scriptlivver | 25.07.2012 13:18 | GVU Trojaner auf Win7 :-( Hallo zusammen,
auch mich hats mit dem neuen GVU Trojaner erwischt.
Wie bekomme ich das Ding am schnellsten weg? Windows Unblocker & CO. bringen nichts. Sobald ich das LAN Kabel verbinde, wars das.
Danke und Grüße
script
OTL Log: Code:
OTL logfile created on: 25.07.2012 13:48:25 - Run 2
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Max\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,79 Gb Available Physical Memory | 59,84% Memory free
6,00 Gb Paging File | 4,64 Gb Available in Paging File | 77,46% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297,99 Gb Total Space | 79,14 Gb Free Space | 26,56% Space Free | Partition Type: NTFS
Drive D: | 470,75 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: SG | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.07.24 14:56:10 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
PRC - [2012.07.16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.07.05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.06.27 12:29:26 | 001,996,200 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2012.06.27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2012.01.18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.12.08 21:42:00 | 000,342,480 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe
PRC - [2011.11.11 15:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011.11.11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2011.09.23 18:07:30 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.09.23 18:00:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.09.23 12:07:43 | 000,463,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2011.09.23 11:37:31 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.09.23 11:35:15 | 000,616,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe
PRC - [2011.09.16 02:33:55 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.08.12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2011.08.01 15:56:42 | 001,821,576 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliPoint\ipoint.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.03.07 15:33:08 | 000,089,456 | ---- | M] (Elaborate Bytes AG) -- C:\Programme\VirtualCloneDrive\VCDDaemon.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.04.17 12:56:08 | 000,394,984 | ---- | M] (tzuk) -- C:\Programme\Sandboxie\SbieCtrl.exe
PRC - [2010.04.17 12:56:06 | 000,073,960 | ---- | M] (tzuk) -- C:\Programme\Sandboxie\SbieSvc.exe
PRC - [2010.04.10 09:03:46 | 000,077,824 | ---- | M] () -- C:\Windows\KMService.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.02.27 09:18:32 | 000,217,088 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\Apoint.exe
PRC - [2009.02.06 17:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009.01.31 15:15:38 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApntEx.exe
PRC - [2009.01.31 13:43:30 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\hidfind.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.11.24 04:56:46 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApMsgFwd.exe
PRC - [2007.09.13 14:45:38 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007.09.13 14:44:48 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2007.02.16 18:58:12 | 000,856,064 | ---- | M] (Christian Diefer) -- C:\Programme\I8kfanGUI\I8kfanGUI.exe
PRC - [2003.04.18 19:06:26 | 000,008,192 | ---- | M] () -- C:\Windows\System32\srvany.exe
========== Modules (No Company Name) ==========
MOD - [2012.07.23 23:02:32 | 000,193,952 | ---- | M] () -- C:\Users\Max\AppData\Local\Temp\fe0_zip.exe
MOD - [2011.11.11 15:09:20 | 000,336,408 | ---- | M] () -- C:\Programme\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2011.11.11 15:07:54 | 000,265,240 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2011.08.12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.05.07 19:37:40 | 000,126,808 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010.05.07 19:37:40 | 000,027,480 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010.05.07 19:36:54 | 000,340,824 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010.05.07 19:35:56 | 007,954,776 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010.05.07 19:35:44 | 002,143,576 | ---- | M] () -- C:\Programme\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2009.08.16 17:06:02 | 000,141,312 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- G:\TuneUpPortable\App\TuneUp\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2012.07.18 19:20:04 | 000,114,160 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.07.05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.06.27 15:53:24 | 000,724,376 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012.06.27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.12.08 21:42:00 | 000,342,480 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011.09.23 18:07:30 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.09.23 18:00:15 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.09.23 12:07:43 | 000,463,824 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2011.09.23 11:35:15 | 000,616,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe -- (AntiVirFirewallService)
SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.09.30 10:39:43 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010.04.17 12:56:06 | 000,073,960 | ---- | M] (tzuk) [On_Demand | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.10.20 20:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [Disabled | Stopped] -- C:\Programme\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.02.06 17:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2007.09.13 14:45:38 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2003.04.18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Windows\System32\srvany.exe -- (KMService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- G:\TuneUpPortable\App\TuneUp\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\WNt500x86\Sandra.sys -- (SANDRA)
DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\DellBIOS.Sys -- (DellBIOS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\TEMP\cpuz135\cpuz135_x32.sys -- (cpuz135)
DRV - [2012.06.27 15:18:52 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2012.02.15 18:10:25 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.01.18 08:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2012.01.18 08:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2012.01.09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2012.01.09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2012.01.09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.09.16 15:55:38 | 000,111,160 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avfwot.sys -- (avfwot)
DRV - [2011.09.16 15:55:38 | 000,091,096 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avfwim.sys -- (avfwim)
DRV - [2011.09.15 23:55:04 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.09.15 23:55:03 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.07.09 02:32:16 | 000,686,872 | ---- | M] (www.ext2fsd.com) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\ext2fsd.sys -- (Ext2Fsd)
DRV - [2011.03.18 13:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.10.07 14:11:37 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32)
DRV - [2010.07.15 09:44:20 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2010.07.15 09:44:20 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2010.07.01 12:10:00 | 000,188,392 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL2832UBDA.sys -- (RTL2832UBDA)
DRV - [2010.07.01 12:10:00 | 000,032,872 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL2832UUSB.sys -- (RTL2832UUSB)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.06.17 05:01:30 | 000,059,464 | ---- | M] (Ross-Tech LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT-USB.SYS -- (RT-USB)
DRV - [2010.05.07 19:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2010.04.17 12:56:02 | 000,115,944 | ---- | M] (tzuk) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2009.12.18 11:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Programme\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2009.10.26 09:33:39 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2009.10.20 20:19:44 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2009.10.07 10:48:18 | 000,066,456 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvselsus.sys -- (lvselsus)
DRV - [2009.08.22 20:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Programme\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys -- (RivaTuner32)
DRV - [2009.07.22 23:54:19 | 000,293,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV - [2009.07.22 23:54:19 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV - [2009.07.22 23:53:23 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV - [2009.07.22 23:53:21 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vpcuxd.sys -- (vpcuxd)
DRV - [2009.07.22 23:53:19 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32)
DRV - [2009.07.13 07:46:38 | 000,037,280 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL2832U_IRHID.sys -- (RTL2832U_IRHID)
DRV - [2009.03.24 16:25:24 | 000,197,680 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2009.03.18 17:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.03.06 11:52:00 | 007,545,088 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.11.05 14:20:24 | 000,048,128 | ---- | M] (REDC) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008.10.11 06:56:00 | 000,045,056 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008.07.29 06:41:36 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.09.13 14:46:06 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007.06.27 14:05:52 | 000,053,184 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2007.02.16 11:05:48 | 000,014,464 | ---- | M] (Christian Diefer) [Kernel | System | Running] -- C:\Windows\System32\drivers\fanio.sys -- (fanio)
DRV - [2006.12.26 14:54:35 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006.11.10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2005.09.23 23:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2005.01.17 21:49:27 | 000,018,048 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2003.10.16 20:11:04 | 000,012,928 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DGUSB.sys -- (DGUSB)
DRV - [2003.04.19 00:32:04 | 000,004,736 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tandpl.sys -- (tandpl)
