Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Unbekannter Virus: Windows Explorer stürzt ab, Rechner teilweise stark verlangsamt usw. (https://www.trojaner-board.de/111005-unbekannter-virus-windows-explorer-stuerzt-ab-rechner-teilweise-stark-verlangsamt-usw.html)

markus32 06.03.2012 14:39

Unbekannter Virus: Windows Explorer stürzt ab, Rechner teilweise stark verlangsamt usw.
 
Hi,

vor einigen Tagen reagierte mein Laptop beim anmelden in meinem üblichen Benutzerkonto zunächst gar nicht, nach einigen Minuten dann meistens ein Blackout.
Im "Gast" Benutzerkonto sowie im abgesichterten Modus schien jedoch alles normal. Mittlerweile habe ich (mit dem Programm Malwarebytes Anti-Malware) es hinbekommen, das ich mich zumindest in meinem normalen Benutzerkonto einloggen kann. Das Programm hatte einen Virus angezeigt und diesen entfernt, in den Logfiles steht aber leider nicht mehr was das für ein Virus war.

Jedoch reagiert der Laptop auch nach dem Scan in den ersten 5 Minuten nach dem Anmelden ins normale Benutzerkonto auch nur sehr verzögert, der Windows Explorer stürzt sehr sehr häufig ab, und beim Herunterfahren hängt er Stundenlang beim "Abmelden..."-Bildschirm fest.

Avira Antivir zeigt mittlerweile bei einem vollständigen Scan an, dass möglicherweise ein verdeckter Virus gefunden wurde, aber man müsse für einen erneuten Scan neustarten. Nach dem Neustart macht Avira jedoch wieder gar nix.

Das DDS und Attach Logfile ist im Anhang.

Viele Grüße, Markus

cosinus 07.03.2012 00:48

Zitat:

Das Programm hatte einen Virus angezeigt und diesen entfernt, in den Logfiles steht aber leider nicht mehr was das für ein Virus war.
Das ist eigentlich Quatsch. Malwarebytes speichert alle Logs automatisch, sichtbar sind sie im Reiter Logdateien

markus32 07.03.2012 09:46

Das dachte ich auch, ja. Ich hab leider auch keine Ahnung wieso der nicht aufgelistet wird. Alle Logs sind da, bis auf das erste in dem der Virus gefunden wurde.

cosinus 07.03.2012 11:53

Hast du da den Scan mit einem anderen Windows-Benutzer gemacht? Die Logs sind benutzerabhängig

markus32 07.03.2012 17:03

Vielen Dank!
Malwarebytes hat folgendes gefunden:
Zitat:

Infizierte Dateien: 1
C:\Windows\Installer\MSI3B6A.tmp (HackTool.Hiderun) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Die Probleme (v.A. Verlangsamung des Computers, Windows Explorer Abstürze) sind nach wie vor vorhanden.

cosinus 07.03.2012 22:17

Was soll sowas?! Unvollständige Logs sind sinnfrei!

markus32 07.03.2012 22:32

Ich hatte für eine bessere Übersicht die Teile des Logs, in denen nichts unaufälliges stand gekürzt. Hier der ganze Log:

Zitat:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: v2012.03.04.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Allgemein :: CHRISTIAN [Administrator]

Schutz: Aktiviert

04.03.2012 15:20:50
mbam-log-2012-03-04 (15-20-50).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 211440
Laufzeit: 37 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Windows\Installer\MSI3B6A.tmp (HackTool.Hiderun) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

cosinus 07.03.2012 23:35

Zitat:

in denen nichts unaufälliges stand gekürzt.
So ein Log hat aber ein paar mehr Infos als nur Fund oder kein Fund!

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

markus32 08.03.2012 14:32

Malwarebytes:
Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.06.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Christian :: CHRISTIAN [Administrator]

Schutz: Aktiviert

07.03.2012 23:39:11
mbam-log-2012-03-07 (23-39-11).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 652479
Laufzeit: 2 Stunde(n), 37 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)



ESET-Log:
Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=230ceba1dc46c643a8c487a75358050f
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-07 11:00:04
# local_time=2012-03-08 12:00:04 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 12480688 12480688 0 0
# compatibility_mode=5893 16776573 100 94 7770 82791016 0 0
# compatibility_mode=8192 67108863 100 0 3866 3866 0 0
# scanned=1405
# found=0
# cleaned=0
# scan_time=38
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=230ceba1dc46c643a8c487a75358050f
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-08 01:24:38
# local_time=2012-03-08 02:24:38 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 12487380 12487380 0 0
# compatibility_mode=5893 16776574 100 94 8383 82797708 0 0
# compatibility_mode=8192 67108863 100 0 10558 10558 0 0
# scanned=455792
# found=2
# cleaned=0
# scan_time=45240
C:\Windows\FixCamera.exe        a variant of Win32/KillProc.A application (unable to clean)        00000000000000000000000000000000        I
${Memory}        a variant of Win32/KillProc.A application        00000000000000000000000000000000        I


cosinus 08.03.2012 14:37

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


markus32 08.03.2012 16:14

Aufgrund der Länge hab ich das File als Anhang im nächsten Post ("Neuer ZIP-komprimierter Ordner.zip") hochgeladen.

Ansonsten, hier der erste Teil der OTL.txt:

Code:

OTL logfile created on: 08.03.2012 15:31:44 - Run 1
OTL by OldTimer - Version 3.2.36.1    Folder = C:\Users\Christian\Videos\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,97 Gb Total Physical Memory | 2,43 Gb Available Physical Memory | 61,40% Memory free
7,93 Gb Paging File | 5,60 Gb Available in Paging File | 70,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111,77 Gb Total Space | 25,86 Gb Free Space | 23,14% Space Free | Partition Type: NTFS
Drive F: | 106,42 Gb Total Space | 33,37 Gb Free Space | 31,35% Space Free | Partition Type: NTFS
Drive H: | 7,39 Gb Total Space | 7,39 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
 
Computer Name: CHRISTIAN | User Name: Christian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Christian\Videos\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\Last.fm\LastFM.exe (Last.fm)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files (x86)\FreePDF_XP\fpassist.exe (shbox.de)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\tsnpstd3.exe ()
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Windows\FixCamera.exe ()
PRC - C:\Windows\vsnpstd3.exe ()
PRC - C:\Program Files (x86)\Creative\Creative Live! Cam\VideoFX\StartFX.exe (Creative Technology Ltd.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\eedf95f16a7e81ca43dd8accf11498a3\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\OutputLog.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Programme\TortoiseSVN\bin\libsasl32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll ()
MOD - C:\Program Files (x86)\Last.fm\ext_messengernotify.dll ()
MOD - C:\Program Files (x86)\Last.fm\ext_skypenotify.dll ()
MOD - C:\Program Files (x86)\Last.fm\srv_madtranscode.dll ()
MOD - C:\Program Files (x86)\Last.fm\srv_httpinput.dll ()
MOD - C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll ()
MOD - C:\Program Files (x86)\Last.fm\breakpad.dll ()
MOD - C:\Program Files (x86)\Last.fm\Moose1.dll ()
MOD - C:\Program Files (x86)\Last.fm\LastFmTools1.dll ()
MOD - C:\Program Files (x86)\Last.fm\libfftw3f-3.dll ()
MOD - C:\Program Files (x86)\Last.fm\zlibwapi.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Windows\tsnpstd3.exe ()
MOD - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files (x86)\Last.fm\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Last.fm\QtSql4.dll ()
MOD - C:\Program Files (x86)\Last.fm\QtGui4.dll ()
MOD - C:\Program Files (x86)\Last.fm\QtXml4.dll ()
MOD - C:\Program Files (x86)\Last.fm\QtCore4.dll ()
MOD - C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll ()
MOD - C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll ()
MOD - C:\Windows\FixCamera.exe ()
MOD - C:\Windows\vsnpstd3.exe ()
MOD - C:\Program Files (x86)\Creative\Creative Live! Cam\VideoFX\EyeCatcherEx.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (wltrysvc) -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (vpnagent) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (Secunia PSI Agent) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) -- C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (CVPND) -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe ()
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DockLoginService) -- C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (taphss) -- C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (vpnva) -- C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (acsock) -- C:\Windows\SysNative\drivers\acsock64.sys (Cisco Systems, Inc.)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (PSI) -- C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (BDA_Loader_225) -- C:\Windows\SysNative\drivers\BDA_Loader_225_x64.sys (WideView Technology Inc.)
DRV:64bit: - (BDA_Capture_225) -- C:\Windows\SysNative\drivers\BDA_Capture_225_x64.sys (WideViewer Electronics CO., LTD)
DRV:64bit: - (CVPNDRVA) -- C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (CVirtA) -- C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (StarOpen) -- C:\Windows\SysNative\drivers\StarOpen.sys ()
DRV:64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\Windows\SysNative\drivers\snpstd3.sys (Sonix Co. Ltd.)
DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (rimmptsk) -- C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) -- C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) -- C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (k57nd60a) Broadcom NetLink (TM) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (DNE) -- C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks, Inc.)
DRV:64bit: - (ManyCam) -- C:\Windows\SysNative\drivers\ManyCam_x64.sys (ManyCam LLC.)
DRV:64bit: - (SynasUSB) -- C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) -- c:\Programme\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV - (StarOpen) -- C:\Windows\SysWow64\drivers\StarOpen.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\Windows\SysWOW64\drivers\snpstd3.sys (Sonix Co. Ltd.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0540005F-107E-4C4D-B1CD-64DE04847137}
IE:64bit: - HKLM\..\SearchScopes\{0540005F-107E-4C4D-B1CD-64DE04847137}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKLM\..\SearchScopes\{3E4A5BD3-2D23-461A-98CD-FC106A31775C}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\..\SearchScopes\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}: "URL" = hxxp://search.kikin.com/search/?q={searchTerms}
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: multilinks@plugin:3.0.0.16
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: facepad@lazyrussian.com:0.9.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: fbchathistory@firechm.com:1.1.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.autoconfig_url: "hxxp://pac.lrz.de/"
FF - prefs.js..network.proxy.type: 2
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Christian\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Christian\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Christian\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Christian\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Christian\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.03.08 00:41:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.08 00:46:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.08 00:35:47 | 000,000,000 | ---D | M]
 
