keepsake | 08.09.2013 12:47 | adware bprotect Hallo ihr lieben Helfer,
Antivir hat mir gemeldet dass Malware in Form von Adware dprotect gefunden wurde. ich habe die befallenen datein mit avira in quaratäne verschoben.
Ich habe bis jetzt OTL, mbam und AdwCleaner drüber laufen lassen. Bei AdwCleaner habe ich bereits den Löschen button betätigt nach dem suchlauf und neu gestartet. die anderen beiden programme habe ich nur suchen lassen, aber nichts weiter gelöscht.
Symptome hat mein laptop nicht wirklich, ich finde er is langsamer als vorher. es gibt aber keine vermehrten pop ups oder sowas in der richtung. wenn ihr mehr wisen wollte stehe ich euch gern zur verfügung. Ich mag bloß gern das blöde gefrumse wieder vom rechner runter haben :)
OTL:logfile Code:
OTL logfile created on: 07.09.2013 19:28:39 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\XXXX\Downloads
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 0,52 Gb Available Physical Memory | 26,04% Memory free
4,22 Gb Paging File | 1,86 Gb Available in Paging File | 44,19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 85,71 Gb Total Space | 2,48 Gb Free Space | 2,90% Space Free | Partition Type: NTFS
Drive D: | 3,67 Gb Total Space | 3,46 Gb Free Space | 94,27% Space Free | Partition Type: FAT32
Computer Name: LÄPPI | User Name: XXXX | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - C:\Programme\Mendeley Desktop\MendeleyWordPlugin.exe ()
PRC - C:\Programme\Mendeley Desktop\MendeleyDesktop.exe (Mendeley Ltd.)
PRC - C:\Users\XXXX\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
PRC - C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlug in_11_8_800_94.exe (Adobe Systems, Inc.)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\XXXX\AppData\Roaming\Spotify\Data\Spotify WebHelper.exe (Spotify Ltd)
PRC - C:\Users\XXXX\AppData\Roaming\Dropbox\bin\Dropbox. exe (Dropbox, Inc.)
PRC - C:\Users\XXXX\AppData\Local\Temp\Foxit Reader Updater.exe (Foxit Corporation)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Programme\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\sony\VAIO Power Management\OPT Drive Power Saving.exe (Sony Corporation)
PRC - C:\Programme\sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Programme\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
PRC - C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Programme\sony\Network Utility\LANUtil.exe (Sony Corporation)
PRC - C:\Programme\sony\Network Utility\NSUService.exe (Sony Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Windows\System32\GtFlashSwitch.exe (OptionNV)
PRC - C:\Windows\System32\Gtdetectsc.exe (OptionNV)
PRC - C:\Programme\sony\WWAN\WWAN_reminder.exe (NSCE)
PRC - C:\Programme\sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Programme\sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Programme\sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
PRC - C:\Programme\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Programme\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Programme\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Programme\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) ========== Modules (No Company Name) ==========
MOD - C:\Programme\Mendeley Desktop\MendeleyWordPlugin.exe ()
MOD - C:\Programme\Mendeley Desktop\Mendeley.dll ()
MOD - C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_8_80 0_94.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Theme\8ea4590b552b63ce4433042b1bec5bcd\Kies.Them e.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Dev icePodcast\c33ebf3f502bf3dea9da6d24342334b1\Device Podcast.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Dev iceVideo\6812e556337e8e227341c2773cdcd7e5\DeviceVi deo.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Dev icePhoto\faf647240faed549d62042f7401b784b\DevicePh oto.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Dev iceMusic\71cf8fb0e2375141b7ea52ea91d29c95\DeviceMu sic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Vid eoManager\a55f6fcadd38f63761cbc3343d5bd4f3\VideoMa nager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pod castService\d6ff0d26a5db846d3692364a8cfe6b3e\Podca stService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pod caster\386882aa7fffa5b7f48887b4e5e58e66\Podcaster. ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pho toManager\9a058b7d790c9ab295494c6bcb87a85e\PhotoMa nager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Dev iceHost\97f7960284f0fd1b52d5d39054568c4e\DeviceHos t.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pho nebook\4f7fd72525e490c075581e05b4421e7b\Phonebook. ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\CPK TMusicPlugin\22ee8caaf8ecd18c26a90fc73320320f\CPKT MusicPlugin.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Mus icManager\d9d7272dd830d904264fb358556dfdcc\MusicMa nager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\EBo okManager\c8f91c1f87adb5388e4355ab466b7a4a\EBookMa nager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\BAT Plugin\9c06dd9add7d7a382a8920a427410138\BATPlugin. ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\All ShareController\d6381ee39b47d6ea76cb1bffaebcf33d\A llShareController.