Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: BKA Virus Windows zerschossen

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 22.01.2015, 14:53   #1
SPK
 
BKA Virus Windows zerschossen - Standard

BKA Virus Windows zerschossen



Hatte diesen BKA Virus auf dem Rechner welchen ich schnell mit Malewarebytes entfernen konnte aber nun macht Windows Probleme erst war der BootMGR gelöscht welchen ich mit der Windows CD wiederherstellen musste nun bekomm ich folgende Fehler

Beim Start kommt erstmal das mein Windows erneut aktiviert werden muss welches immer fehlschlägt habs mit mehreren Orginalen Keys versucht

Danach kommen 3 rundll .cpp Fehler

Desktop hat nach dem Neustart immer ein Schwarzes Hintergrundbild

OTL log:

Code:
ATTFilter
OTL logfile created on: 22.01.2015 14:42:14 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Admin\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
15,96 Gb Total Physical Memory | 13,21 Gb Available Physical Memory | 82,78% Memory free
31,91 Gb Paging File | 28,91 Gb Available in Paging File | 90,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 68,69 Gb Free Space | 14,75% Space Free | Partition Type: NTFS
Drive D: | 372,61 Gb Total Space | 336,64 Gb Free Space | 90,35% Space Free | Partition Type: NTFS
Drive E: | 4,19 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 127,99 Gb Total Space | 77,46 Gb Free Space | 60,52% Space Free | Partition Type: NTFS
Drive G: | 338,75 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2015.01.22 14:33:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads\OTL.exe
PRC - [2015.01.22 14:28:36 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\rubyw.exe
PRC - [2015.01.22 14:28:31 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\rubyw.exe
PRC - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe
PRC - [2015.01.17 03:11:45 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015.01.14 05:19:01 | 000,389,744 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2014.12.13 01:13:07 | 002,531,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe
PRC - [2014.10.27 17:37:08 | 003,095,840 | ---- | M] (Nota Inc.) -- C:\Program Files (x86)\Gyazo\GyStation.exe
PRC - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014.06.23 12:35:12 | 000,436,720 | ---- | M] (QIP.ru) -- C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe
PRC - [2014.02.20 21:32:04 | 001,553,688 | ---- | M] (Comfort Software Group) -- C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe
PRC - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2013.08.07 13:24:00 | 000,287,592 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2012.05.20 17:26:26 | 000,291,648 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2015.01.22 14:28:42 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015.01.22 14:28:40 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015.01.22 14:28:40 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015.01.22 14:28:40 | 000,036,352 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
MOD - [2015.01.22 14:28:40 | 000,023,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
MOD - [2015.01.22 14:28:40 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015.01.22 14:28:40 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
MOD - [2015.01.22 14:28:40 | 000,008,192 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
MOD - [2015.01.22 14:28:38 | 000,275,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
MOD - [2015.01.22 14:28:38 | 000,069,120 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
MOD - [2015.01.22 14:28:38 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
MOD - [2015.01.22 14:28:38 | 000,015,360 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
MOD - [2015.01.22 14:28:36 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\libffi-6.dll
MOD - [2015.01.22 14:28:36 | 000,118,784 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
MOD - [2015.01.22 14:28:36 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:36 | 000,083,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\zlib1.dll
MOD - [2015.01.22 14:28:36 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015.01.22 14:28:36 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015.01.22 14:28:36 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015.01.22 14:28:36 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015.01.22 14:28:36 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015.01.22 14:28:36 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015.01.22 14:28:33 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015.01.22 14:28:33 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015.01.22 14:28:33 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:33 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015.01.22 14:28:33 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015.01.22 14:28:33 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015.01.22 14:28:33 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015.01.22 14:28:33 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015.01.22 14:28:33 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015.01.22 14:28:33 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015.01.22 14:28:33 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015.01.22 14:28:32 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\libffi-6.dll
MOD - [2015.01.22 14:28:31 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe
MOD - [2015.01.17 03:11:44 | 003,925,104 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2015.01.14 05:19:02 | 003,347,056 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2015.01.14 05:19:02 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
MOD - [2015.01.14 05:19:02 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
MOD - [2014.11.12 00:38:39 | 000,059,904 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll
MOD - [2014.11.12 00:38:34 | 001,234,944 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll
MOD - [2014.11.12 00:38:34 | 001,198,592 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll
MOD - [2014.11.12 00:38:34 | 000,815,104 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll
MOD - [2014.11.12 00:38:34 | 000,642,048 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll
MOD - [2014.11.12 00:38:34 | 000,511,488 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll
MOD - [2014.11.12 00:38:34 | 000,290,816 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll
MOD - [2014.11.12 00:38:33 | 000,745,472 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll
MOD - [2014.11.12 00:38:32 | 000,344,064 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll
MOD - [2014.11.12 00:38:32 | 000,217,088 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll
MOD - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe
MOD - [2014.11.12 00:38:31 | 000,368,640 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll
MOD - [2014.11.12 00:38:31 | 000,200,704 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll
MOD - [2014.11.12 00:38:31 | 000,180,224 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll
MOD - [2014.09.29 22:25:43 | 001,203,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\ad9facc364268611cc4ca65f77caeddd\System.WorkflowServices.ni.dll
MOD - [2014.09.29 22:25:23 | 001,127,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56\System.ServiceModel.Discovery.ni.dll
MOD - [2014.09.29 22:25:23 | 000,365,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76a5d670ce969c0c65a905b7303d4bbf\System.ServiceModel.Routing.ni.dll
MOD - [2014.09.29 22:25:22 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c3831eb95ccf3904bab81a97a9b08ed3\System.ServiceModel.Channels.ni.dll
MOD - [2014.09.29 22:25:15 | 001,388,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b\System.ServiceModel.Activities.ni.dll
MOD - [2014.09.29 22:25:14 | 001,065,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll
MOD - [2014.09.29 22:25:13 | 017,919,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll
MOD - [2014.09.29 22:25:05 | 001,046,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\51c60db370e050d9cdcac17060aaac53\System.ServiceModel.Web.ni.dll
MOD - [2014.09.29 22:24:11 | 002,625,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll
MOD - [2014.09.29 22:24:11 | 001,011,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll
MOD - [2014.09.29 22:24:11 | 000,142,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba\SMDiagnostics.ni.dll
MOD - [2014.09.29 22:23:53 | 001,776,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll
MOD - [2014.09.29 22:21:37 | 013,006,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll
MOD - [2014.09.29 22:21:32 | 001,651,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll
MOD - [2014.09.29 22:21:04 | 005,571,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll
MOD - [2014.09.29 22:21:02 | 000,973,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll
MOD - [2014.09.29 22:21:01 | 007,025,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll
MOD - [2014.09.29 22:20:57 | 009,000,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll
MOD - [2014.09.29 22:20:54 | 014,415,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll
MOD - [2014.08.10 15:40:22 | 000,065,792 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\TortoiseStub32.dll
MOD - [2014.08.10 15:40:10 | 000,071,936 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\libsasl32.dll
MOD - [2014.06.23 12:35:12 | 000,378,864 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\QipGuard\chrome.dll
MOD - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.12.11 11:00:52 | 000,027,768 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015.01.17 03:11:44 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015.01.14 16:04:13 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014.12.13 01:13:04 | 001,148,560 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV - [2014.12.13 01:13:03 | 019,823,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV - [2014.12.11 10:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014.11.07 13:02:56 | 000,331,776 | ---- | M] () [Auto | Stopped] -- C:\ProgramData\4519DF80.dot -- (Winmgmt)
SRV - [2014.10.14 20:33:28 | 000,174,600 | ---- | M] (Sandboxie Holdings, LLC) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2013.08.27 13:32:30 | 000,828,376 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV - [2013.08.27 13:32:14 | 000,747,520 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2013.08.07 13:24:00 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.11.18 23:05:00 | 000,065,536 | ---- | M] (CodeGear) [Auto | Running] -- C:\Program Files (x86)\Embarcadero\RAD Studio\7.0\bin\BSQLServer.exe -- (BlackfishSQL)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014.11.22 11:46:30 | 000,038,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014.11.05 05:49:12 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2014.09.29 21:27:28 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014.09.17 05:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2013.12.16 09:46:34 | 000,690,864 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2013.10.17 15:27:02 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2013.09.16 11:17:42 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:64bit: - [2013.08.22 09:40:24 | 000,040,664 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2013.08.07 13:23:46 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013.08.07 13:23:46 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2013.07.18 06:54:52 | 000,129,224 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2013.01.03 02:31:20 | 000,301,256 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv)
DRV:64bit: - [2013.01.03 02:31:18 | 000,231,112 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB)
DRV:64bit: - [2012.05.20 17:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012.05.20 17:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012.05.20 17:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2010.03.09 04:08:36 | 000,121,800 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HtcVComV64.sys -- (HtcVCom32)
DRV:64bit: - [2009.11.02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2014.12.13 01:13:03 | 000,019,600 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV - [2014.10.14 20:33:28 | 000,185,352 | ---- | M] (Sandboxie Holdings, LLC) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 6F AD F2 47 00 D0 01  [binary data]
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B6AC85730-7D0F-4de0-B3FA-21142DD85326%7D:2.8
FF - prefs.js..extensions.enabledAddons: %7B9c51bd27-6ed8-4000-a2bf-36cb95c0c947%7D:11.0.1
FF - prefs.js..extensions.enabledAddons: foxyproxy%40eric.h.jung:4.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2014.09.29 20:15:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2014.09.29 20:25:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\f\extensions
