Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Trojaner/Virus sbcvvhost_win86 behindert Zugriff auf Windows in allem Modi (https://www.trojaner-board.de/106898-trojaner-virus-sbcvvhost_win86-behindert-zugriff-windows-allem-modi.html)

Doppelgrunz 26.12.2011 01:14

Trojaner/Virus sbcvvhost_win86 behindert Zugriff auf Windows in allem Modi
 
Liebes Trojaner-Board,

ich habe, wie mittlerweile einige andere hier im Forum das Problem, dass mein Windows 7 komplett lahmgelegt wird. Da die Symptome ähnlich sind wie die von anderen hier beschriebenen (z.B., grauer Bildschirm nach booten mit der Message "Es besteht noch keine Internetverbindung, bitte warten"; task manager ist nicht aufrufbar, und wenn man den Computer runterfahren will kommt die Nachricht, dass der sbcvvhost_win86 Prozess das herunterfahren verhindert, starten im abgesicherten modus ergibt das gleiche Ergebnis und die registry ist blockiert...), bin ich mir relativ sicher, dass es sich um einen Trojaner handelt. Ich habe alle Einträge dazu hier im Forum gelesen und die log-files Extras.txt und OTL.txt nach einer abenteuerlichen aber erfolgreichen Reise durch die anderen Posts erstellt (Danke an dieser Stelle an die ausfürlichen Erklärungen, die es sogar einem Laien wie mir ermöglichen diese Schritte durchzuführen!!). Diese sind unten angeführt.

Wichtig ist noch zu erwähnen, dass ich mir diesen Trojaner eingefangen habe, als ich auf einer russischen Seite war (keine Ahnung ob das etwas über den Ursprung des Trojaners sagt) und dass mein Freeware Avira diesen Trojaner nicht entdeckt hat, Zonealarm allerdings fragte ob ich den Internetzugang dieses Programmes zulassen will (was ich natürlich verneint habe...danach kam sofort der graue Bildschirm), und dass die Rescue Disk von Kaspersky, die ich gestern zu Weihnachten geschenkt bekommen habe, zwar zwei weitere Trojaner gefunden hat (beide hatten mit Java zu tun), diesen sbcvvhost_win86 allerdings nicht. Wenn ich die Posts hier im Forum richtig deute, ist das sowieso ein sehr neuer Trojaner, auf den Kaspersky eventuell noch nicht reagiert hat (bevor ich den Virenscan über die Rescue Disc gemacht habe hatte ich alle Updates runtergeladen). Also, es scheint ein Problem zu sein dass noch wächst, und nur hier im Forum habe ich Hoffnung gefunden, dass ich meinen Computer noch retten kann und nicht format C: machen muss...

Hier die logfiles. Ich hoffe sehr dass ihr mir helfen könnt!

Danke im vorraus!

Extras.txt:

Code:



OTL Extras logfile created on: 12/26/2011 12:19:05 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.76 Gb Total Space | 359.27 Gb Free Space | 77.14% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet002
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\PPStream\PPStream.exe" = C:\Program Files (x86)\PPStream\PPStream.exe:*:Enabled:PPSÍøÂçµçÊÓ -- (PPStream Inc.)
"C:\Program Files (x86)\PPStream\PPSAP.exe" = C:\Program Files (x86)\PPStream\PPSAP.exe:*:Enabled:PPS ÍøÂç¼ÓËÙÆ÷ -- (PPStream Inc)
"C:\Program Files (x86)\PPStream\PPStream.exe" = C:\Program Files (x86)\PPStream\PPStream.exe:*:Enabled:PPSÍøÂçµçÊÓ -- (PPStream Inc.)
"C:\Program Files (x86)\PPStream\PPSAP.exe" = C:\Program Files (x86)\PPStream\PPSAP.exe:*:Enabled:PPS ÍøÂç¼ÓËÙÆ÷ -- (PPStream Inc)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\garry_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
< End of report >

OTL.txt

Code:

OTL logfile created on: 12/26/2011 12:19:05 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.76 Gb Total Space | 359.27 Gb Free Space | 77.14% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet002
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Application Updater) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (vsmon) -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) @C:\Program Files (x86) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (PLFlash DeviceIoControl Service) -- C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (ISWKL) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) Logitech Webcam 200(UVC) -- C:\Windows\System32\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) -- C:\Windows\System32\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (Vsdatant) -- C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (Ntfs) -- C:\Windows\System32\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) -- C:\Windows\System32\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\system32\DRIVERS\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\System32\drivers\b57nd60a.sys (Broadcom Corporation)
DRV - (Vsdatant) -- C:\Windows\SysWOW64\drivers\vsdatant.sys (Check Point Software Technologies LTD)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 E8 9F CC 86 75 CC 01  [binary data]
IE - HKU\garry_ON_C\..\URLSearchHook: {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - Reg Error: Key error. File not found
IE - HKU\garry_ON_C\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - Reg Error: Key error. File not found
IE - HKU\garry_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=386496&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:5.1
FF - prefs.js..extensions.enabledItems: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.232.0
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF64_11_1_102.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011/08/26 18:45:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/08/21 03:59:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/04 08:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/30 15:42:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010/04/02 10:57:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2010/04/02 10:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\Mozilla\Extensions
[2010/04/02 10:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/12/17 21:46:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions
[2010/03/20 14:42:16 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011/12/16 17:51:17 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011/11/06 08:08:33 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2010/04/25 07:13:38 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/11/06 08:07:55 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011/12/17 21:46:25 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}
[2011/03/26 19:43:53 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2011/06/25 12:34:58 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com
[2010/03/20 14:38:15 | 000,000,000 | ---D | M] (Prism for Firefox) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org
[2011/07/05 12:05:16 | 000,000,000 | ---D | M] (Nero Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com
[2010/06/14 17:31:50 | 000,000,943 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\conduit.xml
[2011/11/06 08:07:58 | 000,003,915 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\SweetIM Search.xml
[2011/11/06 08:07:49 | 000,003,915 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\sweetim.xml
[2010/03/21 04:59:22 | 000,001,196 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\winamp-search.xml
[2011/12/04 08:09:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/05 13:31:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/05/14 13:05:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
File not found (No name found) --
[2011/12/04 08:09:03 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM
[2011/11/06 08:14:31 | 000,000,000 | ---D | M] (FreeRIP Toolbar) -- C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF
() (No name found) -- C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/12/04 08:09:02 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/08/05 12:19:00 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/13 17:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011/10/03 09:20:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/10/03 09:20:53 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/10/03 09:20:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/10/03 09:20:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/10/03 09:20:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/10/03 09:20:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll (PriceGong)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3:64bit: - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm-Sicherheit Toolbar) - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [WBhXTAWuFpmNyON] C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKU\garry_ON_C..\Run: [{AC438F5B-8F71-9645-E9E6-312C38A5E9A0}]  File not found
O4 - HKU\garry_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\garry_ON_C..\Run: [PPS Accelerator] C:\Program Files (x86)\PPStream\PPSAP.exe (PPStream Inc)
O4 - HKU\garry_ON_C..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKU\garry_ON_C..\Run: [WBhXTAWuFpmNyON] C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O4 - HKU\LocalService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin]  File not found
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin]  File not found
O4 - Startup: C:\Users\garry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PPS.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\garry_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\garry_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\garry_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8:64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe) - C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKU\garry_ON_C Winlogon: Shell - (C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe) - C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell\AutoRun\command - "" = E:\TmUnitedForever_Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/12/25 11:12:00 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2011/12/25 00:56:01 | 000,095,744 | ---- | C] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011/12/25 00:53:27 | 000,344,064 | ---- | C] (JqItwY) -- C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe
[2011/12/25 00:33:32 | 000,000,000 | ---D | C] -- C:\Users\garry\AppData\Roaming\Coew
[2011/12/25 00:33:32 | 000,000,000 | ---D | C] -- C:\Users\garry\AppData\Roaming\Cayvr
[2011/12/18 14:36:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2011/12/16 16:38:47 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011/12/16 16:38:27 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/12/16 16:38:27 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011/12/16 16:38:27 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/12/16 16:38:26 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/12/16 16:38:26 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/12/16 16:38:26 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/12/16 16:38:26 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2011/12/16 16:38:26 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 16:37:51 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/12/16 16:37:51 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/12/25 16:40:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/25 15:21:48 | 000,010,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/25 15:21:48 | 000,010,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/25 15:18:48 | 000,658,988 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011/12/25 15:18:48 | 000,620,174 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/25 15:18:48 | 000,132,558 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011/12/25 15:18:48 | 000,108,356 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/25 15:14:22 | 2566,365,184 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/25 00:56:01 | 000,095,744 | ---- | M] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011/12/25 00:53:26 | 000,344,064 | ---- | M] (JqItwY) -- C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe
[2011/12/18 14:38:07 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/16 21:19:39 | 000,388,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/04 08:14:53 | 000,002,056 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/11/06 08:15:03 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011/11/03 20:44:17 | 000,000,086 | ---- | C] () -- C:\Users\garry\AppData\default.pls
[2011/06/24 10:17:55 | 000,252,928 | ---- | C] () -- C:\Windows\SysWow64\DShowRdpFilter.dll
[2011/02/20 09:38:17 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2011/02/20 09:38:17 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2011/02/20 09:38:17 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2011/02/20 07:56:20 | 000,027,266 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2011/02/13 14:33:57 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2011/02/13 14:33:57 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2010/11/09 20:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010/11/09 20:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2010/11/09 20:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010/04/02 10:46:26 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/03/20 14:02:21 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2007/04/27 03:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
 
========== LOP Check ==========
 
[2011/12/25 00:47:48 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Cayvr
[2010/03/20 12:11:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\CheckPoint
[2010/05/23 06:05:28 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ChessBase
[2011/12/25 14:42:20 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Coew
[2010/04/17 16:04:43 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\DAEMON Tools Lite
[2011/02/14 02:17:23 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\FinalMediaPlayer
[2010/12/22 17:49:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2011/04/25 15:09:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\MAGIX
[2011/03/27 15:05:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\NCH Swift Sound
[2011/12/24 21:52:33 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ppstream
[2011/07/25 11:12:19 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ReactGames
[2010/04/02 10:57:37 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Thunderbird
[2010/03/20 07:14:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2010/04/18 12:03:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2010/03/20 12:10:50 | 000,000,000 | ---D | M] -- C:\ProgramData\CheckPoint
[2010/03/20 16:10:08 | 000,000,000 | ---D | M] -- C:\ProgramData\ChessBase
[2010/04/17 16:04:50 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2010/03/20 07:14:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2010/03/20 07:14:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011/11/06 08:14:42 | 000,000,000 | ---D | M] -- C:\ProgramData\FreeRIP
[2011/04/25 15:09:22 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX
[2010/05/16 05:24:50 | 000,000,000 | ---D | M] -- C:\ProgramData\NCH Swift Sound
[2011/02/13 15:26:19 | 000,000,000 | ---D | M] -- C:\ProgramData\SafeNet Sentinel
[2011/02/13 14:35:06 | 000,000,000 | ---D | M] -- C:\ProgramData\SPSS
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2010/03/20 07:14:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2010/05/08 16:48:26 | 000,000,000 | ---D | M] -- C:\ProgramData\TrackMania
[2010/03/20 07:14:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/03/27 04:22:23 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2010/04/25 07:15:45 | 000,000,000 | ---D | M](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式
[2010/04/25 07:15:45 | 000,000,000 | ---D | C](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式
< End of report >


cosinus 26.12.2011 01:19

Zitat:

Wichtig ist noch zu erwähnen, dass ich mir diesen Trojaner eingefangen habe, als ich auf einer russischen Seite war
Was für eine russische Seite, welchem Zweck diente die und was hast du da gemacht? Einfach nur die Seite besucht oder doch etwas mehr?