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.StoreMa#\1a3b7f2d750851d9159eb83d6e8e9cad \Kies.Common.StoreManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.MediaDB\cde96bc29d0e1108d9c9a3c51b094316\ Kies.Common.MediaDB.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF _cSharpAPI\c5efe841e2998c266e0f5e29bed04b55\ASF_cS harpAPI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.AllShare\a98b395bba3483234cf5f3f13e2c26f6 \Kies.Common.AllShare.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\a3d8bee773ca26c9a0a8b1d3643deb1d \Kies.Common.DeviceServiceLib.FirmwareUpdate.Commo n.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\cb84fc991b94ae87e805c7337f830d21 \Kies.Common.DeviceServiceLib.FirmwareUpdate.Downl oader.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\371f07e556fd02c7ebf189013100669c \Kies.Common.DeviceServiceLib.FileService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\00bee429371f9569c1dc5f2b448acdf2 \Kies.Common.DeviceServiceLib.DeviceDataService.ni .dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\7448abb44c5c502633060a6cc639e51e \Kies.Common.DeviceServiceLib.Interface.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\16bccf673ecc1c3af893d975389bb486 \Kies.Common.DeviceServiceLib.DeviceManagement.ni. dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\9a02e59537e11d521d6f566c37c03383 \Kies.Common.DeviceService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.Multime#\7c3f1d107e40d4d1acf2a79810a921dd \Kies.Common.Multimedia.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.MainUI\8f3c23224d649605b02f97c4ac374ef1\K ies.Common.MainUI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DBManag#\1e98e1a178984623f3dc6842b7df0f16 \Kies.Common.DBManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\ICS harpCode.SharpZi#\70c775e13456b1975ac67f549ee29b53 \ICSharpCode.SharpZipLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.Util\f69a0fd8c98acd0d7c0daed896223c1a\Kie s.Common.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Locale\98c9133eed4ba2d997a39c56246f9a38\Kies.Loc ale.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.MVVM\6222abd000d73a556064306b6e3ed4c7\Kies.MVVM. ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.UI\e0ea55ba9dca94811b7550c77649b762\Kies.UI.ni.d ll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Gon gSolutions.Wpf.D#\c53add3b694c642897bc85713ee57ec2 \GongSolutions.Wpf.DragDrop.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Interface\043bc768300ba87bbdca3c1b098ebfd4\Kies. Interface.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.ServiceProce#\5974034f0f53755b11bde4c9698261cb \System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Configuration\b8e424ef545f262fd6cb9f35b97fc8b9 \System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Xml\09f5b3f7a363b742a73937e818595597\System.Xm l.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Windows.Forms\f575e4c534a93294c72fea670ca73492 \System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Drawing\c0df7e124d8d5e2821fd7d3921d404f7\Syste m.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem\d7153acb7b6ccb5a6a886d6f0ab732b1\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.ServiceProce#\d8f4106eee38420ac5eda7d630dc53fc \System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Runtime.Remo#\f17c7bc239be0eb7661cbcd3cff1ea16 \System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Xaml\c8648331484537c338fe2b606a9db8b7\System.X aml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s\6733715b4b716c51b75acfc8163738a9\Kies.ni.exe ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pre sentationFramewo#\8532e498c23b60bee2e5ffcf4411c86d \PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Windows.Forms\5cc02b72a68b85674a570b126c39ad7d \System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Pre sentationCore\40841519650bcf0de403049960550c20\Pre sentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Drawing\2154273cb2d7a8b1a47d672b6d0808bf\Syste m.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Win dowsBase\d2382128944d16da8adf76c58fb8e6f1\WindowsB ase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Xml\b7285e9f3d19a05d5cc2c049e451685d\System.Xm l.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Core\7b6f508b953eebe51c55ad40f468af2e\System.C ore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Configuration\11467cefb818233a909bdd3426ccab69 \System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem\08c630893416f3379c9455870908ad6c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\msc orlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni .dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Kie s.Common.DeviceS#\feb091eff0150ebdd8b28ccfc439824b \Kies.Common.DeviceServiceLib.FirmwareUpdate.Firmw areUpdateAgentHelper.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.DevFileServ#\9f5132483649edef1dd6c849fd240da8 \Interop.DevFileServiceLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.MP3FileInfo#\be9d4a331a41a83465c56b735845c86b \Interop.MP3FileInfoCOMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.OGGFileInfo#\0cd09e4839a2bfe65311191d2e61c698 \Interop.OGGFileInfoCOMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.PRPLAYERCOR#\46e37ca6c73aee2fd773ae739f5324d8 \Interop.PRPLAYERCORELib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.P3MPINTERFA#\a474771ad225ef2b83d38a86a160ed53 \Interop.P3MPINTERFACECTRLLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Cab Lib\abebd90a3673cde0cd3a1b81a9f18f86\CabLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Int erop.DeviceSearc#\eea8db63092ff4b46a05dde0562aa7e5 \Interop.DeviceSearchLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\msc orlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni .dll ()
