![]() |
|
Plagegeister aller Art und deren Bekämpfung: BKA Virus Windows zerschossenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() BKA Virus Windows zerschossen Hatte diesen BKA Virus auf dem Rechner welchen ich schnell mit Malewarebytes entfernen konnte aber nun macht Windows Probleme erst war der BootMGR gelöscht welchen ich mit der Windows CD wiederherstellen musste nun bekomm ich folgende Fehler Beim Start kommt erstmal das mein Windows erneut aktiviert werden muss welches immer fehlschlägt habs mit mehreren Orginalen Keys versucht Danach kommen 3 rundll .cpp Fehler Desktop hat nach dem Neustart immer ein Schwarzes Hintergrundbild OTL log: Code:
ATTFilter OTL logfile created on: 22.01.2015 14:42:14 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Downloads 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 15,96 Gb Total Physical Memory | 13,21 Gb Available Physical Memory | 82,78% Memory free 31,91 Gb Paging File | 28,91 Gb Available in Paging File | 90,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,76 Gb Total Space | 68,69 Gb Free Space | 14,75% Space Free | Partition Type: NTFS Drive D: | 372,61 Gb Total Space | 336,64 Gb Free Space | 90,35% Space Free | Partition Type: NTFS Drive E: | 4,19 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Drive F: | 127,99 Gb Total Space | 77,46 Gb Free Space | 60,52% Space Free | Partition Type: NTFS Drive G: | 338,75 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2015.01.22 14:33:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads\OTL.exe PRC - [2015.01.22 14:28:36 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\rubyw.exe PRC - [2015.01.22 14:28:31 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\rubyw.exe PRC - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe PRC - [2015.01.17 03:11:45 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2015.01.14 05:19:01 | 000,389,744 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe PRC - [2014.12.13 01:13:07 | 002,531,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe PRC - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe PRC - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe PRC - [2014.10.27 17:37:08 | 003,095,840 | ---- | M] (Nota Inc.) -- C:\Program Files (x86)\Gyazo\GyStation.exe PRC - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2014.06.23 12:35:12 | 000,436,720 | ---- | M] (QIP.ru) -- C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe PRC - [2014.02.20 21:32:04 | 001,553,688 | ---- | M] (Comfort Software Group) -- C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe PRC - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe PRC - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe PRC - [2013.08.07 13:24:00 | 000,287,592 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2012.05.20 17:26:26 | 000,291,648 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe PRC - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe ========== Modules (No Company Name) ========== MOD - [2015.01.22 14:28:42 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so MOD - [2015.01.22 14:28:40 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so MOD - [2015.01.22 14:28:40 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so MOD - [2015.01.22 14:28:40 | 000,036,352 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so MOD - [2015.01.22 14:28:40 | 000,023,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so MOD - [2015.01.22 14:28:40 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so MOD - [2015.01.22 14:28:40 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so MOD - [2015.01.22 14:28:40 | 000,008,192 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so MOD - [2015.01.22 14:28:38 | 000,275,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so MOD - [2015.01.22 14:28:38 | 000,069,120 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so MOD - [2015.01.22 14:28:38 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so MOD - [2015.01.22 14:28:38 | 000,015,360 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so MOD - [2015.01.22 14:28:36 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\libffi-6.dll MOD - [2015.01.22 14:28:36 | 000,118,784 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so MOD - [2015.01.22 14:28:36 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\src\rgloader\rgloader193.mswin.so MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so MOD - [2015.01.22 14:28:36 | 000,083,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\zlib1.dll MOD - [2015.01.22 14:28:36 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so MOD - [2015.01.22 14:28:36 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so MOD - [2015.01.22 14:28:36 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so MOD - [2015.01.22 14:28:36 