![]() |
windows security center achtung ihre pc wurde gesperrt hallo, ich habe eine problem ich glaub ich habe mir einen trojaner eingefangen als ich im internet surfte dann erscheinte plötzlich einen weissen bildschirm und stan dort:windowns security center Aus Sicherheitsgründen wurde Ihr PC gesperrt ich muss 100 Euro zahlen um wieder zu aktieviren ich hab mir den OTL runtergeladen und habe scannen gedrückt und dan sind 2 dataien erschienen OTL.TXT und Extras.TXT hier sind die beide dataien OTL.TXT OTL logfile created on: 01.02.2012 22:17:14 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kurt\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,97 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 70,70% Memory free 8,97 Gb Paging File | 8,44 Gb Available in Paging File | 94,18% Paging File free Paging file location(s): c:\pagefile.sys 6144 6144 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 289,22 Gb Total Space | 103,99 Gb Free Space | 35,96% Space Free | Partition Type: NTFS Drive D: | 298,09 Gb Total Space | 28,81 Gb Free Space | 9,67% Space Free | Partition Type: NTFS Drive E: | 8,87 Gb Total Space | 8,80 Gb Free Space | 99,19% Space Free | Partition Type: NTFS Computer Name: KURT-PC | User Name: Kurt | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Kurt\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - c:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Programme\Mozilla Firefox\mozjs.dll () MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll () MOD - C:\Programme\Notepad++\NppShell_04.dll () MOD - C:\Programme\WinRAR\RarExt.dll () MOD - C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF () ========== Win32 Services (SafeList) ========== SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_e286960.dll () SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation) SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software) SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation) SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation) SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation) SRV - (S3DSvc32) S3D Service (Win32) -- C:\Programme\iZ3D Driver\Win32\S3DCService.exe (iZ3D Inc.) SRV - (btwdins) -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.) SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG) SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe (IDT, Inc.) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe (Andrea Electronics Corporation) SRV - (KMService) -- C:\Windows\System32\srvany.exe () ========== Driver Services (SafeList) ========== DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Company) DRV - (Accelerometer) -- C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Company) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation) DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation) DRV - (TuneUpUtilitiesDrv) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software) DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation) DRV - (johci) -- C:\Windows\System32\drivers\johci.sys (JMicron Technology Corp.) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (NETwNs32) ___ Intel(R) -- C:\Windows\System32\drivers\NETwNs32.sys (Intel Corporation) DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation) DRV - (iZ3DInjectionDriver) -- C:\Programme\iZ3D Driver\Win32\S3DInjectionDriver.sys () DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.) DRV - (NETw5s32) Intel(R) -- C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation) DRV - (cpudrv) -- C:\Programme\SystemRequirementsLab\cpudrv.sys () DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation) DRV - (netw5v32) Intel(R) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation) DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.) DRV - (s1029unic) Sony Ericsson Device 1029 USB Ethernet Emulation (WDM) -- C:\Windows\System32\drivers\s1029unic.sys (MCCI Corporation) DRV - (s1029mdm) -- C:\Windows\System32\drivers\s1029mdm.sys (MCCI Corporation) DRV - (s1029bus) Sony Ericsson Device 1029 driver (WDM) -- C:\Windows\System32\drivers\s1029bus.sys (MCCI Corporation) DRV - (s1029mdfl) -- C:\Windows\System32\drivers\s1029mdfl.sys (MCCI Corporation) DRV - (s1029mgmt) Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\s1029mgmt.sys (MCCI Corporation) DRV - (s1029obex) -- C:\Windows\System32\drivers\s1029obex.sys (MCCI Corporation) DRV - (s1029nd5) Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS) -- C:\Windows\System32\drivers\s1029nd5.sys (MCCI Corporation) DRV - (AVerAF15) -- C:\Windows\System32\drivers\AVerAF15.sys (AVerMedia TECHNOLOGIES, Inc.) DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchqu.com/406 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F8 D2 03 D6 DA 64 CB 01 [binary data] IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421; ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Search Results" FF - prefs.js..browser.search.order.1: "Search Results" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "google.de" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900 FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900 FF - prefs.js..extensions.enabledItems: mail@gutscheinrausch.de:2.6 FF - prefs.js..keyword.URL: "hxxp://dts.search-results.com/sr?src=ffb&appid=113&systemid=406&sr=0&q=" FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Users\Kurt\Desktop\Veetle\VLCBroadcast\npvbp.dll File not found FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.06.14 16:38:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.06.14 16:38:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.01 16:31:20 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.20 10:54:37 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Kurt\AppData\Roaming\IDM\idmmzcc5 [2012.01.24 19:32:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kurt\AppData\Roaming\mozilla\Extensions [2012.01.24 20:42:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kurt\AppData\Roaming\mozilla\Firefox\Profiles\2cxek9mf.default\extensions [2012.01.22 08:55:31 | 000,000,000 | ---D | M] (Cookies Manager+) -- C:\Users\Kurt\AppData\Roaming\mozilla\Firefox\Profiles\2cxek9mf.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2011.01.25 23:42:07 | 000,000,000 | ---D | M] (Gutscheinrausch.de) -- C:\Users\Kurt\AppData\Roaming\mozilla\Firefox\Profiles\2cxek9mf.default\extensions\mail@gutscheinrausch.de [2010.10.12 17:58:32 | 000,002,059 | ---- | M] () -- C:\Users\Kurt\AppData\Roaming\Mozilla\Firefox\Profiles\2cxek9mf.default\searchplugins\daemon-search.xml [2012.01.24 19:32:34 | 000,002,519 | ---- | M] () -- C:\Users\Kurt\AppData\Roaming\Mozilla\Firefox\Profiles\2cxek9mf.default\searchplugins\Search_Results.xml [2010.07.19 10:37:10 | 000,001,589 | ---- | M] () -- C:\Users\Kurt\AppData\Roaming\Mozilla\Firefox\Profiles\2cxek9mf.default\searchplugins\web-search.xml [2012.01.24 19:32:39 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions () (No name found) -- C:\USERS\KURT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CXEK9MF.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI () (No name found) -- C:\USERS\KURT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CXEK9MF.DEFAULT\EXTENSIONS\ICH@MALTEGOETZ.DE.XPI () (No name found) -- C:\USERS\KURT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CXEK9MF.DEFAULT\EXTENSIONS\STEALTHYEXTENSION@GMAIL.COM.XPI [2012.02.01 16:31:20 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.01.17 16:30:40 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.01.17 16:30:40 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.01.17 16:30:40 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.01.17 16:30:40 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.01.24 19:32:34 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml [2012.01.17 16:30:40 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.01.17 16:30:40 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.01.25 23:15:53 | 000,000,826 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Programme\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [DATAMNGR] C:\Programme\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc) O4 - HKLM..\Run: [FILSHtray] C:\Program Files\FILSHtray\FILSHtray.exe (FILSH Media GmbH) O4 - HKLM..\Run: [IAStorIcon] C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.) O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Kurt\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - HKCU..\Run: [vasja] C:\Users\Kurt\AppData\Local\Temp\0.16726738343385916.exe (Orb Networks) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab (SysInfo Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{47642194-5764-4FD3-86A3-E39D52814580}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B28A0DA-10BF-4254-9B16-96110B2D2FAA}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll) -C:\Programme\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Programme\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O27 - HKLM IFEO\backitup.exe: Debugger - C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe (TuneUp Software) O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{28555277-9fc8-11df-8d6b-0021866607e5}\Shell - "" = AutoRun O33 - MountPoints2\{28555277-9fc8-11df-8d6b-0021866607e5}\Shell\AutoRun\command - "" = H:\Startme.exe O33 - MountPoints2\{4dfaff12-d958-11df-8681-0021866607e5}\Shell - "" = AutoRun O33 - MountPoints2\{4dfaff12-d958-11df-8681-0021866607e5}\Shell\AutoRun\command - "" = H:\NokiaPCIA_Autorun.exe O33 - MountPoints2\{58f7290b-9261-11df-aeac-0021866607e5}\Shell - "" = AutoRun O33 - MountPoints2\{58f7290b-9261-11df-aeac-0021866607e5}\Shell\AutoRun\command - "" = G:\Autorun.exe O33 - MountPoints2\{d050251a-da1b-11e0-a1f9-001eec815664}\Shell - "" = AutoRun O33 - MountPoints2\{d050251a-da1b-11e0-a1f9-001eec815664}\Shell\AutoRun\command - "" = H:\NokiaPCIA_Autorun.exe O33 - MountPoints2\{d34473c0-942e-11e0-a393-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{d34473c0-942e-11e0-a393-806e6f6e6963}\Shell\AutoRun\command - "" = G:\_aomg.