Zitat:

Zonealarm allerdings fragte ob ich den Internetzugang dieses Programmes zulassen will
ZoneAlarm ist kontraproduktiver Nonsens...

Doppelgrunz 26.12.2011 01:29

Die genaue URL der russische Seite weiss ich nicht mehr, aber es ging dabei um einen Sport-Live-stream, und ich wurde dorthin weitergeleitet ohne hin zu wollen.

Und ja, ZA ist wirklich eine Sache die ich nicht empfehlen kann.

PS. Ich sehe gerade, dass ich eventuell mein Thema in dem Plagegeisterforum hätte posten sollen... ist das schlimm dass es jetzt hier bei Log-Analyse ist?

cosinus 26.12.2011 01:37

Nein in diesem Bereich ist es auch ok.
Was genau gefunden wurde hast du natürlich nicht mehr in Erinnerung oder hast gar die Logs gespeichert?

Doppelgrunz 26.12.2011 01:47

Du meinst, welche beiden Trojaner von der Rescue Disc gefunden wurden, oder? Ich weisst nicht, ob die vielleicht automatisch gespeichert wurden. Wenn Du mir sagst wie ich das herausfinde kann ich gerne mal nachschauen. Als der Virenscan durch war, habe ich sofort neugestartet mit der Hoffnung jetzt sei das Problem behoben... daher habe ich nichts selber abgespeichert...

cosinus 26.12.2011 01:57

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Doppelgrunz 26.12.2011 02:27

Hm, ich habe jetzt Malwarebytes heruntergeladen und versucht zu installieren. Ich sollte Dir vielleicht sagen, dass ich mich die ganze Zeit auf eurem REATOGO-X-PE befinde (da ja Windows nicht mehr geht), und auf einem separaten Laptop alle downloads mache (sowie hier meine Messages zu posten). Auf jeden Fall habe ich Schwierigkeiten, nach der Installation Malwarebytes zu starten... die Updates kann ich noch herunterladen, aber das Programm wird nicht ausgeführt. Ich habe schon gecheckt, ob vielleicht andere Programme im Hintergrund laufen, die dies verhindern könnten... allerdings im task manager nichts gefunden was sonst noch an wäre. Da ich auf REATOGO-X-PE bin, gehe ich auch davon aus, dass keine meiner Antivirenprogramme gerade an ist.

Kannst Du mir einen Tipp geben, wie ich weitermachen soll? Danke!

Ich habe nun auch den ESET Test versucht durchzuführen mit dem Explorer (portable Firefox scheint nicht zu funktionieren). Schon bei Step 2 out of 4 (Downloading virus signature database) bekomme ich bei 95% eine Fehlermeldung "Cannot get update. Is proxy configured?". Wie schon eingangs erwähnt habe ich nicht besonders gute Kenntnisse von Computern, kann also mit dieser Fehlermeldung wenig anfangen. Aber nochmal die Frage: Macht es einen Unterschied, dass ich Malwarebytes und ESET von REATOGO-X-PE ausführen will? Kann mir gut vorstellen, dass es unter Windows keine Probleme geben würde.... aber genau das funktioniert ja nicht mehr.

In einigen der anderen Threats mit dem selben Problem wie ich habt ihr den Usern einen fix geschickt nachdem die die Extras.txt und OTL.txt geschickt haben. Wäre das bei mir auch möglich, oder sehe ich das zu kurzsichtig?

cosinus 26.12.2011 04:07

Zitat:

Ich sollte Dir vielleicht sagen, dass ich mich die ganze Zeit auf eurem REATOGO-X-PE befinde (da ja Windows nicht mehr geht)
Nee sry in der Live-CD geht das auch nicht, sry :headbang:

Mach einen OTL-Fix über OTLPE, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
SRV - (Application Updater) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 E8 9F CC 86 75 CC 01  [binary data]
IE - HKU\garry_ON_C\..\URLSearchHook: {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - Reg Error: Key error. File not found
IE - HKU\garry_ON_C\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=386496&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..keyword.URL: "http://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p="
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011/08/26 18:45:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/08/21 03:59:15 | 000,000,000 | ---D | M]
[2010/03/20 14:42:16 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011/11/06 08:08:33 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2010/04/25 07:13:38 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/11/06 08:07:55 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011/12/17 21:46:25 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}
[2011/06/25 12:34:58 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com
[2011/07/05 12:05:16 | 000,000,000 | ---D | M] (Nero Toolbar) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com
[2010/06/14 17:31:50 | 000,000,943 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\conduit.xml
[2011/11/06 08:07:58 | 000,003,915 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\SweetIM Search.xml
[2011/11/06 08:07:49 | 000,003,915 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\sweetim.xml
[2010/03/21 04:59:22 | 000,001,196 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\winamp-search.xml
[2011/11/06 08:14:31 | 000,000,000 | ---D | M] (FreeRIP Toolbar) -- C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF
() (No name found) -- C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2010/01/13 17:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll (PriceGong)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3:64bit: - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\garry_ON_C\..\Toolbar\WebBrowser: (ZoneAlarm-Sicherheit Toolbar) - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll (Conduit Ltd.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [WBhXTAWuFpmNyON] C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\garry_ON_C..\Run: [{AC438F5B-8F71-9645-E9E6-312C38A5E9A0}]  File not found
O4 - HKU\garry_ON_C..\Run: [WBhXTAWuFpmNyON] C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin]  File not found
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin]  File not found
O4 - Startup: C:\Users\garry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PPS.lnk ()
O20 - HKLM Winlogon: Shell - (C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe) - C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O20 - HKU\garry_ON_C Winlogon: Shell - (C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe) - C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe (JqItwY)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell\AutoRun\command - "" = E:\TmUnitedForever_Setup.exe
:Files
C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe
C:\Users\garry\AppData\Roaming\Coew
C:\Users\garry\AppData\Roaming\Cayvr
C:\Program Files (x86)\Application Updater
C:\Program Files (x86)\Ask.com
C:\Program Files (x86)\PriceGong
C:\Program Files (x86)\Winamp Toolbar
C:\Program Files (x86)\FreeRIP Toolbar
C:\Program Files (x86)\DAEMON Tools Toolbar
:Commands
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Danach sollte Windows wieder normal starten - stell uns bitte den Quarantäneordner von OTL zur Verfügung. Dabei bitte so vorgehen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinträchtigen!
2.) Ordner movedfiles in C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html
4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Doppelgrunz 27.12.2011 05:06

Super, der Fix hat gewirkt! Nachdem ich den Fix über OTLPE habe laufen lassen, startet Windows jetzt wieder normal. Den gewünschten MovedFiles Ordner habe ich hochgeladen. Allerdings habe ich folgende Veränderungen gemerkt:

1. Mein Desktop ist leergespült und ich kann die Daten, die darauf waren, nicht mehr finden.

2. Wenn ich den TaskManager starten will, erhalte ich die Nachricht, dass der Task-Manager vom Administrator gesperrt wurde.

Kannst Du mir bitte sagen, wie ich den Taskmanager entsperren kann? Und falls meine Desktopdaten nicht gelöscht wurden, wäre es gut, diese wiederfinden zu können.

Aber mal ganz angesehen von diesen beiden Kleinigkeiten, möchte ich Dir (und allen anderen Leuten bei Trojaner-Board) ganz herzlich danken! Ich hatte mich schon damit abgefunden, dass der Trojaner meinen Rechner fertiggemacht hat und ich alles nochmal neu installieren muss. Eure Arbeit hier ist fantastisch, sowohl von der Qualität, der Kommunikation, dem Timing, und dem unermüdlichen Einsatz! :daumenhoc Wenn Du mehr rausfinden solltest über "meinen" Trojaner, würde ich mich freuen von Dir zu hören. Ach ja, und wenn du die beiden Fragen oben noch beantworten könntest wäre das super. Du kannst mir weiterhin auch sagen, was ich jetzt mit dem Quarantäneordner OTL machen soll. Ein Antivir-Check hat gerade nichts gefunden....

PS. Du hattest gesagt, dass ein logfile erscheinen soll nachdem der OTLPE Fix gemacht wurde. Dem war nicht so. Allerdings befindet sich eine logfile in dem MovedFiles order. So schaut sie aus:

Code:

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Application Updater deleted successfully.
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\garry_ON_C\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E634228A-03CF-4BC8-B0AB-668257F1FD8C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ deleted successfully.
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ deleted successfully.
Prefs.js: "Yahoo" removed from browser.search.defaultenginename
Prefs.js: "chr-greentree_ff&type=386496&ilc=12" removed from browser.search.param.yahoo-fr
Prefs.js: "Yahoo" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p=" removed from keyword.URL
Prefs.js: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=386496&p=" removed from sweetim.toolbar.previous.keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\MozillaPlugins\@checkpoint.com/FFApi\ deleted successfully.
File C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll () not found.
File HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker not found.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\modules folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\components folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\skin folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale\en-US folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\locale folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome\content folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\META-INF folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\META-INF folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\components folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\skin folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\nl-NL folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\it-IT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\fr-FR folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\es-ES folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\en-US folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\de-DE folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\content folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\searchplugin folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\modules folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\META-INF folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\defaults folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\components folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com\components\Resources folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com\components folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com\chrome\content folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\DTToolbar@toolbarnet.com folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\searchplugins folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\logs folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\defaults\preferences folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\defaults folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\datastore folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sun-27-Jun-2010-12-57-41-GMT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sun-14-Nov-2010-12-19-41-GMT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sat-13-Nov-2010-00-09-21-GMT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sat-03-Apr-2010-07-51-12-GMT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Fri-25-Mar-2011-13-11-28-GMT folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\temp folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\skin folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome\content folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com\chrome folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\toolbar@ask.com folder moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\conduit.xml moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\SweetIM Search.xml moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\sweetim.xml moved successfully.
C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\searchplugins\winamp-search.xml moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF\chrome\skin folder moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF\chrome\locale\EN-US folder moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF\chrome\locale folder moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF\chrome\content folder moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF\chrome folder moved successfully.
C:\PROGRAM FILES (X86)\FREERIP TOOLBAR\FF folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
C:\Program Files (x86)\Winamp Toolbar\winamptb.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ not found.
C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found.
C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully.
File C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{E634228A-03CF-4BC8-B0AB-668257F1FD8C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ not found.
File C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.
File C:\Program Files (x86)\Winamp Toolbar\winamptb.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully.
File C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found.
File Sicherheit\tbZone.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
File C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL not found.
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}\ not found.
File C:\Program Files (x86)\Winamp Toolbar\winamptb.dll not found.
64bit-Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.
File C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll not found.
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.
File C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll not found.
Registry value HKEY_USERS\garry_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC2B76FC-2132-4D80-A9A3-1F5C6E49066B}\ not found.
File Sicherheit\tbZone.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\WBhXTAWuFpmNyON deleted successfully.
C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
C:\Program Files (x86)\Winamp\winampa.exe moved successfully.
Registry key HKEY_USERS\garry_ON_C\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC438F5B-8F71-9645-E9E6-312C38A5E9A0}\ not found.
Registry key HKEY_USERS\garry_ON_C\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found.
File C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe not found.
Registry key HKEY_USERS\LocalService_ON_C\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found.
Registry key HKEY_USERS\NetworkService_ON_C\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found.
C:\Users\garry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PPS.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe deleted successfully.
File C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe not found.
Registry value HKEY_USERS\garry_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe deleted successfully.
File C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe not found.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File move failed. X:\AUTORUN.INF scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
File F:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
File E:\TmUnitedForever_Setup.exe not found.
========== FILES ==========
File\Folder C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe not found.
C:\Users\garry\AppData\Roaming\Coew folder moved successfully.
C:\Users\garry\AppData\Roaming\Cayvr folder moved successfully.
C:\Program Files (x86)\Application Updater folder moved successfully.
C:\Program Files (x86)\Ask.com\Updater folder moved successfully.
C:\Program Files (x86)\Ask.com\assets\oobe folder moved successfully.
C:\Program Files (x86)\Ask.com\assets folder moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
C:\Program Files (x86)\PriceGong\2.5.1 folder moved successfully.
C:\Program Files (x86)\PriceGong folder moved successfully.
C:\Program Files (x86)\Winamp Toolbar folder moved successfully.
C:\Program Files (x86)\FreeRIP Toolbar\Res\Lang folder moved successfully.
C:\Program Files (x86)\FreeRIP Toolbar\Res folder moved successfully.
C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7 folder moved successfully.
C:\Program Files (x86)\FreeRIP Toolbar\IE folder moved successfully.
C:\Program Files (x86)\FreeRIP Toolbar folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTLPE by OldTimer - Version 3.1.48.0 log created on 12272011_040919


