ok hier die logs:
combofix: Code:
ComboFix 12-09-13.01 - xx 09/13/2012 16:55:30.2.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3037.1925 [GMT 2:00]
Running from: c:\users\xx\Desktop\ComboFix.exe
Command switches used :: /nombr c:\users\xx\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\xx\AppData\Local\Temp\26b4a1dd-e07b-48af-be4e-9642b273284b\CliSecureRT.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_COMSysApp
.
.
((((((((((((((((((((((((( Files Created from 2012-08-13 to 2012-09-13 )))))))))))))))))))))))))))))))
.
.
2012-09-13 15:03 . 2012-09-13 15:03 -------- d-----w- C:\microsoft
2012-09-13 15:02 . 2012-09-13 15:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-13 13:45 . 2012-09-13 13:45 -------- d-----w- c:\program files\Common Files\Java
2012-09-13 13:45 . 2012-09-13 13:45 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-12 07:27 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 07:27 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 07:27 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 07:27 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 07:27 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 07:27 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-11 23:43 . 2012-09-13 15:03 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F4F3636-887A-4822-A7E7-C03F73C8E4D8}\offreg.dll
2012-09-11 10:52 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F4F3636-887A-4822-A7E7-C03F73C8E4D8}\mpengine.dll
2012-09-08 13:39 . 2012-09-11 11:34 -------- d-----w- C:\TDSSKiller_Quarantine
2012-09-07 21:57 . 2012-09-07 21:57 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-09-07 12:34 . 2012-09-07 12:34 -------- d-----w- c:\program files\ESET
2012-09-07 12:21 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-09-06 23:00 . 2012-09-07 00:28 -------- d-----w- c:\programdata\SecTaskMan
2012-09-06 23:00 . 2012-09-06 23:00 -------- d-----w- c:\program files\Security Task Manager
2012-09-06 22:28 . 2012-09-06 22:28 -------- d-----w- c:\users\xx\AppData\Roaming\Malwarebytes
2012-09-06 22:28 . 2012-09-06 22:28 -------- d-----w- c:\programdata\Malwarebytes
2012-09-06 22:28 . 2012-09-06 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-06 22:28 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-06 20:07 . 2012-09-06 20:07 -------- d-----w- C:\bd_logs
2012-09-06 12:15 . 2012-09-07 23:07 -------- d-----w- c:\programdata\xtffwgbyekmqwbw
2012-08-21 06:52 . 2012-08-21 06:52 565616 ----a-w- c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor14.dll
2012-08-16 05:27 . 2012-07-18 17:47 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-08-16 05:27 . 2012-05-05 07:46 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-16 05:27 . 2012-07-04 21:14 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-16 05:27 . 2012-07-04 21:14 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-16 05:27 . 2012-02-11 05:43 492032 ----a-w- c:\windows\system32\win32spl.dll
2012-08-16 05:27 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-16 05:27 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 13:45 . 2012-05-09 16:12 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-13 13:45 . 2010-08-22 23:29 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-15 16:24 . 2012-06-14 12:56 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 16:24 . 2011-05-14 14:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-17 18:22 . 2011-02-06 00:48 22328 ----a-w- c:\users\xx\AppData\Roaming\PnkBstrK.sys
2012-07-17 18:21 . 2012-02-10 10:13 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-12 15:03 . 2012-07-12 15:03 3262 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2012-09-07 21:57 . 2011-04-23 18:23 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-06-08 21432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2009-03-09 55160]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2009-09-05 385024]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-06-08 3521464]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\xx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\xx\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
CardManagementTool.lnk - c:\program files\KOBIL Systems\KOBIL Smart Key\Smart Key\Microsoft CSP\CMT.exe [2010-8-22 1069056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-20 19:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-27 03:09 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 KOBCCEX;KOBCCEX;c:\windows\system32\drivers\KOBCCEX.sys [x]
R3 KOBCCID;KOBCCID;c:\windows\system32\drivers\KOBCCID.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [x]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 XDva382;XDva382;c:\windows\system32\XDva382.sys [x]
R3 XDva383;XDva383;c:\windows\system32\XDva383.sys [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\openvpnas.exe [x]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 enecirhid;ENE CIR HID Receiver;c:\windows\system32\DRIVERS\enecirhid.sys [x]
S3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\system32\DRIVERS\enecirhidma.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-14 16:24]
.
2012-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-24 19:25]
.