MOD - C:\Users\XXXX\AppData\Roaming\Dropbox\bin\libcef.d ll ()
MOD - C:\Users\XXXX\AppData\Roaming\Dropbox\bin\wxmsw28u h_vc.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
MOD - C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2. 0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Programme\sony\WWAN\Win32Interop.dll ()
MOD - C:\Programme\sony\VAIO Camera Utility\VCULib.dll ()
MOD - C:\Windows\System32\TosCommAPI.dll () ========== Services (SafeList) ==========
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (vpnagent) -- C:\Programme\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpda teService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (VUAgent) -- C:\Programme\sony\VAIO Update Common\VUAgent.exe (Sony Corporation)
SRV - (SQLWriter) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (MSSQL$VAIO_VEDB) -- C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQL$MSSMLBIZ) -- C:\Programme\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) -- C:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (VMCService) -- C:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (osppsvc) -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Vcsw) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResou rceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VCFw) -- C:\Programme\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (BcmSqlStartupSvc) -- C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (NSUService) -- C:\Programme\sony\Network Utility\NSUService.exe (Sony Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (GtFlashSwitch) -- C:\Windows\System32\GtFlashSwitch.exe (OptionNV)
SRV - (gtdetectsc) -- C:\Windows\System32\Gtdetectsc.exe (OptionNV)
SRV - (VAIO Event Service) -- C:\Programme\sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (TOSHIBA Bluetooth Service) -- C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (SSScsiSV) -- C:\Programme\Common Files\Sony Shared\AvLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) -- C:\Programme\Common Files\Sony Shared\AvLib\SsBeSvc.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) -- C:\Programme\sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-UPnP) -- C:\Programme\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) -- C:\Programme\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-AppServer) -- C:\Programme\sony\VAIO Media Integrated Server\UCLS.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-UCLS-HTTP) -- C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) -- C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) -- C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (AdobeActiveFileMonitor5.0) -- C:\Programme\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (MSCSPTISRV) -- C:\Programme\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) -- C:\Programme\Common Files\Sony Shared\AvLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) -- C:\Programme\Common Files\Sony Shared\AvLib\PACSPTISVR.exe () ========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (acsmux) -- C:\Windows\System32\drivers\acsmux.sys (Cisco Systems, Inc.)
DRV - (acsint) -- C:\Windows\System32\drivers\acsint.sys (Cisco Systems, Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (vpnva) -- C:\Windows\System32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (ssudserd) -- C:\Windows\System32\drivers\ssudserd.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (ssudmdm) -- C:\Windows\System32\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (dg_ssudbus) -- C:\Windows\System32\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (sscemdm) -- C:\Windows\System32\drivers\sscemdm.sys (MCCI Corporation)
DRV - (ssceserd) -- C:\Windows\System32\drivers\ssceserd.sys (MCCI Corporation)
DRV - (sscebus) -- C:\Windows\System32\drivers\sscebus.sys (MCCI Corporation)
DRV - (sscemdfl) -- C:\Windows\System32\drivers\sscemdfl.sys (MCCI Corporation)
DRV - (ZTEusbnet) -- C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) -- C:\Windows\System32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (KMWDFILTER) -- C:\Windows\System32\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (NETw4v32) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (tosrfusb) -- C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (tosrfbd) -- C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (GTUQBUS) -- C:\Windows\System32\drivers\gtuqbus.sys (Option N.V.)
DRV - (GTSCSER) -- C:\Windows\System32\drivers\gtscser.sys (Option N.V.)
DRV - (GTPTSER) -- C:\Windows\System32\drivers\gtptser.sys (Option N.V.)