cosinus 27.12.2011 16:47

Probier bitte jetzt nochmal Malwarebytes und ESET aus

Doppelgrunz 30.12.2011 05:39

Lieber Arne,

nach 2 Tagen ohne Internet bin ich jetzt bereit, den Kampf gegen den Trojaner mit aller Entschlossenheit wieder aufzunehmen! Ich habe die beiden Scans mit Malwarebytes und ESET erfolgreich durchgeführt und werde sie hier posten. Wie Du sehen kannst, wurden mehrere Dinge gefunden, und unser Freund sbcvvhost_win86 war auch dabei. Danach habe ich alles entfernt und den ESET test durchgeführt. Der hat dann noch viel mehr gefunden... am besten Du schaust es Dir mal an. Und wie gesagt, ich würde mich freuen wenn Du mich ein wenig in die Suche einweihen könntest. Wie geht es weiter? Wird mein Computer wieder normal funktionieren? Wie bekomme ich die Administratorrechte vom Task Manager wieder zurück? Ich habe in einem anderen Thread gelesen dass das auch mit einem OTL-Fix geht. Kannst Du mir den schicken?

Vielen Dank!

Hier die log von Malwarebytes:
Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2011.12.30.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
garry :: LARRY [Administrator]

Schutz: Aktiviert

30.12.2011 03:07:21
mbam-log-2011-12-30 (03-07-21).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 377000
Laufzeit: 45 Minute(n), 10 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6ScJzIf0-kevt-RkjF-pr7R-UIAZ3ihJ5KXN} (Backdoor.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 4
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Hijack.Shell.Gen) -> Daten: C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{AC438F5B-8F71-9645-E9E6-312C38A5E9A0} (Trojan.ZbotR.Gen) -> Daten: C:\Users\garry\AppData\Roaming\Coew\coro.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WBhXTAWuFpmNyON (Trojan.Agent) -> Daten: C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WBhXTAWuFpmNyON (Trojan.Agent) -> Daten: C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 5
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|HideIcons (PUM.Hidden.Desktop) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDesktop (PUM.Hidden.Desktop) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Hijack.Shell.Gen.A) -> Bösartig: (C:\Users\garry\AppData\Roaming\sbcvvhost_win86.exe) Gut: (Explorer.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Users\garry\AppData\Local\Temp\0.5954754544611864.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\garry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\57650353-7b4afd00 (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\12272011_040919\C_Users\garry\AppData\Roaming\sbcvvhost_win86.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Und hier die log von ESET:
Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=35f9a08f42ac7f40949d4756a8bcd331
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-30 04:23:46
# local_time=2011-12-30 05:23:46 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1797 16775165 100 94 0 61754917 1103 0
# compatibility_mode=5893 16776573 100 94 0 76844311 0 0
# compatibility_mode=8192 67108863 100 0 3879 3879 0 0
# compatibility_mode=9217 16777214 75 66 11297271 27175163 0 0
# scanned=215441
# found=18
# cleaned=0
# scan_time=4565
C:\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\Local\Temp\NERO14992\Toolbar.exe        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\358d72cc-4ecd8dc1        Java/Exploit.CVE-2011-3544.L trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\150cad71-34025faa        Java/Exploit.CVE-2011-3544.L trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\freeripmp3.61-setup.exe        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SoftonicDownloader_fuer_magix-mp3-maker.exe        a variant of Win32/SoftonicDownloader.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\40094e8.msi        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Application Updater\ApplicationUpdater.exe        probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I


cosinus 30.12.2011 18:27

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Doppelgrunz 30.12.2011 21:41

Okay, habe den Scan mit OTL nochmal durchgeführt und poste die log files jetzt hier:

OTL:
Code:

OTL logfile created on: 30.12.2011 21:10:09 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\garry\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,19 Gb Total Physical Memory | 2,32 Gb Available Physical Memory | 72,87% Memory free
6,37 Gb Paging File | 4,90 Gb Available in Paging File | 76,83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 359,46 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
 
Computer Name: LARRY | User Name: garry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\garry\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\PPStream\PPSAP.exe (PPStream Inc)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (vsmon) -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (PLFlash DeviceIoControl Service) -- C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) Logitech Webcam 200(UVC) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) -- C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (Vsdatant) -- C:\Windows\SysNative\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (ISWKL) -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) -- C:\Windows\SysWOW64\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\InprocServer32 File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 E8 9F CC 86 75 CC 01  [binary data]
IE - HKCU\..\URLSearchHook: {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\InprocServer32 File not found
IE - HKCU\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\InprocServer32 File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:5.1
FF - prefs.js..extensions.enabledItems: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.232.0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011.08.27 00:45:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011.08.21 09:59:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.12.04 14:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.30 21:42:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010.04.02 16:57:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2010.04.02 16:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Extensions
[2010.04.02 16:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.12.30 02:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions
[2011.12.16 23:51:17 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011.03.27 01:43:53 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2010.03.20 20:38:15 | 000,000,000 | ---D | M] (Prism for Firefox) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org
[2011.12.30 04:00:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.11.05 19:31:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.05.14 19:05:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) -- C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.12.04 14:09:02 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.05 18:19:00 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.03 15:20:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.03 15:20:53 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.10.03 15:20:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.03 15:20:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.03 15:20:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.03 15:20:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.12.27 10:09:35 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll File not found
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O2 - BHO: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll File not found
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm-Sicherheit Toolbar) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm-Sicherheit Toolbar) - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - C:\Program Files (x86)\ZoneAlarm-Sicherheit\tbZone.dll File not found
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" File not found
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PPS Accelerator] C:\Program Files (x86)\PPStream\ppsap.exe (PPStream Inc)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8:64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E43CC620-6F4B-4BDA-B0E3-BD4F1A83D927}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell\AutoRun\command - "" = E:\TmUnitedForever_Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: vsmon - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.30 04:03:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.30 03:03:00 | 000,000,000 | ---D | C] -- C:\Users\garry\AppData\Roaming\Malwarebytes
[2011.12.30 03:00:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.30 03:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.12.30 03:00:23 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.12.30 03:00:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.27 10:09:33 | 002,237,440 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe
[2011.12.27 10:09:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.26 08:10:53 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware
[2011.12.26 07:43:32 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.12.25 17:12:00 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2011.12.25 06:56:01 | 000,095,744 | ---- | C] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011.12.18 20:36:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.30 21:01:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.30 13:43:44 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 13:43:44 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.30 13:43:31 | 001,512,418 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.30 13:43:31 | 000,658,988 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.30 13:43:31 | 000,620,174 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.30 13:43:31 | 000,132,558 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.30 13:43:31 | 000,108,356 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.30 13:36:18 | 2566,365,184 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.30 03:00:25 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.25 06:56:01 | 000,095,744 | ---- | M] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011.12.17 03:19:39 | 000,388,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.30 03:00:25 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.11.06 14:15:03 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.02.20 15:38:17 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2011.02.20 15:38:17 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2011.02.20 15:38:17 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2011.02.20 13:56:20 | 000,027,266 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2011.02.13 20:33:57 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2011.02.13 20:33:57 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2010.11.10 02:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010.11.10 02:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2010.11.10 02:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010.04.02 16:46:26 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2010.03.20 20:02:21 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2007.04.27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
 
========== LOP Check ==========
 
[2010.03.20 18:11:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\CheckPoint
[2010.05.23 12:05:28 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ChessBase
[2010.04.17 22:04:43 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\DAEMON Tools Lite
[2011.02.14 08:17:23 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\FinalMediaPlayer
[2010.12.22 23:49:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2011.04.25 21:09:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\MAGIX
[2011.03.27 21:05:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\NCH Swift Sound
[2011.12.25 03:52:33 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ppstream
[2011.07.25 17:12:19 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ReactGames
[2010.04.02 16:57:37 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Thunderbird
[2011.03.27 10:22:23 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.04.25 13:16:49 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Adobe
[2011.11.04 02:44:17 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Ahead
[2011.01.23 12:43:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Avira
[2010.03.20 18:11:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\CheckPoint
[2010.05.23 12:05:28 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ChessBase
[2010.04.17 22:04:43 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\DAEMON Tools Lite
[2011.02.14 08:17:23 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\FinalMediaPlayer
[2010.12.22 23:49:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2011.12.25 06:33:36 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Identities
[2011.07.22 11:57:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\InstallShield
[2010.03.20 18:19:59 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Macromedia
[2011.04.25 21:09:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\MAGIX
[2011.12.30 03:03:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Malwarebytes
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Media Center Programs
[2010.03.20 21:54:54 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Media Player Classic
[2011.07.26 18:42:30 | 000,000,000 | --SD | M] -- C:\Users\garry\AppData\Roaming\Microsoft
[2010.03.20 18:07:27 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Mozilla
[2011.03.27 21:05:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\NCH Swift Sound
[2010.04.03 04:04:02 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Nero
[2011.12.25 03:52:33 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ppstream
[2011.07.25 17:12:19 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ReactGames
[2011.04.26 23:24:58 | 000,000,000 | RH-D | M] -- C:\Users\garry\AppData\Roaming\SecuROM
[2011.12.24 18:09:03 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Skype
[2011.06.25 15:00:34 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\skypePM
[2010.04.02 16:57:37 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Thunderbird
[2011.12.25 03:52:34 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Winamp
[2010.05.08 19:36:24 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2011.12.13 16:57:24 | 000,141,312 | ---- | M] (getfireshot.com) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-container.exe
[2011.12.13 16:57:20 | 000,068,096 | ---- | M] (getfireshot.com) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-deploy.exe
[2010.02.04 11:09:16 | 000,010,752 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org\prism\nsinstall.exe
[2010.02.04 11:10:00 | 000,044,018 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org\prism\regprot.exe
 
