Babylove | 21.11.2011 19:28 | windowsystem blockiert windows 7 Natürlich hab ich alles im Abgesicherten Modus vollzogen.
ah ok den hab ich hier : Code:
OTS logfile created on: 21.11.2011 18:59:14 - Run 1
OTS by OldTimer - Version 3.1.46.0 Folder = E:\
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 81,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 92,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,66 Gb Total Space | 361,76 Gb Free Space | 80,09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,88 Gb Total Space | 0,98 Gb Free Space | 52,03% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: +++++
Current User Name: +++++
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> E:\OTS.exe -> [2011.11.21 18:56:24 | 000,646,144 | ---- | M] (OldTimer Tools)
avscan.exe -> C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe -> [2011.07.02 10:16:14 | 000,484,008 | ---- | M] (Avira GmbH)
[Modules - No Company Name]
sqlite3.dll -> C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll -> [2010.06.17 14:27:02 | 000,355,688 | ---- | M] ()
[Win32 Services - Safe List]
64bit-(AMD External Events Utility) [Auto | Stopped] -> C:\Windows\SysNative\atiesrxx.exe -> [2010.01.22 02:01:12 | 000,202,752 | ---- | M] (AMD)
(AntiVirService) Avira AntiVir Guard [Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -> [2011.07.02 10:16:14 | 000,269,480 | ---- | M] (Avira GmbH)
(AntiVirSchedulerService) Avira AntiVir Planer [Auto | Stopped] -> C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -> [2011.04.27 16:59:59 | 000,136,360 | ---- | M] (Avira GmbH)
(MyWebSearchService) My Web Search Service [Auto | Stopped] -> C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwssvc.exe -> [2011.03.24 22:45:01 | 000,028,762 | ---- | M] (MyWebSearch.com)
(MWLService) MyWinLocker Service [On_Demand | Stopped] -> C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -> [2010.04.17 06:56:48 | 000,305,520 | ---- | M] (Egis Technology Inc.)
(DsiWMIService) Dritek WMI Service [Auto | Stopped] -> C:\Program Files (x86)\Launch Manager\dsiwmis.exe -> [2010.04.08 05:18:38 | 000,312,400 | ---- | M] (Dritek System Inc.)
(clr_optimization_v4.0.30319_32) Microsoft .NET Framework NGEN v4.0.30319_X86 [Auto | Stopped] -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -> [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation)
(UNS) Intel(R) Management & Security Application User Notification Service [Auto | Stopped] -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -> [2010.03.18 05:57:02 | 002,320,920 | ---- | M] (Intel Corporation)
(LMS) Intel(R) Management and Security Application Local Management Service [Auto | Stopped] -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -> [2010.03.18 05:56:56 | 000,268,824 | ---- | M] (Intel Corporation)
(ePowerSvc) Acer ePower Service [Auto | Stopped] -> C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe -> [2010.03.17 09:56:12 | 000,866,336 | ---- | M] (Acer Incorporated)
(NTI IScheduleSvc) NTI IScheduleSvc [Auto | Stopped] -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -> [2010.03.09 00:58:24 | 000,250,368 | ---- | M] (NewTech Infosystems, Inc.)
(Updater Service) Updater Service [Auto | Stopped] -> C:\Programme\Acer\Acer Updater\UpdaterService.exe -> [2010.01.29 00:27:36 | 000,243,232 | ---- | M] (Acer Group)
(McComponentHostService) McAfee Security Scan Component Host Service [On_Demand | Stopped] -> C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -> [2010.01.15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.)
(GREGService) GREGService [Auto | Stopped] -> C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -> [2010.01.08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated)
(IAStorDataMgrSvc) Intel(R) Rapid Storage Technology [Auto | Stopped] -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -> [2009.12.24 01:39:04 | 000,013,336 | ---- | M] (Intel Corporation)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Disabled | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation)
(ServiceLayer) ServiceLayer [On_Demand | Stopped] -> C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -> [2008.11.11 08:38:06 | 000,620,544 | ---- | M] (Nokia.)
[Driver Services - Safe List]
64bit-(ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ssudmdm.sys -> [2011.08.11 18:31:36 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr))
64bit-(dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ssudbus.sys -> [2011.08.11 18:31:32 | 000,095,544 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr))
64bit-(avipbb) avipbb [Kernel | System | Stopped] -> C:\Windows\SysNative\drivers\avipbb.sys -> [2011.07.02 10:16:19 | 000,123,784 | ---- | M] (Avira GmbH)
64bit-(avgntflt) avgntflt [File_System | Auto | Stopped] -> C:\Windows\SysNative\drivers\avgntflt.sys -> [2011.07.02 10:16:19 | 000,088,288 | ---- | M] (Avira GmbH)
64bit-(Netaapl) Apple Mobile Device Ethernet Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\netaapl64.sys -> [2011.05.10 07:06:14 | 000,022,528 | ---- | M] (Apple Inc.)
64bit-(USBAAPL64) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\usbaapl64.sys -> [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.)