[2009.12.09 17:15:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions
[2012.03.06 21:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions
[2012.01.31 18:47:24 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2012.03.05 17:49:37 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.08.06 16:20:25 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.03.05 17:49:37 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.01.25 20:37:18 | 000,000,000 | ---D | M] (PhotoJacker: Photo Album Downloader for Facebook (fka FacePAD)) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\facepad@lazyrussian.com
[2011.03.26 10:30:06 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\ietab@ip.cn
[2009.12.30 20:55:03 | 000,000,000 | ---D | M] (Snap Links Plus with Checkboxes Extension) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\dkqm69cp.default\extensions\snaplinks_checkboxes@mozilla.org
[2012.03.08 00:46:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DKQM69CP.DEFAULT\EXTENSIONS\CLIENT@ANONYMOX.NET.XPI
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DKQM69CP.DEFAULT\EXTENSIONS\MULTILINKS@PLUGIN.XPI
[2012.02.16 15:55:34 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.03.08 00:32:39 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.07.11 22:48:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.02.16 12:08:43 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012.02.16 11:48:01 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.16 12:08:43 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012.02.16 12:08:43 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012.02.16 12:08:43 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: MetaProducts Download Express integration (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkppcbheeedepkoakmkmnjjnfefhhakh\1.1.2_0\plugin/mpde.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Christian\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Christian\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Christian\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Unfriend Finder for Facebook = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecolodplncpedbpiicabmflhfemjnool\14_0\
CHR - Extension: Google Kalender = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: PanicButton = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm\0.14.1.5_0\
CHR - Extension: AdBlock = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.20_0\
CHR - Extension: cats = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmekamlpkbcegncocdmhnoogddkeekgn\1_0\
CHR - Extension: BrowserTexting = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\idijdgooojpepbnadlbkiagcmilndffa\1.27_0\
CHR - Extension: Snap Links Lite = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\idmmhhijggcmbeejedibpdcahpkneegg\1.2.4_0\
CHR - Extension: uSelect iDownload = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ileabdhfjmgaognikmjgmhhkjffggejc\1.3_0\
CHR - Extension: Unfriend Finder = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kddnblacojpnmjdlpnndlcamnmmkfina\35_0\
CHR - Extension: StayFocusd = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji\1.2.0.15_0\
CHR - Extension: TeX The World for Chromium = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbfninnbhfepghkkcgdnmfmhhbjmhggn\1.3.2_1\
CHR - Extension: Google Dictionary (by Google) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.11_0\
CHR - Extension: Google Mail-Checker = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Google Play Books = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.3_0\
CHR - Extension: MetaProducts Download Express integration = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkppcbheeedepkoakmkmnjjnfefhhakh\1.1.2_0\
 
O1 HOSTS File: ([2011.10.15 13:35:32 | 000,002,415 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com     
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 activate.adobe.com:443
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
O1 - Hosts: 27 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Programme\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Programme\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVFX Engine] C:\Program Files (x86)\Creative\Creative Live! Cam\VideoFX\StartFX.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files (x86)\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NuonSoft ShellEnhancer StartupHelper] C:\Program Files (x86)\NuonSoft\ShellEnhancer\StartupHelper.exe ()
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1302499063-601275286-625076348-1000..\Run: [AdobeBridge]  File not found
O4 - HKU\S-1-5-21-1302499063-601275286-625076348-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1302499063-601275286-625076348-1000..\Run: [Facebook Update] C:\Users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-1302499063-601275286-625076348-1000..\Run: [PureSync] C:\Program Files (x86)\PureSync\PureSyncTray.exe (Jumping Bytes)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Allgemein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk =  File not found
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.euro.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35545307-1B5F-45FC-B0D5-FBFAE5B7A543}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D6FBEC54-3FF1-4B6E-9489-E3E145A96D8B}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30:64bit: - LSA: Authentication Packages - (setuid) - C:\Windows\SysWow64\setuid.dll (March-Hare Software Ltd)
O30 - LSA: Authentication Packages - (setuid) - C:\Windows\SysWow64\setuid.dll (March-Hare Software Ltd)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\Shell - "" = AutoRun
O33 - MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: WheelMouse - hkey= - key= - C:\Program Files (x86)\Mouse Driver\4DMAIN.EXE ()
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: mcmscsvc - Service
SafeBootMin:64bit: MCODS - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: mcmscsvc - Service
SafeBootMin: MCODS - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: mcmscsvc - Service
SafeBootNet:64bit: MCODS - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MpfService - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: mcmscsvc - Service
SafeBootNet: MCODS - Service
SafeBootNet: Messenger - Service
SafeBootNet: MpfService - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {74FA3C8A-1739-4AE0-B578-0E4E288B6688} - C:\ProgramData\VoicePro12\VoiceProInstallCurrentUser.exe install
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {AC053600-5E30-EDF4-B393-7DCC6AA46DEA} - Internet Explorer
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.08 00:35:26 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.03.08 00:33:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.03.08 00:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.03.08 00:13:51 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Local\Secunia PSI
[2012.03.07 23:55:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.03.07 22:40:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2012.03.06 18:38:50 | 000,000,000 | ---D | C] -- C:\Users\Christian\Documents\MATLAB
[2012.03.06 18:38:50 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\MathWorks
[2012.03.06 17:40:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB
[2012.03.06 17:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\MATLAB
[2012.03.06 15:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.06 15:48:06 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.03.06 15:48:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.04 18:45:01 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\Malwarebytes
[2012.03.04 15:17:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.02.27 14:11:57 | 000,000,000 | ---D | C] -- C:\Users\Christian\Desktop\Studium
[2012.02.19 18:21:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.02.17 13:09:17 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\Jumping Bytes
[2012.02.17 13:03:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PureSync
[2012.02.17 13:03:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PureSync
[2012.02.17 13:03:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Jumping Bytes
[2012.02.17 12:10:26 | 000,000,000 | R--D | C] -- C:\Users\Christian\Saved Games
[2012.02.17 12:10:26 | 000,000,000 | R--D | C] -- C:\Users\Christian\Links
[2012.02.17 12:10:26 | 000,000,000 | R--D | C] -- C:\Users\Christian\Contacts
[2012.02.16 22:44:33 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\TuneUp Software
[2012.02.16 22:43:23 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.02.16 22:43:11 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012.02.16 16:32:14 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\mkvtoolnix
[2012.02.16 16:31:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix
[2012.02.16 16:31:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MKVToolNix
[2012.02.16 10:32:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011.10.15 18:27:56 | 004,962,008 | ---- | C] (Flexera Software) -- C:\Program Files (x86)\MapleToolbox_WindowsX86_64.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.08 11:01:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.08 00:46:33 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.07 23:32:27 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.07 23:32:27 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.07 23:24:15 | 3193,585,664 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.07 22:41:10 | 000,328,630 | ---- | M] () -- C:\Users\Christian\Desktop\Bleistift Llösungen.pdf
[2012.03.07 22:40:06 | 000,001,068 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.03.07 17:03:41 | 000,002,424 | ---- | M] () -- C:\Users\Christian\Desktop\Google Chrome.lnk
[2012.03.07 09:54:32 | 000,023,552 | ---- | M] () -- C:\Users\Christian\3160773_460s.jpg
[2012.03.07 09:51:52 | 000,186,091 | ---- | M] () -- C:\Users\Christian\3171050_460s.jpg
[2012.03.07 09:51:06 | 000,269,904 | ---- | M] () -- C:\Users\Christian\3170574_460s.jpg
[2012.03.07 09:50:02 | 000,045,113 | ---- | M] () -- C:\Users\Christian\3168541_460s.jpg
[2012.03.07 09:48:26 | 000,062,892 | ---- | M] () -- C:\Users\Christian\3159779_460s.jpg
[2012.03.06 22:23:44 | 000,033,491 | ---- | M] () -- C:\Users\Christian\407868_352929411404069_174773712552974_1048462_2032134122_n.jpg
[2012.03.06 18:30:43 | 000,000,554 | ---- | M] () -- C:\Windows\tasks\MATLAB R2011b Startup Accelerator.job
[2012.03.06 17:40:03 | 000,001,309 | ---- | M] () -- C:\Users\Christian\Desktop\MATLAB R2011b.lnk
[2012.03.06 15:48:07 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.06 12:51:55 | 001,623,448 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.06 12:51:55 | 000,701,140 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.06 12:51:55 | 000,655,522 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.06 12:51:55 | 000,149,680 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.06 12:51:55 | 000,122,394 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.02.28 10:43:06 | 001,599,970 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.28 00:22:47 | 000,056,273 | ---- | M] () -- C:\Users\Christian\2951314_460s.jpg
[2012.02.28 00:08:52 | 000,073,391 | ---- | M] () -- C:\Users\Christian\2978673_460s.jpg
[2012.02.24 18:22:52 | 001,570,931 | ---- | M] () -- C:\Users\Christian\Desktop\lernanleitung1.pdf
[2012.02.21 13:38:08 | 002,200,292 | ---- | M] () -- C:\Users\Christian\Desktop\Meine Facharbeit (1).pdf
[2012.02.21 13:06:23 | 000,001,017 | ---- | M] () -- C:\Users\Christian\Desktop\P1.lnk
[2012.02.19 14:30:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.02.19 14:10:04 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.17 13:04:02 | 000,000,899 | ---- | M] () -- C:\Users\Public\Desktop\PureSync.lnk
[2012.02.17 11:21:55 | 005,051,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.02.15 19:35:38 | 000,000,132 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.02.15 14:58:35 | 000,132,320 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.02.10 22:59:55 | 000,035,499 | ---- | M] () -- C:\Users\Christian\Desktop\small.png
[2012.02.08 23:55:00 | 000,001,136 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000UA.job
[2012.02.08 22:55:00 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000Core.job
[2012.02.08 21:08:33 | 000,001,826 | ---- | M] () -- C:\Users\Christian\Desktop\physik-lmu.lnk
 