DRV - (SonyImgF) -- C:\Windows\System32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (R5U870FLx86) -- C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) -- C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (risdptsk) -- C:\Windows\System32\drivers\risdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (shpf) -- C:\Windows\System32\drivers\shpf.sys (Sony Corporation)
DRV - (Tosrfhid) -- C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (SNC) -- C:\Windows\System32\drivers\SonyNC.sys (Sony Corporation)
DRV - (tosrfbnp) -- C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (NETw3v32) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (DMICall) -- C:\Windows\System32\drivers\DMICall.sys (Sony Corporation)
DRV - (tosporte) -- C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (SPI) -- C:\Windows\System32\drivers\SonyPI.sys (Sony Corporation)
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Tosrfcom) -- C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfnds) -- C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{F9872F96-C881-4FA4-827B-A50BC1CFE4E6}: "URL" = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVer sion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Inter net Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://partnerpage.google.com/eu.s [Binary data over 200 bytes]
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\..\SearchScopes\{F9872F96-C881-4FA4-827B-A50BC1CFE4E6}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language }:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7&rlz=1I7SNYK_deDE453
IE - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: amznUWL2%40amazon.com:1.10
FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:4.2.1.9
FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.145
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515
FF - prefs.js..extensions.enabledAddons: toolbar%40web.de:2.6.1
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.11
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_80 0_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\XXXX\AppData\Local\Facebook\Video\Skype\n pFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.11.10 23:39:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.08.19 21:45:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.09.06 11:13:24 | 000,000,000 | ---D | M]
[2011.10.14 13:24:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\Extensions
[2013.08.20 06:28:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\Firefox\Prof iles\iiv46cq4.default\extensions
[2013.05.17 19:05:05 | 000,000,000 | ---D | M] (WOT) -- C:\Users\XXXX\AppData\Roaming\mozilla\Firefox\Prof iles\iiv46cq4.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.08.14 07:31:10 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\XXXX\AppData\Roaming\mozilla\Firefox\Prof iles\iiv46cq4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012.11.01 11:41:49 | 000,243,287 | ---- | M] () (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\extensions\amznUWL2@amazon.c om.xpi
[2013.06.23 20:01:25 | 000,613,211 | ---- | M] () (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\extensions\toolbar@web.de.xp i
[2012.12.11 18:22:00 | 000,036,098 | ---- | M] () (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2013.08.13 07:30:33 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.08.13 00:21:15 | 000,275,449 | ---- | M] () (No name found) -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011.12.19 15:04:35 | 000,005,508 | ---- | M] () -- C:\Users\XXXX\AppData\Roaming\mozilla\firefox\prof iles\iiv46cq4.default\searchplugins\webde-suche.xml
[2013.08.19 21:48:29 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.08.19 21:48:28 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013.08.19 21:48:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.08.19 21:45:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.08.19 21:54:47 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013.08.19 21:45:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2013.08.19 21:46:48 | 000,000,000 | ---D | M] (WEB.DE Toolbar) -- C:\Programme\Mozilla Firefox\distribution\extensions\toolbar@web.de
[2011.11.10 23:39:51 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video> -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programme\Google BAE\BAE.dll (Your Company Name)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [AML] C:\Program Files\Sony\VAIO AV Mode Launcher\AML.exe (Sony)
O4 - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [VAIOCameraUtility] C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WWAN_reminder] C:\Programme\sony\WWAN\WWAN_reminder.exe (NSCE)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [Facebook Update] C:\Users\XXXX\AppData\Local\Facebook\Update\Facebo okUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\ KiesPDLR.exe ()
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [NSUFloatingUI] C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
O4 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004..\Run: [Spotify Web Helper] C:\Users\XXXX\AppData\Roaming\Spotify\Data\Spotify WebHelper.exe (Spotify Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\XXXX\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Startup\Dropbox.lnk = C:\Users\XXXX\AppData\Roaming\Dropbox\bin\Dropbox. exe (Dropbox, Inc.)