2012-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-24 19:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
uInternet Settings,ProxyOverride = *.local
IE: &Citavi Picker... - file://c:\program files\Internet Explorer\PLUGINS\Citavi Picker\ShowContextMenu.html
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - prefs.js: keyword.URL - hxxp://utils.babylon.com/abt/index.php?url=
FF - prefs.js: network.proxy.type - 2
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-17185805-2931279960-2750159110-1000\Software\SecuROM\License information*]
"datasecu"=hex:9e,be,b3,9e,6a,11,91,95,53,25,7e,5d,fe,6e,9b,eb,f4,a8,d9,3a,56,
d0,25,a9,b0,bc,27,16,70,5d,90,18,f3,8f,de,dd,2b,e4,74,c7,5c,0a,db,28,d4,68,\
"rkeysecu"=hex:54,a7,5e,99,73,31,48,81,08,cb,af,ec,2b,7b,90,b1
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\system32\brsvc01a.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\windows\system32\brss01a.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\ThpSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-09-13 17:09:49 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-13 15:09
ComboFix2.txt 2012-09-13 13:10
.
Pre-Run: 66,808,741,888 bytes free
Post-Run: 66,219,483,136 bytes free
.
- - End Of File - - 398E71B7452B4DE49BE87CB2F76755C4 mbam: Code:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Datenbank Version: v2012.09.13.08
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
xx:: xx PC [Administrator]
9/13/2012 5:26:56 PM
mbam-log-2012-09-13 (17-26-56).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 205272
Laufzeit: 5 Minute(n), 59 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) aswmbr: Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-13 17:33:55
-----------------------------
17:33:55.129 OS Version: Windows 6.1.7601 Service Pack 1
17:33:55.129 Number of processors: 2 586 0x170A
17:33:55.129 ComputerName: xx-PC UserName: xx
17:33:56.205 Initialize success
17:36:14.158 AVAST engine defs: 12091300
17:52:13.433 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
17:52:13.433 Disk 0 Vendor: Hitachi_HTS545050B9A300 PB4OC64G Size: 476940MB BusType: 11
17:52:13.473 Disk 0 MBR read successfully
17:52:13.473 Disk 0 MBR scan
17:52:13.473 Disk 0 unknown MBR code
17:52:13.493 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
17:52:13.503 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238470 MB offset 3074048
17:52:13.533 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 236969 MB offset 491460608
17:52:13.543 Disk 0 scanning sectors +976773120
17:52:13.853 Disk 0 scanning C:\Windows\system32\drivers
17:52:27.466 Service scanning
17:53:13.947 Modules scanning
17:53:31.089 Disk 0 trace - called modules:
17:53:31.448 ntkrnlpa.exe CLASSPNP.SYS disk.sys thpdrv.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys
17:53:31.454 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865b5030]
17:53:31.459 3 CLASSPNP.SYS[8b40459e] -> nt!IofCallDriver -> \Device\THPDRV1[0x865b3030]
17:53:31.465 5 thpdrv.sys[8b7e7bd9] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x864ab338]
17:53:32.296 AVAST engine scan C:\Windows
17:53:35.719 AVAST engine scan C:\Windows\system32
17:57:57.885 AVAST engine scan C:\Windows\system32\drivers
17:58:14.240 AVAST engine scan C:\Users\xx
18:12:14.342 AVAST engine scan C:\ProgramData
18:13:56.262 Scan finished successfully
18:15:24.078 Disk 0 MBR has been saved successfully to "C:\Users\xx\Desktop\MBR.dat"
18:15:24.078 The log file has been saved successfully to "C:\Users\xx\Desktop\aswMBR.txt" beim eset scan hab ich vergessen eine logfile zu erstellen, es wurde aber auch nichts gefunden.
allerdings hat antivir gestern und vorgestern jeweils (automatisch) einen trojaner endeckt:
am 12.09: C:\Users\xx\AppData\Local\Temp\resoancwmx.exe [TR\Kazy.92382.1]
am 13.09: C:\ProgramData\ubbitbtlgtfzhom.exe [TR\Weelsof.LE.6]
ansonsten läuft das system stabil, keinerlei störungen o.ä.