DRV - [2003.03.02 17:44:26 | 000,007,552 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\enodpl.sys -- (enodpl)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-8.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 22 C7 A6 2B FF 1E CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {17394513-BDC1-41FF-8D69-84B06A05E609}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{17394513-BDC1-41FF-8D69-84B06A05E609}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKCU\..\SearchScopes\{18032637-E021-4ACE-B21E-AE2DE49701A3}: "URL" = hxxp://suche.t-online.de/fast-cgi/tsc?sr=tweb&q={searchTerms}&dia=tie8
IE - HKCU\..\SearchScopes\{192A50FE-20C4-40BD-AA63-9549FAF1942A}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-23097-0/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{7DD8A80D-9D07-4692-AD54-ABC7DE52FD38}: "URL" = hxxp://suche.t-online.de/fast-cgi/tsc?sr=twiki&q={searchTerms}&dia=tie8
IE - HKCU\..\SearchScopes\{C23F0F7E-B4BC-45FE-8158-442849D91E4F}: "URL" = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tonline_internetexplorer-browser-suche-21&index=blended&linkCode=ur2&camp=1638&creative=6742
IE - HKCU\..\SearchScopes\{E16DDF24-0662-40F4-8333-00CF74C03205}: "URL" = hxxp://de.wikipedia.org/wiki/Spezial:Search?search={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Components: C:\Program Files\Firefox Aurora\components [2012.07.18 19:20:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Plugins: C:\Program Files\Firefox Aurora\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.08.04 18:33:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 12\components [2012.05.23 09:06:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.10.01 21:20:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.06.26 21:04:53 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\finder@meingutscheincode.de: C:\Program Files\Mein Gutscheincode Finder\Firefox [2011.05.30 17:00:56 | 000,000,000 | ---D | M]
[2009.09.05 00:18:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\Extensions
[2012.05.23 09:07:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\u7hs57z8.default\extensions
[2010.08.18 21:59:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\u7hs57z8.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.23 09:07:13 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\u7hs57z8.default\extensions\ich@maltegoetz.de
[2012.06.26 23:14:53 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.05.15 15:26:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.01 21:20:16 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.01 21:20:16 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.01 21:20:16 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.01 21:20:16 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.01 21:20:16 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&output=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.xenocode.com/
O1 HOSTS File: ([2012.06.26 21:39:31 | 000,443,290 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 192.168.234.5 MAM-SRV-ARCH01
O1 - Hosts: 192.168.234.6 MAM-SRV-ARCH02
O1 - Hosts: 192.168.234.7 MAM-SRV-ARCH03
O1 - Hosts: 192.168.234.8 MAM-SRV-ARCH04
O1 - Hosts: 192.168.234.9 MAM-SRV-ARCH05
O1 - Hosts: 192.168.234.10 MAM-SRV-ARCH06
O1 - Hosts: 192.168.234.11 MAM-SRV-ARCH07
O1 - Hosts: 192.168.234.16 MAM-SRV-DB
O1 - Hosts: 192.168.241.41 pam-srv-trans01
O1 - Hosts: 192.168.241.42 pam-srv-trans02
O1 - Hosts: 192.168.241.43 pam-srv-trans03
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 15226 more lines...
O2 - BHO: (Mein Gutscheincode Finder zeigt automatisch Shopping-Gutscheine an mit denen Sie beim Online-Einkauf sparen können.) - {1ED16E0A-E8C4-40A0-8BC2-79485D21F796} - C:\Programme\Mein Gutscheincode Finder\Internet Explorer\x86\ConversionOneIE.dll (Conversion One GmbH)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\System32\ExplorerFrame.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Apoint] C:\Programme\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Programme\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [i8kfangui] C:\Program Files\I8kfanGUI\I8kfanGUI.exe (Christian Diefer)
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (tzuk)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Max\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Programme\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Programme\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{02129743-6F56-4D8D-8DB6-AEDD9902353C}: NameServer = 192.168.178.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{22184aaf-2de1-11df-b490-001c232bf1f2}\Shell - "" = AutoRun
O33 - MountPoints2\{22184aaf-2de1-11df-b490-001c232bf1f2}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{691496b3-64ef-11e0-817c-001c232bf1f2}\Shell - "" = AutoRun
O33 - MountPoints2\{691496b3-64ef-11e0-817c-001c232bf1f2}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.07.25 13:48:21 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
[2012.07.24 12:22:23 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.07.23 22:51:08 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\GABY
[2012.07.23 21:54:02 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{0E876457-010F-46F5-A6C5-3B1019EAD19D}
[2012.07.23 21:53:50 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DE05D193-B386-4AF8-8D99-D38E23796187}
[2012.07.23 19:01:50 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\UPG
[2012.07.23 09:53:34 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9B8F2DA1-E055-40F9-8BB2-0CEBC52B8847}