64bit-(amdsata) amdsata [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsata.sys -> [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices)
64bit-(amdxata) amdxata [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\amdxata.sys -> [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices)
64bit-(sscdmdm) SAMSUNG Mobile Modem Drivers [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\sscdmdm.sys -> [2010.12.21 06:55:02 | 000,172,104 | ---- | M] (MCCI Corporation)
64bit-(ss_bmdm) SAMSUNG USB Mobile Modem [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ss_bmdm.sys -> [2010.12.21 06:55:02 | 000,161,280 | ---- | M] (MCCI Corporation)
64bit-(sscdbus) SAMSUNG USB Composite Device driver (WDM) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\sscdbus.sys -> [2010.12.21 06:55:02 | 000,136,264 | ---- | M] (MCCI Corporation)
64bit-(ss_bbus) SAMSUNG USB Mobile Device (WDM) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ss_bbus.sys -> [2010.12.21 06:55:02 | 000,127,488 | ---- | M] (MCCI)
64bit-(sscdmdfl) SAMSUNG Mobile Modem Filter [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\sscdmdfl.sys -> [2010.12.21 06:55:02 | 000,019,016 | ---- | M] (MCCI Corporation)
64bit-(ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ss_bmdfl.sys -> [2010.12.21 06:55:02 | 000,018,944 | ---- | M] (MCCI Corporation)
64bit-(HpSAMD) HpSAMD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HpSAMD.sys -> [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company)
64bit-(TsUsbFlt) TsUsbFlt [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\TsUsbFlt.sys -> [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation)
64bit-(BCM43XX) Treiber für Broadcom 802.11-Netzwerkadapter [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\BCMWL664.SYS -> [2010.04.01 09:18:30 | 003,060,800 | ---- | M] (Broadcom Corporation)
64bit-(k57nd60a) Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\k57nd60a.sys -> [2010.03.21 10:59:08 | 000,321,064 | ---- | M] (Broadcom Corporation)
64bit-(RSUSBSTOR) RtsUStor.Sys Realtek USB Card Reader [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\RtsUStor.sys -> [2010.03.01 08:20:56 | 000,239,136 | ---- | M] (Realtek Semiconductor Corp.)
64bit-(amdkmdag) amdkmdag [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\atipmdag.sys -> [2010.01.22 02:13:24 | 006,233,088 | ---- | M] (ATI Technologies Inc.)
64bit-(amdkmdap) amdkmdap [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\atikmpag.sys -> [2010.01.22 01:07:56 | 000,161,280 | ---- | M] (Advanced Micro Devices, Inc.)
64bit-(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\iaStor.sys -> [2009.12.17 18:42:08 | 000,538,136 | ---- | M] (Intel Corporation)
64bit-(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\SynTP.sys -> [2009.12.10 12:25:10 | 000,301,104 | ---- | M] (Synaptics Incorporated)
64bit-(RTHDMIAzAudService) Service for HDMI [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\RtHDMIVX.sys -> [2009.12.02 08:01:24 | 000,213,280 | ---- | M] (Realtek Semiconductor Corp.)
64bit-(HECIx64) Intel(R) Management Engine Interface [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\HECIx64.sys -> [2009.09.17 06:54:54 | 000,056,344 | ---- | M] (Intel Corporation)
64bit-(amdsbs) amdsbs [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsbs.sys -> [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.)
64bit-(LSI_SAS2) LSI_SAS2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\lsi_sas2.sys -> [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation)
64bit-(stexstor) stexstor [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\stexstor.sys -> [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology)
64bit-(ebdrv) Broadcom NetXtreme II 10 GigE VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\evbda.sys -> [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation)
64bit-(b06bdrv) Broadcom NetXtreme II VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\bxvbda.sys -> [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation)
64bit-(b57nd60a) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\b57nd60a.sys -> [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation)
64bit-(hcw85cir) Hauppauge Consumer Infrared Receiver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\hcw85cir.sys -> [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.)
64bit-(mwlPSDVDisk) mwlPSDVDisk [Kernel | System | Stopped] -> C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -> [2009.06.03 03:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.)
64bit-(mwlPSDFilter) mwlPSDFilter [File_System | System | Stopped] -> C:\Windows\SysNative\drivers\mwlPSDFilter.sys -> [2009.06.03 03:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.)
64bit-(mwlPSDNServ) mwlPSDNServ [Kernel | System | Stopped] -> C:\Windows\SysNative\drivers\mwlPSDNserv.sys -> [2009.06.03 03:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.)
64bit-(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\GEARAspiWDM.sys -> [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.)
64bit-(NTIDrvr) NTIDrvr [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\NTIDrvr.sys -> [2009.05.05 09:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.)