hier auch noch mal die OTL-logfile:
[/CODE]
OTL: Code:
OTL logfile created on: 9/14/2012 12:20:39 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\xx\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.97 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 56.81% Memory free
5.93 Gb Paging File | 4.34 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 60.73 Gb Free Space | 26.08% Space Free | Partition Type: NTFS
Drive D: | 231.42 Gb Total Space | 216.86 Gb Free Space | 93.71% Space Free | Partition Type: NTFS
Drive F: | 465.65 Gb Total Space | 304.97 Gb Free Space | 65.49% Space Free | Partition Type: FAT32
Computer Name: XX-PC | User Name: xx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\xx\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Users\xx\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
PRC - C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\KOBIL Systems\KOBIL Smart Key\Smart Key\Microsoft CSP\CMT.exe (KOBIL Systems GmbH)
========== Modules (No Company Name) ==========
MOD - C:\Users\xx\AppData\Local\Temp\26b4a1dd-e07b-48af-be4e-9642b273284b\CliSecureRT.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\d0e1cdaff8f9055187f8e7b52c060dff\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\31fab24c51c0cfe8b8115f24545f169f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\b68bee05c7e518172982cc92059c3315\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d239f585ee55f833dbe21e897e1265ac\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\00a4922fbf869a79c043b665035516b6\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\608d29d7cc89f3a9a195c91354561915\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b7de318e9fd1ef519ca6c1f3b5dba8e0\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\4230ed1c7990e4ee8352baf67a2a85fa\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a6e37a05b8d0cedbc5c3ea266ae3fc31\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\09bd2126bba2ab4f29ed52afde1470d7\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9abe44a0f82070ead5f1256683a4d25a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a6be120e49f895ef6b00e9918402395b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c1af4ec9a36f671617a8ecaec00373f4\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files\Hotspot Shield\bin\lang\gui-eng.dll ()
MOD - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC\Interop.SHDocVw\1.1.0.0__4b827ebe229d539f\Interop.SHDocVw.dll ()
MOD - C:\Windows\assembly\GAC_32\Asz.Citavi.IEPicker\1.0.0.0__f59eabe05cc67589\Asz.Citavi.IEPicker.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Toshiba\TBS\NotifyTBS.dll ()
MOD - C:\Program Files\Toshiba\FlashCards\Hotkey\FnZ.dll ()
MOD - C:\Program Files\Toshiba\FlashCards\BlackPng.dll ()
MOD - C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (HssTrayService) -- C:\Program Files\Hotspot Shield\bin\HSSTrayService.exe ()
SRV - (hshld) -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) -- C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Thpsrv) -- C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (XDva383) -- C:\Windows\system32\XDva383.sys File not found
DRV - (XDva382) -- C:\Windows\system32\XDva382.sys File not found
DRV - (Tosrfcom) -- File not found
DRV - (catchme) -- C:\Users\xx\AppData\Local\Temp\catchmeirbk.sys File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (DrvAgent32) -- C:\Windows\System32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (HssDrv) -- C:\Windows\System32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (sscdmdm) -- C:\Windows\System32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdbus) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (sscdmdfl) -- C:\Windows\System32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (ssadmdm) -- C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) -- C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (androidusb) -- C:\Windows\System32\drivers\ssadadb.sys (Google Inc)
DRV - (ssadmdfl) -- C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (MSHUSBVideo) -- C:\Windows\System32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (KOBCCEX) -- C:\Windows\System32\drivers\KOBCCEX.sys (KOBIL Systems GmbH)
DRV - (KOBCCID) -- C:\Windows\System32\drivers\KOBCCID.sys (KOBIL Systems GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (NETw5s32) -- C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (TVALZ) -- C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (tosrfec) -- C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (Thpdrv) -- C:\Windows\System32\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV - (Thpevm) -- C:\Windows\System32\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (mod7700) -- C:\Windows\System32\drivers\dvb7700all.sys (DiBcom)
DRV - (LPCFilter) -- C:\Windows\System32\drivers\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (enecirhid) -- C:\Windows\System32\drivers\enecirhid.sys (ENE TECHNOLOGY INC.)
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (enecirhidma) -- C:\Windows\System32\drivers\enecirhidma.sys (ENE TECHNOLOGY INC.)