[2012.07.23 09:53:20 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{01D92DAD-632D-4094-A93D-FD7EED01FC83}
[2012.07.22 00:55:49 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{57700641-55EB-4676-B94D-1839FA0A7CCC}
[2012.07.22 00:55:26 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C97F71EE-8FA1-45DB-AA2A-31901ED05F96}
[2012.07.21 12:55:13 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{AB57F648-80F2-416A-80B7-64847985F8B7}
[2012.07.21 12:54:50 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{0D5F1440-CD16-4ED8-84FD-B6670B1873A0}
[2012.07.21 00:54:36 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{B5C474BE-EF29-4F98-A109-194AB1D74EAA}
[2012.07.21 00:54:13 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E049A0FB-E5C9-4397-AC59-14FB30973E4B}
[2012.07.20 12:53:59 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8097DE49-2717-4B1D-8B79-3DC944C42258}
[2012.07.20 12:53:36 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8600FF88-A5B6-468B-99EA-D4BBD2386575}
[2012.07.20 00:53:22 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8B9B31B8-4C41-41CE-A293-8107E6541C75}
[2012.07.20 00:52:59 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{7CB3C92A-54A1-4821-8EA3-66478A2E3103}
[2012.07.19 18:29:53 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\47pfl6877k_12_fus_deu_NEW
[2012.07.19 12:52:34 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{4DA42110-4555-4834-A985-6569E4F56907}
[2012.07.19 12:48:36 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{BB0D9972-61E6-42AF-A39E-4CD5B0B29477}
[2012.07.19 12:48:14 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{39BE5A2D-1E0C-4D8B-8708-696FF87E5738}
[2012.07.19 00:48:00 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{BD83A855-3037-495A-AA7E-22222F4A7E78}
[2012.07.19 00:47:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{AE8515F5-FC3D-4C01-BA81-54B50CF49557}
[2012.07.18 19:36:37 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\Macromedia
[2012.07.18 12:47:06 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{7D9CD1A0-2E33-4010-B3D5-22BB7145DA39}
[2012.07.18 12:46:40 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{4800F460-0B5A-4634-ABD7-981066FE9A68}
[2012.07.18 00:46:24 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{FF665716-A3EE-4CFB-BE84-EEAD9C60C006}
[2012.07.18 00:45:59 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CD28118D-351C-4EDF-9237-D7E4CED33407}
[2012.07.17 12:45:39 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{2A5A4C9E-AC03-455B-941A-84CB1C736BC5}
[2012.07.17 12:45:14 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{D7043730-1129-43FF-B60F-94D14BE8AB00}
[2012.07.17 00:44:56 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{F1313CA3-01F3-43DB-B6DE-4CC15099DD60}
[2012.07.17 00:44:32 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E639068E-8692-4991-BCCE-F04E7E57AB3B}
[2012.07.16 19:37:50 | 000,019,072 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
[2012.07.16 19:37:41 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
[2012.07.16 12:44:13 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{0DEC3840-38BB-4C8C-AC87-753E99A88EB5}
[2012.07.16 12:43:46 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8B52BFEC-9C68-46AD-B480-9419D6B147DC}
[2012.07.16 12:36:55 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.07.16 12:33:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2012.07.16 12:33:12 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012.07.16 12:33:06 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2012.07.16 00:43:29 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{97BB92EC-0640-490C-BCB1-DBEFCAE071E3}
[2012.07.16 00:43:03 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9E9F7E2F-8EEA-4424-817C-BA264F1088AB}
[2012.07.15 12:42:48 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{B714D027-53C5-4488-89C2-17BBF1F53B9B}
[2012.07.15 12:42:23 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{3B246F8C-93EE-48AF-B0DB-DB5A7EC14855}
[2012.07.15 00:42:07 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8D66CC6F-BBE0-408D-A4E4-CE73B79FEB2E}
[2012.07.15 00:41:42 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{F59051D5-4363-4F6D-BE77-C453BD1F9970}
[2012.07.14 12:41:20 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{87F1065F-9C22-4195-A59D-D32CDF9327C5}
[2012.07.14 12:40:51 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{3E71E62E-B06C-4558-AD71-88E2A8574E90}
[2012.07.14 00:40:35 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5DCA5CB3-A29B-4803-A619-8DE4628E31A0}
[2012.07.14 00:40:12 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{27842783-DACF-4C13-9C07-0F73D68F55FE}
[2012.07.13 12:39:58 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{6C409AA7-91F1-4198-97E1-BDD4407A2C3C}
[2012.07.13 12:39:35 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{A91050C1-41AF-4BB3-84CB-8581DDECA97F}
[2012.07.13 00:39:20 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{0ABC423F-CDDA-49A4-AC3E-A0F033D4812A}
[2012.07.13 00:38:57 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{ED926501-21EF-4347-B24D-266F66BDFB35}
[2012.07.12 12:38:42 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{750AF375-F060-4ACB-904C-800C1C3916AD}