64bit-(UBHelper) UBHelper [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\UBHelper.sys -> [2009.05.05 09:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation)
64bit-(pccsmcfd) PCCS Mode Change Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\pccsmcfdx64.sys -> [2008.08.28 10:44:42 | 000,025,600 | ---- | M] (Nokia)
(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\SysWOW64\drivers\wimmount.sys -> [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation)
(StarOpen) StarOpen [File_System | System | Stopped] -> C:\Windows\SysWow64\drivers\StarOpen.sys -> [2006.07.24 15:05:00 | 000,005,632 | ---- | M] ()
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741zg&r=27361010x915l0494z1l5t4662q22p ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741zg&r=27361010x915l0494z1l5t4662q22p ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741zg&r=27361010x915l0494z1l5t4662q22p ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\Windows\SysWOW64\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741zg&r=27361010x915l0494z1l5t4662q22p ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Default_Page_URL" -> hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741zg&r=27361010x915l0494z1l5t4662q22p ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> hxxp://www.google.de/ ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{00A6FAF6-072E-44cf-8957-5838F569A31D}" [HKLM] -> C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSSRCAS.DLL [] -> [2011.03.24 22:45:01 | 000,054,704 | ---- | M] (MyWebSearch.com)
HKEY_CURRENT_USER\: URLSearchHooks\\"{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
HKEY_CURRENT_USER\: "ProxyEnable" -> 1 ->
HKEY_CURRENT_USER\: "ProxyOverride" -> *.local ->
HKEY_CURRENT_USER\: "ProxyServer" -> http=127.0.0.1:58101 ->
< FireFox Settings [Prefs.js] > -> C:\Users\Yasemin\AppData\Roaming\Mozilla\FireFox\Profiles\l6ckyfr7.default\prefs.js ->
browser.search.defaultenginename -> "" ->
extensions.enabledItems -> webbooster@iminent.com:3.33.0 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 ->
extensions.enabledItems -> m3ffxtbr@mywebsearch.com:1.1 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 ->
extensions.enabledItems -> {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.7 ->
extensions.enabledItems -> fbsidebardisabler@vittgam.net:1.8-ffbuild1 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27 ->
network.proxy.http -> "127.0.0.1" ->
network.proxy.http_port -> 58101 ->
network.proxy.type -> 1 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com -> C:\PROGRAM FILES (X86)\MYWEBSEARCH\BAR\2.BIN [C:\PROGRAM FILES (X86)\MYWEBSEARCH\BAR\2.BIN] -> [2011.10.12 04:47:05 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.24\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2011.11.10 22:11:40 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2011.11.10 22:11:40 | 000,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Users\Yasemin\AppData\Roaming\mozilla\Extensions -> [2010.10.10 01:45:37 | 000,000,000 | ---D | M]
-> C:\Users\Yasemin\AppData\Roaming\mozilla\Firefox\Profiles\l6ckyfr7.default\extensions -> [2011.11.20 22:44:03 | 000,000,000 | ---D | M]
Greasemonkey -> C:\Users\Yasemin\AppData\Roaming\mozilla\Firefox\Profiles\l6ckyfr7.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} -> [2011.07.27 05:14:37 | 000,000,000 | ---D | M]
-> C:\Users\Yasemin\AppData\Roaming\mozilla\Firefox\Profiles\l6ckyfr7.default\extensions\fbsidebardisabler@vittgam.net -> [2011.08.08 23:40:23 | 000,000,000 | ---D | M]
-> C:\Users\Yasemin\AppData\Roaming\mozilla\Firefox\Profiles\l6ckyfr7.default\extensions\m3ffxtbr@mywebsearch.com -> [2011.10.12 04:47:06 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files (x86)\mozilla firefox\extensions -> [2011.09.26 18:55:32 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} -> [2010.10.10 23:20:59 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} -> [2010.11.15 11:12:52 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} -> [2011.02.06 09:35:23 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} -> [2011.06.07 23:28:28 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} -> [2011.09.26 18:55:32 | 000,000,000 | ---D | M]
-> C:\Program Files (x86)\mozilla firefox\extensions\webbooster@iminent.com -> [2011.02.01 19:05:03 | 000,000,000 | ---D | M]
Iminent WebBooster -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\WEBBOOSTER@IMINENT.COM -> [2011.02.01 19:05:03 | 000,000,000 | ---D | M]
FB Chat Sidebar Disabler -> C:\USERS\YASEMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\L6CKYFR7.DEFAULT\EXTENSIONS\FBSIDEBARDISABLER@VITTGAM.NET -> [2011.08.08 23:40:23 | 000,000,000 | ---D | M]
My Web Search -> C:\USERS\YASEMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\L6CKYFR7.DEFAULT\EXTENSIONS\M3FFXTBR@MYWEBSEARCH.COM -> [2011.10.12 04:47:06 | 000,000,000 | ---D | M]
< HOSTS File > ([2009.06.10 22:00:26 | 000,000,824 | ---- | M] - 21 lines) -> C:\Windows\SysNative\Drivers\etc\hosts ->
Reset Hosts
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar Helper] -> [2011.09.09 14:56:02 | 000,410,288 | ---- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Programme\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll [Google Toolbar Notifier BHO] -> [2011.05.20 22:44:50 | 000,341,048 | ---- | M] (Google Inc.)
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{00A6FAF1-072E-44cf-8957-5838F569A31D} [HKLM] -> C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSSRCAS.DLL [MyWebSearch Search Assistant BHO] -> [2011.03.24 22:45:01 | 000,054,704 | ---- | M] (MyWebSearch.com)
{07B18EA1-A523-4961-B6BB-170DE4475CCA} [HKLM] -> C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL [mwsBar BHO] -> [2011.03.24 22:45:01 | 000,800,272 | ---- | M] (MyWebSearch.com)
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} [HKLM] -> C:\Program Files (x86)\Iminent\IMBooster4Web\Iminent.WebBooster.dll [IMinent WebBooster (BHO)] -> [2010.11.19 17:35:44 | 000,336,376 | ---- | M] (Iminent)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [Google Toolbar Notifier BHO] -> [2011.05.20 22:44:50 | 001,007,160 | ---- | M] (Google Inc.)
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2011.09.09 14:56:02 | 000,410,288 | ---- | M] (Google Inc.)