< %SYSTEMDRIVE%\*.exe >
[2008.04.11 07:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2011.07.13 03:55:05 | 002,237,440 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
========== Files - Unicode (All) ==========
[2010.04.25 13:15:45 | 000,000,000 | ---D | M](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式
[2010.04.25 13:15:45 | 000,000,000 | ---D | C](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式

< End of report >

Extras:
Code:

OTL Extras logfile created on: 30.12.2011 21:10:09 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\garry\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,19 Gb Total Physical Memory | 2,32 Gb Available Physical Memory | 72,87% Memory free
6,37 Gb Paging File | 4,90 Gb Available in Paging File | 76,83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 359,46 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
 
Computer Name: LARRY | User Name: garry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\PPStream\PPStream.exe" = C:\Program Files (x86)\PPStream\PPStream.exe:*:Enabled:PPSÍøÂçµçÊÓ -- (PPStream Inc.)
"C:\Program Files (x86)\PPStream\PPSAP.exe" = C:\Program Files (x86)\PPStream\PPSAP.exe:*:Enabled:PPS ÍøÂç¼ÓËÙÆ÷ -- (PPStream Inc)
"C:\Program Files (x86)\PPStream\PPStream.exe" = C:\Program Files (x86)\PPStream\PPStream.exe:*:Enabled:PPSÍøÂçµçÊÓ -- (PPStream Inc.)
"C:\Program Files (x86)\PPStream\PPSAP.exe" = C:\Program Files (x86)\PPStream\PPSAP.exe:*:Enabled:PPS ÍøÂç¼ÓËÙÆ÷ -- (PPStream Inc)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06C43FAA-7226-41EF-A05E-9AE0AA849FFE}" = IBM SPSS Statistics 19
"{1023383E-D9F6-478C-A965-23A4657B3C9A}" = Sacred 2
"{1761AE92-1301-4B96-9FE4-F04DFDA5E33A}" = FreeRIP Toolbar v4.7
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26
"{2E97F7E8-ABDE-4E0D-B0AD-B6B4BAD89E24}" = Rome - Total War - Gold Edition
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F4182DA-3D58-41E3-913D-480F8DA5C863}" = Fritz 12
"{501451DE-5808-4599-B544-8BD0915B6B24}_is1" = FreeRIP v3.61
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{554AF605-3BC3-4015-8B80-BA8897D9C139}" = ArchonPC
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{6333C013-366F-45BD-B598-9E0B25E41605}" = MAGIX Screenshare
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{806907e0-5c06-4b2f-834b-ade28b272962}" = Nero 9 Lite
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}" = AGEIA PhysX v7.11.13
"{98EFD8F0-08DE-48DB-B922-A2EBAB711028}" = Nero 7 Ultra Edition
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C4436D2-3644-40E9-985C-D3D015F87285}" = MAGIX Speed burnR (MSI)
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.6 - Deutsch
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EAEAAF8C-8E86-4CAC-AC08-1A33EDCA34AC}" = Prince of Persia The Forgotten Sands
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F43CF77A-A8FA-4AFD-ADC6-08F4A35F12A5}" = MAGIX Music Maker 17 Premium
"{F6CCD38C-8298-4F7B-91C5-C8DED0B24E5A}" = Fritz 12
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Amiga Classix Gold 2" = Amiga Classix Gold 2 1.0
"AskTBar Uninstall" = Ask Toolbar
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Battle Chess" = Battle Chess
"CCleaner" = CCleaner
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Diablo II" = Diablo II
"ESET Online Scanner" = ESET Online Scanner v3
"ExpressBurn" = Express Burn
"FinalMediaPlayer_is1" = Final Media Player 2011
"Free Mp3 Wma Ogg Converter_is1" = Free Mp3 Wma Ogg Converter 7.1.2
"MAGIX_MSI_mm17dlx" = MAGIX Music Maker 17 Premium
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox 8.0.1 (x86 de)" = Mozilla Firefox 8.0.1 (x86 de)
"Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4)
"OpenAL" = OpenAL
"PPStream" = PPStream V2.6.86.9024 Final
"PriceGong" = PriceGong 2.5.1
"Steam App 99100" = Dungeons & Dragons: Daggerdale
"TeamViewer 6" = TeamViewer 6
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"Trusted Software Assistant_is1" = File Type Assistant
"VirtualCloneDrive" = VirtualCloneDrive
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"WinUAE" = WinUAE 2.3.0
"ZoneAlarm" = ZoneAlarm
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 30.12.2011 08:38:42 | Computer Name = Larry | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 30.12.2011 08:48:51 | Computer Name = Larry | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
Error - 30.12.2011 09:18:44 | Computer Name = Larry | Source = SideBySide | ID = 16842827
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe". Fehler in Manifest-
 oder Richtliniendatei "C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe"
 in Zeile 2.  Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig.
 
Error - 30.12.2011 09:19:06 | Computer Name = Larry | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe". Fehler in Manifest- oder Richtliniendatei
 "C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack200.exe" in Zeile
19.  Der Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist
 ungültig.
 
Error - 30.12.2011 09:19:42 | Computer Name = Larry | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll". Fehler in Manifest- oder Richtliniendatei
 "C:\Program Files (x86)\IBM\SPSS\Statistics\19\JRE\bin\unpack.dll" in Zeile 19.
Der
 Wert "6.0.0.6u9b41" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 30.12.2011 09:20:31 | Computer Name = Larry | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in  Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 30.12.2011 09:22:18 | Computer Name = Larry | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\Users\garry\downloads\esetsmartinstaller_enu.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 30.12.2011 16:05:53 | Computer Name = Larry | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\garry\Downloads\esetsmartinstaller_enu.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 30.12.2011 16:07:03 | Computer Name = Larry | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\garry\Downloads\SoftonicDownloader_fuer_magix-mp3-maker.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
 
Error - 30.12.2011 16:09:21 | Computer Name = Larry | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
.
 
[ System Events ]
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "TCP/IP-NetBIOS-Hilfsdienst" ist vom Dienst "Ancillary
Function Driver for Winsock" abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%31
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerkspeicher-Schnittstellendienst" ist vom Dienst
"NSI proxy service driver." abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%31
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "TrueVector Internet Monitor" ist vom Dienst "Zone Alarm
 Firewall Driver" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
  %%31
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Arbeitsstationsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "IP-Hilfsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB-Miniredirector-Wrapper und -Modul" ist vom Dienst
"Umgeleitetes Puffersubsystem" abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%31
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7001
Description = Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 25.12.2011 14:48:37 | Computer Name = Larry | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  AFD  avipbb  DfsC  discache  ElbyCDIO  NetBIOS  NetBT  nsiproxy  Psched  rdbss  spldr  sptd  tdx  Vsdatant
Wanarpv6
WfpLwf
 
 
< End of report >


cosinus 30.12.2011 22:41

Zitat:

O2 - BHO: (ZoneAlarm-Sicherheit Toolbar)
ZoneAlarm ist kontraproduktiver Müll, bitte umgehend deinstallieren und die Windows-Firewall einschalten!

Mach danach wieder ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

[code] hier steht das Log [/code

Doppelgrunz 31.12.2011 00:35

Okay habe Zonealarm deinstalliert und den scan nochmal gemacht. Bei der Deinstallation gab es eine Fehermeldung, allerdings kann ich Zonealarm nicht mehr auf dem Rechner finden (als Programm), nur noch ein Folder mit dem Namen existiert.

Hier das log-file:

Code:

OTL logfile created on: 31.12.2011 00:18:52 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\garry\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,19 Gb Total Physical Memory | 2,08 Gb Available Physical Memory | 65,14% Memory free
6,37 Gb Paging File | 4,92 Gb Available in Paging File | 77,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 361,26 Gb Free Space | 77,56% Space Free | Partition Type: NTFS
 
Computer Name: LARRY | User Name: garry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\garry\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\PPStream\PPSAP.exe (PPStream Inc)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.DLL ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (PLFlash DeviceIoControl Service) -- C:\Windows\SysWOW64\IoctlSvc.exe (Prolific Technology Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) Logitech Webcam 200(UVC) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) -- C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 E8 9F CC 86 75 CC 01  [binary data]
IE - HKCU\..\URLSearchHook: {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\InprocServer32 File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:5.1
FF - prefs.js..extensions.enabledItems: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.232.0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.12.04 14:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.30 21:42:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2010.04.02 16:57:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2010.04.02 16:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Extensions
[2010.04.02 16:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.12.30 02:50:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions
[2011.12.16 23:51:17 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011.03.27 01:43:53 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2010.03.20 20:38:15 | 000,000,000 | ---D | M] (Prism for Firefox) -- C:\Users\garry\AppData\Roaming\mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org
[2011.12.30 04:00:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.11.05 19:31:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.05.14 19:05:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) -- C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.12.04 14:09:02 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.05 18:19:00 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.03 15:20:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.03 15:20:53 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.10.03 15:20:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.03 15:20:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.03 15:20:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.03 15:20:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.12.27 10:09:35 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll File not found
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O2 - BHO: (no name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No CLSID value found.
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" File not found
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PPS Accelerator] C:\Program Files (x86)\PPStream\ppsap.exe (PPStream Inc)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8:64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E43CC620-6F4B-4BDA-B0E3-BD4F1A83D927}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell\AutoRun\command - "" = E:\TmUnitedForever_Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: vsmon - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: vsmon - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.31 00:13:03 | 000,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2011.12.30 04:03:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.30 03:03:00 | 000,000,000 | ---D | C] -- C:\Users\garry\AppData\Roaming\Malwarebytes
[2011.12.30 03:00:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.30 03:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.12.30 03:00:23 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.12.30 03:00:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.27 10:09:33 | 002,237,440 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe
[2011.12.27 10:09:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.26 08:10:53 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware
[2011.12.26 07:43:32 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.12.25 17:12:00 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2011.12.25 06:56:01 | 000,095,744 | ---- | C] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011.12.18 20:36:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.31 00:17:24 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.31 00:17:24 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.31 00:17:07 | 001,512,418 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.31 00:17:07 | 000,658,988 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.31 00:17:07 | 000,620,174 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.31 00:17:07 | 000,132,558 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.31 00:17:07 | 000,108,356 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.31 00:09:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.31 00:09:56 | 2566,365,184 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.30 03:00:25 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.12.25 06:56:01 | 000,095,744 | ---- | M] (Kassl GmbH) -- C:\Users\garry\AppData\Roaming\dwlGina3.dll
[2011.12.17 03:19:39 | 000,388,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.30 03:00:25 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011.11.06 14:15:03 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.02.20 15:38:17 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2011.02.20 15:38:17 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2011.02.20 15:38:17 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2011.02.20 13:56:20 | 000,027,266 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2011.02.13 20:33:57 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2011.02.13 20:33:57 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2010.11.10 02:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010.11.10 02:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2010.11.10 02:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010.04.02 16:46:26 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2010.03.20 20:02:21 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007.07.23 08:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007.07.23 08:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2007.04.27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
 