DRV - (AmdLLD) -- C:\Windows\System32\drivers\AmdLLD.sys (AMD, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.hotspotshield.com/g/?c=h
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 AF 58 21 66 41 CB 01 [binary data]
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes,DefaultScope = {BFB62D3D-B24A-4403-A3BC-7F075DD7A79B}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{3FB8C5C1-D76B-4E1D-9602-4636BEE0069A}: "URL" = hxxp://search.microsoft.com/results.aspx?mkt=en-US&setlang=en-US&q={searchTerms}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{5E87B477-2069-478D-8A97-60039D605D61}: "URL" = hxxp://rover.ebay.com/rover/1/711-43047-14818-1/4?satitle={searchTerms}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{AD02027D-CEB1-4E22-9439-D6781B5FFFFA}: "URL" = hxxp://www.amazon.com/gp/search?ie=UTF8&tag=ie8search-20&index=blended&linkCode=qs&camp=1789&creative=9325&keywords={searchTerms}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{BFB62D3D-B24A-4403-A3BC-7F075DD7A79B}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\..\SearchScopes\{F2412434-27C6-4541-AC06-42EC6AEFD8C4}: "URL" = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}:5.0.13
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/07 23:57:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/28 04:07:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/09/15 17:16:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011/09/07 14:36:27 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/07 23:57:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/28 04:07:17 | 000,000,000 | ---D | M]
[2010/08/22 05:25:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Extensions
[2010/08/22 05:25:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/02/05 00:52:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\iivaumjc.Default User_22.8.10\extensions
[2010/08/22 18:14:25 | 000,000,000 | ---D | M] (Foxit Toolbar) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\iivaumjc.Default User_22.8.10\extensions\toolbar@ask.com
[2011/04/29 07:45:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\v8noktwa.S3c, chipkarte\extensions
[2011/04/29 07:45:39 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\v8noktwa.S3c, chipkarte\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012/09/06 14:31:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions
[2012/03/31 17:56:06 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/09/06 14:31:37 | 000,000,000 | ---D | M] (FoxClocks) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012/05/11 23:30:40 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\battlefieldplay4free@ea.com
[2012/06/05 16:30:36 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\fastdial@telega.phpnet.us
[2010/08/22 04:06:25 | 000,000,000 | ---D | M] (FoxStocks) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\foxstocks@ilan.cohen
[2012/05/18 14:16:10 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\ich@maltegoetz.de
[2012/07/31 10:17:20 | 000,550,833 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\DivXWebPlayer@divx.com.xpi
[2012/06/27 23:47:38 | 000,827,050 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\ffe_ff3aeroff4@game-point.net.xpi
[2012/06/27 23:47:39 | 000,811,915 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\ffe_ff3ff4@game-point.net.xpi
[2012/04/03 16:58:16 | 000,140,964 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\firegestures@xuldev.org.xpi
[2012/06/15 13:20:29 | 000,007,834 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\last-tab-close-button@victor.sacharin.xpi
[2011/09/09 15:03:36 | 000,514,913 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\menuiconsplus@codedawn.com.xpi
[2011/12/10 12:57:01 | 000,005,909 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\openbookmarkintab@piro.sakura.ne.jp.xpi
[2012/07/10 01:18:16 | 000,163,080 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\status4evar@caligonstudios.com.xpi
[2012/09/06 14:31:27 | 000,031,748 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\webmaster@keep-tube.com.xpi
[2011/08/26 14:21:57 | 000,011,510 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\youtube2mp3@mondayx.de.xpi
[2011/06/19 02:59:33 | 000,022,819 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{21e48e29-f574-4619-b65d-0f00eea92e5b}.xpi
[2011/06/19 02:28:12 | 000,009,833 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{42975993-6fa0-46f5-a45f-706915f18ebf}.xpi
[2012/08/30 18:29:47 | 000,199,396 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012/07/25 18:20:32 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/01/30 17:30:45 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2011/11/03 14:26:32 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012/03/29 00:48:04 | 000,685,019 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
[2012/08/15 16:47:18 | 000,045,226 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi
[2011/06/24 21:02:53 | 000,742,707 | ---- | M] () (No name found) -- C:\Users\xx\AppData\Roaming\Mozilla\Firefox\Profiles\wd3myjq5.default\extensions\{f36c6cd1-da73-491d-b290-8fc9115bfa55}.xpi
[2012/02/22 02:02:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/05/28 20:21:59 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/11/02 23:07:40 | 000,000,000 | ---D | M] ("Citavi Picker") -- C:\Program Files\Mozilla Firefox\extensions\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}
[2012/02/22 02:02:08 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
[2011/02/11 22:58:23 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/08/22 01:57:37 | 000,000,000 | ---D | M] (FoxTab) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/08/22 01:57:36 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\fastdial@telega.phpnet.us
[2010/08/22 01:57:36 | 000,000,000 | ---D | M] (Last tab close button) -- C:\Program Files\Mozilla Firefox\Back-up profiles\wd3myjq5.default\extensions\last-tab-close-button@victor.sacharin