O7 - HKU\S-1-5-21-1349350522-1392879031-607472974-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\XXXX\AppData\Roaming\DVDVideoSoftIEHelper s\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - Reg Error: Value error. File not found
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Programme\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/ge...sh/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 193.189.244.202 193.189.244.194
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{78A30AB4-6687-4673-B098-B9890A92A86C}: DhcpNameServer = 192.168.1.1 193.189.244.202 193.189.244.194
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{79EC265C-D24C-4A08-A85B-D77A3C8BF3BB}: DhcpNameServer = 139.7.30.125 139.7.30.126
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{AA47AD90-1313-4EA9-BEAD-B2B58AC19124}: DhcpNameServer = 192.168.1.1 193.189.244.194 193.189.244.202
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Users\XXXX\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\XXXX\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{b549f8f4-4585-11e1-9ff3-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{b549f8f4-4585-11e1-9ff3-00a0c6000000}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrvonServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ==========
[2013.09.06 14:33:19 | 000,039,888 | R--- | C] (Cisco Systems, Inc.) -- C:\Windows\System32\drivers\acsint.sys
[2013.09.06 12:14:46 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013.09.06 12:14:45 | 000,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Malwarebytes
[2013.09.06 12:14:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.09.06 12:14:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.09.06 12:14:15 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.09.06 12:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.09.06 11:39:14 | 000,000,000 | ---D | C] -- C:\Users\XXXX\Desktop\Bewerbungen
[2013.09.06 10:34:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.09.03 20:34:47 | 000,000,000 | ---D | C] -- C:\Users\XXXX\Documents\WG
[2013.08.31 00:10:50 | 000,011,152 | ---- | C] (Cisco Systems, Inc.) -- C:\Windows\System32\vpncategories.dll
[2013.08.31 00:10:47 | 000,034,192 | ---- | C] (Cisco Systems, Inc.) -- C:\Windows\System32\vpnevents.dll
[2013.08.30 23:51:25 | 000,058,320 | R--- | C] (Cisco Systems, Inc.) -- C:\Windows\System32\drivers\acsmux.sys
[2013.08.28 23:32:14 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2013.08.19 21:45:08 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.08.19 21:05:11 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.08.19 21:05:07 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.08.19 21:05:06 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.08.19 21:05:06 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.08.19 21:05:05 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.08.19 21:05:03 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.08.19 21:05:02 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.08.19 21:04:58 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.08.14 06:45:06 | 003,603,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013.08.14 06:45:06 | 003,551,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.08.14 06:43:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013.08.13 23:55:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SigmaPlot
[2013.08.13 23:53:57 | 000,000,000 | ---D | C] -- C:\Program Files\SigmaPlot
[2013.08.13 00:53:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2013.08.13 00:50:09 | 000,000,000 | ---D | C] -- C:\Users\XXXX\AppData\Roaming\Avira
[2013.08.13 00:22:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.08.13 00:21:04 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.08.13 00:21:01 | 000,136,672 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.08.13 00:21:01 | 000,088,840 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013.08.13 00:21:01 | 000,037,352 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013.08.13 00:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013.08.13 00:18:35 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2013.08.09 03:03:03 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[3 C:\Users\XXXX\Desktop\*.tmp files -> C:\Users\XXXX\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2013.09.07 19:47:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.09.07 19:02:27 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1349350522-1392879031-607472974-1004UA.job
[2013.09.07 17:57:08 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.09.07 17:57:07 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.09.07 17:56:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.09.07 03:18:26 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1349350522-1392879031-607472974-1004Core.job
[2013.09.06 12:16:27 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013.09.06 12:14:20 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.09.06 11:00:15 | 000,002,473 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat - Schnellstart.lnk
[2013.09.06 10:57:06 | 2137,055,232 | -HS- | M] () -- C:\hiberfil.sys
[2013.09.02 15:25:36 | 000,136,672 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.09.02 15:25:36 | 000,088,840 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013.08.31 00:10:50 | 000,011,152 | ---- | M] (Cisco Systems, Inc.) -- C:\Windows\System32\vpncategories.dll
[2013.08.31 00:10:47 | 000,034,192 | ---- | M] (Cisco Systems, Inc.) -- C:\Windows\System32\vpnevents.dll
[2013.08.30 23:51:25 | 000,058,320 | R--- | M] (Cisco Systems, Inc.) -- C:\Windows\System32\drivers\acsmux.sys
[2013.08.30 23:51:25 | 000,039,888 | R--- | M] (Cisco Systems, Inc.) -- C:\Windows\System32\drivers\acsint.sys
[2013.08.28 09:18:07 | 000,000,680 | ---- | M] () -- C:\Users\XXXX\AppData\Local\d3d9caps.dat
[2013.08.20 22:47:39 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.08.20 22:47:39 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.08.19 21:21:12 | 000,742,932 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.08.19 21:21:12 | 000,689,662 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.08.19 21:21:12 | 000,173,622 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.08.19 21:21:12 | 000,139,424 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.08.13 23:55:13 | 000,000,816 | ---- | M] () -- C:\Users\Public\Desktop\SigmaPlot 12.0.lnk
[2013.08.13 23:50:02 | 000,001,025 | ---- | M] () -- C:\Windows\System32\cjgbm28.tgz
[2013.08.13 23:50:02 | 000,001,025 | ---- | M] () -- C:\Windows\System32\cjgbm28.dll