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so MOD - [2015.01.22 14:28:36 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so MOD - [2015.01.22 14:28:36 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so MOD - [2015.01.22 14:28:33 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so MOD - [2015.01.22 14:28:33 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so MOD - [2015.01.22 14:28:33 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so MOD - [2015.01.22 14:28:33 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so MOD - [2015.01.22 14:28:33 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so MOD - [2015.01.22 14:28:33 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so MOD - [2015.01.22 14:28:33 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so MOD - [2015.01.22 14:28:33 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so MOD - [2015.01.22 14:28:33 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so MOD - [2015.01.22 14:28:33 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so MOD - [2015.01.22 14:28:33 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so MOD - [2015.01.22 14:28:32 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\libffi-6.dll MOD - [2015.01.22 14:28:31 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\src\rgloader\rgloader193.mswin.so MOD - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe MOD - [2015.01.17 03:11:44 | 003,925,104 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2015.01.14 05:19:02 | 003,347,056 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll MOD - [2015.01.14 05:19:02 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll MOD - [2015.01.14 05:19:02 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll MOD - [2014.11.12 00:38:39 | 000,059,904 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll MOD - [2014.11.12 00:38:34 | 001,234,944 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll MOD - [2014.11.12 00:38:34 | 001,198,592 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll MOD - [2014.11.12 00:38:34 | 000,815,104 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll MOD - [2014.11.12 00:38:34 | 000,642,048 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll MOD - [2014.11.12 00:38:34 | 000,511,488 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll MOD - [2014.11.12 00:38:34 | 000,290,816 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll MOD - [2014.11.12 00:38:33 | 000,745,472 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll MOD - [2014.11.12 00:38:32 | 000,344,064 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll MOD - [2014.11.12 00:38:32 | 000,217,088 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll MOD - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe MOD - [2014.11.12 00:38:31 | 000,368,640 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll MOD - [2014.11.12 00:38:31 | 000,200,704 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll MOD - [2014.11.12 00:38:31 | 000,180,224 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll MOD - [2014.09.29 22:25:43 | 001,203,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\ad9facc364268611cc4ca65f77caeddd\System.WorkflowServices.ni.dll MOD - [2014.09.29 22:25:23 | 001,127,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56\System.ServiceModel.Discovery.ni.dll MOD - [2014.09.29 22:25:23 | 000,365,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76a5d670ce969c0c65a905b7303d4bbf\System.ServiceModel.Routing.ni.dll MOD - [2014.09.29 22:25:22 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c3831eb95ccf3904bab81a97a9b08ed3\System.ServiceModel.Channels.ni.dll MOD - [2014.09.29 22:25:15 | 001,388,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b\System.ServiceModel.Activities.ni.dll MOD - [2014.09.29 22:25:14 | 001,065,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll MOD - [2014.09.29 22:25:13 | 017,919,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll MOD - [2014.09.29 22:25:05 | 001,046,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\51c60db370e050d9cdcac17060aaac53\System.ServiceModel.Web.ni.dll MOD - [2014.09.29 22:24:11 | 002,625,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll MOD - [2014.09.29 22:24:11 | 001,011,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll MOD - [2014.09.29 22:24:11 | 000,142,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba\SMDiagnostics.ni.dll MOD - [2014.09.29 22:23:53 | 001,776,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll MOD - [2014.09.29 22:21:37 | 013,006,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll MOD - [2014.09.29 22:21:32 | 001,651,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll MOD - [2014.09.29 22:21:04 | 005,571,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll MOD - [2014.09.29 22:21:02 | 