[2015.01.18 20:39:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions
[2014.09.29 21:01:58 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2015.01.18 20:39:13 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\foxyproxy@eric.h.jung
[2014.12.09 10:42:07 | 002,551,632 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\firebug@software.joehewitt.com.xpi
[2014.11.08 23:14:43 | 000,080,872 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi
[2015.01.15 14:12:06 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.09.11 16:15:07 | 000,002,438 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\englische-ergebnisse.xml
[2014.09.11 16:15:07 | 000,002,916 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\gmx-suche.xml
[2014.09.11 16:15:07 | 000,002,457 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\lastminute.xml
[2014.09.11 16:15:07 | 000,005,729 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\webde-suche.xml
[2015.01.17 03:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2015.01.17 03:11:45 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2015.01.22 13:05:36 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {2193d8fb-a459-4acc-b40d-5cefd11384dc} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (WebMoneyAdvisorBHO) - {E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O3 - HKLM\..\Toolbar: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O3 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\Toolbar\WebBrowser: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [wmagent.exe] C:\Program Files (x86)\WebMoney Agent\wmagent.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [AdobeBridge]  File not found
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Ditto] C:\Programme\Ditto\Ditto.exe ()
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe (Nota Inc.)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [QIP Internet Guardian] C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe (QIP.ru)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (Sandboxie Holdings, LLC)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([https] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([https] in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE1F8C0-6F4D-4476-8933-97871E5E3032}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) -  File not found
O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) -  File not found
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -  File not found
O20 - HKLM Winlogon: UserInit - (userinit.exe) -  File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) -  File not found
O29 - HKLM SecurityProviders - (credssp.dll) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.07.14 12:08:10 | 000,000,043 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2015.01.22 14:23:35 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015.01.22 14:04:48 | 000,040,664 | ---- | C] (The OpenVPN Project) -- C:\Windows\SysNative\drivers\tap0901.sys
[2015.01.17 03:11:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015.01.14 05:18:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2015.01.10 11:35:17 | 000,000,000 | ---D | C] -- C:\Users\Admin\cminstaller
[2015.01.04 21:44:02 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
[2015.01.04 13:22:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Gyazo
[2015.01.04 13:22:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
[2015.01.04 13:22:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gyazo
[2015.01.03 15:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2014.12.26 16:46:19 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software
[2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Runtime Software
[2014.12.25 19:48:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
[2014.12.25 19:46:27 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft
[2014.11.23 19:08:02 | 000,755,269 | ---- | C] (CheatHappens) -- C:\Users\Admin\coh2-Spike1338.exe
[2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2015.01.22 14:28:30 | 000,001,684 | ---- | M] () -- C:\Windows\tasks\MQJGALU.job
[2015.01.22 14:28:30 | 000,001,340 | ---- | M] () -- C:\Windows\tasks\SYKWCLB.job
[2015.01.22 14:28:30 | 000,001,338 | ---- | M] () -- C:\Windows\tasks\FRVOIK.job
[2015.01.22 14:28:30 | 000,001,336 | ---- | M] () -- C:\Windows\tasks\FWWLD.job
[2015.01.22 14:28:30 | 000,001,334 | ---- | M] () -- C:\Windows\tasks\MQBB.job
[2015.01.22 14:28:30 | 000,001,330 | ---- | M] () -- C:\Windows\tasks\WF.job
[2015.01.22 14:28:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.01.22 14:28:11 | 4261,040,126 | -HS- | M] () -- C:\hiberfil.sys
[2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.01.22 14:04:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.01.22 13:25:50 | 000,001,780 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2015.01.22 13:19:11 | 000,002,008 | -H-- | M] () -- C:\Users\Admin\Documents\Default.rdp
[2015.01.22 13:05:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2015.01.10 14:54:51 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015.01.05 09:41:49 | 001,025,097 | ---- | M] () -- C:\Users\Admin\IMAG0189.jpg
[2015.01.04 21:51:02 | 000,000,842 | ---- | M] () -- C:\Users\Admin\Desktop\uploads.html
[2015.01.04 13:22:42 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk
[2015.01.04 13:22:41 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo.lnk
[2015.01.03 15:23:17 | 000,002,576 | ---- | M] () -- C:\Users\Admin\Documents\Vegas Pro registrieren.htm
[2014.12.29 00:20:24 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.12.27 23:13:26 | 000,092,530 | ---- | M] () -- C:\Users\Admin\click_link.jpg
[2014.12.27 10:42:50 | 000,004,744 | ---- | M] () -- C:\Users\Admin\toprlz.png
[2014.12.27 10:42:50 | 000,000,132 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.12.26 14:42:33 | 395,306,822 | ---- | M] () -- C:\Users\Admin\unbenannt.st3
[2014.12.25 21:21:04 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk
[2014.12.25 21:20:12 | 000,000,621 | ---- | M] () -- C:\Users\Admin\Last session Admin.prj
[2014.12.25 21:20:05 | 000,001,994 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk
[2014.12.25 20:51:45 | 000,000,009 | RHS- | M] () -- C:\wedaolu
[2014.12.25 19:48:34 | 000,001,435 | ---- | M] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk
[2014.12.25 19:48:34 | 000,001,247 | ---- | M] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
[2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 