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{07B18EA9-A523-4961-B6BB-170DE4475CCA}" [HKLM] -> C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL [My Web Search] -> [2011.03.24 22:45:01 | 000,800,272 | ---- | M] (MyWebSearch.com)
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{07B18EA9-A523-4961-B6BB-170DE4475CCA}" [HKLM] -> C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL [My Web Search] -> [2011.03.24 22:45:01 | 000,800,272 | ---- | M] (MyWebSearch.com)
64bit-WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2011.09.09 14:56:02 | 000,410,288 | ---- | M] (Google Inc.)
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Acer ePower Management" -> C:\Programme\Acer\Acer ePower Management\ePowerTray.exe [C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe] -> [2010.03.17 09:56:12 | 000,860,704 | ---- | M] (Acer Incorporated)
"mwlDaemon" -> C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe] -> [2010.04.17 06:57:08 | 000,349,552 | ---- | M] (Egis Technology Inc.)
"RtHDVCpl" -> C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s] -> [2009.12.29 11:51:46 | 009,913,376 | ---- | M] (Realtek Semiconductor)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AB6.exe" -> C:\Program Files (x86)\LP\5004\AB6.exe [C:\Program Files (x86)\LP\5004\AB6.exe] -> [2011.11.18 20:57:08 | 000,292,352 | ---- | M] ()
"APSDaemon" -> C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe ["C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"] -> [2011.09.27 06:22:28 | 000,059,240 | ---- | M] (Apple Inc.)
"avgnt" -> C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe ["C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min] -> [2010.12.13 08:39:19 | 000,281,768 | ---- | M] (Avira GmbH)
"BackupManagerTray" -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe ["C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k] -> [2010.03.09 00:56:38 | 000,260,608 | ---- | M] (NewTech Infosystems, Inc.)
"EgisTecPMMUpdate" -> C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe ["C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"] -> [2010.03.11 06:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.)
"EgisUpdate" -> C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe ["C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d] -> [2010.03.11 06:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.)
"IAStorIcon" -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe] -> [2009.12.24 01:39:02 | 000,284,696 | ---- | M] (Intel Corporation)
"IMBooster" -> C:\Program Files (x86)\Iminent\IMBooster\imbooster.exe [C:\Program Files (x86)\Iminent\IMBooster\imbooster.exe /warmup] -> [2010.11.19 17:35:46 | 001,323,000 | ---- | M] (Iminent)
"Iminent.Notifier" -> C:\Program Files (x86)\Iminent\SearchTheWeb\Iminent.Notifier.exe [C:\Program Files (x86)\Iminent\SearchTheWeb\Iminent.Notifier.exe] -> [2011.01.26 17:52:14 | 001,863,168 | ---- | M] (Iminent)
"LManager" -> C:\Program Files (x86)\Launch Manager\LManager.exe [C:\Program Files (x86)\Launch Manager\LManager.exe] -> [2010.04.08 05:18:38 | 000,908,368 | ---- | M] (Dritek System Inc.)
"My Web Search Bar Search Scope Monitor" -> ["C:\PROGRA~2\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h] -> File not found
"MyWebSearch Email Plugin" -> C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe [C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe] -> [2011.03.24 22:45:01 | 000,032,849 | ---- | M] (MyWebSearch.com)
"NortonOnlineBackupReminder" -> C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe ["C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED] -> [2009.07.25 00:31:08 | 000,588,648 | ---- | M] (Symantec Corporation)
"StartCCC" -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun] -> [2010.01.22 07:50:56 | 000,098,304 | ---- | M] (Advanced Micro Devices, Inc.)
"SuiteTray" -> C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe ["C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"] -> [2010.04.17 07:28:28 | 000,337,264 | ---- | M] (Egis Technology Inc.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"{3D2D74B9-62C6-11DF-8A65-806E6F6E6963}" -> C:\Users\Yasemin\AppData\Roaming\Microsoft\svhcost.exe [C:\Users\Yasemin\AppData\Roaming\Microsoft\svhcost.exe] -> [2011.02.25 07:19:30 | 000,066,184 | ---- | M] (Datarescue sa/nv)
"AB6.exe" -> C:\Users\Yasemin\AppData\Roaming\Microsoft\5004\AB6.exe [C:\Users\Yasemin\AppData\Roaming\Microsoft\5004\AB6.exe] -> [2011.11.18 20:48:38 | 000,292,352 | ---- | M] ()
"iCloudServices" -> C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe] -> [2011.10.06 03:34:56 | 000,059,240 | ---- | M] (Apple Inc.)
"KiesHelper" -> C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s] -> [2011.08.01 04:32:08 | 000,958,352 | ---- | M] (Samsung)
"KiesPDLR" -> C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe] -> [2011.08.01 04:32:20 | 000,020,880 | ---- | M] ()
"KiesTrayAgent" -> C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe] -> [2011.08.01 04:32:10 | 003,507,088 | ---- | M] (Samsung Electronics Co., Ltd.)