========== LOP Check ==========
 
[2010.03.20 18:11:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\CheckPoint
[2010.05.23 12:05:28 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ChessBase
[2010.04.17 22:04:43 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\DAEMON Tools Lite
[2011.02.14 08:17:23 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\FinalMediaPlayer
[2010.12.22 23:49:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2011.04.25 21:09:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\MAGIX
[2011.03.27 21:05:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\NCH Swift Sound
[2011.12.25 03:52:33 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ppstream
[2011.07.25 17:12:19 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ReactGames
[2010.04.02 16:57:37 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Thunderbird
[2011.03.27 10:22:23 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.04.25 13:16:49 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Adobe
[2011.11.04 02:44:17 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Ahead
[2011.01.23 12:43:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Avira
[2010.03.20 18:11:55 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\CheckPoint
[2010.05.23 12:05:28 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ChessBase
[2010.04.17 22:04:43 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\DAEMON Tools Lite
[2011.02.14 08:17:23 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\FinalMediaPlayer
[2010.12.22 23:49:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Free Mp3 Wma Ogg Converter
[2011.12.25 06:33:36 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Identities
[2011.07.22 11:57:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\InstallShield
[2010.03.20 18:19:59 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Macromedia
[2011.04.25 21:09:22 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\MAGIX
[2011.12.30 03:03:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Malwarebytes
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Media Center Programs
[2010.03.20 21:54:54 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Media Player Classic
[2011.07.26 18:42:30 | 000,000,000 | --SD | M] -- C:\Users\garry\AppData\Roaming\Microsoft
[2010.03.20 18:07:27 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Mozilla
[2011.03.27 21:05:00 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\NCH Swift Sound
[2010.04.03 04:04:02 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Nero
[2011.12.25 03:52:33 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ppstream
[2011.07.25 17:12:19 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\ReactGames
[2011.04.26 23:24:58 | 000,000,000 | RH-D | M] -- C:\Users\garry\AppData\Roaming\SecuROM
[2011.12.24 18:09:03 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Skype
[2011.06.25 15:00:34 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\skypePM
[2010.04.02 16:57:37 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Thunderbird
[2011.12.30 21:56:09 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\Winamp
[2010.05.08 19:36:24 | 000,000,000 | ---D | M] -- C:\Users\garry\AppData\Roaming\WinRAR
 
< %APPDATA%\*.exe /s >
[2011.12.13 16:57:24 | 000,141,312 | ---- | M] (getfireshot.com) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-container.exe
[2011.12.13 16:57:20 | 000,068,096 | ---- | M] (getfireshot.com) -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-deploy.exe
[2010.02.04 11:09:16 | 000,010,752 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org\prism\nsinstall.exe
[2010.02.04 11:10:00 | 000,044,018 | ---- | M] () -- C:\Users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\extensions\refractor@developer.mozilla.org\prism\regprot.exe
 
< %SYSTEMDRIVE%\*.exe >
[2008.04.11 07:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2011.07.13 03:55:05 | 002,237,440 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
<          >
 
========== Files - Unicode (All) ==========
[2010.04.25 13:15:45 | 000,000,000 | ---D | M](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式
[2010.04.25 13:15:45 | 000,000,000 | ---D | C](C:\Users\Public\Desktop\Adobe 9 Reader ????) -- C:\Users\Public\Desktop\Adobe 9 Reader 安裝程式

< End of report >


cosinus 31.12.2011 15:22

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.1\PriceGongIE.dll File not found
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O2 - BHO: (no name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No CLSID value found.
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (FreeRIP Toolbar) - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files (x86)\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll File not found
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll File not found
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" File not found
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O8:64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell - "" = AutoRun
O33 - MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\Shell\AutoRun\command - "" = E:\TmUnitedForever_Setup.exe
:Files
C:\Windows\Internet Logs
C:\Users\garry\AppData\Roaming\CheckPoint
C:\Program Files\CheckPoint
C:\Program Files (x86)\Ask.com
C:\Program Files (x86)\Winamp Toolbar
C:\Program Files (x86)\FreeRIP Toolbar
C:\Program Files (x86)\AskTBar
C:\Program Files (x86)\PriceGong
C:\Program Files (x86)\Skype\Toolbars
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Doppelgrunz 31.12.2011 19:34

Okay, alles ausgeführt. Hier ist der log.

Code:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{E634228A-03CF-4BC8-B0AB-668257F1FD8C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E634228A-03CF-4BC8-B0AB-668257F1FD8C}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}\ not found.
64bit-Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Winamp Search\ deleted successfully.
C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html moved successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft &Excel exportieren\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Winamp Search\ not found.
File C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7242f609-0e0f-11e0-8158-001966d640e5}\ not found.
File F:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{975257b6-4a65-11df-b326-001966d640e5}\ not found.
File E:\TmUnitedForever_Setup.exe not found.
========== FILES ==========
C:\Windows\Internet Logs folder moved successfully.
C:\Users\garry\AppData\Roaming\CheckPoint\ZoneAlarm Toolbar\TrustChecker folder moved successfully.
C:\Users\garry\AppData\Roaming\CheckPoint\ZoneAlarm Toolbar\PTPCACHE folder moved successfully.
C:\Users\garry\AppData\Roaming\CheckPoint\ZoneAlarm Toolbar folder moved successfully.
C:\Users\garry\AppData\Roaming\CheckPoint folder moved successfully.
C:\Program Files\CheckPoint\ZAForceField folder moved successfully.
C:\Program Files\CheckPoint folder moved successfully.
File\Folder C:\Program Files (x86)\Ask.com not found.
File\Folder C:\Program Files (x86)\Winamp Toolbar not found.
File\Folder C:\Program Files (x86)\FreeRIP Toolbar not found.
C:\Program Files (x86)\AskTBar\bar\Settings folder moved successfully.
C:\Program Files (x86)\AskTBar\bar\History folder moved successfully.
C:\Program Files (x86)\AskTBar\bar\Cache folder moved successfully.
C:\Program Files (x86)\AskTBar\bar\1.bin folder moved successfully.
C:\Program Files (x86)\AskTBar\bar folder moved successfully.
C:\Program Files (x86)\AskTBar folder moved successfully.
File\Folder C:\Program Files (x86)\PriceGong not found.
C:\Program Files (x86)\Skype\Toolbars\Shared folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: garry
->Temp folder emptied: 2341645893 bytes
->Temporary Internet Files folder emptied: 375084580 bytes
->Java cache emptied: 82106 bytes
->FireFox cache emptied: 74228937 bytes
->Flash cache emptied: 7516 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 1618992 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 109531886 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 119624 bytes
RecycleBin emptied: 8322817 bytes
 
Total Files Cleaned = 2.776,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 12312011_192216

Files\Folders moved on Reboot...
C:\Users\garry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Wie gehts weiter?

cosinus 02.01.2012 11:13

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

Doppelgrunz 02.01.2012 12:53

Hallo Arne,

hier der log des TDSS Killers.

Code:

12:28:58.0798 1864        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
12:28:58.0971 1864        ============================================================
12:28:58.0971 1864        Current date / time: 2012/01/02 12:28:58.0971
12:28:58.0971 1864        SystemInfo:
12:28:58.0971 1864       
12:28:58.0972 1864        OS Version: 6.1.7601 ServicePack: 1.0
12:28:58.0972 1864        Product type: Workstation
12:28:58.0972 1864        ComputerName: LARRY
12:28:58.0973 1864        UserName: garry
12:28:58.0974 1864        Windows directory: C:\Windows
12:28:58.0974 1864        System windows directory: C:\Windows
12:28:58.0974 1864        Running under WOW64
12:28:58.0974 1864        Processor architecture: Intel x64
12:28:58.0974 1864        Number of processors: 2
12:28:58.0974 1864        Page size: 0x1000
12:28:58.0974 1864        Boot type: Normal boot
12:28:58.0974 1864        ============================================================
12:28:59.0804 1864        Initialize success
12:29:36.0984 3012        ============================================================
12:29:36.0984 3012        Scan started
12:29:36.0984 3012        Mode: Manual; SigCheck; TDLFS;
12:29:36.0984 3012        ============================================================
12:29:37.0689 3012        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
12:29:37.0817 3012        1394ohci - ok
12:29:37.0892 3012        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
12:29:37.0913 3012        ACPI - ok
12:29:37.0930 3012        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
12:29:37.0991 3012        AcpiPmi - ok
12:29:38.0033 3012        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
12:29:38.0058 3012        adp94xx - ok
12:29:38.0078 3012        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
12:29:38.0091 3012        adpahci - ok
12:29:38.0117 3012        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
12:29:38.0128 3012        adpu320 - ok
12:29:38.0191 3012        AFD            (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
12:29:38.0235 3012        AFD - ok
12:29:38.0279 3012        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
12:29:38.0295 3012        agp440 - ok
12:29:38.0331 3012        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
12:29:38.0344 3012        aliide - ok
12:29:38.0356 3012        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
12:29:38.0370 3012        amdide - ok
12:29:38.0395 3012        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
12:29:38.0442 3012        AmdK8 - ok
12:29:38.0472 3012        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
12:29:38.0493 3012        AmdPPM - ok
12:29:38.0527 3012        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
12:29:38.0536 3012        amdsata - ok
12:29:38.0551 3012        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
12:29:38.0562 3012        amdsbs - ok
12:29:38.0579 3012        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
12:29:38.0588 3012        amdxata - ok
12:29:38.0628 3012        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
12:29:38.0731 3012        AppID - ok
12:29:38.0781 3012        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
12:29:38.0790 3012        arc - ok
12:29:38.0808 3012        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
12:29:38.0817 3012        arcsas - ok
12:29:38.0848 3012        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
12:29:38.0942 3012        AsyncMac - ok
12:29:39.0007 3012        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
12:29:39.0015 3012        atapi - ok
12:29:39.0058 3012        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
12:29:39.0111 3012        avgntflt - ok
12:29:39.0178 3012        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
12:29:39.0190 3012        avipbb - ok
12:29:39.0226 3012        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
12:29:39.0277 3012        b06bdrv - ok
12:29:39.0301 3012        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
12:29:39.0344 3012        b57nd60a - ok
12:29:39.0373 3012        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
12:29:39.0423 3012        Beep - ok
12:29:39.0468 3012        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
12:29:39.0491 3012        blbdrive - ok
12:29:39.0542 3012        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
12:29:39.0576 3012        bowser - ok
12:29:39.0604 3012        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:29:39.0653 3012        BrFiltLo - ok
12:29:39.0670 3012        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:29:39.0683 3012        BrFiltUp - ok
12:29:39.0706 3012        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
12:29:39.0736 3012        Brserid - ok
12:29:39.0754 3012        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
12:29:39.0775 3012        BrSerWdm - ok
12:29:39.0792 3012        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
12:29:39.0810 3012        BrUsbMdm - ok
12:29:39.0824 3012        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
12:29:39.0845 3012        BrUsbSer - ok
12:29:39.0861 3012        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
12:29:39.0882 3012        BTHMODEM - ok
12:29:39.0918 3012        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
12:29:39.0949 3012        cdfs - ok
12:29:39.0977 3012        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
12:29:39.0995 3012        cdrom - ok
12:29:40.0018 3012        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
12:29:40.0039 3012        circlass - ok
12:29:40.0083 3012        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
12:29:40.0105 3012        CLFS - ok
12:29:40.0146 3012        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
12:29:40.0165 3012        CmBatt - ok
12:29:40.0197 3012        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
12:29:40.0212 3012        cmdide - ok
12:29:40.0258 3012        CNG            (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
12:29:40.0289 3012        CNG - ok
12:29:40.0301 3012        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
12:29:40.0309 3012        Compbatt - ok
12:29:40.0334 3012        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
12:29:40.0364 3012        CompositeBus - ok
12:29:40.0379 3012        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
12:29:40.0387 3012        crcdisk - ok
12:29:40.0443 3012        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
12:29:40.0478 3012        DfsC - ok
12:29:40.0512 3012        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
12:29:40.0541 3012        discache - ok
12:29:40.0569 3012        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
12:29:40.0579 3012        Disk - ok
12:29:40.0608 3012        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
12:29:40.0631 3012        drmkaud - ok
12:29:40.0684 3012        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
12:29:40.0715 3012        DXGKrnl - ok
12:29:40.0788 3012        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
12:29:40.0866 3012        ebdrv - ok
12:29:40.0900 3012        ElbyCDIO        (9a47ac3dfcf81d30922cdaaf1c2d579f) C:\Windows\system32\Drivers\ElbyCDIO.sys
12:29:40.0908 3012        ElbyCDIO - ok
12:29:40.0937 3012        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
12:29:40.0953 3012        elxstor - ok
12:29:40.0982 3012        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
12:29:41.0010 3012        ErrDev - ok
12:29:41.0050 3012        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
12:29:41.0083 3012        exfat - ok
12:29:41.0110 3012        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
12:29:41.0150 3012        fastfat - ok
12:29:41.0173 3012        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
12:29:41.0201 3012        fdc - ok
12:29:41.0229 3012        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
12:29:41.0238 3012        FileInfo - ok
12:29:41.0252 3012        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
12:29:41.0290 3012        Filetrace - ok
12:29:41.0310 3012        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
12:29:41.0329 3012        flpydisk - ok
12:29:41.0377 3012        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
12:29:41.0398 3012        FltMgr - ok
12:29:41.0418 3012        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
12:29:41.0427 3012        FsDepends - ok
12:29:41.0443 3012        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
12:29:41.0453 3012        Fs_Rec - ok
12:29:41.0478 3012        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
12:29:41.0491 3012        fvevol - ok
12:29:41.0505 3012        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
12:29:41.0514 3012        gagp30kx - ok
12:29:41.0543 3012        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
12:29:41.0568 3012        hcw85cir - ok
12:29:41.0617 3012        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
12:29:41.0649 3012        HdAudAddService - ok
12:29:41.0683 3012        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
12:29:41.0713 3012        HDAudBus - ok
12:29:41.0745 3012        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
12:29:41.0766 3012        HidBatt - ok
12:29:41.0780 3012        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
12:29:41.0805 3012        HidBth - ok
12:29:41.0820 3012        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
12:29:41.0833 3012        HidIr - ok
12:29:41.0873 3012        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
12:29:41.0899 3012        HidUsb - ok
12:29:41.0936 3012        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
12:29:41.0945 3012        HpSAMD - ok
12:29:41.0994 3012        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
12:29:42.0037 3012        HTTP - ok
12:29:42.0081 3012        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
12:29:42.0090 3012        hwpolicy - ok
12:29:42.0129 3012        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
12:29:42.0140 3012        i8042prt - ok
12:29:42.0173 3012        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
12:29:42.0187 3012        iaStorV - ok
12:29:42.0228 3012        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
12:29:42.0237 3012        iirsp - ok
12:29:42.0259 3012        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
12:29:42.0268 3012        intelide - ok
12:29:42.0287 3012        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
12:29:42.0306 3012        intelppm - ok
12:29:42.0344 3012        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:29:42.0372 3012        IpFilterDriver - ok
12:29:42.0411 3012        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
12:29:42.0423 3012        IPMIDRV - ok
12:29:42.0439 3012        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
12:29:42.0478 3012        IPNAT - ok
12:29:42.0495 3012        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
12:29:42.0519 3012        IRENUM - ok
12:29:42.0565 3012        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
12:29:42.0577 3012        isapnp - ok
12:29:42.0610 3012        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
12:29:42.0630 3012        iScsiPrt - ok
12:29:42.0646 3012        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
12:29:42.0660 3012        kbdclass - ok
12:29:42.0685 3012        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
12:29:42.0702 3012        kbdhid - ok
12:29:42.0737 3012        KSecDD          (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
12:29:42.0747 3012        KSecDD - ok
12:29:42.0793 3012        KSecPkg        (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
12:29:42.0810 3012        KSecPkg - ok
12:29:42.0842 3012        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
12:29:42.0898 3012        ksthunk - ok
12:29:42.0920 3012        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
12:29:42.0957 3012        lltdio - ok
12:29:42.0985 3012        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
12:29:42.0994 3012        LSI_FC - ok
12:29:43.0007 3012        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
12:29:43.0017 3012        LSI_SAS - ok
12:29:43.0029 3012        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:29:43.0038 3012        LSI_SAS2 - ok
12:29:43.0058 3012        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:29:43.0068 3012        LSI_SCSI - ok
12:29:43.0093 3012        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
12:29:43.0131 3012        luafv - ok
12:29:43.0176 3012        LVRS64          (803085f59ec92b3827cc4d90fcbfd335) C:\Windows\system32\DRIVERS\lvrs64.sys
12:29:43.0193 3012        LVRS64 - ok
12:29:43.0286 3012        LVUVC64        (a8d7c97016e6b76ef472a4c7ab357ee3) C:\Windows\system32\DRIVERS\lvuvc64.sys
12:29:43.0384 3012        LVUVC64 - ok
12:29:43.0415 3012        MBAMProtector  (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
12:29:43.0422 3012        MBAMProtector - ok
12:29:43.0450 3012        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
12:29:43.0458 3012        megasas - ok
12:29:43.0478 3012        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
12:29:43.0490 3012        MegaSR - ok
12:29:43.0513 3012        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
12:29:43.0552 3012        Modem - ok
12:29:43.0571 3012        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
12:29:43.0595 3012        monitor - ok
12:29:43.0634 3012        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
12:29:43.0642 3012        mouclass - ok
12:29:43.0656 3012        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
12:29:43.0667 3012        mouhid - ok
12:29:43.0695 3012        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
12:29:43.0705 3012        mountmgr - ok
12:29:43.0731 3012        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
12:29:43.0741 3012        mpio - ok
12:29:43.0767 3012        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
12:29:43.0810 3012        mpsdrv - ok
12:29:43.0842 3012        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
12:29:43.0865 3012        MRxDAV - ok
12:29:43.0906 3012        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
12:29:43.0934 3012        mrxsmb - ok
12:29:43.0977 3012        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:29:44.0009 3012        mrxsmb10 - ok
12:29:44.0042 3012        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:29:44.0054 3012        mrxsmb20 - ok
12:29:44.0088 3012        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
12:29:44.0097 3012        msahci - ok
12:29:44.0113 3012        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
12:29:44.0122 3012        msdsm - ok
12:29:44.0167 3012        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
12:29:44.0204 3012        Msfs - ok
12:29:44.0216 3012        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
12:29:44.0251 3012        mshidkmdf - ok
12:29:44.0269 3012        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
12:29:44.0278 3012        msisadrv - ok
12:29:44.0301 3012        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
12:29:44.0335 3012        MSKSSRV - ok
12:29:44.0359 3012        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
12:29:44.0397 3012        MSPCLOCK - ok
12:29:44.0426 3012        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
12:29:44.0463 3012        MSPQM - ok
12:29:44.0504 3012        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
12:29:44.0518 3012        MsRPC - ok
12:29:44.0552 3012        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
12:29:44.0561 3012        mssmbios - ok
12:29:44.0580 3012        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
12:29:44.0619 3012        MSTEE - ok
12:29:44.0637 3012        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
12:29:44.0653 3012        MTConfig - ok
12:29:44.0669 3012        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
12:29:44.0694 3012        Mup - ok
12:29:44.0724 3012        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
12:29:44.0747 3012        NativeWifiP - ok
12:29:44.0815 3012        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
12:29:44.0836 3012        NDIS - ok
12:29:44.0853 3012        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
12:29:44.0883 3012        NdisCap - ok
12:29:44.0896 3012        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
12:29:44.0936 3012        NdisTapi - ok
12:29:44.0959 3012        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
12:29:45.0002 3012        Ndisuio - ok
12:29:45.0033 3012        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
12:29:45.0071 3012        NdisWan - ok
12:29:45.0112 3012        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
12:29:45.0144 3012        NDProxy - ok
12:29:45.0173 3012        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
12:29:45.0210 3012        NetBIOS - ok
12:29:45.0267 3012        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
12:29:45.0321 3012        NetBT - ok
12:29:45.0381 3012        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
12:29:45.0390 3012        nfrd960 - ok
12:29:45.0420 3012        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
12:29:45.0456 3012        Npfs - ok
12:29:45.0482 3012        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
12:29:45.0524 3012        nsiproxy - ok
12:29:45.0580 3012        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
12:29:45.0637 3012        Ntfs - ok
12:29:45.0660 3012        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
12:29:45.0697 3012        Null - ok
12:29:45.0927 3012        nvlddmkm        (ac8cbe9a0663e88f6429ee5530d5e32b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:29:46.0210 3012        nvlddmkm - ok
12:29:46.0282 3012        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
12:29:46.0299 3012        nvraid - ok
12:29:46.0318 3012        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
12:29:46.0328 3012        nvstor - ok
12:29:46.0364 3012        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
12:29:46.0375 3012        nv_agp - ok
12:29:46.0405 3012        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
12:29:46.0440 3012        ohci1394 - ok
12:29:46.0472 3012        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
12:29:46.0484 3012        Parport - ok
12:29:46.0532 3012        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
12:29:46.0541 3012        partmgr - ok
12:29:46.0579 3012        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
12:29:46.0589 3012        pci - ok
12:29:46.0622 3012        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
12:29:46.0631 3012        pciide - ok
12:29:46.0650 3012        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
12:29:46.0662 3012        pcmcia - ok
12:29:46.0686 3012        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
12:29:46.0695 3012        pcw - ok
12:29:46.0720 3012        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
12:29:46.0768 3012        PEAUTH - ok
12:29:46.0839 3012        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
12:29:46.0877 3012        PptpMiniport - ok
12:29:46.0892 3012        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
12:29:46.0908 3012        Processor - ok
12:29:46.0952 3012        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
12:29:46.0994 3012        Psched - ok
12:29:47.0032 3012        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
12:29:47.0077 3012        ql2300 - ok
12:29:47.0101 3012        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
12:29:47.0111 3012        ql40xx - ok
12:29:47.0131 3012        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
12:29:47.0156 3012        QWAVEdrv - ok
12:29:47.0172 3012        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
12:29:47.0210 3012        RasAcd - ok
12:29:47.0235 3012        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
12:29:47.0264 3012        RasAgileVpn - ok
12:29:47.0310 3012        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
12:29:47.0368 3012        Rasl2tp - ok
12:29:47.0397 3012        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
12:29:47.0439 3012        RasPppoe - ok
12:29:47.0456 3012        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
12:29:47.0496 3012        RasSstp - ok
12:29:47.0535 3012        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
12:29:47.0576 3012        rdbss - ok
12:29:47.0587 3012        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
12:29:47.0611 3012        rdpbus - ok
12:29:47.0623 3012        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
12:29:47.0662 3012        RDPCDD - ok
12:29:47.0682 3012        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
12:29:47.0723 3012        RDPENCDD - ok
12:29:47.0736 3012        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
12:29:47.0766 3012        RDPREFMP - ok
12:29:47.0797 3012        RDPWD          (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
12:29:47.0842 3012        RDPWD - ok
12:29:47.0875 3012        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
12:29:47.0885 3012        rdyboost - ok
12:29:47.0926 3012        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
12:29:47.0969 3012        rspndr - ok
12:29:47.0999 3012        RTL8167        (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
12:29:48.0012 3012        RTL8167 - ok
12:29:48.0040 3012        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
12:29:48.0051 3012        sbp2port - ok
12:29:48.0095 3012        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
12:29:48.0149 3012        scfilter - ok
12:29:48.0188 3012        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
12:29:48.0227 3012        secdrv - ok
12:29:48.0252 3012        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
12:29:48.0264 3012        Serenum - ok
12:29:48.0282 3012        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
12:29:48.0305 3012        Serial - ok
12:29:48.0336 3012        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
12:29:48.0347 3012        sermouse - ok
12:29:48.0389 3012        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
12:29:48.0412 3012        sffdisk - ok
12:29:48.0419 3012        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
12:29:48.0441 3012        sffp_mmc - ok
12:29:48.0448 3012        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
12:29:48.0477 3012        sffp_sd - ok
12:29:48.0504 3012        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
12:29:48.0525 3012        sfloppy - ok
12:29:48.0556 3012        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:29:48.0566 3012        SiSRaid2 - ok
12:29:48.0589 3012        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
12:29:48.0599 3012        SiSRaid4 - ok
12:29:48.0623 3012        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
12:29:48.0662 3012        Smb - ok
12:29:48.0705 3012        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
12:29:48.0713 3012        spldr - ok
12:29:48.0757 3012        sptd            (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
12:29:48.0757 3012        Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
12:29:48.0759 3012        sptd ( LockedFile.Multi.Generic ) - warning
12:29:48.0759 3012        sptd - detected LockedFile.Multi.Generic (1)
12:29:48.0807 3012        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
12:29:48.0844 3012        srv - ok
12:29:48.0879 3012        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
12:29:48.0907 3012        srv2 - ok
12:29:48.0952 3012        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
12:29:48.0980 3012        srvnet - ok
12:29:49.0022 3012        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
12:29:49.0037 3012        stexstor - ok
12:29:49.0080 3012        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
12:29:49.0095 3012        swenum - ok
12:29:49.0174 3012        Tcpip          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
12:29:49.0239 3012        Tcpip - ok
12:29:49.0279 3012        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
12:29:49.0310 3012        TCPIP6 - ok
12:29:49.0349 3012        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
12:29:49.0387 3012        tcpipreg - ok
12:29:49.0412 3012        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
12:29:49.0442 3012        TDPIPE - ok
12:29:49.0452 3012        TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
12:29:49.0489 3012        TDTCP - ok
12:29:49.0529 3012        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
12:29:49.0570 3012        tdx - ok
12:29:49.0609 3012        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
12:29:49.0619 3012        TermDD - ok
12:29:49.0662 3012        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
12:29:49.0699 3012        tssecsrv - ok
12:29:49.0730 3012        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
12:29:49.0751 3012        TsUsbFlt - ok
12:29:49.0790 3012        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
12:29:49.0824 3012        tunnel - ok
12:29:49.0847 3012        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
12:29:49.0857 3012        uagp35 - ok
12:29:49.0893 3012        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
12:29:49.0934 3012        udfs - ok
12:29:49.0979 3012        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
12:29:49.0995 3012        uliagpkx - ok
12:29:50.0036 3012        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
12:29:50.0059 3012        umbus - ok
12:29:50.0081 3012        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
12:29:50.0108 3012        UmPass - ok
12:29:50.0169 3012        usbaudio        (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
12:29:50.0200 3012        usbaudio - ok
12:29:50.0220 3012        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
12:29:50.0255 3012        usbccgp - ok
12:29:50.0279 3012        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
12:29:50.0313 3012        usbcir - ok
12:29:50.0334 3012        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
12:29:50.0356 3012        usbehci - ok
12:29:50.0406 3012        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
12:29:50.0434 3012        usbhub - ok
12:29:50.0475 3012        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
12:29:50.0499 3012        usbohci - ok
12:29:50.0528 3012        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
12:29:50.0557 3012        usbprint - ok
12:29:50.0578 3012        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:29:50.0606 3012        USBSTOR - ok
12:29:50.0620 3012        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
12:29:50.0640 3012        usbuhci - ok
12:29:50.0668 3012        VClone          (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys
12:29:50.0690 3012        VClone - ok
12:29:50.0728 3012        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
12:29:50.0743 3012        vdrvroot - ok
12:29:50.0768 3012        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
12:29:50.0782 3012        vga - ok
12:29:50.0794 3012        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
12:29:50.0834 3012        VgaSave - ok
12:29:50.0865 3012        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
12:29:50.0877 3012        vhdmp - ok
12:29:50.0894 3012        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
12:29:50.0903 3012        viaide - ok
12:29:50.0932 3012        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
12:29:50.0941 3012        volmgr - ok
12:29:50.0988 3012        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
12:29:51.0001 3012        volmgrx - ok
12:29:51.0021 3012        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
12:29:51.0033 3012        volsnap - ok
12:29:51.0064 3012        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
12:29:51.0075 3012        vsmraid - ok
12:29:51.0099 3012        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
12:29:51.0121 3012        vwifibus - ok
12:29:51.0138 3012        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
12:29:51.0155 3012        WacomPen - ok
12:29:51.0190 3012        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
12:29:51.0227 3012        WANARP - ok
12:29:51.0241 3012        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
12:29:51.0270 3012        Wanarpv6 - ok
12:29:51.0299 3012        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
12:29:51.0308 3012        Wd - ok
12:29:51.0333 3012        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
12:29:51.0350 3012        Wdf01000 - ok
12:29:51.0376 3012        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
12:29:51.0406 3012        WfpLwf - ok
12:29:51.0422 3012        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
12:29:51.0431 3012        WIMMount - ok
12:29:51.0485 3012        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
12:29:51.0508 3012        WinUsb - ok
12:29:51.0526 3012        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
12:29:51.0538 3012        WmiAcpi - ok
12:29:51.0557 3012        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
12:29:51.0595 3012        ws2ifsl - ok
12:29:51.0635 3012        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
12:29:51.0674 3012        WudfPf - ok
12:29:51.0705 3012        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
12:29:51.0742 3012        WUDFRd - ok
12:29:51.0760 3012        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
12:29:51.0870 3012        \Device\Harddisk0\DR0 - ok
12:29:51.0874 3012        Boot (0x1200)  (1b20caf158eaad23477aa9a8317139d0) \Device\Harddisk0\DR0\Partition0
12:29:51.0875 3012        \Device\Harddisk0\DR0\Partition0 - ok
12:29:51.0876 3012        ============================================================
12:29:51.0877 3012        Scan finished
12:29:51.0877 3012        ============================================================
12:29:51.0892 2804        Detected object count: 1
12:29:51.0892 2804        Actual detected object count: 1
12:48:39.0029 2804        sptd ( LockedFile.Multi.Generic ) - skipped by user
12:48:39.0029 2804        sptd ( LockedFile.Multi.Generic ) - User select action: Skip
12:48:58.0474 4036        Deinitialize success