[2015.01.10 14:54:51 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015.01.05 09:44:32 | 001,025,097 | ---- | C] () -- C:\Users\Admin\IMAG0189.jpg
[2015.01.04 21:51:02 | 000,000,842 | ---- | C] () -- C:\Users\Admin\Desktop\uploads.html
[2015.01.04 13:22:42 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk
[2015.01.04 13:22:41 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo.lnk
[2014.12.27 23:13:24 | 000,092,530 | ---- | C] () -- C:\Users\Admin\click_link.jpg
[2014.12.27 10:42:48 | 000,004,744 | ---- | C] () -- C:\Users\Admin\toprlz.png
[2014.12.26 14:40:02 | 395,306,822 | ---- | C] () -- C:\Users\Admin\unbenannt.st3
[2014.12.26 14:39:05 | 000,000,274 | ---- | C] () -- C:\Users\Admin\DE.reg.x64.reg
[2014.12.25 21:21:04 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk
[2014.12.25 21:20:12 | 000,000,621 | ---- | C] () -- C:\Users\Admin\Last session Admin.prj
[2014.12.25 21:20:05 | 000,001,994 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk
[2014.12.25 20:51:45 | 000,000,009 | RHS- | C] () -- C:\wedaolu
[2014.12.25 19:48:34 | 000,001,435 | ---- | C] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk
[2014.12.25 19:48:34 | 000,001,247 | ---- | C] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
[2014.12.20 12:25:57 | 000,959,853 | ---- | C] () -- C:\Users\Admin\IMAG0188.jpg
[2014.12.07 19:47:33 | 000,007,211 | ---- | C] () -- C:\Users\Admin\postmortem.nfo
[2014.11.17 13:56:11 | 000,607,800 | ---- | C] () -- C:\Users\Admin\fc4-Spike1338.exe
[2014.11.16 13:52:35 | 000,366,592 | ---- | C] () -- C:\Users\Admin\GamersGoMakers_CH.exe
[2014.11.13 21:41:19 | 000,074,488 | ---- | C] () -- C:\Users\Admin\VSa - Advanced Registration.xml
[2014.11.13 00:38:41 | 000,543,289 | ---- | C] () -- C:\Users\Admin\fa15-Spike1338.exe
[2014.11.12 09:38:11 | 000,002,903 | ---- | C] () -- C:\Users\Admin\ucms_update_entries.sql
[2014.11.12 09:38:11 | 000,002,269 | ---- | C] () -- C:\Users\Admin\ucms_update_partners.sql
[2014.11.12 09:38:11 | 000,000,504 | ---- | C] () -- C:\Users\Admin\ucms_update_entry_log.sql
[2014.11.12 09:23:21 | 000,018,613 | ---- | C] () -- C:\Users\Admin\ucms.sql
[2014.11.11 18:42:56 | 000,165,603 | ---- | C] () -- C:\Users\Admin\VSa_AFStats.xml
[2014.11.11 14:27:23 | 000,013,172 | ---- | C] () -- C:\Users\Admin\logo.png
[2014.11.11 14:23:56 | 000,000,326 | ---- | C] () -- C:\Users\Admin\primus-slate-fluid.xml
[2014.11.11 14:22:43 | 000,879,411 | ---- | C] () -- C:\Users\Admin\primus-slate-forum.xml
[2014.11.11 14:20:05 | 000,000,306 | ---- | C] () -- C:\Users\Admin\primus-blue-fluid.xml
[2014.11.11 12:28:32 | 000,221,639 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fixed.xml
[2014.11.11 12:28:32 | 000,221,635 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fluid.xml
[2014.11.10 22:52:23 | 000,028,925 | ---- | C] () -- C:\Users\Admin\functions.php
[2014.11.10 20:11:44 | 000,001,780 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2014.11.10 16:13:23 | 025,570,303 | ---- | C] () -- C:\Users\Admin\gezload_main-DB-11.1.08.sql
[2014.11.10 16:09:58 | 000,005,508 | ---- | C] () -- C:\Users\Admin\evo_beatz.sql
[2014.11.09 00:48:24 | 000,000,026 | ---- | C] () -- C:\Windows\Ditto.INI
[2014.11.07 13:02:56 | 000,331,776 | ---- | C] () -- C:\ProgramData\4519DF80.dot
[2014.11.05 06:37:59 | 000,000,612 | ---- | C] () -- C:\Users\Admin\index.html
[2014.11.03 22:31:53 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.10.25 10:20:53 | 002,594,031 | ---- | C] () -- C:\Users\Admin\WinRAR.rar
[2014.10.24 21:06:45 | 000,000,553 | ---- | C] () -- C:\Windows\eReg.dat
[2014.10.05 21:37:25 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen
[2014.10.05 20:56:03 | 000,089,432 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2014.10.02 15:44:19 | 000,048,644 | ---- | C] () -- C:\Users\Admin\warezking.in_xml.xml
[2014.09.29 20:29:44 | 000,000,024 | ---- | C] () -- C:\Windows\SetupTemp.ini
[2014.09.29 20:28:48 | 001,186,161 | ---- | C] () -- C:\Windows\unins000.exe
[2014.09.29 20:28:48 | 000,001,134 | ---- | C] () -- C:\Windows\unins000.dat
[2014.09.29 20:24:08 | 001,591,716 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\WF
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\SYKWCLB
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FWWLD
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQJGALU
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQBB
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FRVOIK
[2013.11.16 13:39:18 | 000,063,852 | ---- | C] () -- C:\Users\Admin\index.php
[2013.08.27 13:00:08 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2013.03.21 05:10:16 | 000,042,880 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010.08.11 16:06:39 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010.08.11 16:06:39 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2015.01.22 13:19:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\.purple
[2014.11.07 10:53:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Affilorama
[2014.11.02 00:25:46 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CodeGear
[2015.01.22 13:28:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2014.12.25 19:48:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft
[2014.10.27 01:54:55 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\EasySetup
[2014.11.02 00:09:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Embarcadero
[2015.01.22 13:28:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FileZilla
[2015.01.04 13:25:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Gyazo
[2014.11.06 11:53:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\HTC
[2014.11.08 16:11:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai
[2014.11.08 16:11:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2014.11.10 12:18:40 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MyImgur
[2014.10.03 11:02:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Notepad++
[2014.10.27 01:49:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Opera Software
[2014.10.05 21:25:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PDAppFlex
[2014.11.16 16:39:36 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Publish Providers
[2014.10.02 13:49:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QIP
[2014.10.02 13:49:32 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QipGuard
[2014.12.21 13:42:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QuickScan
[2015.01.03 15:16:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Sony
[2014.11.07 10:38:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Spiritsoft
[2014.09.30 13:01:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Steam
[2014.11.02 00:24:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Subversion
[2014.09.29 20:27:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thunderbird
[2014.11.12 00:42:59 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Titanium
[2014.11.07 10:54:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Traffic Travis v4
[2014.11.05 16:02:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TrueCrypt
[2014.11.07 16:01:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\UBot Studio
[2015.01.22 13:06:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WebMoney
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A064CECC
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:41ADDB8A