========== Files Created - No Company Name ==========
 
[2012.03.08 00:46:33 | 000,001,020 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.07 22:41:13 | 000,328,630 | ---- | C] () -- C:\Users\Christian\Desktop\Bleistift Llösungen.pdf
[2012.03.07 22:40:06 | 000,001,068 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.03.07 22:40:06 | 000,001,031 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012.03.07 09:54:32 | 000,023,552 | ---- | C] () -- C:\Users\Christian\3160773_460s.jpg
[2012.03.07 09:51:53 | 000,186,091 | ---- | C] () -- C:\Users\Christian\3171050_460s.jpg
[2012.03.07 09:51:06 | 000,269,904 | ---- | C] () -- C:\Users\Christian\3170574_460s.jpg
[2012.03.07 09:50:03 | 000,045,113 | ---- | C] () -- C:\Users\Christian\3168541_460s.jpg
[2012.03.07 09:48:27 | 000,062,892 | ---- | C] () -- C:\Users\Christian\3159779_460s.jpg
[2012.03.06 22:23:50 | 000,033,491 | ---- | C] () -- C:\Users\Christian\407868_352929411404069_174773712552974_1048462_2032134122_n.jpg
[2012.03.06 19:52:19 | 000,001,309 | ---- | C] () -- C:\Users\Christian\Desktop\MATLAB R2011b.lnk
[2012.03.06 17:40:03 | 000,001,297 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2011b.lnk
[2012.03.06 17:39:56 | 000,000,554 | ---- | C] () -- C:\Windows\tasks\MATLAB R2011b Startup Accelerator.job
[2012.03.06 15:48:07 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.28 00:22:48 | 000,056,273 | ---- | C] () -- C:\Users\Christian\2951314_460s.jpg
[2012.02.28 00:08:56 | 000,073,391 | ---- | C] () -- C:\Users\Christian\2978673_460s.jpg
[2012.02.24 18:23:01 | 001,570,931 | ---- | C] () -- C:\Users\Christian\Desktop\lernanleitung1.pdf
[2012.02.21 13:34:41 | 002,200,292 | ---- | C] () -- C:\Users\Christian\Desktop\Meine Facharbeit (1).pdf
[2012.02.21 13:06:23 | 000,001,017 | ---- | C] () -- C:\Users\Christian\Desktop\P1.lnk
[2012.02.17 13:04:02 | 000,000,899 | ---- | C] () -- C:\Users\Public\Desktop\PureSync.lnk
[2012.02.10 22:59:53 | 000,035,499 | ---- | C] () -- C:\Users\Christian\Desktop\small.png
[2012.02.08 21:08:03 | 000,001,826 | ---- | C] () -- C:\Users\Christian\Desktop\physik-lmu.lnk
[2012.01.26 23:58:20 | 000,001,456 | ---- | C] () -- C:\Users\Christian\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2011.10.15 18:27:56 | 000,000,106 | ---- | C] () -- C:\Program Files (x86)\MapleToolbox.bat
[2011.10.15 18:25:10 | 000,253,797 | ---- | C] () -- C:\Program Files (x86)\Install.html
[2011.10.15 18:25:10 | 000,067,783 | ---- | C] () -- C:\Program Files (x86)\EULA.html
[2011.10.15 18:25:10 | 000,006,296 | ---- | C] () -- C:\Program Files (x86)\Maple Cloud Terms of Service.html
[2011.09.30 11:57:14 | 000,000,132 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011.09.26 09:51:08 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2011.02.01 17:06:45 | 344,120,320 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\Messages.qdb
[2011.01.15 17:11:24 | 000,000,132 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011.01.06 18:27:09 | 000,007,605 | ---- | C] () -- C:\Users\Christian\AppData\Local\Resmon.ResmonCfg
[2010.11.30 15:52:47 | 000,020,480 | ---- | C] () -- C:\Windows\FixCamera.exe
[2010.11.30 15:52:45 | 000,835,584 | ---- | C] () -- C:\Windows\vsnpstd3.exe
[2010.11.30 15:52:45 | 000,356,352 | ---- | C] () -- C:\Windows\tsnpstd3.exe
[2010.11.30 15:52:45 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini
[2010.11.30 15:52:44 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\rsnpstd3.dll
[2010.11.30 15:52:44 | 000,061,440 | ---- | C] ( ) -- C:\Windows\SysWow64\vsnpstd3.dll
[2010.11.30 15:52:43 | 000,053,248 | ---- | C] ( ) -- C:\Windows\csnpstd3.dll
[2010.11.02 19:45:32 | 000,000,132 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010.09.10 22:17:16 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.09.05 18:55:07 | 000,003,777 | ---- | C] () -- C:\Windows\scad3.INI
[2010.08.24 12:04:13 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.05.23 12:09:39 | 000,002,892 | ---- | C] () -- C:\Windows\SysWow64\audcon.sys
[2010.04.15 21:32:02 | 000,000,476 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\Poladroid prefs.plist
[2010.04.11 15:12:57 | 001,599,970 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.03.23 23:19:47 | 000,007,168 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2010.03.23 18:43:36 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
 
========== LOP Check ==========
 
[2010.06.07 12:39:27 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\GrabPro
[2012.02.28 17:16:01 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\HTC
[2011.03.03 18:14:31 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\ICQ
[2011.06.21 19:15:50 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\kikin
[2010.10.01 16:46:56 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\LockHunter
[2012.03.04 15:59:40 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\Orbit
[2011.09.27 16:04:20 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\ProgSense
[2011.11.25 14:33:47 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\Subversion
[2011.09.18 12:13:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Binary Fortress Software
[2010.03.23 23:19:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Canneverbe Limited
[2010.01.06 15:15:27 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Crazysoft
[2012.03.07 18:36:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DAEMON Tools Lite
[2011.02.23 17:08:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\diginet
[2012.02.02 01:40:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoft
[2011.09.08 11:58:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 15:47:12 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\FireShot
[2010.04.11 14:01:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GetRightToGo
[2010.05.22 15:17:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GrabPro
[2012.01.31 10:17:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC
[2011.09.19 13:44:38 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.02.02 06:16:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ
[2010.08.05 12:56:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\inkscape
[2012.02.17 13:09:17 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Jumping Bytes
[2011.02.21 19:45:37 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\kikin
[2009.12.10 21:14:56 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LockHunter
[2010.03.21 22:06:00 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ManyCam
[2012.02.16 16:32:14 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\mkvtoolnix
[2010.09.19 09:22:51 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\National Instruments
[2011.08.04 22:19:29 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenCandy
[2009.12.09 21:44:39 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org
[2012.03.08 14:28:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Orbit
[2010.12.12 14:09:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PCDr
[2010.10.02 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PhotoScape
[2010.08.16 20:28:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ProgSense
[2010.05.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Steinberg
[2010.04.21 21:01:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Stellarium
[2011.10.22 18:38:20 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Subversion
[2010.01.21 19:43:10 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\syntevo
[2010.02.02 21:32:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\temp
[2009.12.09 21:34:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template
[2012.02.16 22:44:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TuneUp Software
[2011.06.14 03:19:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Unified Remote
[2010.01.30 14:31:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\xm1
[2011.02.16 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\XMedia Recode
[2011.09.07 22:18:28 | 000,000,922 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000Core.job
[2011.09.08 13:45:00 | 000,000,944 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000UA.job
[2012.03.06 18:30:43 | 000,000,554 | ---- | M] () -- C:\Windows\Tasks\MATLAB R2011b Startup Accelerator.job
[2011.09.01 17:00:00 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011.09.08 16:25:48 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012.03.07 19:25:13 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.09.08 16:25:48 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.10.15 14:47:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Adobe
[2011.12.03 13:32:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Apple Computer
[2009.12.09 16:45:34 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ATI
[2011.10.15 13:08:42 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Avira
[2010.08.14 15:38:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\AVS4YOU
[2011.09.18 12:13:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Binary Fortress Software
[2010.03.23 23:19:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Canneverbe Limited
[2010.01.06 15:15:27 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Crazysoft
[2009.12.09 17:13:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Creative
[2009.12.09 20:21:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\CyberLink
[2012.03.07 18:36:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DAEMON Tools Lite
[2011.06.01 13:23:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Dell
[2011.02.23 17:08:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\diginet
[2011.11.26 13:31:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\dvdcss
[2012.02.02 01:40:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoft
[2011.09.08 11:58:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 15:47:12 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\FireShot
[2010.04.11 14:01:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GetRightToGo
[2010.05.22 15:17:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GrabPro
[2012.01.31 10:17:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC
[2011.09.19 13:44:38 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.02.02 06:16:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ
[2009.12.09 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Identities
[2010.08.05 12:56:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\inkscape
[2010.11.30 15:51:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\InstallShield
[2012.02.17 13:09:17 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Jumping Bytes
[2011.02.21 19:45:37 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\kikin
[2009.12.10 21:14:56 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LockHunter
[2009.12.09 16:49:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Macromedia
[2012.03.04 18:45:01 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Malwarebytes
[2010.03.21 22:06:00 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ManyCam
[2011.10.15 19:13:17 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mathematica
[2012.03.06 18:38:50 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MathWorks
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Media Center Programs
[2010.03.06 17:48:37 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Media Player Classic
[2011.11.16 17:41:03 | 000,000,000 | --SD | M] -- C:\Users\Christian\AppData\Roaming\Microsoft
[2010.01.30 13:51:45 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MiKTeX
[2012.02.16 16:32:14 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\mkvtoolnix
[2011.12.24 18:00:18 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla
[2010.09.19 09:22:51 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\National Instruments
[2011.08.04 22:19:29 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenCandy
[2009.12.09 21:44:39 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org
[2012.03.08 14:28:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Orbit
[2010.12.12 14:09:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PCDr
[2010.10.02 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PhotoScape
[2010.08.16 20:28:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ProgSense
[2010.03.06 18:33:59 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Real
[2009.12.09 18:34:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Reallusion
[2009.12.09 16:45:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roxio
[2009.12.09 19:12:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roxio Log Files
[2010.06.08 17:24:51 | 000,000,000 | RH-D | M] -- C:\Users\Christian\AppData\Roaming\SecuROM
[2012.03.07 22:59:34 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Skype
[2011.12.06 20:32:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\skypePM
[2010.05.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Steinberg
[2010.04.21 21:01:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Stellarium
[2011.10.22 18:38:20 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Subversion
[2010.01.21 19:43:10 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\syntevo
[2010.02.02 21:32:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\temp
[2009.12.09 21:34:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template
[2011.10.23 12:40:23 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TortoiseSVN
[2012.02.16 22:44:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TuneUp Software
[2011.06.14 03:19:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Unified Remote
[2012.03.04 16:52:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\vlc
[2011.09.18 20:16:24 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Winamp
[2010.08.06 14:31:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\WinRAR
[2010.01.30 14:31:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\xm1
[2011.02.16 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\XMedia Recode

Fortsetzung in folgendem Post.

markus32 08.03.2012 16:18

zweiter Teil:

Code:

[2011.09.07 22:18:28 | 000,000,922 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000Core.job
[2011.09.08 13:45:00 | 000,000,944 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000UA.job
[2012.03.06 18:30:43 | 000,000,554 | ---- | M] () -- C:\Windows\Tasks\MATLAB R2011b Startup Accelerator.job
[2011.09.01 17:00:00 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2011.09.08 16:25:48 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012.03.07 19:25:13 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.09.08 16:25:48 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.10.15 14:47:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Adobe
[2011.12.03 13:32:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Apple Computer
[2009.12.09 16:45:34 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ATI
[2011.10.15 13:08:42 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Avira
[2010.08.14 15:38:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\AVS4YOU
[2011.09.18 12:13:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Binary Fortress Software
[2010.03.23 23:19:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Canneverbe Limited
[2010.01.06 15:15:27 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Crazysoft
[2009.12.09 17:13:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Creative
[2009.12.09 20:21:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\CyberLink
[2012.03.07 18:36:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DAEMON Tools Lite
[2011.06.01 13:23:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Dell
[2011.02.23 17:08:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\diginet
[2011.11.26 13:31:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\dvdcss
[2012.02.02 01:40:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoft
[2011.09.08 11:58:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 15:47:12 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\FireShot
[2010.04.11 14:01:21 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GetRightToGo
[2010.05.22 15:17:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GrabPro
[2012.01.31 10:17:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC
[2011.09.19 13:44:38 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.02.02 06:16:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ
[2009.12.09 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Identities
[2010.08.05 12:56:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\inkscape
[2010.11.30 15:51:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\InstallShield
[2012.02.17 13:09:17 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Jumping Bytes
[2011.02.21 19:45:37 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\kikin
[2009.12.10 21:14:56 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LockHunter
[2009.12.09 16:49:32 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Macromedia
[2012.03.04 18:45:01 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Malwarebytes
[2010.03.21 22:06:00 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ManyCam
[2011.10.15 19:13:17 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mathematica
[2012.03.06 18:38:50 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MathWorks
[2009.07.14 19:18:18 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Media Center Programs
[2010.03.06 17:48:37 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Media Player Classic
[2011.11.16 17:41:03 | 000,000,000 | --SD | M] -- C:\Users\Christian\AppData\Roaming\Microsoft
[2010.01.30 13:51:45 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MiKTeX
[2012.02.16 16:32:14 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\mkvtoolnix
[2011.12.24 18:00:18 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Mozilla
[2010.09.19 09:22:51 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\National Instruments
[2011.08.04 22:19:29 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenCandy
[2009.12.09 21:44:39 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org
[2012.03.08 14:28:04 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Orbit
[2010.12.12 14:09:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PCDr
[2010.10.02 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PhotoScape
[2010.08.16 20:28:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ProgSense
[2010.03.06 18:33:59 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Real
[2009.12.09 18:34:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Reallusion
[2009.12.09 16:45:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roxio
[2009.12.09 19:12:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roxio Log Files
[2010.06.08 17:24:51 | 000,000,000 | RH-D | M] -- C:\Users\Christian\AppData\Roaming\SecuROM
[2012.03.07 22:59:34 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Skype
[2011.12.06 20:32:31 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\skypePM
[2010.05.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Steinberg
[2010.04.21 21:01:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Stellarium
[2011.10.22 18:38:20 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Subversion
[2010.01.21 19:43:10 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\syntevo
[2010.02.02 21:32:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\temp
[2009.12.09 21:34:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template
[2011.10.23 12:40:23 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TortoiseSVN
[2012.02.16 22:44:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TuneUp Software
[2011.06.14 03:19:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Unified Remote
[2012.03.04 16:52:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\vlc
[2011.09.18 20:16:24 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Winamp
[2010.08.06 14:31:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\WinRAR
[2010.01.30 14:31:40 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\xm1
[2011.02.16 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\XMedia Recode
 
< %APPDATA%\*.exe /s >
[2011.12.20 16:41:41 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Christian\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.02.09 21:31:00 | 008,197,280 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Christian\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2011.08.29 19:08:04 | 003,088,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Christian\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2011.09.15 20:38:23 | 000,188,152 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\dkqm69cp.default\FlashGot.exe
[2012.01.22 15:59:26 | 000,141,312 | ---- | M] (getfireshot.com) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-container.exe
[2012.01.22 15:59:20 | 000,068,096 | ---- | M] (getfireshot.com) -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\dkqm69cp.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fireshot-deploy.exe
[2011.08.04 22:19:33 | 000,416,160 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\OpenCandy\OpenCandy_336CCD1FACBB4E609A98B9653FF58089\LatestDLMgr.exe
[2011.07.06 00:04:56 | 028,957,528 | ---- | M] (TuneUp Media, Inc.) -- C:\Users\Christian\AppData\Roaming\OpenCandy\OpenCandy_336CCD1FACBB4E609A98B9653FF58089\TuneUpInst-2.1.1-cmp185.exe
[2011.08.29 11:47:19 | 005,922,104 | ---- | M] (Dell Inc) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Binaries\patch_dsc_583014to583017_64_03.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\03bef837-788b-4241-b967-5952193b4592\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\1d22a976-a231-41ea-8ee7-d0d44fb53478\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\1ee30331-e8fd-44f5-bc58-07261ada97e4\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\25adb911-0323-4ad7-b035-e265a28dd4f4\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\27b55b9e-3558-426a-bb5a-43c176c5084c\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\2ca413c7-a944-47fe-b8b4-681b5b9ae6de\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\2de9d8b5-6108-40f0-8c14-96105f37f400\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\2ecae5b7-a6a4-4c50-b275-903100810369\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\31c467fb-ecc6-42b5-8abd-3398afa715bf\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\33921bdc-9bba-425a-849e-6b36a639fb8b\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\356f44e0-5bee-47d6-a9c6-83c9f6a12000\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\3f9d64a7-8115-4a89-a2d3-558bce81ae8f\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\41dde72e-3026-4995-9e6c-721c5b7a2702\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\473b6ff7-42e7-47fa-8fbe-c0c98edd8cb1\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\47dbce18-f26a-4565-a1ca-3743cdbade8b\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\4a39418e-a198-496f-983b-2e331fea0bd5\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\510e3a2b-e455-4118-bb6e-55b4f16efbac\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\6063532b-677a-4b7f-ae7c-e80beec08c6d\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\65de4c85-f685-43fa-b072-2a8cfb78705b\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\6662a0e8-8ab8-4c6c-b2b7-3c7e1ecd85d6\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\6855b47c-a743-4431-a7e8-74ee1cfabd66\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\7d1b827f-c0b6-42f8-adab-bf28f5ab1402\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\82fc5371-c902-42e6-bcd5-f6b39210f03f\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\87ab7313-87fa-473e-b812-a8f537d8d35f\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\8bb14870-c7b2-4a91-8adb-71a20a43aa5f\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\8f73616e-c7c1-444b-a07c-90b6311e3f37\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\90c2ff4e-fe16-4fb5-ae04-81f907df7978\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\a035b40a-7a55-4a00-a57f-9b2c0aa408f6\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\a6f4601d-9ca1-4f15-b78c-486368c3a02e\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\af7a7b18-7b6a-4f2d-9501-4accf2c805ae\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\bda5715d-2c52-4175-aa2b-f90c6b737779\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\c2318bca-ffaa-4dbf-abf6-901268368ca8\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\d251c456-62da-43c8-ad19-48d0ace2d812\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\d3374892-0af4-4116-ba12-6fdc5945d303\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\db5fba58-2f19-4266-8dcf-3a3a517d4bcb\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\e0e4d150-199e-4174-ad56-013ba88c5255\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\e635e368-cf74-4743-8d0c-b7f0c0b9720a\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 12:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\e67c87bf-8514-461a-a896-2f24472af5ac\DellSignedAppUpdaterRules_dsc\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\eba89507-33c1-43f9-bbab-5ae403f05ad7\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
[2010.10.12 21:36:00 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Christian\AppData\Roaming\PCDr\Update\Rules\fed5c9a8-fcff-4537-a66b-9d24e132792f\DellSignedAppUpdaterRules_5830_14\AddCertificate.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2010.01.26 23:29:28 | 000,028,797 | ---- | M] () MD5=4571E750E4A920D773511F50A2E62A20 -- C:\Program Files\MATLAB\R2011b\sys\perl\win32\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >

< End of report >


cosinus 08.03.2012 19:27

Code:

[Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com     
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com

Aus welcher Quelle stammt dein Acrobat10? Wie konntest du es aktivieren wenn das über die HOSTS gesperrt wurde? :pfeiff:

markus32 08.03.2012 19:32

Den Acrobat hab ich von meiner Uni, es gibt da nen Lizenzvertrag mit (unter Anderem) Adobe. Die Hosts wurden erst nach der Aktivierung gesperrt.
Die Sperrung ist eigentlich eh sinnfrei. Aber ich denke mal du wolltest sichergehen dass die Software keine Raubkopie ist.

cosinus 08.03.2012 20:22

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0540005F-107E-4C4D-B1CD-64DE04847137}
IE:64bit: - HKLM\..\SearchScopes\{0540005F-107E-4C4D-B1CD-64DE04847137}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKLM\..\SearchScopes\{3E4A5BD3-2D23-461A-98CD-FC106A31775C}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\..\SearchScopes,DefaultScope = {3E4A5BD3-2D23-461A-98CD-FC106A31775C}
IE - HKU\S-1-5-21-1302499063-601275286-625076348-1000\..\SearchScopes\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}: "URL" = http://search.kikin.com/search/?q={searchTerms}
[2012.02.16 12:08:43 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKU\S-1-5-21-1302499063-601275286-625076348-1000..\Run: [AdobeBridge]  File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Allgemein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk =  File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files (x86)\kikin\ie_kikin.dll (kikin)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\Shell - "" = AutoRun
O33 - MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\Shell\AutoRun\command - "" = G:\setup.exe
[2011.06.21 19:15:50 | 000,000,000 | ---D | M] -- C:\Users\Allgemein\AppData\Roaming\kikin
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

markus32 08.03.2012 20:33

Vielen Dank, das hier ist der OTL-Log nach dem Fix:

Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0540005F-107E-4C4D-B1CD-64DE04847137}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0540005F-107E-4C4D-B1CD-64DE04847137}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3E4A5BD3-2D23-461A-98CD-FC106A31775C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E4A5BD3-2D23-461A-98CD-FC106A31775C}\ not found.
HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC129BF9-68BF-4bc4-A1DC-ECB62712FF99}\ not found.
C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ deleted successfully.
C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E601996F-E400-41CA-804B-CD6373A7EEE2}\ deleted successfully.
C:\Program Files (x86)\kikin\ie_kikin.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\FixCamera deleted successfully.
C:\Windows\FixCamera.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Users\Allgemein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk moved successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk moved successfully.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\LogonHoursAction deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DontDisplayLogonHoursWarnings deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65}\ not found.
File C:\Program Files (x86)\kikin\ie_kikin.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06e9706d-2611-11e0-95e9-0026b9124de7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{06e9706d-2611-11e0-95e9-0026b9124de7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06e9706d-2611-11e0-95e9-0026b9124de7}\ not found.
File G:\setup.exe not found.
C:\Users\Allgemein\AppData\Roaming\kikin folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Allgemein
->Temp folder emptied: 50826508 bytes
->Temporary Internet Files folder emptied: 8286410 bytes
->Java cache emptied: 36444676 bytes
->FireFox cache emptied: 111633541 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 21596 bytes
 
User: Christian
->Temp folder emptied: 37411317 bytes
->Temporary Internet Files folder emptied: 4394696 bytes
->Java cache emptied: 46423599 bytes
->FireFox cache emptied: 50731571 bytes
->Google Chrome cache emptied: 332116326 bytes
->Flash cache emptied: 11350825 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 540066 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67899 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 658,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.36.1 log created on 03082012_202606

Files\Folders moved on Reboot...
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!
C:\Users\Christian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


cosinus 08.03.2012 20:38

Wieso hast du den Command [resethosts] rausgenommen :balla:

markus32 08.03.2012 20:42

Habe ich nicht (wissentlich). Kann ich den auch isoliert noch einmal laufen lassen? Also in das Feld nur die Zeile [resthosts] ?
Edit: Also zumindest steht in dem Log "HOSTS file reset successfully".. also hat der Hosts doch resettet?
An deinem Skript habe ich definitiv nichts verändert.

cosinus 08.03.2012 20:43

Ups sry vergiss es, du hast drin gehabt, ich habs nur übersehen blind wie ich bin :stirn:

Zitat:

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

markus32 08.03.2012 21:01

Code:

20:48:25.0949 5980        TDSS rootkit removing tool 2.7.19.0 Mar  5 2012 11:23:39
20:48:26.0170 5980        ============================================================
20:48:26.0171 5980        Current date / time: 2012/03/08 20:48:26.0170
20:48:26.0171 5980        SystemInfo:
20:48:26.0171 5980       
20:48:26.0171 5980        OS Version: 6.1.7601 ServicePack: 1.0
20:48:26.0171 5980        Product type: Workstation
20:48:26.0171 5980        ComputerName: CHRISTIAN
20:48:26.0171 5980        UserName: Christian
20:48:26.0171 5980        Windows directory: C:\Windows
20:48:26.0171 5980        System windows directory: C:\Windows
20:48:26.0171 5980        Running under WOW64
20:48:26.0171 5980        Processor architecture: Intel x64
20:48:26.0171 5980        Number of processors: 2
20:48:26.0171 5980        Page size: 0x1000
20:48:26.0171 5980        Boot type: Normal boot
20:48:26.0171 5980        ============================================================
20:48:27.0483 5980        Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:48:27.0490 5980        \Device\Harddisk0\DR0:
20:48:27.0490 5980        MBR used
20:48:27.0490 5980        Initialize success
20:48:27.0490 5980        ============================================================
20:59:40.0527 5604        ============================================================
20:59:40.0527 5604        Scan started
20:59:40.0527 5604        Mode: Manual; SigCheck; TDLFS;
20:59:40.0527 5604        ============================================================
20:59:40.0620 5604        1394ohci - ok
20:59:40.0636 5604        ACPI - ok
20:59:40.0636 5604        AcpiPmi - ok
20:59:40.0667 5604        acsock - ok
20:59:40.0683 5604        adp94xx - ok
20:59:40.0698 5604        adpahci - ok
20:59:40.0698 5604        adpu320 - ok
20:59:40.0729 5604        AFD - ok
20:59:40.0729 5604        agp440 - ok
20:59:40.0745 5604        aliide - ok
20:59:40.0761 5604        amdide - ok
20:59:40.0761 5604        AmdK8 - ok
20:59:40.0776 5604        AmdPPM - ok
20:59:40.0776 5604        amdsata - ok
20:59:40.0792 5604        amdsbs - ok
20:59:40.0792 5604        amdxata - ok
20:59:40.0839 5604        AppID - ok
20:59:40.0854 5604        arc - ok
20:59:40.0854 5604        arcsas - ok
20:59:40.0885 5604        AsyncMac - ok
20:59:40.0885 5604        atapi - ok
20:59:40.0901 5604        AtiHdmiService - ok
20:59:40.0901 5604        atikmdag - ok
20:59:40.0932 5604        avgntflt - ok
20:59:40.0948 5604        avipbb - ok
20:59:40.0979 5604        avkmgr - ok
20:59:40.0995 5604        b06bdrv - ok
20:59:40.0995 5604        b57nd60a - ok
20:59:41.0026 5604        BCM42RLY - ok
20:59:41.0026 5604        BCM43XX - ok
20:59:41.0041 5604        BDA_Capture_225 - ok
20:59:41.0041 5604        BDA_Loader_225 - ok
20:59:41.0057 5604        Beep - ok
20:59:41.0088 5604        blbdrive - ok
20:59:41.0104 5604        bowser - ok
20:59:41.0119 5604        BrFiltLo - ok
20:59:41.0119 5604        BrFiltUp - ok
20:59:41.0135 5604        Brserid - ok
20:59:41.0135 5604        BrSerWdm - ok
20:59:41.0151 5604        BrUsbMdm - ok
20:59:41.0151 5604        BrUsbSer - ok
20:59:41.0166 5604        BTHMODEM - ok
20:59:41.0182 5604        cdfs - ok
20:59:41.0182 5604        cdrom - ok
20:59:41.0197 5604        circlass - ok
20:59:41.0197 5604        CLFS - ok
20:59:41.0229 5604        CmBatt - ok
20:59:41.0229 5604        cmdide - ok
20:59:41.0244 5604        CNG - ok
20:59:41.0244 5604        Compbatt - ok
20:59:41.0260 5604        CompositeBus - ok
20:59:41.0275 5604        crcdisk - ok
20:59:41.0275 5604        CtClsFlt - ok
20:59:41.0291 5604        CVirtA - ok
20:59:41.0307 5604        CVPNDRVA - ok
20:59:41.0322 5604        DfsC - ok
20:59:41.0338 5604        discache - ok
20:59:41.0338 5604        Disk - ok
20:59:41.0369 5604        DNE - ok
20:59:41.0385 5604        drmkaud - ok
20:59:41.0400 5604        DXGKrnl - ok
20:59:41.0416 5604        ebdrv - ok
20:59:41.0431 5604        elxstor - ok
20:59:41.0431 5604        ErrDev - ok
20:59:41.0447 5604        exfat - ok
20:59:41.0463 5604        fastfat - ok
20:59:41.0463 5604        fdc - ok
20:59:41.0478 5604        FileInfo - ok
20:59:41.0494 5604        Filetrace - ok
20:59:41.0494 5604        flpydisk - ok
20:59:41.0509 5604        FltMgr - ok
20:59:41.0525 5604        FsDepends - ok
20:59:41.0525 5604        Fs_Rec - ok
20:59:41.0556 5604        fvevol - ok
20:59:41.0556 5604        gagp30kx - ok
20:59:41.0572 5604        GEARAspiWDM - ok
20:59:41.0603 5604        hcw85cir - ok
20:59:41.0619 5604        HDAudBus - ok
20:59:41.0634 5604        HidBatt - ok
20:59:41.0650 5604        HidBth - ok
20:59:41.0650 5604        HidIr - ok
20:59:41.0681 5604        HidUsb - ok
20:59:41.0712 5604        HpSAMD - ok
20:59:41.0712 5604        HTCAND64 - ok
20:59:41.0728 5604        htcnprot - ok
20:59:41.0728 5604        HTTP - ok
20:59:41.0728 5604        hwpolicy - ok
20:59:41.0743 5604        i8042prt - ok
20:59:41.0743 5604        iaStorV - ok
20:59:41.0759 5604        iirsp - ok
20:59:41.0775 5604        intelide - ok
20:59:41.0775 5604        intelppm - ok
20:59:41.0790 5604        IpFilterDriver - ok
20:59:41.0806 5604        IPMIDRV - ok
20:59:41.0806 5604        IPNAT - ok
20:59:41.0837 5604        IRENUM - ok
20:59:41.0837 5604        isapnp - ok
20:59:41.0853 5604        iScsiPrt - ok
20:59:41.0853 5604        k57nd60a - ok
20:59:41.0868 5604        kbdclass - ok
20:59:41.0868 5604        kbdhid - ok
20:59:41.0884 5604        KSecDD - ok
20:59:41.0884 5604        KSecPkg - ok
20:59:41.0884 5604        ksthunk - ok
20:59:41.0915 5604        lltdio - ok
20:59:41.0931 5604        LSI_FC - ok
20:59:41.0931 5604        LSI_SAS - ok
20:59:41.0946 5604        LSI_SAS2 - ok
20:59:41.0946 5604        LSI_SCSI - ok
20:59:41.0962 5604        luafv - ok
20:59:41.0962 5604        ManyCam - ok
20:59:41.0977 5604        MBAMProtector - ok
20:59:41.0993 5604        megasas - ok
20:59:42.0009 5604        MegaSR - ok
20:59:42.0024 5604        Modem - ok
20:59:42.0024 5604        monitor - ok
20:59:42.0040 5604        mouclass - ok
20:59:42.0040 5604        mouhid - ok
20:59:42.0055 5604        mountmgr - ok
20:59:42.0055 5604        mpio - ok
20:59:42.0071 5604        mpsdrv - ok
20:59:42.0071 5604        MRxDAV - ok
20:59:42.0087 5604        mrxsmb - ok
20:59:42.0087 5604        mrxsmb10 - ok
20:59:42.0102 5604        mrxsmb20 - ok
20:59:42.0102 5604        msahci - ok
20:59:42.0118 5604        msdsm - ok
20:59:42.0133 5604        Msfs - ok
20:59:42.0133 5604        mshidkmdf - ok
20:59:42.0149 5604        msisadrv - ok
20:59:42.0165 5604        MSKSSRV - ok
20:59:42.0165 5604        MSPCLOCK - ok
20:59:42.0180 5604        MSPQM - ok
20:59:42.0180 5604        MsRPC - ok
20:59:42.0196 5604        mssmbios - ok
20:59:42.0196 5604        MSTEE - ok
20:59:42.0211 5604        MTConfig - ok
20:59:42.0211 5604        Mup - ok
20:59:42.0227 5604        NativeWifiP - ok
20:59:42.0227 5604        NDIS - ok
20:59:42.0243 5604        NdisCap - ok
20:59:42.0243 5604        NdisTapi - ok
20:59:42.0258 5604        Ndisuio - ok
20:59:42.0258 5604        NdisWan - ok
20:59:42.0274 5604        NDProxy - ok
20:59:42.0274 5604        NetBIOS - ok
20:59:42.0289 5604        NetBT - ok
20:59:42.0336 5604        nfrd960 - ok
20:59:42.0352 5604        Npfs - ok
20:59:42.0367 5604        nsiproxy - ok
20:59:42.0383 5604        Ntfs - ok
20:59:42.0383 5604        Null - ok
20:59:42.0399 5604        nvraid - ok
20:59:42.0399 5604        nvstor - ok
20:59:42.0414 5604        nv_agp - ok
20:59:42.0430 5604        ohci1394 - ok
20:59:42.0461 5604        Parport - ok
20:59:42.0461 5604        partmgr - ok
20:59:42.0477 5604        PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
20:59:42.0492 5604        pci - ok
20:59:42.0492 5604        pciide - ok
20:59:42.0508 5604        pcmcia - ok