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012.02.01 22:15:31 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Kurt\Desktop\OTL.exe [2012.02.01 12:30:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP [2012.02.01 12:30:18 | 000,000,000 | ---D | C] -- C:\Program Files\WinSCP [2012.01.25 22:34:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012.01.25 22:33:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012.01.25 22:24:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\openIPSW [2012.01.25 22:24:06 | 000,000,000 | ---D | C] -- C:\Program Files\openIPSW [2012.01.24 19:33:12 | 000,000,000 | ---D | C] -- C:\Users\Kurt\AppData\Local\Ilivid Player [2012.01.24 19:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\iLivid [2012.01.24 19:32:34 | 000,000,000 | ---D | C] -- C:\Program Files\Windows iLivid Toolbar [2012.01.24 19:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess [2012.01.23 17:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft-Maus [2012.01.23 17:19:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliPoint [2012.01.21 17:46:37 | 000,000,000 | ---D | C] -- C:\Program Files\Cobra 11 - Crash Time [2012.01.20 11:04:17 | 000,000,000 | ---D | C] -- C:\Users\Kurt\Documents\FILSHtray [2012.01.20 11:04:17 | 000,000,000 | ---D | C] -- C:\Users\Kurt\AppData\Local\FILSH_Media_GmbH [2012.01.20 11:04:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FILSHtray [2012.01.20 11:04:13 | 000,000,000 | ---D | C] -- C:\Program Files\FILSHtray [2012.01.19 09:07:41 | 000,000,000 | ---D | C] -- C:\Users\Kurt\AppData\Local\Chromium [2012.01.19 08:38:48 | 000,000,000 | ---D | C] -- C:\Program Files\Rockstar Games [2012.01.19 08:36:18 | 000,000,000 | ---D | C] -- C:\Users\Kurt\Documents\Rockstar Games [2012.01.19 08:21:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Rockstar Games [2012.01.18 18:14:48 | 000,000,000 | ---D | C] -- C:\Users\Kurt\Neuer Ordner [2012.01.18 11:40:57 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll [2012.01.18 11:40:56 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll [2012.01.17 22:49:56 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012.01.17 22:49:54 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012.01.17 22:49:54 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012.01.17 22:49:53 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012.01.17 22:49:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012.01.17 22:49:51 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012.01.17 22:41:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2012.01.17 17:28:26 | 000,000,000 | ---D | C] -- C:\Users\Kurt\AppData\Local\Akamai [2012.01.17 16:51:54 | 002,342,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2012.01.17 16:51:53 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll [2012.01.17 16:51:53 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax [2012.01.17 16:51:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2012.01.17 16:51:30 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll [2012.01.17 16:51:29 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2012.01.17 16:51:28 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll [2012.01.17 16:51:28 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll [2012.01.17 16:51:28 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2012.01.17 16:50:08 | 003,912,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2012.01.17 16:50:07 | 003,967,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2012.01.17 16:22:09 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012.01.17 16:19:43 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2012.01.17 16:08:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2012.01.17 16:08:38 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime [2011.02.08 12:01:54 | 002,779,195 | ---- | C] (TeamViewer GmbH) -- C:\Users\Kurt\AppData\Roaming\TeamViewer.exe [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.02.01 22:16:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Kurt\Desktop\OTL.exe [2012.02.01 22:05:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.02.01 22:05:37 | 2389,929,984 | -HS- | M] () -- C:\hiberfil.sys [2012.02.01 22:03:36 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.02.01 20:51:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.02.01 15:58:25 | 000,698,970 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.02.01 15:58:25 | 000,654,248 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.02.01 15:58:25 | 000,149,134 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.02.01 15:58:25 | 000,122,080 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.02.01 12:54:04 | 000,000,600 | ---- | M] () -- C:\Users\Kurt\AppData\Roaming\winscp.rnd [2012.02.01 12:30:19 | 000,001,799 | ---- | M] () -- C:\Users\Kurt\Desktop\WinSCP.lnk [2012.02.01 09:00:38 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.02.01 09:00:38 | 000,016,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.01.31 13:44:05 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2012.01.25 22:34:23 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.01.25 17:59:51 | 000,000,472 | ---- | M] () -- C:\Volume (E) - Verknüpfung.lnk [2012.01.24 20:39:40 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012.01.24 08:23:49 | 000,410,928 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.01.21 16:08:40 | 000,138,160 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012.01.21 16:08:19 | 000,271,200 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr [2012.01.21 16:08:19 | 000,271,200 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0 [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.02.01 12:30:19 | 000,001,799 | ---- | C] () -- C:\Users\Kurt\Desktop\WinSCP.lnk [2012.01.25 22:34:23 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012.01.25 17:59:51 | 000,000,472 | ---- | C] () -- C:\Volume (E) - Verknüpfung.lnk [2012.01.20 10:54:37 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk [2011.09.14 18:42:03 | 000,000,600 | ---- | C] () -- C:\Users\Kurt\AppData\Roaming\winscp.rnd [2011.09.11 23:24:25 | 000,140,380 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat [2011.09.02 17:23:06 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2011.06.27 11:00:54 | 000,190,464 | ---- | C] () -- C:\Windows\System32\PCGW32.DLL [2011.06.23 09:05:15 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2011.06.23 09:04:06 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.06.15 08:18:16 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2011.04.14 02:40:42 | 000,024,064 | ---- | C] () -- C:\Windows\System32\ssb3ml3.dll [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011.02.10 23:13:42 | 000,007,665 | ---- | C] () -- C:\Users\Kurt\AppData\Local\resmon.resmoncfg [2011.02.08 12:01:59 | 000,000,000 | ---- | C] () -- C:\Users\Kurt\AppData\Roaming\chrtmp [2011.02.07 19:27:48 | 000,008,192 | ---- | C] () -- C:\Windows\System32\srvany.exe [2010.10.16 22:55:10 | 000,008,192 | ---- | C] () -- C:\Users\Kurt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.07.18 13:46:57 | 000,138,160 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2010.07.18 13:46:57 | 000,022,328 | ---- | C] () -- C:\Users\Kurt\AppData\Roaming\PnkBstrK.sys [2010.07.18 13:46:22 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2010.07.18 13:46:21 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2010.07.18 13:46:20 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini [2010.07.18 12:10:46 | 000,000,350 | ---- | C] () -- C:\Windows\System32\AP6RMHV.BIN [2010.07.18 12:10:46 | 000,000,308 | ---- | C] () -- C:\Windows\System32\AP6RMKV.BIN [2010.07.18 12:10:46 | 000,000,252 | ---- | C] () -- C:\Windows\System32\AP6RMJH.BIN [2010.07.18 12:10:46 | 000,000,238 | ---- | C] () -- C:\Windows\System32\AP6RMFP.BIN [2010.07.18 12:10:46 | 000,000,189 | ---- | C] () -- C:\Windows\System32\AP6RMKS.BIN [2010.07.18 12:10:46 | 000,000,126 | ---- | C] () -- C:\Windows\System32\AP6RMHR.BIN [2010.06.29 23:12:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL [2010.06.07 16:47:34 | 000,258,142 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin [2010.03.10 16:31:46 | 000,274,432 | ---- | C] () -- C:\Windows\System32\SaMinDrv.dll [2010.03.10 16:31:46 | 000,106,496 | ---- | C] () -- C:\Windows\System32\SaImgFlt.dll [2010.03.10 16:31:46 | 000,090,112 | ---- | C] () -- C:\Windows\System32\SaSegFlt.dll [2010.03.10 16:31:44 | 000,061,440 | ---- | C] () -- C:\Windows\System32\SaErHdlr.dll [2009.07.14 09:47:43 | 000,698,970 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:47:43 | 000,149,134 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,410,928 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,654,248 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,122,080 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 01:55:09 | 001,332,736 | ---- | C] () -- C:\Windows\System32\hpotiop1.dll [2009.07.14 01:55:09 | 000,585,216 | ---- | C] () -- C:\Windows\System32\hpotscld.dll [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2004.07.08 20:44:07 | 000,011,376 | R--- | C] () -- C:\Windows\System32\drivers\SECDRV.SYS ========== LOP Check ========== [2010.07.18 12:45:09 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\DAEMON Tools Lite [2011.02.08 14:16:06 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\DAEMON Tools Pro [2011.09.20 08:11:56 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\DMCache [2010.07.20 23:21:48 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\DVDVideoSoftIEHelpers [2011.09.18 17:33:46 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\FileZilla [2010.07.19 09:34:53 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\gnupg [2011.06.27 11:00:50 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\iZ3D Driver [2011.08.11 16:13:16 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\LaunchPad [2011.02.01 17:31:12 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\Leadertech [2011.01.22 15:36:07 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\Nokia [2011.09.03 18:40:36 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\Notepad++ [2010.09.19 01:54:12 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\PC Suite [2011.06.11 16:52:49 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\PunkBuster [2012.01.25 23:52:11 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\redsn0w [2011.06.12 14:47:16 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\SuperHideIP [2011.02.08 12:01:55 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\TeamViewer [2011.06.14 16:00:08 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\TuneUp Software [2011.06.15 08:31:41 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\WinBatch [2011.09.01 15:52:08 | 000,000,000 | ---D | M] -- C:\Users\Kurt\AppData\Roaming\Xilisoft [2012.01.29 14:25:07 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > ich hoffe ihr konnt mir helfen |
Extras.TXTOTL EXTRAS Logfile: Code: OTL Extras logfile created on: 01.02.2012 22:17:14 - Run 1 |
hat sich erledigt mit Malwarebytes Anti-Malware kann geclosed werden |
Alle Zeitangaben in WEZ +1. Es ist jetzt 10:05 Uhr. |
Copyright ©2000-2025, Trojaner-Board