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}
[2012/09/07 23:57:36 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012/09/07 23:57:33 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/29 01:57:34 | 000,001,847 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\privatesearch.xml
[2012/09/07 23:57:33 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/09/13 17:02:50 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKU\S-1-5-21-17185805-2931279960-2750159110-1000..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - Startup: C:\Users\xx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\xx\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-17185805-2931279960-2750159110-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Citavi Picker... - C:\Program Files\Internet Explorer\PLUGINS\Citavi Picker\ShowContextMenu.html ()
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{178892E8-C5C1-4E26-86F3-43F45F1C0D19}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3D321DC8-BA04-4FFF-9DE7-B8E0F39616D5}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/13 17:04:33 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/13 17:03:16 | 000,000,000 | ---D | C] -- C:\microsoft
[2012/09/13 16:09:10 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\xx\Desktop\OTL.exe
[2012/09/13 16:07:31 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\xx\Desktop\aswMBR.exe
[2012/09/13 15:45:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/09/13 15:45:19 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/09/13 15:45:08 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/09/13 15:10:59 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/12 09:27:50 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\RNDISMP.sys
[2012/09/12 09:27:49 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012/09/12 09:27:49 | 000,187,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/09/12 09:27:48 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2012/09/11 15:07:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/11 15:07:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/11 15:07:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/11 15:07:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/11 15:07:11 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/11 14:46:03 | 004,750,981 | R--- | C] (Swearware) -- C:\Users\xx\Desktop\ComboFix.exe
[2012/09/08 15:39:26 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/09/08 14:23:30 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\xx\Desktop\tdsskiller.exe
[2012/09/07 14:34:56 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/09/07 14:21:03 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012/09/07 02:51:31 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012/09/07 02:51:31 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012/09/07 02:51:31 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/09/07 02:51:30 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012/09/07 02:51:30 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/09/07 02:51:30 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012/09/07 02:51:30 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012/09/07 02:51:30 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012/09/07 02:51:30 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012/09/07 02:51:30 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/09/07 02:51:30 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012/09/07 02:51:30 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/09/07 02:51:30 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012/09/07 02:51:30 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012/09/07 02:51:30 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012/09/07 02:51:30 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012/09/07 02:51:30 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012/09/07 02:51:30 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012/09/07 02:51:30 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012/09/07 02:51:30 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012/09/07 02:51:30 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012/09/07 02:51:30 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012/09/07 02:51:30 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012/09/07 02:51:29 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012/09/07 02:51:29 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012/09/07 02:51:29 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012/09/07 02:51:29 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012/09/07 02:51:29 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012/09/07 02:51:28 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/09/07 02:51:28 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/09/07 02:51:28 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012/09/07 02:51:28 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012/09/07 02:51:28 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/09/07 02:51:28 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012/09/07 02:51:28 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012/09/07 02:51:28 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012/09/07 02:51:28 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012/09/07 01:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2012/09/07 01:00:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager
[2012/09/07 01:00:53 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
[2012/09/07 00:28:16 | 000,000,000 | ---D | C] -- C:\Users\xx\AppData\Roaming\Malwarebytes
[2012/09/07 00:28:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/07 00:28:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/07 00:28:07 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/07 00:28:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/06 22:07:00 | 000,000,000 | ---D | C] -- C:\bd_logs