< End of report >
         

 

Themen zu BKA Virus Windows zerschossen
adobe, autorun, bho, bootmgr, dll, entfernen, explorer, firefox, flash player, format, geforce, helper, logfile, mozilla, neustart, nvidia, opera, registry, rundll, scan, software, temp, usb, virus, windows, windows probleme




Ähnliche Themen: BKA Virus Windows zerschossen


  1. Windows 8.1 nach Programminstallation komplett zerschossen
    Log-Analyse und Auswertung - 14.03.2015 (13)
  2. Windows zerschossen durch Virenscanner-Update
    Antiviren-, Firewall- und andere Schutzprogramme - 20.11.2014 (3)
  3. Malwarebytes zerschossen
    Plagegeister aller Art und deren Bekämpfung - 23.07.2014 (9)
  4. PC bei Installation zerschossen
    Alles rund um Mac OSX & Linux - 26.07.2012 (6)
  5. PC bei Installation zerschossen
    Netzwerk und Hardware - 17.06.2012 (1)
  6. Windows Installer beschädigt? Zerschossen?
    Alles rund um Windows - 24.03.2012 (4)
  7. GEMA-Virus hat einige Einträge meiner Registry zerschossen
    Log-Analyse und Auswertung - 19.02.2012 (1)
  8. Mainboard Samsung NP-NC 10 zerschossen
    Alles rund um Windows - 26.11.2011 (4)
  9. Netbook: explorer.exe zerschossen?
    Alles rund um Windows - 06.05.2010 (1)
  10. Outlook zerschossen - Spoofing.gen
    Log-Analyse und Auswertung - 25.01.2010 (3)
  11. kann keine .exe-Dateien mehr öffnen, registry von virus zerschossen!?
    Log-Analyse und Auswertung - 09.04.2009 (1)
  12. XP zerschossen, boild_tmp , Virus oder Board
    Log-Analyse und Auswertung - 30.03.2009 (0)
  13. Rechner zerschossen?
    Plagegeister aller Art und deren Bekämpfung - 01.04.2008 (9)
  14. probleme - sys zerschossen -
    Alles rund um Windows - 14.01.2006 (19)
  15. Spybot S & D zerschossen?
    Antiviren-, Firewall- und andere Schutzprogramme - 10.12.2005 (6)
  16. Master Boot Record zerschossen?
    Alles rund um Mac OSX & Linux - 11.02.2004 (2)
  17. HILFE! MS DOS zerschossen!!!
    Archiv - 19.01.2003 (24)

Zum Thema BKA Virus Windows zerschossen - Hatte diesen BKA Virus auf dem Rechner welchen ich schnell mit Malewarebytes entfernen konnte aber nun macht Windows Probleme erst war der BootMGR gelöscht welchen ich mit der Windows CD - BKA Virus Windows zerschossen...
Archiv
Du betrachtest: BKA Virus Windows zerschossen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.