"MyWebSearch Email Plugin" -> C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe [C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe] -> [2011.03.24 22:45:01 | 000,032,849 | ---- | M] (MyWebSearch.com)
< 64bit-WinNT Load [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\load ->
64bit-*load* -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\load ->
C:\Users\Yasemin\AppData\Roaming\02565\lvvm.exe -> C:\Users\Yasemin\AppData\Roaming\02565\lvvm.exe -> [2011.11.19 17:01:55 | 000,183,296 | ---- | M] ()
*MultiFile Done* -> ->
< WinNT Load [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\load ->
*load* -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\load ->
C:\Users\Yasemin\AppData\Roaming\02565\lvvm.exe -> C:\Users\Yasemin\AppData\Roaming\02565\lvvm.exe -> [2011.11.19 17:01:55 | 000,183,296 | ---- | M] ()
*MultiFile Done* -> ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" -> [1] -> File not found
\\"NoActiveDesktopChanges" -> [1] -> File not found
\\"HideSCAHealth" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" -> [5] -> File not found
\\"ConsentPromptBehaviorUser" -> [3] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> [res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000] -> File not found
Google Sidewiki... -> [res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2009.02.26 18:45:52 | 000,603,040 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2009.02.26 18:45:52 | 000,603,040 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL [Button: Research] -> [2009.03.06 12:04:56 | 000,039,464 | ---- | M] (Microsoft Corporation)
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> hxxp://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> hxxp://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> hxxp://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{888078C6-70B2-4F88-8EE7-1F50DDEA6120} [HKLM] -> https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab [CeWe Color AG & Co. OHG Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab [Java Plug-in 1.6.0_27] ->
{C345E174-3E87-4F41-A01C-B066A90A49B4} [HKLM] -> hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx [WRC Class] ->
{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} [HKLM] -> hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab [Java Plug-in 1.6.0_27] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab [Java Plug-in 1.6.0_27] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.2.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{0FC7D4DA-FB8A-430A-B7C2-CD1B2D011C9F}\\DhcpNameServer -> 193.189.244.225 193.189.244.206 (Apple Mobile Device Ethernet) ->
{CF1C6892-61D2-470E-BAFD-587A3F1E0AB0}\\DhcpNameServer -> 10.57.1.1 (Broadcom NetLink (TM) Gigabit Ethernet) ->
{F1516D25-2258-4352-9CC8-0F62383842A1}\\DhcpNameServer -> 192.168.2.1 (Broadcom 802.11n-Netzwerkadapter) ->
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\Windows\system32\userinit.exe -> C:\Windows\SysNative\userinit.exe -> [2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
SystemPropertiesPerformance.exe -> C:\Windows\SysNative\SystemPropertiesPerformance.exe -> [2009.07.14 02:39:47 | 000,082,432 | ---- | M] (Microsoft Corporation)
/pagefile -> -> File not found
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
userinit.exe -> C:\Windows\SysWow64\userinit.exe -> [2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
/pagefile -> -> File not found
*MultiFile Done* -> ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation)
C:\Users\Yasemin\AppData\Roaming\44202\9CCB6.exe -> C:\Users\Yasemin\AppData\Roaming\44202\9CCB6.exe -> [2011.11.21 18:36:28 | 000,166,912 | ---- | M] ()
*MultiFile Done* -> ->
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0E93DC48-5DE3-4DDE-B32F-20B0355F54D8} -> lport=139 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system |
{14E5F29E-C91E-4536-BFDE-63739C8A1B8A} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system |
{1679EDCA-1430-459E-AFD4-91D370B0AD16} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{219D2262-545C-4DBC-9421-289378D0BF6F} -> lport=138 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system |
{2C958B11-E4BB-435C-B9AD-829C6EA07C84} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{3DB610E3-1D09-41F8-ADC8-9B99B505AE60} -> rport=5355 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{4079DB6E-EA86-44E9-BE52-253920E949A4} -> rport=445 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system |
{55C35142-F69D-4A29-9792-BD5D4C790AB4} -> rport=139 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system |
{59F6EF3C-E7B2-4CD9-A599-32866FA04984} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss |
{63F4E4D5-F81F-44F8-A261-60584A3E2A1F} -> rport=138 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system |
{7D3FCC9C-22A0-4057-A516-F11B0BAD7D3B} -> lport=1900 | protocol=17 | dir=in | action=allow | name=windows live messenger (ssdp-in) | app=svchost.exe | svc=ssdpsrv |
{A0EE809F-15D1-4463-9D02-7F74AA9DB9A6} -> rport=5355 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{A64A4691-E1AD-4845-99D9-AD10B5D34FB5} -> lport=5355 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{A6D53C7E-0C3B-461C-AD12-43ED0859CEB1} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{A9CBD74D-5C8C-4E0A-9317-ED4049096F94} -> rport=137 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system |
{BF411864-E2E9-4AC2-B784-C953DA7AB524} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{C41DB8D6-60D2-4C1F-A7DA-F25C38AD7F60} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{C87570A1-C1B5-4A98-84DB-8246B7703F25} -> lport=2869 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system |
{D1F558E8-B751-47DA-9DD1-000CD0528E7E} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system |
{DC932214-9359-4B3A-AD76-463B668DF94E} -> lport=2869 | protocol=6 | dir=in | action=allow | name=windows live messenger (upnp-in) | app=system |
{DF48BF96-E5C2-49D9-B2F9-6EF99D1C9D9A} -> lport=137 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system |
{E1A161A7-EF7C-4914-9DE5-AFE476888392} -> lport=5355 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{E6EAB259-C643-46BD-983E-1066FC697199} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{EBBD362B-90B8-4B86-8D42-35C3AF407C07} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler |
{FD08AA82-7F5C-41B2-9246-D947195DEE41} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system |
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0E79C12F-6C74-41D8-95F6-B0624EFE8C86} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe |
{0E979A23-D2F9-40FA-BFCD-53FB75220345} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe |
{17AFF962-60B2-4448-B8CF-7A6EBA8FF84B} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe |
{1E25A764-D1C2-4463-9626-740C4B28B0EC} -> profile=private | protocol=17 | dir=in | action=allow | name=dienst "bonjour" | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{1EB388D1-2150-467A-8AFA-61FD15522962} -> profile=public | protocol=17 | dir=in | action=allow | name=schedulersvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
{2A5A7BBA-ED5B-4550-A719-D0C8F9F9C939} -> profile=public | protocol=6 | dir=in | action=allow | name=schedulersvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
{2AA72683-82A4-43E0-B89F-C603F1A89D31} -> profile=public | protocol=17 | dir=in | action=allow | name=mcafee shared service host | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
{2EC6980B-5FDF-45A7-88D5-B0440C370E77} -> profile=private | protocol=6 | dir=in | action=allow | name=dienst "bonjour" | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{2F52EA74-D333-4EB7-B0CA-87DCAEEEE8E1} -> dir=in | action=allow | name=windows live messenger | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
{378BCED4-FB79-4E64-AC68-3FCF98E5E1D7} -> dir=in | action=allow | name=itunes | app=c:\program files (x86)\itunes\itunes.exe |
{3B492FF8-5A31-4ABA-9173-18469C1A549A} -> profile=private | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 |
{3BA9231C-CC02-4C02-BC84-AA3F06E91A47} -> profile=public | protocol=6 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
{492F7FF1-6038-4EEC-A078-1B1E2E877535} -> dir=in | action=allow | name=windows live sync | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
{5B02360C-9758-429D-907C-9EE444F67657} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{63887531-2F39-4339-AF80-8EA64AD3D49A} -> profile=private | protocol=17 | dir=in | action=allow | name=dienst "bonjour" | app=c:\program files\bonjour\mdnsresponder.exe |
{65FA5B6D-1E4B-43E8-9F34-108EF2055963} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe |
{67A51617-FF8C-47A1-9CD2-5B0D05D56469} -> profile=public | protocol=6 | dir=in | action=allow | name=backupsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
{6B05BE3D-E06C-41C5-98A2-E29D9B24957C} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system |
{713BFA57-2D7C-4DBD-8228-670D6F2DB739} -> profile=public | protocol=6 | dir=in | action=allow | name=mcafee shared service host | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
{722A644E-2186-4B95-AC98-0F21816154A4} -> profile=public | protocol=17 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
{747DB514-4B74-4F4F-B805-DAB3EB8303F7} -> profile=private | protocol=17 | dir=in | action=allow | name=muz aod app player | app=c:\windows\syswow64\muzapp.exe |
{7D1FF295-6B38-4227-B8BF-33D6D402BE52} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe |
{8150EB0F-9245-498F-992E-407C6FC5EFCA} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe |
{8AD84E24-1C79-4A7C-8A45-9EB371A59932} -> profile=private | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 |
{8ED192CF-5AD6-4AE8-B425-B51C2F51720A} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe |
{90024C1B-C213-4BDB-8CE8-679748AE73FB} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe |
{B245612A-CC1B-4DB7-82D3-AA34A6B2D32C} -> profile=private | protocol=6 | dir=in | action=allow | name=muz aod app player | app=c:\windows\syswow64\muzapp.exe |
{B5230562-D9ED-428D-B15D-9AA6E5740C89} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost |
{B54D601C-9B1B-449E-8642-60791E27EBD2} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe |
{B904F141-D85D-418C-9A2D-20CAC3B4DFFC} -> profile=public | protocol=17 | dir=in | action=allow | name=backupsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
{BC42BFD4-692B-471E-B081-B72D4FCDB2CA} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe |
{BE94178A-4CA6-44E5-8A0A-B6AF32641003} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{C7FB25EB-6520-4E55-8355-0983377D45DD} -> dir=in | action=allow | name=windows live call | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
{CB7F96ED-A158-4745-8699-27AEB6589614} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{D778E583-9F4A-42A3-B128-DB932DBE77DA} -> dir=in | action=allow | name=cyberlink powerdvd 9.0 | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
{E8ECEE42-D32B-4FDE-92E2-471C815239C0} -> profile=private | protocol=6 | dir=in | action=allow | name=dienst "bonjour" | app=c:\program files\bonjour\mdnsresponder.exe |
{F09A83F8-AE20-4BB3-AFA7-E9699D157D02} -> profile=private | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 |
{F6D6809F-49CA-41E6-B4CD-51A4D8774638} -> dir=in | action=allow | name=webkit | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
{FB1E2AFB-EEC2-4927-909D-E79510E04155} -> profile=private | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 |
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM-Laufwerktreiber ->
"ImagePath" -> [\SystemRoot\system32\drivers\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
E:\Autorun.INF [[Autorun] | Icon=Autostart.exe | ShellExecute=Autostart.exe | UseAutoplay=1 | ] -> E:\Autorun.INF [ FAT32 ] -> [2009.01.13 19:40:00 | 000,000,072 | ---- | M] ()
E:\Autostart.exe [MZ | ] -> E:\Autostart.exe [ FAT32 ] -> [2009.05.29 08:39:00 | 000,771,072 | ---- | M] (Verlag Heinrich Vogel in der Springer Transport Media GmbH)
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
64bit-comfile [open] -> "%1" %*
64bit-exefile [open] -> "%1" %*
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Files/Folders - Created Within 30 Days]
02565 -> C:\Program Files (x86)\02565 -> [2011.11.21 18:36:38 | 000,000,000 | ---D | C]
LP -> C:\Program Files (x86)\LP -> [2011.11.18 20:57:08 | 000,000,000 | ---D | C]
02565 -> C:\Users\Yasemin\AppData\Roaming\02565 -> [2011.11.18 20:49:13 | 000,000,000 | ---D | C]
44202 -> C:\Users\Yasemin\AppData\Roaming\44202 -> [2011.11.18 20:48:38 | 000,000,000 | ---D | C]
iCloudSetup.exe -> C:\Users\Yasemin\Desktop\iCloudSetup.exe -> [2011.11.16 19:59:57 | 041,730,408 | ---- | C] (Apple Inc.)