[2012/09/06 14:15:04 | 000,000,000 | ---D | C] -- C:\ProgramData\xtffwgbyekmqwbw
[2012/08/16 07:27:42 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/08/16 07:27:40 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012/08/16 07:27:19 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/14 12:24:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/14 12:11:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/13 20:53:08 | 000,016,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/13 20:53:08 | 000,016,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/13 20:50:07 | 000,633,180 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/13 20:50:07 | 000,110,782 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/13 20:45:56 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/13 20:45:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/13 20:45:38 | 2388,283,392 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/13 18:15:24 | 000,000,512 | ---- | M] () -- C:\Users\xx\Desktop\MBR.dat
[2012/09/13 17:26:16 | 000,001,076 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/13 17:02:50 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/09/13 16:11:04 | 004,750,981 | R--- | M] (Swearware) -- C:\Users\xx\Desktop\ComboFix.exe
[2012/09/13 16:09:12 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\xx\Desktop\OTL.exe
[2012/09/13 16:07:53 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\xx\Desktop\aswMBR.exe
[2012/09/13 15:45:03 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/09/13 15:45:03 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/09/13 15:45:03 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/09/13 15:45:03 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/09/13 15:45:02 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/09/13 15:45:02 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012/09/13 13:51:41 | 000,002,924 | ---- | M] () -- C:\Users\xx\AppData\Roaming\benibelawordCount.usage
[2012/09/11 18:00:54 | 000,002,061 | ---- | M] () -- C:\Users\xx\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/09/08 14:23:53 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\xx\Desktop\tdsskiller.exe
[2012/09/07 23:58:07 | 000,001,995 | ---- | M] () -- C:\Users\xx\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/07 13:40:15 | 000,001,416 | ---- | M] () -- C:\Users\xx\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/09/07 02:51:31 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2012/09/07 02:51:31 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2012/09/07 02:51:31 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/09/07 02:51:30 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2012/09/07 02:51:30 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/09/07 02:51:30 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2012/09/07 02:51:30 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012/09/07 02:51:30 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2012/09/07 02:51:30 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012/09/07 02:51:30 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/09/07 02:51:30 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2012/09/07 02:51:30 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/09/07 02:51:30 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2012/09/07 02:51:30 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2012/09/07 02:51:30 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2012/09/07 02:51:30 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012/09/07 02:51:30 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2012/09/07 02:51:30 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012/09/07 02:51:30 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012/09/07 02:51:30 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/09/07 02:51:30 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2012/09/07 02:51:30 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012/09/07 02:51:30 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012/09/07 02:51:30 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012/09/07 02:51:29 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012/09/07 02:51:29 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2012/09/07 02:51:29 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2012/09/07 02:51:29 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2012/09/07 02:51:29 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012/09/07 02:51:28 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/09/07 02:51:28 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/09/07 02:51:28 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2012/09/07 02:51:28 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2012/09/07 02:51:28 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/09/07 02:51:28 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012/09/07 02:51:28 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2012/09/07 02:51:28 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2012/09/07 02:51:28 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2012/09/07 02:04:08 | 000,000,000 | ---- | M] () -- C:\ProgramData\E23VeBLen.dat
[2012/09/07 02:03:53 | 000,000,001 | ---- | M] () -- C:\ProgramData\NkH7rLHY.exe_.b
[2012/09/07 02:03:53 | 000,000,001 | ---- | M] () -- C:\ProgramData\NkH7rLHY.exe.b
[2012/08/22 19:16:46 | 000,240,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2012/08/22 19:16:36 | 000,187,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/08/17 10:31:00 | 000,410,472 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/15 18:24:43 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/08/15 18:24:43 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/13 18:15:24 | 000,000,512 | ---- | C] () -- C:\Users\xx\Desktop\MBR.dat