000,973,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll MOD - [2014.09.29 22:21:01 | 007,025,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll MOD - [2014.09.29 22:20:57 | 009,000,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll MOD - [2014.09.29 22:20:54 | 014,415,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll MOD - [2014.08.10 15:40:22 | 000,065,792 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\TortoiseStub32.dll MOD - [2014.08.10 15:40:10 | 000,071,936 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\libsasl32.dll MOD - [2014.06.23 12:35:12 | 000,378,864 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\QipGuard\chrome.dll MOD - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe ========== Services (SafeList) ========== SRV:64bit: - [2012.12.11 11:00:52 | 000,027,768 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2015.01.17 03:11:44 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2015.01.14 16:04:13 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService) SRV - [2014.12.13 01:13:04 | 001,148,560 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService) SRV - [2014.12.13 01:13:03 | 019,823,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc) SRV - [2014.12.11 10:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2014.11.07 13:02:56 | 000,331,776 | ---- | M] () [Auto | Stopped] -- C:\ProgramData\4519DF80.dot -- (Winmgmt) SRV - [2014.10.14 20:33:28 | 000,174,600 | ---- | M] (Sandboxie Holdings, LLC) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc) SRV - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service) SRV - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service) SRV - [2013.08.27 13:32:30 | 000,828,376 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R) SRV - [2013.08.27 13:32:14 | 000,747,520 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV - [2013.08.07 13:24:00 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.11.18 23:05:00 | 000,065,536 | ---- | M] (CodeGear) [Auto | Running] -- C:\Program Files (x86)\Embarcadero\RAD Studio\7.0\bin\BSQLServer.exe -- (BlackfishSQL) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2014.11.22 11:46:30 | 000,038,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible) DRV:64bit: - [2014.11.05 05:49:12 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt) DRV:64bit: - [2014.09.29 21:27:28 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2014.09.17 05:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2013.12.16 09:46:34 | 000,690,864 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV:64bit: - [2013.10.17 15:27:02 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot) DRV:64bit: - [2013.09.16 11:17:42 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64) DRV:64bit: - [2013.08.22 09:40:24 | 000,040,664 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901) DRV:64bit: - [2013.08.07 13:23:46 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA) DRV:64bit: - [2013.08.07 13:23:46 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF) DRV:64bit: - [2013.07.18 06:54:52 | 000,129,224 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2013.01.03 02:31:20 | 000,301,256 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv) DRV:64bit: - [2013.01.03 02:31:18 | 000,231,112 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB) DRV:64bit: - [2012.05.20 17:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc) DRV:64bit: - [2012.05.20 17:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub) DRV:64bit: - [2012.05.20 17:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs) DRV:64bit: - [2010.03.09 04:08:36 | 000,121,800 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HtcVComV64.sys -- (HtcVCom32) DRV:64bit: - [2009.11.02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64) DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2014.12.13 01:13:03 | 000,019,600 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms) DRV - [2014.10.14 20:33:28 | 000,185,352 | ---- | M] (Sandboxie Holdings, LLC) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 6F AD F2 47 00 D0 01 [binary data] IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.isUS: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: %7B6AC85730-7D0F-4de0-B3FA-21142DD85326%7D:2.8 FF - prefs.js..extensions.enabledAddons: %7B9c51bd27-6ed8-4000-a2bf-36cb95c0c947%7D:11.0.1 FF - prefs.js..extensions.enabledAddons: foxyproxy%40eric.h.jung:4.5 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2014.09.29 20:15:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2014.09.29 20:25:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\f\extensions [2015.01.18 20:39:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions [2014.09.29 21:01:58 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015.01.18 20:39:13 