20:59:42.0508 5604        pcw - ok
20:59:42.0508 5604        PEAUTH - ok
20:59:42.0555 5604        PptpMiniport - ok
20:59:42.0570 5604        Processor - ok
20:59:42.0586 5604        Psched - ok
20:59:42.0586 5604        PSI - ok
20:59:42.0601 5604        PxHlpa64 - ok
20:59:42.0601 5604        ql2300 - ok
20:59:42.0617 5604        ql40xx - ok
20:59:42.0617 5604        QWAVEdrv - ok
20:59:42.0648 5604        RasAcd - ok
20:59:42.0648 5604        RasAgileVpn - ok
20:59:42.0664 5604        Rasl2tp - ok
20:59:42.0664 5604        RasPppoe - ok
20:59:42.0679 5604        RasSstp - ok
20:59:42.0679 5604        rdbss - ok
20:59:42.0695 5604        rdpbus - ok
20:59:42.0695 5604        RDPCDD - ok
20:59:42.0711 5604        RDPENCDD - ok
20:59:42.0726 5604        RDPREFMP - ok
20:59:42.0726 5604        RDPWD - ok
20:59:42.0742 5604        rdyboost - ok
20:59:42.0742 5604        rimmptsk - ok
20:59:42.0757 5604        rimsptsk - ok
20:59:42.0757 5604        rismxdp - ok
20:59:42.0773 5604        rspndr - ok
20:59:42.0789 5604        sbp2port - ok
20:59:42.0804 5604        scfilter - ok
20:59:42.0820 5604        sdbus - ok
20:59:42.0835 5604        secdrv - ok
20:59:42.0851 5604        Serenum - ok
20:59:42.0867 5604        Serial - ok
20:59:42.0867 5604        sermouse - ok
20:59:42.0898 5604        sffdisk - ok
20:59:42.0898 5604        sffp_mmc - ok
20:59:42.0913 5604        sffp_sd - ok
20:59:42.0913 5604        sfloppy - ok
20:59:42.0929 5604        SiSRaid2 - ok
20:59:42.0929 5604        SiSRaid4 - ok
20:59:42.0945 5604        Smb - ok
20:59:42.0960 5604        SNPSTD3 - ok
20:59:42.0976 5604        spldr - ok
20:59:42.0991 5604        sptd - ok
20:59:43.0007 5604        srv - ok
20:59:43.0007 5604        srv2 - ok
20:59:43.0023 5604        srvnet - ok
20:59:43.0038 5604        StarOpen - ok
20:59:43.0054 5604        stexstor - ok
20:59:43.0054 5604        STHDA - ok
20:59:43.0069 5604        swenum - ok
20:59:43.0085 5604        SynasUSB - ok
20:59:43.0101 5604        SynTP - ok
20:59:43.0116 5604        taphss - ok
20:59:43.0132 5604        Tcpip - ok
20:59:43.0132 5604        TCPIP6 - ok
20:59:43.0147 5604        tcpipreg - ok
20:59:43.0147 5604        TDPIPE - ok
20:59:43.0163 5604        TDTCP - ok
20:59:43.0163 5604        tdx - ok
20:59:43.0179 5604        TermDD - ok
20:59:43.0194 5604        tssecsrv - ok
20:59:43.0210 5604        TsUsbFlt - ok
20:59:43.0210 5604        tunnel - ok
20:59:43.0225 5604        uagp35 - ok
20:59:43.0225 5604        udfs - ok
20:59:43.0241 5604        uliagpkx - ok
20:59:43.0257 5604        umbus - ok
20:59:43.0257 5604        UmPass - ok
20:59:43.0272 5604        USBAAPL64 - ok
20:59:43.0288 5604        usbccgp - ok
20:59:43.0288 5604        usbcir - ok
20:59:43.0288 5604        usbehci - ok
20:59:43.0303 5604        usbhub - ok
20:59:43.0303 5604        usbohci - ok
20:59:43.0319 5604        usbprint - ok
20:59:43.0319 5604        usbscan - ok
20:59:43.0335 5604        USBSTOR - ok
20:59:43.0335 5604        usbuhci - ok
20:59:43.0366 5604        usbvideo - ok
20:59:43.0381 5604        usb_rndisx - ok
20:59:43.0397 5604        vdrvroot - ok
20:59:43.0413 5604        vga - ok
20:59:43.0413 5604        VgaSave - ok
20:59:43.0428 5604        vhdmp - ok
20:59:43.0428 5604        viaide - ok
20:59:43.0428 5604        volmgr - ok
20:59:43.0444 5604        volmgrx - ok
20:59:43.0444 5604        volsnap - ok
20:59:43.0475 5604        vpnva - ok
20:59:43.0491 5604        vsmraid - ok
20:59:43.0506 5604        vwifibus - ok
20:59:43.0522 5604        vwififlt - ok
20:59:43.0522 5604        vwifimp - ok
20:59:43.0537 5604        WacomPen - ok
20:59:43.0553 5604        WANARP - ok
20:59:43.0553 5604        Wanarpv6 - ok
20:59:43.0584 5604        Wd - ok
20:59:43.0584 5604        Wdf01000 - ok
20:59:43.0615 5604        WfpLwf - ok
20:59:43.0647 5604        WimFltr - ok
20:59:43.0647 5604        WIMMount - ok
20:59:43.0709 5604        WINUSB - ok
20:59:43.0725 5604        WmiAcpi - ok
20:59:43.0740 5604        ws2ifsl - ok
20:59:43.0771 5604        WudfPf - ok
20:59:43.0787 5604        WUDFRd - ok
20:59:43.0834 5604        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
20:59:44.0037 5604        \Device\Harddisk0\DR0 - ok
20:59:44.0037 5604        ============================================================
20:59:44.0037 5604        Scan finished
20:59:44.0037 5604        ============================================================
20:59:44.0068 5892        Detected object count: 0
20:59:44.0068 5892        Actual detected object count: 0
20:59:54.0598 2996        ============================================================
20:59:54.0598 2996        Scan started
20:59:54.0598 2996        Mode: Manual; SigCheck; TDLFS;
20:59:54.0598 2996        ============================================================
20:59:54.0910 2996        1394ohci - ok
20:59:54.0910 2996        ACPI - ok
20:59:54.0925 2996        AcpiPmi - ok
20:59:54.0925 2996        acsock - ok
20:59:54.0957 2996        adp94xx - ok
20:59:54.0957 2996        adpahci - ok
20:59:54.0972 2996        adpu320 - ok
20:59:54.0988 2996        AFD - ok
20:59:55.0003 2996        agp440 - ok
20:59:55.0019 2996        aliide - ok
20:59:55.0035 2996        amdide - ok
20:59:55.0050 2996        AmdK8 - ok
20:59:55.0050 2996        AmdPPM - ok
20:59:55.0066 2996        amdsata - ok
20:59:55.0066 2996        amdsbs - ok
20:59:55.0081 2996        amdxata - ok
20:59:55.0097 2996        AppID - ok
20:59:55.0128 2996        arc - ok
20:59:55.0144 2996        arcsas - ok
20:59:55.0159 2996        AsyncMac - ok
20:59:55.0175 2996        atapi - ok
20:59:55.0191 2996        AtiHdmiService - ok
20:59:55.0191 2996        atikmdag - ok
20:59:55.0222 2996        avgntflt - ok
20:59:55.0222 2996        avipbb - ok
20:59:55.0222 2996        avkmgr - ok
20:59:55.0237 2996        b06bdrv - ok
20:59:55.0253 2996        b57nd60a - ok
20:59:55.0284 2996        BCM42RLY - ok
20:59:55.0284 2996        BCM43XX - ok
20:59:55.0300 2996        BDA_Capture_225 - ok
20:59:55.0315 2996        BDA_Loader_225 - ok
20:59:55.0331 2996        Beep - ok
20:59:55.0347 2996        blbdrive - ok
20:59:55.0362 2996        bowser - ok
20:59:55.0378 2996        BrFiltLo - ok
20:59:55.0378 2996        BrFiltUp - ok
20:59:55.0393 2996        Brserid - ok
20:59:55.0409 2996        BrSerWdm - ok
20:59:55.0425 2996        BrUsbMdm - ok
20:59:55.0425 2996        BrUsbSer - ok
20:59:55.0440 2996        BTHMODEM - ok
20:59:55.0456 2996        cdfs - ok
20:59:55.0471 2996        cdrom - ok
20:59:55.0487 2996        circlass - ok
20:59:55.0487 2996        CLFS - ok
20:59:55.0518 2996        CmBatt - ok
20:59:55.0534 2996        cmdide - ok
20:59:55.0534 2996        CNG - ok
20:59:55.0534 2996        Compbatt - ok
20:59:55.0549 2996        CompositeBus - ok
20:59:55.0565 2996        crcdisk - ok
20:59:55.0581 2996        CtClsFlt - ok
20:59:55.0581 2996        CVirtA - ok
20:59:55.0596 2996        CVPNDRVA - ok
20:59:55.0612 2996        DfsC - ok
20:59:55.0612 2996        discache - ok
20:59:55.0627 2996        Disk - ok
20:59:55.0627 2996        DNE - ok
20:59:55.0659 2996        drmkaud - ok
20:59:55.0659 2996        DXGKrnl - ok
20:59:55.0674 2996        ebdrv - ok
20:59:55.0690 2996        elxstor - ok
20:59:55.0690 2996        ErrDev - ok
20:59:55.0705 2996        exfat - ok
20:59:55.0721 2996        fastfat - ok
20:59:55.0737 2996        fdc - ok
20:59:55.0737 2996        FileInfo - ok
20:59:55.0752 2996        Filetrace - ok
20:59:55.0752 2996        flpydisk - ok
20:59:55.0768 2996        FltMgr - ok
20:59:55.0783 2996        FsDepends - ok
20:59:55.0783 2996        Fs_Rec - ok
20:59:55.0799 2996        fvevol - ok
20:59:55.0799 2996        gagp30kx - ok
20:59:55.0799 2996        GEARAspiWDM - ok
20:59:55.0830 2996        hcw85cir - ok
20:59:55.0830 2996        HDAudBus - ok
