57 ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Themen zu Externe Festplatte infiziert? wscript.exe |
avast, community, datei, externe, externe festplatte, festplatte, infiziert, liebe, löschung, ordner, platte, problem, rojaner gefunden, scan, scanner, schonmal, system, system32, troja, trojaner, trojaners, verknüpfungen, virenscan, virenscanner, virus, wscript.exe, ändert |