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\foxyproxy@eric.h.jung [2014.12.09 10:42:07 | 002,551,632 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\firebug@software.joehewitt.com.xpi [2014.11.08 23:14:43 | 000,080,872 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2015.01.15 14:12:06 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014.09.11 16:15:07 | 000,002,438 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\englische-ergebnisse.xml [2014.09.11 16:15:07 | 000,002,916 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\gmx-suche.xml [2014.09.11 16:15:07 | 000,002,457 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\lastminute.xml [2014.09.11 16:15:07 | 000,005,729 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\webde-suche.xml [2015.01.17 03:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2015.01.17 03:11:45 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2015.01.22 13:05:36 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (no name) - {2193d8fb-a459-4acc-b40d-5cefd11384dc} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (WebMoneyAdvisorBHO) - {E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces) O3 - HKLM\..\Toolbar: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces) O3 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\Toolbar\WebBrowser: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4:64bit: - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) O4 - HKLM..\Run: [wmagent.exe] C:\Program Files (x86)\WebMoney Agent\wmagent.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Ditto] C:\Programme\Ditto\Ditto.exe () O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe (Nota Inc.) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [QIP Internet Guardian] C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe (QIP.ru) O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (Sandboxie Holdings, LLC) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([http] in Trusted sites) O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([https] in Trusted sites) O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([http] in Trusted sites) O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([https] in Trusted sites) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE1F8C0-6F4D-4476-8933-97871E5E3032}: DhcpNameServer = 192.168.178.1 O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) - File not found O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found O29 - HKLM SecurityProviders - (credssp.dll) - File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.07.14 12:08:10 | 000,000,043 | R--- | M] () - E:\autorun.inf -- [ UDF ] O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation) O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation) O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2015.01.22 14:23:35 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2015.01.22 14:04:48 | 000,040,664 | ---- | C] (The OpenVPN Project) -- C:\Windows\SysNative\drivers\tap0901.sys [2015.01.17 03:11:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2015.01.14 05:18:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2015.01.10 11:35:17 | 000,000,000 | ---D | C] -- C:\Users\Admin\cminstaller [2015.01.04 21:44:02 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS [2015.01.04 13:22:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Gyazo [2015.01.04 13:22:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo [2015.01.04 13:22:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gyazo [2015.01.03 15:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony [2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony [2014.12.26 16:46:19 | 000,000,000 | ---D | C] -- C:\Windows\pss [2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software [2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Runtime Software [2014.12.25 19:48:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft [2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft [2014.12.25 19:46:27 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft [2014.11.23 19:08:02 | 000,755,269 | ---- | C] (CheatHappens) -- C:\Users\Admin\coh2-Spike1338.exe [2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ] [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2015.01.22 14:28:30 | 000,001,684 | ---- | M] () -- C:\Windows\tasks\MQJGALU.job [2015.01.22 14:28:30 | 000,001,340 | ---- | M] () -- C:\Windows\tasks\SYKWCLB.job [2015.01.22 14:28:30 | 000,001,338 | ---- | M] () -- C:\Windows\tasks\FRVOIK.job [2015.01.22 14:28:30 | 000,001,336 | ---- | M] () -- C:\Windows\tasks\FWWLD.job [2015.01.22 14:28:30 | 000,001,334 | ---- | M] () -- C:\Windows\tasks\MQBB.job [2015.01.22 14:28:30 | 000,001,330 | ---- | M] () -- C:\Windows\tasks\WF.job [2015.01.22 14:28:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2015.01.22 14:28:11 | 4261,040,126 | -HS- | M] () -- C:\hiberfil.sys [2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2015.01.22 14:04:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2015.01.22 13:25:50 | 000,001,780 | ---- | M] () -- C:\Windows\Sandboxie.ini [2015.01.22 13:19:11 | 000,002,008 | -H-- | M] () -- C:\Users\Admin\Documents\Default.rdp [2015.01.22 13:05:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2015.01.10 14:54:51 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf [2015.01.05 09:41:49 | 001,025,097 | ---- | M] () -- C:\Users\Admin\IMAG0189.jpg [2015.01.04 21:51:02 | 000,000,842 | ---- | M] () -- C:\Users\Admin\Desktop\uploads.html [2015.01.04 13:22:42 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk [2015.01.04 13:22:41 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo.lnk [2015.01.03 15:23:17 | 000,002,576 | ---- | M] () -- C:\Users\Admin\Documents\Vegas Pro registrieren.htm [2014.12.29 00:20:24 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys [2014.12.27 23:13:26 | 000,092,530 | ---- | M] () -- C:\Users\Admin\click_link.jpg [2014.12.27 10:42:50 | 000,004,744 | ---- | M] () -- C:\Users\Admin\toprlz.png [2014.12.27 10:42:50 | 000,000,132 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen [2014.12.26 14:42:33 | 395,306,822 | ---- | M] () -- C:\Users\Admin\unbenannt.st3 [2014.12.25 21:21:04 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk [2014.12.25 21:20:12 | 000,000,621 | ---- | M] () -- C:\Users\Admin\Last session Admin.prj [2014.12.25 21:20:05 | 000,001,994 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk [2014.12.25 20:51:45 | 000,000,009 | RHS- | M] () -- C:\wedaolu [2014.12.25 19:48:34 | 000,001,435 | ---- | M] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk [2014.12.25 19:48:34 | 000,001,247 | ---- | M] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk [2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ] [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2015.01.10 14:54:51 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf [2015.01.05 09:44:32 | 001,025,097 | ---- | C] () -- C:\Users\Admin\IMAG0189.jpg [2015.01.04 21:51:02 | 000,000,842 | ---- | C] () -- C:\Users\Admin\Desktop\uploads.html [2015.01.04 13:22:42 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk [2015.01.04 13:22:41 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo.lnk [2014.12.27 23:13:24 | 000,092,530 | ---- | C] () -- C:\Users\Admin\click_link.jpg [2014.12.27 10:42:48 | 000,004,744 | ---- | C] () -- C:\Users\Admin\toprlz.png [2014.12.26 14:40:02 | 395,306,822 | ---- | C] () -- C:\Users\Admin\unbenannt.st3 [2014.12.26 14:39:05 | 000,000,274 | ---- | C] () -- C:\Users\Admin\DE.reg.x64.reg [2014.12.25 21:21:04 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk [2014.12.25 21:20:12 | 000,000,621 | ---- | C] () -- C:\Users\Admin\Last session Admin.prj [2014.12.25 21:20:05 | 000,001,994 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk [2014.12.25 20:51:45 | 000,000,009 | RHS- | C] () -- C:\wedaolu [2014.12.25 19:48:34 | 000,001,435 | ---- | C] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk [2014.12.25 19:48:34 | 000,001,247 | ---- | C] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk [2014.12.20 12:25:57 | 000,959,853 | ---- | C] () -- C:\Users\Admin\IMAG0188.jpg [2014.12.07 19:47:33 | 000,007,211 | ---- | C] () -- C:\Users\Admin\postmortem.nfo [2014.11.17 13:56:11 | 000,607,800 | ---- | C] () -- C:\Users\Admin\fc4-Spike1338.exe [2014.11.16 13:52:35 | 000,366,592 | ---- | C] () -- C:\Users\Admin\GamersGoMakers_CH.exe [2014.11.13 21:41:19 | 000,074,488 | ---- | C] () -- C:\Users\Admin\VSa - Advanced Registration.xml [2014.11.13 00:38:41 | 000,543,289 | ---- | C] () -- C:\Users\Admin\fa15-Spike1338.exe [2014.11.12 09:38:11 | 000,002,903 | ---- | C] () -- C:\Users\Admin\ucms_update_entries.sql [2014.11.12 09:38:11 | 000,002,269 | ---- | C] () -- C:\Users\Admin\ucms_update_partners.sql [2014.11.12 09:38:11 | 000,000,504 | ---- | C] () -- C:\Users\Admin\ucms_update_entry_log.sql [2014.11.12 09:23:21 | 000,018,613 | ---- | C] () -- C:\Users\Admin\ucms.sql [2014.11.11 18:42:56 | 000,165,603 | ---- | C] () -- C:\Users\Admin\VSa_AFStats.xml [2014.11.11 14:27:23 | 000,013,172 | ---- | C] () -- C:\Users\Admin\logo.png [2014.11.11 14:23:56 | 000,000,326 | ---- | C] () -- C:\Users\Admin\primus-slate-fluid.xml [2014.11.11 14:22:43 | 000,879,411 | ---- | C] () -- C:\Users\Admin\primus-slate-forum.xml [2014.11.11 14:20:05 | 000,000,306 | ---- | C] () -- C:\Users\Admin\primus-blue-fluid.xml [2014.11.11 12:28:32 | 000,221,639 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fixed.xml [2014.11.11 12:28:32 | 000,221,635 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fluid.xml [2014.11.10 22:52:23 | 000,028,925 | ---- | C] () -- C:\Users\Admin\functions.php [2014.11.10 20:11:44 | 