20:59:55.0846 2996        HidBatt - ok
20:59:55.0846 2996        HidBth - ok
20:59:55.0861 2996        HidIr - ok
20:59:55.0861 2996        HidUsb - ok
20:59:55.0877 2996        HpSAMD - ok
20:59:55.0893 2996        HTCAND64 - ok
20:59:55.0893 2996        htcnprot - ok
20:59:55.0908 2996        HTTP - ok
20:59:55.0908 2996        hwpolicy - ok
20:59:55.0924 2996        i8042prt - ok
20:59:55.0924 2996        iaStorV - ok
20:59:55.0939 2996        iirsp - ok
20:59:55.0955 2996        intelide - ok
20:59:55.0971 2996        intelppm - ok
20:59:55.0971 2996        IpFilterDriver - ok
20:59:55.0986 2996        IPMIDRV - ok
20:59:55.0986 2996        IPNAT - ok
20:59:56.0002 2996        IRENUM - ok
20:59:56.0017 2996        isapnp - ok
20:59:56.0017 2996        iScsiPrt - ok
20:59:56.0033 2996        k57nd60a - ok
20:59:56.0033 2996        kbdclass - ok
20:59:56.0049 2996        kbdhid - ok
20:59:56.0049 2996        KSecDD - ok
20:59:56.0064 2996        KSecPkg - ok
20:59:56.0080 2996        ksthunk - ok
20:59:56.0111 2996        lltdio - ok
20:59:56.0127 2996        LSI_FC - ok
20:59:56.0142 2996        LSI_SAS - ok
20:59:56.0142 2996        LSI_SAS2 - ok
20:59:56.0158 2996        LSI_SCSI - ok
20:59:56.0158 2996        luafv - ok
20:59:56.0173 2996        ManyCam - ok
20:59:56.0189 2996        MBAMProtector - ok
20:59:56.0251 2996        megasas - ok
20:59:56.0267 2996        MegaSR - ok
20:59:56.0283 2996        Modem - ok
20:59:56.0298 2996        monitor - ok
20:59:56.0314 2996        mouclass - ok
20:59:56.0314 2996        mouhid - ok
20:59:56.0329 2996        mountmgr - ok
20:59:56.0345 2996        mpio - ok
20:59:56.0361 2996        mpsdrv - ok
20:59:56.0376 2996        MRxDAV - ok
20:59:56.0392 2996        mrxsmb - ok
20:59:56.0392 2996        mrxsmb10 - ok
20:59:56.0407 2996        mrxsmb20 - ok
20:59:56.0423 2996        msahci - ok
20:59:56.0439 2996        msdsm - ok
20:59:56.0470 2996        Msfs - ok
20:59:56.0470 2996        mshidkmdf - ok
20:59:56.0485 2996        msisadrv - ok
20:59:56.0501 2996        MSKSSRV - ok
20:59:56.0517 2996        MSPCLOCK - ok
20:59:56.0517 2996        MSPQM - ok
20:59:56.0532 2996        MsRPC - ok
20:59:56.0548 2996        mssmbios - ok
20:59:56.0563 2996        MSTEE - ok
20:59:56.0579 2996        MTConfig - ok
20:59:56.0579 2996        Mup - ok
20:59:56.0610 2996        NativeWifiP - ok
20:59:56.0610 2996        NDIS - ok
20:59:56.0626 2996        NdisCap - ok
20:59:56.0641 2996        NdisTapi - ok
20:59:56.0657 2996        Ndisuio - ok
20:59:56.0657 2996        NdisWan - ok
20:59:56.0673 2996        NDProxy - ok
20:59:56.0688 2996        NetBIOS - ok
20:59:56.0688 2996        NetBT - ok
20:59:56.0751 2996        nfrd960 - ok
20:59:56.0797 2996        Npfs - ok
20:59:56.0829 2996        nsiproxy - ok
20:59:56.0844 2996        Ntfs - ok
20:59:56.0844 2996        Null - ok
20:59:56.0860 2996        nvraid - ok
20:59:56.0875 2996        nvstor - ok
20:59:56.0875 2996        nv_agp - ok
20:59:56.0907 2996        ohci1394 - ok
20:59:56.0938 2996        Parport - ok
20:59:56.0938 2996        partmgr - ok
20:59:56.0969 2996        PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
20:59:56.0985 2996        pci - ok
20:59:56.0985 2996        pciide - ok
20:59:57.0000 2996        pcmcia - ok
20:59:57.0016 2996        pcw - ok
20:59:57.0031 2996        PEAUTH - ok
20:59:57.0109 2996        PptpMiniport - ok
20:59:57.0109 2996        Processor - ok
20:59:57.0141 2996        Psched - ok
20:59:57.0156 2996        PSI - ok
20:59:57.0172 2996        PxHlpa64 - ok
20:59:57.0172 2996        ql2300 - ok
20:59:57.0187 2996        ql40xx - ok
20:59:57.0203 2996        QWAVEdrv - ok
20:59:57.0219 2996        RasAcd - ok
20:59:57.0234 2996        RasAgileVpn - ok
20:59:57.0250 2996        Rasl2tp - ok
20:59:57.0265 2996        RasPppoe - ok
20:59:57.0265 2996        RasSstp - ok
20:59:57.0281 2996        rdbss - ok
20:59:57.0281 2996        rdpbus - ok
20:59:57.0297 2996        RDPCDD - ok
20:59:57.0312 2996        RDPENCDD - ok
20:59:57.0328 2996        RDPREFMP - ok
20:59:57.0343 2996        RDPWD - ok
20:59:57.0359 2996        rdyboost - ok
20:59:57.0375 2996        rimmptsk - ok
20:59:57.0375 2996        rimsptsk - ok
20:59:57.0390 2996        rismxdp - ok
20:59:57.0406 2996        rspndr - ok
20:59:57.0421 2996        sbp2port - ok
20:59:57.0437 2996        scfilter - ok
20:59:57.0453 2996        sdbus - ok
20:59:57.0468 2996        secdrv - ok
20:59:57.0515 2996        Serenum - ok
20:59:57.0515 2996        Serial - ok
20:59:57.0531 2996        sermouse - ok
20:59:57.0562 2996        sffdisk - ok
20:59:57.0577 2996        sffp_mmc - ok
20:59:57.0577 2996        sffp_sd - ok
20:59:57.0593 2996        sfloppy - ok
20:59:57.0624 2996        SiSRaid2 - ok
20:59:57.0624 2996        SiSRaid4 - ok
20:59:57.0640 2996        Smb - ok
20:59:57.0671 2996        SNPSTD3 - ok
20:59:57.0671 2996        spldr - ok
20:59:57.0702 2996        sptd - ok
20:59:57.0718 2996        srv - ok
20:59:57.0718 2996        srv2 - ok
20:59:57.0733 2996        srvnet - ok
20:59:57.0765 2996        StarOpen - ok
20:59:57.0780 2996        stexstor - ok
20:59:57.0796 2996        STHDA - ok
20:59:57.0811 2996        swenum - ok
20:59:57.0827 2996        SynasUSB - ok
20:59:57.0843 2996        SynTP - ok
20:59:57.0858 2996        taphss - ok
20:59:57.0889 2996        Tcpip - ok
20:59:57.0889 2996        TCPIP6 - ok
20:59:57.0921 2996        tcpipreg - ok
20:59:57.0936 2996        TDPIPE - ok
20:59:57.0936 2996        TDTCP - ok
20:59:57.0952 2996        tdx - ok
20:59:57.0967 2996        TermDD - ok
20:59:58.0014 2996        tssecsrv - ok
20:59:58.0030 2996        TsUsbFlt - ok
20:59:58.0030 2996        tunnel - ok
20:59:58.0045 2996        uagp35 - ok
20:59:58.0061 2996        udfs - ok
20:59:58.0092 2996        uliagpkx - ok
20:59:58.0092 2996        umbus - ok
20:59:58.0108 2996        UmPass - ok
20:59:58.0139 2996        USBAAPL64 - ok
20:59:58.0155 2996        usbccgp - ok
20:59:58.0170 2996        usbcir - ok
20:59:58.0186 2996        usbehci - ok
20:59:58.0201 2996        usbhub - ok
20:59:58.0201 2996        usbohci - ok
20:59:58.0217 2996        usbprint - ok
20:59:58.0233 2996        usbscan - ok
20:59:58.0248 2996        USBSTOR - ok
20:59:58.0248 2996        usbuhci - ok
20:59:58.0264 2996        usbvideo - ok
20:59:58.0279 2996        usb_rndisx - ok
20:59:58.0295 2996        vdrvroot - ok
20:59:58.0311 2996        vga - ok
20:59:58.0326 2996        VgaSave - ok
20:59:58.0342 2996        vhdmp - ok
20:59:58.0357 2996        viaide - ok
20:59:58.0357 2996        volmgr - ok
20:59:58.0373 2996        volmgrx - ok
20:59:58.0389 2996        volsnap - ok
20:59:58.0404 2996        vpnva - ok
20:59:58.0420 2996        vsmraid - ok
20:59:58.0435 2996        vwifibus - ok
20:59:58.0451 2996        vwififlt - ok
20:59:58.0467 2996        vwifimp - ok
20:59:58.0482 2996        WacomPen - ok
20:59:58.0498 2996        WANARP - ok
20:59:58.0513 2996        Wanarpv6 - ok
20:59:58.0545 2996        Wd - ok
20:59:58.0560 2996        Wdf01000 - ok
20:59:58.0607 2996        WfpLwf - ok
20:59:58.0623 2996        WimFltr - ok
20:59:58.0638 2996        WIMMount - ok
20:59:58.0701 2996        WINUSB - ok
20:59:58.0716 2996        WmiAcpi - ok
20:59:58.0763 2996        ws2ifsl - ok
20:59:58.0810 2996        WudfPf - ok
20:59:58.0857 2996        WUDFRd - ok
20:59:58.0919 2996        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
20:59:59.0153 2996        \Device\Harddisk0\DR0 - ok
20:59:59.0153 2996        ============================================================
20:59:59.0153 2996        Scan finished
20:59:59.0153 2996        ============================================================
20:59:59.0169 6056        Detected object count: 0
20:59:59.0169 6056        Actual detected object count: 0