Noch kurz ein Hinweis: Ich werde berufsbedingt die nächsten Tage unterwegs sein, und kann deswegen nicht sofort reagieren wenn Du mir den nächsten Schritt schickst. Ich habe hier im Forum gesehen, dass Mandate nach 3 Tagen ohne Rückmeldung niedergelegt werden, und wollte Dich bitten, dies in diesem Fall nicht zu tun. Du kannst mir einfach den nächsten Schritt hier posten und ich werde ihn spätestens nächstes Wochenende ausführen.

Vielen Dank!

cosinus 02.01.2012 14:12

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Doppelgrunz 07.01.2012 15:50

Okay, Combofix ausgeführt und das hier ist die logdatei:

Code:

Combofix Logfile:

       
Code:

       
ComboFix 12-01-06.03 - garry 07.01.2012  15:35:22.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3263.2163 [GMT 1:00]
ausgeführt von:: c:\users\garry\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\garry\AppData\Roaming\dwlGina3.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-12-07 bis 2012-01-07  ))))))))))))))))))))))))))))))
.
.
2012-01-07 14:39 . 2012-01-07 14:39        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-07 14:26 . 2011-11-21 11:40        8822856        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{09363A2A-5C9F-477C-8AD3-440C0B63060B}\mpengine.dll
2011-12-30 03:03 . 2011-12-30 03:03        --------        d-----w-        c:\program files (x86)\ESET
2011-12-30 02:03 . 2011-12-30 02:03        --------        d-----w-        c:\users\garry\AppData\Roaming\Malwarebytes
2011-12-30 02:00 . 2011-12-30 02:00        --------        d-----w-        c:\programdata\Malwarebytes
2011-12-30 02:00 . 2011-12-30 02:00        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-30 02:00 . 2011-12-10 14:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-27 09:09 . 2011-07-13 02:55        2237440        ----a-r-        C:\OTLPE.exe
2011-12-27 09:09 . 2011-12-27 03:47        --------        d-----w-        C:\_OTL
2011-12-26 07:10 . 2011-12-26 07:23        --------        d-----w-        C:\Malwarebytes' Anti-Malware
2011-12-25 16:12 . 2011-12-25 19:44        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
2011-12-18 19:36 . 2011-12-18 19:36        --------        d-----w-        c:\windows\system32\Macromed
2011-12-16 21:37 . 2011-11-24 04:52        3145216        ----a-w-        c:\windows\system32\win32k.sys
2011-12-16 21:37 . 2011-10-15 06:31        723456        ----a-w-        c:\windows\system32\EncDec.dll
2011-12-16 21:37 . 2011-10-15 05:38        534528        ----a-w-        c:\windows\SysWow64\EncDec.dll
2011-12-16 21:37 . 2011-11-05 05:32        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-12-16 21:37 . 2011-11-05 04:26        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 19:38 . 2011-06-12 11:32        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-15 13:29 . 2010-03-20 17:39        270720        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPS Accelerator"="c:\program files (x86)\PPStream\ppsap.exe" [2010-02-24 214408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-08-05 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-12 281768]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech Webcam 200(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-05-05 136360]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT-Treiber;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper        REG_MULTI_SZ           getPlusHelper
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\garry\AppData\Roaming\Mozilla\Firefox\Profiles\if8yly7h.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
AddRemove-PriceGong - c:\program files (x86)\PriceGong\uninst.exe
AddRemove-Winamp Toolbar - c:\program files (x86)\Winamp Toolbar\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1749393697-2492884230-3525210288-1000\Software\SecuROM\License information*]
"datasecu"=hex:70,46,99,c5,fa,c7,d6,2c,b3,21,50,40,ef,d9,7e,1d,66,61,11,2e,96,
   91,70,eb,47,d6,29,60,35,94,6b,f9,1c,c2,d4,9a,50,88,9e,29,50,04,fa,b4,d3,90,\
"rkeysecu"=hex:aa,2d,c4,ca,c2,6d,a1,98,6f,68,f0,2b,73,62,35,0c
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\IoctlSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-01-07  15:44:46 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-01-07 14:44
.
Vor Suchlauf: 18 Verzeichnis(se), 389.597.216.768 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 389.068.849.152 Bytes frei
.
- - End Of File - - 918620FEBCD4DDA0CA49433624D43CE9