[2013.08.13 23:50:02 | 000,000,218 | ---- | M] () -- C:\Windows\System32\vyg4l5a.tgz
[2013.08.13 23:50:02 | 000,000,204 | ---- | M] () -- C:\Windows\System32\vyg4l5a.dll
[2013.08.13 23:49:57 | 000,001,025 | ---- | M] () -- C:\Windows\System32\grcauth2.dll
[2013.08.13 23:49:57 | 000,001,025 | ---- | M] () -- C:\Windows\System32\grcauth1.dll
[2013.08.13 23:49:57 | 000,000,114 | ---- | M] () -- C:\Windows\System32\prsgrc.tgz
[2013.08.13 23:49:56 | 000,000,100 | ---- | M] () -- C:\Windows\System32\prsgrc.dll
[2013.08.13 23:49:54 | 000,001,025 | ---- | M] () -- C:\Windows\System32\clauth2.dll
[2013.08.13 23:49:54 | 000,001,025 | ---- | M] () -- C:\Windows\System32\clauth1.dll
[2013.08.13 23:49:54 | 000,000,086 | ---- | M] () -- C:\Windows\System32\ssprs.tgz
[2013.08.13 23:49:54 | 000,000,072 | ---- | M] () -- C:\Windows\System32\ssprs.dll
[2013.08.09 20:00:39 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.08.09 20:00:38 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[3 C:\Users\XXXX\Desktop\*.tmp files -> C:\Users\XXXX\Desktop\*.tmp -> ] ========== Files Created - No Company Name ==========
[2013.09.06 12:14:20 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.08.13 23:55:13 | 000,000,816 | ---- | C] () -- C:\Users\Public\Desktop\SigmaPlot 12.0.lnk
[2013.08.13 23:50:02 | 000,001,025 | ---- | C] () -- C:\Windows\System32\cjgbm28.tgz
[2013.08.13 23:50:02 | 000,001,025 | ---- | C] () -- C:\Windows\System32\cjgbm28.dll
[2013.08.13 23:50:02 | 000,000,204 | ---- | C] () -- C:\Windows\System32\vyg4l5a.dll
[2013.08.13 23:49:57 | 000,001,025 | ---- | C] () -- C:\Windows\System32\grcauth2.dll
[2013.08.13 23:49:57 | 000,001,025 | ---- | C] () -- C:\Windows\System32\grcauth1.dll
[2013.08.13 23:49:56 | 000,000,100 | ---- | C] () -- C:\Windows\System32\prsgrc.dll
[2013.08.13 23:49:54 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2013.08.13 23:49:54 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2013.08.13 23:49:54 | 000,000,218 | ---- | C] () -- C:\Windows\System32\vyg4l5a.tgz
[2013.08.13 23:49:54 | 000,000,114 | ---- | C] () -- C:\Windows\System32\prsgrc.tgz
[2013.08.13 23:49:54 | 000,000,086 | ---- | C] () -- C:\Windows\System32\ssprs.tgz
[2013.08.13 23:49:54 | 000,000,072 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2013.08.13 23:49:49 | 000,000,016 | -H-- | C] () -- C:\Windows\System32\vd23d61.dll
[2012.08.28 10:04:34 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012.08.28 10:04:34 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012.08.28 10:04:34 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2012.08.28 10:04:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.08.28 10:04:32 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012.08.24 13:16:01 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2012.08.24 13:13:39 | 000,107,520 | RHS- | C] () -- C:\Windows\System32\TAKDSDecoder.dll
[2012.02.14 00:09:38 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2012.01.22 17:56:44 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.10.27 14:12:31 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.b in
[2011.10.26 23:39:54 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.10.26 23:39:54 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.10.26 23:38:11 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.10.18 12:56:41 | 000,000,680 | ---- | C] () -- C:\Users\XXXX\AppData\Local\d3d9caps.dat
[2011.10.17 16:27:26 | 000,042,496 | ---- | C] () -- C:\Users\XXXX\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.13 18:09:22 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.10.13 17:34:13 | 000,019,968 | ---- | C] () -- C:\Windows\System32\Cpuinf32.dll
[2011.10.13 17:30:50 | 000,532,480 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Sony.dll
[2010.03.15 21:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 ========== ZeroAccess Check ==========
[2006.11.02 14:54:18 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc8 7-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA 9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CD B-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both ========== LOP Check ==========
[2011.10.13 17:15:41 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Alice Systems
[2012.10.16 13:30:21 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Bildverkleinerer
[2013.06.06 10:50:26 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Canon
[2013.01.13 19:57:48 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\DAEMON Tools Lite
[2013.09.06 11:10:10 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Dropbox
[2012.02.08 13:33:36 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\DVDVideoSoft
[2013.03.03 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\EndNote
[2013.06.06 12:58:38 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Foxit Software
[2012.01.08 18:56:17 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Haenlein-Software
[2012.04.10 13:43:00 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\ICQ
[2011.11.24 19:05:50 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Melanie
[2011.11.22 15:15:36 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Opera
[2012.09.08 17:51:49 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Samsung
[2013.09.06 09:55:18 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Spotify
[2012.04.10 15:09:32 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\TuneUp Software
[2012.02.01 12:15:09 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\Vodafone
[2012.03.27 16:49:03 | 000,000,000 | ---D | M] -- C:\Users\XXXX\AppData\Roaming\www.rene-zeidler.de ========== Purity Check ========== ========== Files - Unicode (All) ==========
[2013.09.07 18:01:53 | 096,511,910 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\ꄆᨽᴼˆ
[2013.09.07 18:01:53 | 000,000,000 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\ꄆᨽᴼˆ
[2013.09.06 08:37:09 | 096,304,236 | ---- | M] ()(C:\Windows\System32\????) -- C:\Windows\System32\㔄㼪ᴼœ
[2013.09.06 08:37:09 | 096,304,236 | ---- | C] ()(C:\Windows\System32\????) -- C:\Windows\System32\㔄㼪ᴼœ
< End of report > mbam: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.06.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
XXXX :: LÄPPI [Administrator]
06.09.2013 12:18:05
MBAM-log-2013-09-07 (19-20-23).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 473529
Laufzeit: 6 Stunde(n), 40 Minute(n), 59 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 3
C:\Users\XXXX\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\mt_ffx\Delta\delt a (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\mt_ffx\Delta\delt a\1.8.22.0 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt.