.jenny -> C:\Users\Yasemin\.jenny -> [2011.11.14 21:21:43 | 000,000,000 | ---D | C]
Lied und Bild programme -> C:\Users\Yasemin\Desktop\Lied und Bild programme -> [2011.11.14 19:31:41 | 000,000,000 | ---D | C]
O2 -> C:\Users\Yasemin\Desktop\O2 -> [2011.11.14 19:30:12 | 000,000,000 | ---D | C]
nov 11 -> C:\Users\Yasemin\Desktop\nov 11 -> [2011.11.14 19:29:40 | 000,000,000 | ---D | C]
FlashPlayerCPLApp.cpl -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl -> [2011.11.13 23:21:03 | 000,404,640 | ---- | C] (Adobe Systems Incorporated)
Kool savas Aura -> C:\Users\Yasemin\Desktop\Kool savas Aura -> [2011.11.10 18:21:09 | 000,000,000 | ---D | C]
AVS4YOU -> C:\ProgramData\AVS4YOU -> [2011.11.06 13:22:38 | 000,000,000 | ---D | C]
AVS4YOU -> C:\Users\Yasemin\AppData\Roaming\AVS4YOU -> [2011.11.06 13:22:36 | 000,000,000 | ---D | C]
AVS4YOU -> C:\Users\Yasemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU -> [2011.11.06 13:22:24 | 000,000,000 | ---D | C]
AVS4YOU -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU -> [2011.11.06 13:22:04 | 000,000,000 | ---D | C]
libmfxsw32.dll -> C:\Windows\SysWow64\libmfxsw32.dll -> [2011.11.06 13:21:52 | 011,137,024 | ---- | C] (Intel Corporation)
GdiPlus.dll -> C:\Windows\SysWow64\GdiPlus.dll -> [2011.11.06 13:21:47 | 001,700,352 | ---- | C] (Microsoft Corporation)
AVS4YOU -> C:\Program Files (x86)\AVS4YOU -> [2011.11.06 13:21:41 | 000,000,000 | ---D | C]
AVSMedia -> C:\Program Files (x86)\Common Files\AVSMedia -> [2011.11.06 13:21:23 | 000,000,000 | ---D | C]
NCH Swift Sound -> C:\Program Files (x86)\NCH Swift Sound -> [2011.11.06 13:08:29 | 000,000,000 | ---D | C]
NCH Software -> C:\ProgramData\NCH Software -> [2011.11.06 13:08:25 | 000,000,000 | ---D | C]
NCH Software -> C:\Program Files (x86)\NCH Software -> [2011.11.06 13:08:04 | 000,000,000 | ---D | C]
NCH Software -> C:\Users\Yasemin\AppData\Roaming\NCH Software -> [2011.11.06 13:08:01 | 000,000,000 | ---D | C]
fard -> C:\Users\Yasemin\Desktop\fard -> [2011.11.06 12:59:11 | 000,000,000 | ---D | C]
1 C:\Windows\*.tmp files -> C:\Windows\*.tmp ->
[Files/Folders - Modified Within 30 Days]
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2011.11.21 18:38:23 | 001,512,182 | ---- | M] ()
perfh007.dat -> C:\Windows\SysNative\perfh007.dat -> [2011.11.21 18:38:23 | 000,658,928 | ---- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2011.11.21 18:38:23 | 000,620,114 | ---- | M] ()
perfc007.dat -> C:\Windows\SysNative\perfc007.dat -> [2011.11.21 18:38:23 | 000,132,498 | ---- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2011.11.21 18:38:23 | 000,108,296 | ---- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2011.11.21 18:36:13 | 000,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2011.11.21 18:36:07 | 3113,259,008 | -HS- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2011.11.21 18:25:10 | 000,009,696 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2011.11.21 18:25:10 | 000,009,696 | -H-- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2011.11.21 18:17:52 | 000,001,106 | ---- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2011.11.21 18:07:01 | 000,001,110 | ---- | M] ()
LauncherAccess.dt -> C:\ProgramData\LauncherAccess.dt -> [2011.11.20 19:18:59 | 000,000,000 | ---- | M] ()
At1.job -> C:\Windows\tasks\At1.job -> [2011.11.18 20:58:05 | 000,000,392 | ---- | M] ()
iexplore.exe -> C:\Users\Yasemin\AppData\Roaming\iexplore.exe -> [2011.11.18 20:56:59 | 000,292,352 | ---- | M] ()
mapisvc.inf -> C:\Windows\SysNative\mapisvc.inf -> [2011.11.16 20:02:58 | 000,000,628 | ---- | M] ()
iCloudSetup.exe -> C:\Users\Yasemin\Desktop\iCloudSetup.exe -> [2011.11.16 19:59:57 | 041,730,408 | ---- | M] (Apple Inc.)