--- --- ---

Was jetzt?

cosinus 07.01.2012 16:29

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Doppelgrunz 07.01.2012 17:29

Hier die Logdatei:

Code:

aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-07 17:03:46
-----------------------------
17:03:46.633    OS Version: Windows x64 6.1.7601 Service Pack 1
17:03:46.636    Number of processors: 2 586 0x170A
17:03:46.637    ComputerName: LARRY  UserName: garry
17:03:49.314    Initialize success
17:06:28.138    AVAST engine defs: 12010700
17:09:41.641    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
17:09:41.644    Disk 0 Vendor: STM3500418AS CC35 Size: 476940MB BusType: 3
17:09:41.653    Disk 0 MBR read successfully
17:09:41.656    Disk 0 MBR scan
17:09:41.662    Disk 0 Windows 7 default MBR code
17:09:41.667    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      476938 MB offset 2048
17:09:41.672    Service scanning
17:09:44.291    Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
17:09:45.398    Modules scanning
17:09:45.403    Disk 0 trace - called modules:
17:09:45.423    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80033d92c0]<<
17:09:45.426    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800368f060]
17:09:45.430    3 CLASSPNP.SYS[fffff88001bcb43f] -> nt!IofCallDriver -> [0xfffffa8003517e40]
17:09:45.758    5 ACPI.sys[fffff880010447a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa8003544060]
17:09:45.764    \Driver\atapi[0xfffffa80034ecd60] -> IRP_MJ_CREATE -> 0xfffffa80033d92c0
17:09:48.152    AVAST engine scan C:\Windows
17:09:52.813    AVAST engine scan C:\Windows\system32
17:11:47.494    AVAST engine scan C:\Windows\system32\drivers
17:12:00.456    AVAST engine scan C:\Users\garry
17:21:46.428    AVAST engine scan C:\ProgramData
17:23:11.112    Scan finished successfully
17:27:36.664    Disk 0 MBR has been saved successfully to "C:\Users\garry\Downloads\MBR.dat"
17:27:36.669    The log file has been saved successfully to "C:\Users\garry\Downloads\aswMBR.txt"

Kurz eine Frage: Wieviele Schritte sind es noch? Kannst Du mir kurz sagen, wonach wir eigentlich suchen? Vielen Dank!

cosinus 07.01.2012 17:48

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Doppelgrunz 08.01.2012 01:26

Malwarebytes Scan:

Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.07.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
garry :: LARRY [Administrator]

Schutz: Aktiviert

07.01.2012 20:18:57
mbam-log-2012-01-07 (20-18-57).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 370549
Laufzeit: 44 Minute(n), 57 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

SASW log:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/07/2012 at 09:21 PM

Application Version : 5.0.1142

Core Rules Database Version : 8112
Trace Rules Database Version: 5924

Scan type      : Quick Scan
Total Scan Time : 00:09:59

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 550
Memory threats detected  : 0
Registry items scanned    : 61305
Registry threats detected : 0
File items scanned        : 28358
File threats detected    : 426

Adware.Tracking Cookie
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\M1C0K6UZ.txt [ /2o7.net ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\VG2D09JU.txt [ /atdmt.com ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\REFAT3GM.txt [ /questionmarket.com ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\EP45TYQQ.txt [ /c.atdmt.com ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\E8T9GQKN.txt [ /doubleclick.net ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\QYIN0OVB.txt [ /mediav.com ]
        C:\Users\garry\AppData\Roaming\Microsoft\Windows\Cookies\ZMYE3S63.txt [ /microsoftwllivemkt.112.2o7.net ]
        C:\USERS\GARRY\AppData\Roaming\Microsoft\Windows\Cookies\Low\VAL06FFD.txt [ Cookie:garry@2o7.net/ ]
        C:\USERS\GARRY\AppData\Roaming\Microsoft\Windows\Cookies\Low\WX79CELJ.txt [ Cookie:garry@atdmt.com/ ]
        C:\USERS\GARRY\Cookies\M1C0K6UZ.txt [ Cookie:garry@2o7.net/ ]
        C:\USERS\GARRY\Cookies\VG2D09JU.txt [ Cookie:garry@atdmt.com/ ]
        C:\USERS\GARRY\Cookies\REFAT3GM.txt [ Cookie:garry@questionmarket.com/ ]
        C:\USERS\GARRY\Cookies\EP45TYQQ.txt [ Cookie:garry@c.atdmt.com/ ]
        C:\USERS\GARRY\Cookies\E8T9GQKN.txt [ Cookie:garry@doubleclick.net/ ]
        C:\USERS\GARRY\Cookies\QYIN0OVB.txt [ Cookie:garry@mediav.com/ ]
        .doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        lyricfind.rotator.hadj7.adjuggler.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        lyricfind.rotator.hadj7.adjuggler.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        lyricfind.rotator.hadj7.adjuggler.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        lyricfind.rotator.hadj7.adjuggler.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        lyricfind.rotator.hadj7.adjuggler.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ads.247activemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adsrv1.admediate.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .leylines.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .leylines.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .leylines.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .leylines.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        medianac.nacamar.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .germanwings.112.2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .opodo.122.2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        airfrance.bannerfactory.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.mindshare.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .content.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.ad-track.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ads.adxvalue.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .pmu3.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .pmu3.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .pmu3.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .pmu3.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .openstat.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .spylog.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .h.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        webclickmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        webclickengine.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .sfr.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .sfr.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .sfr.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .sfr.solution.weborama.fr [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adserver2.clipkit.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .viacom.adbureau.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .viacom.adbureau.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .viacom.adbureau.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adlegend.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adlegend.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.mlsat02.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .unitymedia.de [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\GARRY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IF8YLY7H.DEFAULT\COOKIES.SQLITE ]

ESET scan

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=35f9a08f42ac7f40949d4756a8bcd331
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-30 04:23:46
# local_time=2011-12-30 05:23:46 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1797 16775165 100 94 0 61754917 1103 0
# compatibility_mode=5893 16776573 100 94 0 76844311 0 0
# compatibility_mode=8192 67108863 100 0 3879 3879 0 0
# compatibility_mode=9217 16777214 75 66 11297271 27175163 0 0
# scanned=215441
# found=18
# cleaned=0
# scan_time=4565
C:\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\Local\Temp\NERO14992\Toolbar.exe        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\358d72cc-4ecd8dc1        Java/Exploit.CVE-2011-3544.L trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\150cad71-34025faa        Java/Exploit.CVE-2011-3544.L trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\freeripmp3.61-setup.exe        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SoftonicDownloader_fuer_magix-mp3-maker.exe        a variant of Win32/SoftonicDownloader.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\40094e8.msi        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Application Updater\ApplicationUpdater.exe        probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=35f9a08f42ac7f40949d4756a8bcd331
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-07 10:38:10
# local_time=2012-01-07 11:38:10 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1797 16775165 100 94 0 62512229 21902 0
# compatibility_mode=5893 16776573 100 94 27601 77601623 0 0
# compatibility_mode=8192 67108863 100 0 761191 761191 0 0
# scanned=201068
# found=14
# cleaned=0
# scan_time=4117
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\freeripmp3.61-setup.exe        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SoftonicDownloader_fuer_magix-mp3-maker.exe        a variant of Win32/SoftonicDownloader.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\garry\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\40094e8.msi        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Application Updater\ApplicationUpdater.exe        probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12272011_040919\C_Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe        a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\12312011_192216\C_Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I

Was jetzt?

cosinus 08.01.2012 01:48

Da sind nur Cookies und ein paar Adware-Reste.
Löschen wir mit OTL

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":Files" muss mitkopiert werden!!!)

Code:

:Files
C:\Program Files (x86)\Common Files\Spigot
C:\Users\garry\Downloads\freeripmp3.61-setup.exe
C:\Users\garry\Downloads\SoftonicDownloader*
C:\Users\garry\Downloads\SweetImSetup.exe
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Doppelgrunz 08.01.2012 03:39

Okay, fix in OTL durchgeführt. Hier das log:

Code:

All processes killed
========== FILES ==========
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\wtxpcom folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Res folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Lang folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot folder moved successfully.
C:\Users\garry\Downloads\freeripmp3.61-setup.exe moved successfully.
C:\Users\garry\Downloads\SoftonicDownloader_fuer_magix-mp3-maker.exe moved successfully.
C:\Users\garry\Downloads\SweetImSetup.exe moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
->Temp folder emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: garry
->Temp folder emptied: 176296710 bytes
->Temporary Internet Files folder emptied: 50370571 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 116449226 bytes
->Flash cache emptied: 3255 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1678 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 327,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 01082012_033454

Files\Folders moved on Reboot...
C:\Users\garry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Was jetzt?

cosinus 08.01.2012 19:56

Ok der Rest wurde auch entfernt. Den Ornder C:\_OTL kannst du jetzt meinetwegen auch löschen
Rechner soweit wieder im Lot?

Doppelgrunz 08.01.2012 20:25

Hallo Arne,

soweit ich es überblicken kann, ist der Rechner jetzt wieder in Ordnung. Ich habe es geschafft, die Desktop Icons wiederbekommen (durch eigene Recherche), und der Task Manager ist auch nicht mehr gesperrt. Ich habe noch nicht alle Programme wieder ausprobiert, aber das wichtigste war ja, erstmal wieder Zugriff auf den Rechner zu bekommen.

Abschließend möchte ich noch sagen, dass ich es wirklich fantastisch finde, dass ihr mir und anderen Computergeplagten hier quasi umsonst aus der Patsche helft! Ich hätte mich über ein wenig mehr Kommunikation gefreut (also dass auch auf meine Fragen mehr eingegangen wird und sie vielleicht auch mal beantwortet werden), aber da ihr sehr viele Anfragen bekommt kann ich schon verstehen, dass dies hier kein Chat ist sondern ein Forum wo einem geholfen wird (auch wenn man nachher nicht wirklich nachvollziehen kann was am Anfang mit dem Rechner schief gelaufen ist oder was genau gemacht wurde um das Problem zu beheben). Auf jeden Fall läuft mein Rechner jetzt wieder, und ich werde jetzt alle Dateien sichern bevor es weitergeht.

Danke nochmal an Dich! :dankeschoen:

Vielleicht noch eine kurze Frage zum Abschluss: Was soll ich mit den Programmen machen, die ich im Zuge unserer Rettungsaktion auf den Computer geladen habe (Malwarebytes, SASW, ESET ...)? Soll ich die genauso löschen wie OTL?

Beste Grüße,
Doppelgrunz

cosinus 08.01.2012 21:28

Zitat:

Ich hätte mich über ein wenig mehr Kommunikation gefreut
Ich beantworte immer Fragen wenn ich das kann aber sowas mach ich wirklich nicht gerne in einer laufenden Bereinigung weil man dann immer wieder vom Thema wegkommt. Ich hab das anfangs mal gemacht aber mittlerweile nicht mehr. Fragen beantowrte ich wenn man soweit durch ist.

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:29 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131