[2012/09/11 15:07:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/09/11 15:07:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/09/11 15:07:41 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/09/11 15:07:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/09/11 15:07:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/09/07 02:51:30 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/09/07 02:04:08 | 000,000,000 | ---- | C] () -- C:\ProgramData\E23VeBLen.dat
[2012/09/07 02:03:53 | 000,000,001 | ---- | C] () -- C:\ProgramData\NkH7rLHY.exe_.b
[2012/09/07 02:03:53 | 000,000,001 | ---- | C] () -- C:\ProgramData\NkH7rLHY.exe.b
[2012/09/07 00:28:08 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/01 17:47:46 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2012/05/22 06:05:51 | 000,000,030 | ---- | C] () -- C:\Windows\System32\brss01a.ini
[2012/05/22 06:05:50 | 000,000,462 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/05/22 06:05:50 | 000,000,026 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012/05/22 06:04:45 | 000,000,145 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012/05/22 06:04:45 | 000,000,023 | ---- | C] () -- C:\Windows\Brownie.ini
[2012/05/22 06:04:45 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012/05/22 06:04:44 | 000,011,567 | ---- | C] () -- C:\Windows\HL-1230.INI
[2012/05/22 06:04:44 | 000,000,114 | ---- | C] () -- C:\Windows\System32\brlmw03a.ini
[2012/02/20 13:46:34 | 000,327,306 | ---- | C] () -- C:\Users\xx\Clipboard01222.jpg
[2012/02/10 12:13:19 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012/01/31 01:15:44 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/01/31 01:15:42 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012/01/31 01:15:42 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012/01/31 01:15:42 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012/01/31 01:15:42 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/09/23 15:33:00 | 000,002,924 | ---- | C] () -- C:\Users\xx\AppData\Roaming\benibelawordCount.usage
[2011/08/26 15:36:45 | 000,094,577 | ---- | C] () -- C:\Users\xx\Clipboard01.jpg
[2011/05/10 07:57:53 | 000,000,000 | ---- | C] () -- C:\Users\xx\AppData\Local\{18C331F9-0108-418F-90FD-1801DA41CE86}
[2011/04/29 07:22:10 | 000,626,688 | ---- | C] () -- C:\Windows\System32\opensc.dll
[2011/04/29 07:22:10 | 000,147,456 | ---- | C] () -- C:\Windows\System32\pkcs15init.dll
[2011/04/29 07:22:10 | 000,098,304 | ---- | C] () -- C:\Windows\System32\opensc-pkcs11.dll
[2011/04/29 07:22:10 | 000,061,440 | ---- | C] () -- C:\Windows\System32\pkcs11-spy.dll
[2011/04/29 07:22:10 | 000,059,904 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2011/04/29 07:22:10 | 000,023,552 | ---- | C] () -- C:\Windows\System32\libp11.dll
[2011/04/16 19:47:48 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/04/13 04:55:31 | 000,001,182 | ---- | C] () -- C:\Users\xx\AppData\Roaming\evmanage.prf
[2011/02/06 04:53:35 | 000,000,096 | ---- | C] () -- C:\Users\xx\AppData\Local\fusioncache.dat
[2011/02/06 02:48:36 | 000,022,328 | ---- | C] () -- C:\Users\xx\AppData\Roaming\PnkBstrK.sys
[2011/02/04 01:31:27 | 000,000,324 | ---- | C] () -- C:\Windows\game.ini
[2011/01/24 04:36:27 | 000,005,632 | ---- | C] () -- C:\Users\xx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/24 01:10:25 | 000,000,094 | ---- | C] () -- C:\Users\xx\AppData\Roaming\TexPoint.ini
[2010/11/24 01:10:25 | 000,000,033 | ---- | C] () -- C:\Users\xx\AppData\Roaming\TexPoint.lic
[2010/08/29 00:15:45 | 000,003,712 | ---- | C] () -- C:\Users\xx\AppData\Roaming\evpro32.prf
[2010/08/22 18:19:38 | 000,011,264 | ---- | C] () -- C:\Users\xx\gsview32.ini
[2010/08/21 21:37:51 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== LOP Check ==========
[2010/11/02 23:09:05 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Academic Software Zurich
[2011/09/20 22:43:06 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Activision
[2011/09/16 01:27:00 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\benibela
[2012/08/05 19:23:56 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Broken Sword 2.5
[2012/09/14 12:18:33 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Dropbox
[2011/09/14 14:57:52 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Foxit Software
[2012/09/07 13:36:13 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Free Download Manager
[2010/09/05 23:39:28 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\FreeAudioPack
[2010/12/05 06:36:05 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\GetRightToGo
[2011/06/20 01:39:09 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\go
[2010/08/28 19:55:26 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\ICQ
[2010/09/30 02:00:52 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\IrfanView
[2011/12/23 11:41:15 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\l2rshell
[2012/04/29 20:35:18 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\OpenCandy
[2012/04/14 14:15:10 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Opera
[2012/08/20 10:21:50 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Origin
[2012/04/02 15:38:30 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Samsung
[2010/09/30 23:13:56 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Stata10
[2011/09/22 14:23:37 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\SumatraPDF
[2012/04/29 22:25:03 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\SynthMaker
[2012/07/12 15:12:18 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\SystemRequirementsLab
[2012/06/27 23:41:52 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Temp
[2010/08/22 05:25:55 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\Thunderbird
[2010/08/22 05:39:45 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\toshiba
[2010/08/22 05:36:40 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\WinBatch
[2010/08/22 19:25:21 | 000,000,000 | ---D | M] -- C:\Users\xx\AppData\Roaming\xm1
[2012/07/19 06:50:13 | 000,032,618 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report > |