Infizierte Dateien: 14
C:\$Recycle.Bin\S-1-5-21-1349350522-1392879031-607472974-1004\$RU18UQD.exe (PUP.Optional.Installex) -> Keine Aktion durchgeführt.
C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe.vir (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt.
C:\Program Files\ICQ7.6\install_dll\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Microsoft\Windows\Temp orary Internet Files\Content.IE5\TS0A1C35\pack[1].7z (PUP.Optional.BrowserDefender.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Microsoft\Windows\Temp orary Internet Files\Content.IE5\TS0A1C35\WebCakesetup[1].exe (PUP.Optional.Yontoo) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\toolbar3258314.ex e (PUP.Optional.Yontoo) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\toolbar3259375.ex e (PUP.Optional.DeltaTB) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\6B447BF0-BAB0-7891-8E92-5FE604973E34\BabMaint.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\6B447BF0-BAB0-7891-8E92-5FE604973E34\BUSolution.dll (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\6B447BF0-BAB0-7891-8E92-5FE604973E34\ccp.exe (PUP.Babylon.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\6B447BF0-BAB0-7891-8E92-5FE604973E34\MyDeltaTB.exe (PUP.Delta.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\6B447BF0-BAB0-7891-8E92-5FE604973E34\NTRedirect.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\AppData\Local\Temp\7964126B-BAB0-7891-9C9C-F6701A3C360A\Setup.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt.
C:\Users\XXXX\Downloads\SoftonicDownloader_for_sig maplot.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt.
(Ende) Code:
# AdwCleaner v3.002 - Bericht erstellt am 06/09/2013 um 10:34:33
# Updated 01/09/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Business Service Pack 2 (32 bits)
# Benutzername : XXXX - LÄPPI
# Gestartet von : C:\Users\XXXX\Downloads\adwcleaner_3002.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
Datei Gefunden : C:\Users\Public\Desktop\RegClean Pro.lnk
Datei Gefunden : C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Prof iles\iiv46cq4.default\\invalidprefs.js
Datei Gefunden : C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Prof iles\iiv46cq4.default\searchplugins\Babylon.xml
Datei Gefunden : C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Prof iles\iiv46cq4.default\searchplugins\BrowserDefende r.xml
Datei Gefunden : C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Prof iles\iiv46cq4.default\user.js
Datei Gefunden : C:\Windows\system32\roboot.exe
Datei Gefunden : C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
Datei Gefunden : C:\Windows\System32\Tasks\RegClean Pro_UPDATES
Datei Gefunden : C:\Windows\Tasks\RegClean Pro_DEFAULT.job
Datei Gefunden : C:\Windows\Tasks\RegClean Pro_UPDATES.job
Ordner Gefunden C:\Inbox
Ordner Gefunden C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gefunden C:\Program Files\ExpressFiles
Ordner Gefunden C:\Program Files\RegClean Pro
Ordner Gefunden C:\ProgramData\Babylon
Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Ordner Gefunden C:\ProgramData\Tarma Installer
Ordner Gefunden C:\Users\XXXX\AppData\Local\Temp\OCS
Ordner Gefunden C:\Users\XXXX\AppData\LocalLow\boost_interprocess
Ordner Gefunden C:\Users\XXXX\AppData\Roaming\Babylon
Ordner Gefunden C:\Users\XXXX\AppData\Roaming\dvdvideosoftiehelper s
Ordner Gefunden C:\Users\XXXX\AppData\Roaming\ExpressFiles
Ordner Gefunden C:\Users\XXXX\AppData\Roaming\pdfforge
Ordner Gefunden C:\Users\XXXX\AppData\Roaming\Systweak
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Produkt Gefunden : BabylonObjectInstaller
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\BabSolution
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : HKCU\Software\Delta
Schlüssel Gefunden : HKCU\Software\ExpressFiles
Schlüssel Gefunden : HKCU\Software\Microsoft\Babylon
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean Pro_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\systweak
Schlüssel Gefunden : HKLM\SOFTWARE\59ed8dde269ba43
Schlüssel Gefunden : HKLM\Software\Babylon
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\Software\Delta
Schlüssel Gefunden : HKLM\Software\ExpressFiles
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhce odhffomolpfigojocbpcb