FlashPlayerCPLApp.cpl -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl -> [2011.11.13 23:21:03 | 000,404,640 | ---- | M] (Adobe Systems Incorporated)
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2011.11.11 05:49:06 | 000,343,008 | ---- | M] ()
cdplayer.ini -> C:\Windows\cdplayer.ini -> [2011.11.06 13:05:29 | 000,000,368 | ---- | M] ()
23 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp ->
1 C:\Windows\*.tmp files -> C:\Windows\*.tmp ->
[Files - No Company Name]
At1.job -> C:\Windows\tasks\At1.job -> [2011.11.18 20:57:09 | 000,000,392 | ---- | C] ()
iexplore.exe -> C:\Users\Yasemin\AppData\Roaming\iexplore.exe -> [2011.11.18 20:56:59 | 000,292,352 | ---- | C] ()
mapisvc.inf -> C:\Windows\SysNative\mapisvc.inf -> [2011.11.16 20:02:58 | 000,000,628 | ---- | C] ()
Switch Audiodatei-Konverter.lnk -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Audiodatei-Konverter.lnk -> [2011.11.06 13:08:04 | 000,001,150 | ---- | C] ()
cdplayer.ini -> C:\Windows\cdplayer.ini -> [2011.11.06 13:02:38 | 000,000,368 | ---- | C] ()
UserTile.png -> C:\Users\Yasemin\AppData\Roaming\UserTile.png -> [2011.06.20 16:56:18 | 000,033,134 | ---- | C] ()
LauncherAccess.dt -> C:\ProgramData\LauncherAccess.dt -> [2011.06.15 18:33:32 | 000,000,000 | ---- | C] ()
StarOpen.sys -> C:\Windows\SysWow64\drivers\StarOpen.sys -> [2011.06.15 18:28:53 | 000,005,632 | ---- | C] ()
cis-2.4.dll -> C:\Windows\SysWow64\cis-2.4.dll -> [2011.06.07 10:13:38 | 000,974,848 | ---- | C] ()
issacapi_bs-2.3.dll -> C:\Windows\SysWow64\issacapi_bs-2.3.dll -> [2011.06.07 10:13:38 | 000,081,920 | ---- | C] ()
issacapi_pe-2.3.dll -> C:\Windows\SysWow64\issacapi_pe-2.3.dll -> [2011.06.07 10:13:38 | 000,065,536 | ---- | C] ()
issacapi_se-2.3.dll -> C:\Windows\SysWow64\issacapi_se-2.3.dll -> [2011.06.07 10:13:38 | 000,057,344 | ---- | C] ()
MusiccityDownload.exe -> C:\Windows\MusiccityDownload.exe -> [2011.06.07 10:13:38 | 000,030,568 | ---- | C] ()
wininit.ini -> C:\Windows\wininit.ini -> [2011.02.12 02:21:34 | 000,000,161 | ---- | C] ()
wklnhst.dat -> C:\Users\Yasemin\AppData\Roaming\wklnhst.dat -> [2010.10.17 15:50:55 | 000,000,000 | ---- | C] ()
nsreg.dat -> C:\Windows\nsreg.dat -> [2010.10.10 01:45:23 | 000,000,000 | ---- | C] ()
ativpsrm.bin -> C:\Windows\ativpsrm.bin -> [2010.05.18 22:48:14 | 000,000,000 | ---- | C] ()
atipblag.dat -> C:\Windows\SysWow64\atipblag.dat -> [2010.04.21 12:17:27 | 000,001,035 | ---- | C] ()
FullRemove.exe -> C:\ProgramData\FullRemove.exe -> [2010.04.21 11:41:04 | 000,131,472 | ---- | C] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009.07.14 06:38:36 | 000,067,584 | --S- | C] ()
NOISE.DAT -> C:\Windows\SysWow64\NOISE.DAT -> [2009.07.14 03:35:51 | 000,000,741 | ---- | C] ()
dssec.dat -> C:\Windows\SysWow64\dssec.dat -> [2009.07.14 03:34:42 | 000,215,943 | ---- | C] ()
mib.bin -> C:\Windows\mib.bin -> [2009.07.14 01:10:29 | 000,043,131 | ---- | C] ()
BWContextHandler.dll -> C:\Windows\SysWow64\BWContextHandler.dll -> [2009.07.14 00:42:10 | 000,064,000 | ---- | C] ()
msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2009.07.13 22:03:59 | 000,364,544 | ---- | C] ()
mlang.dat -> C:\Windows\SysWow64\mlang.dat -> [2009.06.10 22:26:10 | 000,673,088 | ---- | C] ()
[Alternate Data Streams]
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:798A3728
< End of report > otl.txt fehlt noch
er hat mir nur das angezeigt was du hier siehst mehr hab ich nicht
Aber müsste jetzt nicht durch die Systemwiederherstellung der Virus auch vom pc sein? jetzt läuft alles wieder normal |