cosinus 08.03.2012 22:39

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

markus32 08.03.2012 23:30

Code:

ComboFix 12-03-08.04 - Christian 08.03.2012  23:00:42.1.2 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4061.1895 [GMT 1:00]
ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\etc
c:\program files (x86)\etc\maple2e.sty
c:\program files (x86)\etc\mapleenv.def
c:\program files (x86)\etc\mapleenv.sty
c:\program files (x86)\etc\mapleplots.sty
c:\program files (x86)\etc\maplestd2e.sty
c:\program files (x86)\etc\maplestyle.sty
c:\program files (x86)\etc\mapletab.sty
c:\program files (x86)\etc\mapleutil.sty
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk
c:\windows\system32\setuid.dll
c:\windows\SysWow64\Gdiplus.dll
c:\windows\SysWow64\scvideo.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-08 bis 2012-03-08  ))))))))))))))))))))))))))))))
.
.
2012-03-08 19:26 . 2012-03-08 19:26        --------        d-----w-        C:\_OTL
2012-03-07 23:46 . 2012-02-16 14:55        45016        ----a-w-        c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-03-07 23:46 . 2012-02-16 10:41        626688        ----a-w-        c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-03-07 23:46 . 2012-02-16 10:41        548864        ----a-w-        c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-03-07 23:46 . 2012-02-16 10:41        479232        ----a-w-        c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-03-07 23:33 . 2012-03-07 23:33        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-03-07 23:29 . 2012-03-07 23:29        525544        ----a-w-        c:\windows\system32\deployJava1.dll
2012-03-07 23:29 . 2012-03-07 23:29        --------        d-----w-        c:\program files\Java
2012-03-07 23:13 . 2012-03-07 23:13        --------        d-----w-        c:\users\Christian\AppData\Local\Secunia PSI
2012-03-07 22:55 . 2012-03-07 22:55        --------        d-----w-        c:\program files (x86)\ESET
2012-03-07 21:40 . 2012-03-07 21:40        --------        d-----w-        c:\program files (x86)\Secunia
2012-03-06 17:38 . 2012-03-06 17:38        --------        d-----w-        c:\users\Christian\AppData\Roaming\MathWorks
2012-03-06 16:39 . 2004-07-29 20:35        1077344        ----a-w-        c:\windows\system32\MSCOMCTL.OCX
2012-03-06 16:39 . 2004-03-01 21:05        407104        ----a-w-        c:\windows\system32\MSHFLXGD.OCX
2012-03-06 16:39 . 2004-02-11 13:37        203976        ----a-w-        c:\windows\system32\RICHTX32.OCX
2012-03-06 16:10 . 2012-03-06 16:10        --------        d-----w-        c:\program files\MATLAB
2012-03-06 16:00 . 2012-02-08 07:13        8643640        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{86170759-CD0F-42BF-90E0-2BD28FD4B5B8}\mpengine.dll
2012-03-06 14:48 . 2012-03-06 14:48        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-06 14:48 . 2011-12-10 14:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-03-04 17:45 . 2012-03-04 17:45        --------        d-----w-        c:\users\Christian\AppData\Roaming\Malwarebytes
2012-03-04 14:17 . 2012-03-04 14:17        --------        d-----w-        c:\users\Allgemein\AppData\Roaming\Malwarebytes
2012-03-04 14:17 . 2012-03-04 14:17        --------        d-----w-        c:\programdata\Malwarebytes
2012-02-17 12:09 . 2012-02-17 12:09        --------        d-----w-        c:\users\Christian\AppData\Roaming\Jumping Bytes
2012-02-17 12:03 . 2012-02-17 12:04        --------        d-----w-        c:\program files (x86)\PureSync
2012-02-17 12:03 . 2012-02-17 12:04        --------        d-----w-        c:\program files (x86)\Common Files\Jumping Bytes
2012-02-16 21:44 . 2012-02-16 21:44        --------        d-----w-        c:\users\Christian\AppData\Roaming\TuneUp Software
2012-02-16 21:43 . 2012-02-16 21:45        --------        d-----w-        c:\programdata\TuneUp Software
2012-02-16 21:43 . 2012-02-16 21:43        --------        d-sh--w-        c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-02-16 15:32 . 2012-02-16 15:32        --------        d-----w-        c:\users\Christian\AppData\Roaming\mkvtoolnix
2012-02-16 15:31 . 2012-02-16 15:31        --------        d-----w-        c:\program files (x86)\MKVToolNix
2012-02-16 08:21 . 2011-12-30 06:26        515584        ----a-w-        c:\windows\system32\timedate.cpl
2012-02-16 08:21 . 2011-12-30 05:27        478720        ----a-w-        c:\windows\SysWow64\timedate.cpl
2012-02-16 08:21 . 2012-01-04 10:44        509952        ----a-w-        c:\windows\system32\ntshrui.dll
2012-02-16 08:21 . 2012-01-04 08:58        442880        ----a-w-        c:\windows\SysWow64\ntshrui.dll
2012-02-16 08:21 . 2011-12-28 03:59        498688        ----a-w-        c:\windows\system32\drivers\afd.sys
2012-02-16 08:21 . 2012-01-14 04:06        3145728        ----a-w-        c:\windows\system32\win32k.sys
2012-02-16 08:21 . 2011-12-16 08:46        634880        ----a-w-        c:\windows\system32\msvcrt.dll
2012-02-16 08:21 . 2011-12-16 07:52        690688        ----a-w-        c:\windows\SysWow64\msvcrt.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 23:48 . 2011-12-16 12:28        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-07 23:32 . 2010-06-28 10:15        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-02-23 08:18 . 2009-12-14 20:03        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-15 13:58 . 2011-10-15 12:07        132320        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-01-12 00:19 . 2012-01-12 00:19        4448256        ----a-w-        c:\windows\SysWow64\GPhotos.scr
2012-01-04 23:01 . 2012-01-04 23:01        37888        ----a-w-        c:\windows\system32\drivers\taphss.sys
2011-10-15 19:18 . 2011-10-15 17:27        4962008        ----a-w-        c:\program files (x86)\MapleToolbox_WindowsX86_64.exe
2011-10-15 17:27 . 2011-10-15 17:27        106        ----a-w-        c:\program files (x86)\MapleToolbox.bat
2006-05-03 10:06        163328        --sha-r-        c:\windows\SysWOW64\flvDX.dll
2007-02-21 11:47        31232        --sha-r-        c:\windows\SysWOW64\msfDX.dll
2008-03-16 13:30        216064        --sha-r-        c:\windows\SysWOW64\nbDX.dll
2010-01-06 22:00        107520        --sha-r-        c:\windows\SysWOW64\TAKDSDecoder.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        64792        ----a-w-        c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-09-02 137536]
"PureSync"="c:\program files (x86)\PureSync\PureSyncTray.exe" [2011-12-12 837696]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-26 98304]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2009-09-05 385024]
"AVFX Engine"="c:\program files (x86)\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-10-09 20480]
"NuonSoft ShellEnhancer StartupHelper"="c:\program files (x86)\NuonSoft\ShellEnhancer\StartupHelper.exe" [2006-12-16 65536]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"snpstd3"="c:\windows\vsnpstd3.exe" [2007-05-10 835584]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2009-07-08 356352]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2011-09-09 523216]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-06-06 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-06-06 2903448]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-12-20 634880]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-7-29 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-09 135664]
R3 BDA_Capture_225;USB Digital-TV receiver. Driver 3.0.1.18;c:\windows\system32\Drivers\BDA_Capture_225_x64.sys [x]
R3 BDA_Loader_225;USB Digital-TV Receiver. Firmware Loader 7.1.9.0;c:\windows\system32\Drivers\BDA_Loader_225_x64.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-09 135664]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 k57nd60a;Broadcom NetLink (TM)-Gigabit-Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynUSB64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-07-29 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-07-29 399416]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2011-09-09 475088]
S3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{74FA3C8A-1739-4AE0-B578-0E4E288B6688}]
2009-12-16 19:12        126736        ----a-w-        c:\programdata\VoicePro12\VoiceProInstallCurrentUser.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-09-07 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000Core.job
- c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-02 18:40]
.
2011-09-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000UA.job
- c:\users\Christian\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-02 18:40]
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-09 19:59]
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-09 19:59]
.
2012-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000Core.job
- c:\users\Christian\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-09 21:20]
.
2012-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302499063-601275286-625076348-1000UA.job
- c:\users\Christian\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-09 21:20]
.
2012-03-06 c:\windows\Tasks\MATLAB R2011b Startup Accelerator.job
- c:\program files\MATLAB\R2011b\bin\win64\MATLABStartupAccelerator.exe [2012-03-06 14:34]
.
2011-09-01 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
.
2011-09-08 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
.
2011-09-08 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 09:20        75544        ----a-w-        c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2009-07-02 3180624]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]
"snpstd3"="c:\windows\vsnpstd3.exe" [2007-05-10 835584]
"combofix"="c:\combofix\CF16861.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page =
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: Free YouTube Download - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\dkqm69cp.default\
FF - prefs.js: network.proxy.type - 2
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-mcmscsvc
SafeBoot-MCODS
BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1302499063-601275286-625076348-1000\Software\SecuROM\License information*]
"datasecu"=hex:a2,83,b5,48,d6,e5,96,19,cd,74,21,7d,71,5f,68,3c,f7,5b,34,c7,a4,
  b6,75,74,14,1f,2f,f6,88,e3,b2,84,fe,b8,78,ee,53,25,1c,40,f0,75,c4,fe,26,f6,\
"rkeysecu"=hex:65,3c,b3,07,d3,4b,bd,88,b9,9e,f2,98,b1,77,61,a3
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Cisco Systems\VPN Client\cvpnd.exe
c:\program files (x86)\CDBurnerXP\NMSAccessU.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-08  23:20:45 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-03-08 22:20
.
Vor Suchlauf: 17 Verzeichnis(se), 27.277.410.304 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 26.896.732.160 Bytes frei
.
- - End Of File - - 51EBB3970518B7139A43209C817A6FDF

ComboFix-Log.

Unter weitere laufende Prozesse listet ComboFix den Avira Antivir-Guad auf, ich hab aber vor dem Scan die Checkbox "Echtzeit-Scanner aktivieren" auf deaktivieren geklickt. Wenn das nur die laufenden Prozesse nach dem Reboot sind passts wohl.

cosinus 08.03.2012 23:35

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

markus32 08.03.2012 23:51

Code:

aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-08 23:39:39
-----------------------------
23:39:39.024    OS Version: Windows x64 6.1.7601 Service Pack 1
23:39:39.024    Number of processors: 2 586 0x170A
23:39:39.024    ComputerName: CHRISTIAN  UserName: Christian
23:39:40.490    Initialize success
23:41:02.516    AVAST engine defs: 12030801
23:41:05.698    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:41:05.698    Disk 0 Vendor: WDC_WD2500BJKT-75F4T0 11.01A11 Size: 238475MB BusType: 11
23:41:05.714    Disk 1  \Device\Harddisk1\SR0 -> \Device\SdBus-0
23:41:05.714    Disk 1 Vendor: (  Size: 7580MB BusType: 12
23:41:05.729    Disk 0 MBR read successfully
23:41:05.729    Disk 0 MBR scan
23:41:05.745    Disk 0 Windows VISTA default MBR code
23:41:05.745    Disk 0 Partition 1 00    DE Dell Utility Dell 8.0      39 MB offset 63
23:41:05.761    Disk 0 Partition 2 80 (A) 42          SFS NTFS        15000 MB offset 80325
23:41:05.776    Disk 0 Partition 3 00    42          SFS NTFS      114457 MB offset 30800325
23:41:05.807    Disk 0 Partition 4 00    42          SFS            108977 MB offset 265208261
23:41:05.807    Disk 0 scanning C:\Windows\system32\drivers
23:41:05.823    Service scanning
23:41:32.047    Modules scanning
23:41:32.047    Disk 0 trace - called modules:
23:41:32.094    ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80049d82c0]<<spmc.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
23:41:32.109    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004cf2460]
23:41:32.109    3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004b2c060]
23:41:32.125    \Driver\atapi[0xfffffa8004aef060] -> IRP_MJ_CREATE -> 0xfffffa80049d82c0
23:41:33.685    AVAST engine scan C:\Windows
23:41:33.700    AVAST engine scan C:\Windows\system32
23:41:33.700    AVAST engine scan C:\Windows\system32\drivers
23:41:33.716    AVAST engine scan C:\Users\Christian
23:41:33.716    AVAST engine scan C:\ProgramData
23:41:33.732    Scan finished successfully
23:50:05.231    Disk 0 MBR has been saved successfully to "C:\Users\Christian\Desktop\MBR.dat"
23:50:05.231    The log file has been saved successfully to "C:\Users\Christian\Desktop\aswMBR.txt"


cosinus 08.03.2012 23:53

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

markus32 12.03.2012 14:16

Super AntiSpyware Log:
(Die Herkunftsangaben von den Tracking-Cookies hab ich selbst gelöscht.)
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/12/2012 at 07:46 AM

Application Version : 5.0.1146

Core Rules Database Version : 8324
Trace Rules Database Version: 6136

Scan type      : Complete Scan
Total Scan Time : 04:31:44

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 719
Memory threats detected  : 0
Registry items scanned    : 69007
Registry threats detected : 0
File items scanned        : 492689
File threats detected    : 44

Adware.Tracking Cookie
       
[...]

Malwarebytes-Log:

Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.11.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Christian :: CHRISTIAN [Administrator]

Schutz: Aktiviert

11.03.2012 17:53:21
mbam-log-2012-03-11 (17-53-21).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 653979
Laufzeit: 2 Stunde(n), 16 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 12.03.2012 15:34

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

markus32 12.03.2012 15:38

Also bis jetzt sehe ich keine weiteren Probleme. Vielen Dank für die Hilfe!

cosinus 12.03.2012 15:42

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:33 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27