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\RegClea n Pro_DEFAULT
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\RegClea n Pro_UPDATES
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\RegClea n Pro_DEFAULT
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\RegClea n Pro_UPDATES
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\{83AA2913-C123-4146-85BD-AD8F93971D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\RegClean Pro_is1
Schlüssel Gefunden : HKLM\Software\PIP
Schlüssel Gefunden : HKLM\Software\systweak
Schlüssel Gefunden : HKLM\Software\Tarma Installer
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16502
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.babylon.com/?affID=111304&tt=3412_1&babsrc=HP_ss&mntrId=2864fe f2000000000000001bfbceb400
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\XXXX\AppData\Roaming\Mozilla\Firefox\Prof iles\iiv46cq4.default\prefs.js ]
Zeile gefunden : user_pref("extensions.BabylonToolbar.admin", false);
Zeile gefunden : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Zeile gefunden : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Zeile gefunden : user_pref("extensions.BabylonToolbar.excTlbr", false);
Zeile gefunden : user_pref("extensions.BabylonToolbar.id", "2864fef2000000000000001bfbceb400");
Zeile gefunden : user_pref("extensions.BabylonToolbar.instlDay", "15576");
Zeile gefunden : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Zeile gefunden : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Zeile gefunden : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Zeile gefunden : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Zeile gefunden : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://www.google.com/search?babsrc=TB_ggl&q=");
Zeile gefunden : user_pref("extensions.BabylonToolbar.vrsn", "1.6.4.6");
Zeile gefunden : user_pref("extensions.BabylonToolbar.vrsni", "1.6.4.6");
Zeile gefunden : user_pref("extensions.BabylonToolbar_i.babExt", "");
Zeile gefunden : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111304&tt=3412_1");
Zeile gefunden : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Zeile gefunden : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Zeile gefunden : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.4.613:12:37");
Zeile gefunden : user_pref("extensions.delta.admin", false);
Zeile gefunden : user_pref("extensions.delta.aflt", "babsst");
Zeile gefunden : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gefunden : user_pref("extensions.delta.autoRvrt", "false");
Zeile gefunden : user_pref("extensions.delta.dfltLng", "de");
Zeile gefunden : user_pref("extensions.delta.excTlbr", false);
Zeile gefunden : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gefunden : user_pref("extensions.delta.id", "2864fef2000000000000001cbf5660d0");
Zeile gefunden : user_pref("extensions.delta.instlDay", "15929");
Zeile gefunden : user_pref("extensions.delta.instlRef", "sst");
Zeile gefunden : user_pref("extensions.delta.newTab", false);
Zeile gefunden : user_pref("extensions.delta.prdct", "delta");
Zeile gefunden : user_pref("extensions.delta.prtnrId", "delta");
Zeile gefunden : user_pref("extensions.delta.rvrt", "false");
Zeile gefunden : user_pref("extensions.delta.smplGrp", "none");
Zeile gefunden : user_pref("extensions.delta.tlbrId", "base");
Zeile gefunden : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gefunden : user_pref("extensions.delta.vrsn", "1.8.22.0");
Zeile gefunden : user_pref("extensions.delta.vrsnTs", "1.8.22.01:07:22");
Zeile gefunden : user_pref("extensions.delta.vrsni", "1.8.22.0");
Zeile gefunden : user_pref("extensions.delta_i.babExt", "");
Zeile gefunden : user_pref("extensions.delta_i.babTrack", "affID=122303&tt=070813_wt4&tsp=4972");
Zeile gefunden : user_pref("extensions.delta_i.srcExt", "ss");
*************************
AdwCleaner[R0].txt - [9856 octets] - [06/09/2013 10:34:33]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [9916 octets] ########## ich werde jetzt noch die 4 schritte zur informationsbeschaffung durchgehen wie bei der anleitung für hilfesuchende steht. ich dachte vieleicht könnt ihr aber mit den logfiles schon was anfangen.
LG eure Keepsake |