000,001,780 | ---- | C] () -- C:\Windows\Sandboxie.ini [2014.11.10 16:13:23 | 025,570,303 | ---- | C] () -- C:\Users\Admin\gezload_main-DB-11.1.08.sql [2014.11.10 16:09:58 | 000,005,508 | ---- | C] () -- C:\Users\Admin\evo_beatz.sql [2014.11.09 00:48:24 | 000,000,026 | ---- | C] () -- C:\Windows\Ditto.INI [2014.11.07 13:02:56 | 000,331,776 | ---- | C] () -- C:\ProgramData\4519DF80.dot [2014.11.05 06:37:59 | 000,000,612 | ---- | C] () -- C:\Users\Admin\index.html [2014.11.03 22:31:53 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen [2014.10.25 10:20:53 | 002,594,031 | ---- | C] () -- C:\Users\Admin\WinRAR.rar [2014.10.24 21:06:45 | 000,000,553 | ---- | C] () -- C:\Windows\eReg.dat [2014.10.05 21:37:25 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen [2014.10.05 20:56:03 | 000,089,432 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat [2014.10.02 15:44:19 | 000,048,644 | ---- | C] () -- C:\Users\Admin\warezking.in_xml.xml [2014.09.29 20:29:44 | 000,000,024 | ---- | C] () -- C:\Windows\SetupTemp.ini [2014.09.29 20:28:48 | 001,186,161 | ---- | C] () -- C:\Windows\unins000.exe [2014.09.29 20:28:48 | 000,001,134 | ---- | C] () -- C:\Windows\unins000.dat [2014.09.29 20:24:08 | 001,591,716 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\WF [2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\SYKWCLB [2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FWWLD [2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQJGALU [2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQBB [2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FRVOIK [2013.11.16 13:39:18 | 000,063,852 | ---- | C] () -- C:\Users\Admin\index.php [2013.08.27 13:00:08 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll [2013.03.21 05:10:16 | 000,042,880 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2010.08.11 16:06:39 | 014,162,944 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010.08.11 16:06:39 | 012,867,584 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2015.01.22 13:19:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\.purple [2014.11.07 10:53:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Affilorama [2014.11.02 00:25:46 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CodeGear [2015.01.22 13:28:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite [2014.12.25 19:48:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft [2014.10.27 01:54:55 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\EasySetup [2014.11.02 00:09:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Embarcadero [2015.01.22 13:28:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FileZilla [2015.01.04 13:25:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Gyazo [2014.11.06 11:53:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\HTC [2014.11.08 16:11:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai [2014.11.08 16:11:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1 [2014.11.10 12:18:40 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MyImgur [2014.10.03 11:02:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Notepad++ [2014.10.27 01:49:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Opera Software [2014.10.05 21:25:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PDAppFlex [2014.11.16 16:39:36 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Publish Providers [2014.10.02 13:49:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QIP [2014.10.02 13:49:32 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QipGuard [2014.12.21 13:42:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QuickScan [2015.01.03 15:16:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Sony [2014.11.07 10:38:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Spiritsoft [2014.09.30 13:01:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Steam [2014.11.02 00:24:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Subversion [2014.09.29 20:27:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thunderbird [2014.11.12 00:42:59 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Titanium [2014.11.07 10:54:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Traffic Travis v4 [2014.11.05 16:02:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TrueCrypt [2014.11.07 16:01:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\UBot Studio [2015.01.22 13:06:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WebMoney ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A064CECC @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:41ADDB8A < End of report > |
Themen zu BKA Virus Windows zerschossen |
adobe, autorun, bho, bootmgr, dll, entfernen, explorer, firefox, flash player, format, geforce, helper, logfile, mozilla, neustart, nvidia, opera, registry, rundll, scan, software, temp, usb, virus, windows, windows probleme |