[2012.07.12 12:38:18 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8BFDB160-B230-4985-820A-F6B013869B68}
[2012.07.12 00:38:04 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C4D930A7-B8F3-45D3-B29B-D3180093E9DA}
[2012.07.12 00:37:41 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DDEC7E9F-0B86-4C9C-9894-C2B9AD435735}
[2012.07.11 12:37:25 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C9863C55-CE1B-4C1D-B1E3-03A2F9FB4DAA}
[2012.07.11 12:37:02 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{B8E76645-67A3-439B-AB32-4F1C03BA070B}
[2012.07.11 00:36:47 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{F45DEB39-7A88-400A-AEB1-29436264CC8F}
[2012.07.11 00:36:24 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CA8224B1-9DC7-446B-AE6E-3A457E9ED6DC}
[2012.07.10 12:36:10 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E167EDB6-858C-4E1D-AD53-467E4ECD6030}
[2012.07.10 12:35:47 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9B1AF5DF-D480-4AB6-9BD3-0774E081F2E6}
[2012.07.10 00:35:33 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C5F173CF-2A9E-4DD2-9B26-95F1B57D71B5}
[2012.07.10 00:35:10 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C595D5F1-F0E0-4332-8C0E-F709594958A6}
[2012.07.09 12:34:56 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DC281656-CEC8-45BE-AA16-3F4CDB701A4D}
[2012.07.09 12:34:32 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{1145E29D-EFB2-43A3-B2AB-F138273304BE}
[2012.07.09 00:34:14 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E8C9D7BE-AD8A-4D96-BC9F-9F50571754A6}
[2012.07.09 00:34:01 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{59750591-D1A2-4141-95CE-2667E731CF47}
[2012.07.08 12:33:47 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9D835FFF-368B-41A1-99DD-CFB23EA92FED}
[2012.07.08 12:33:23 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{CA9AB6E7-F7C5-4700-A713-BE73DA712358}
[2012.07.08 00:32:56 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E03F5716-F733-4259-BFCF-7B9687D64BAA}
[2012.07.08 00:32:32 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{FF460A66-659A-46D9-A9BB-8FBAB64A2FF4}
[2012.07.07 12:32:03 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{522EFB4E-3A71-4570-BEAC-CCAD0E7CB50A}
[2012.07.07 12:31:46 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DBB0BE6D-FC74-4E83-98D2-2B7D412E251F}
[2012.07.06 15:22:26 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DCE925D7-7E27-4BAD-BC08-19002E42BC24}
[2012.07.06 15:22:03 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{FDA6C431-0EF1-4ADB-B955-19795DE2A27B}
[2012.07.06 03:21:50 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{4BF29B2C-2712-44F5-851E-64E57FE8132E}
[2012.07.06 03:21:26 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{D138C0B3-83B8-49E7-B1E4-407AB227530B}
[2012.07.05 15:21:12 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{DCF643DD-A94F-4C0E-9C23-AA37C10ABEBF}
[2012.07.05 15:20:49 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{D46C2760-EDBC-4D1D-ABE2-843022B36C65}
[2012.07.05 03:20:34 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{735A045C-274F-4383-8E06-7D1E69E11452}
[2012.07.05 03:20:10 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{63BDDC6B-CAFB-4281-8AA8-BBB586FAD15F}
[2012.07.04 15:19:57 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{9B11552B-9B0A-47E0-B502-72777D9DC399}
[2012.07.04 15:19:34 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{79C841C7-CE25-4FDA-87FB-CBAF0E7161FA}
[2012.07.04 03:19:20 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{F9965F6C-6AAC-44BF-8700-6009458E8B11}
[2012.07.04 03:18:57 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{63C86A0B-7F4E-41AD-90E6-49A6B0CBDC89}
[2012.07.03 15:18:44 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{89069210-65BA-457F-95A0-E38393207E30}
[2012.07.03 15:18:21 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{40B98341-95CA-45EF-B422-C0F4403F3B69}
[2012.07.03 03:18:07 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{2A8BC292-F06A-49B4-849E-CB2D0D26DFD3}
[2012.07.03 03:17:43 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5F8078EB-AE66-4479-9F66-D3609AADEE40}
[2012.07.02 15:17:15 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{ED572693-7787-4E6A-9F61-F88D13789F2F}
[2012.07.02 15:16:52 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{60B4AE59-2E74-4F8E-A4F5-3C253CC06B66}
[2012.07.02 03:16:39 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{B1C923A2-5681-40B1-926F-7FE70B5416E6}
[2012.07.02 03:16:15 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{28A4ECA0-4584-4520-B615-B8FB96CC3149}
[2012.07.01 17:19:42 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\bdp7700_12_fus_deu
[2012.07.01 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{4F4288E5-D71C-4980-92D7-D040C2AFDEA0}
[2012.07.01 15:15:39 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{44A6E1CB-F1A0-4A89-85B0-837317E557FD}
[2012.07.01 03:15:26 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5EC02976-8934-4428-8E6D-BE7D3FB19BD3}
[2012.07.01 03:15:03 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{82964F9F-ABD1-4D3D-A84F-3B003B244914}
[2012.06.30 15:14:50 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{2373D420-726D-47AB-8933-5F358BBA2166}
[2012.06.30 15:14:27 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{1749EE95-0CB4-4944-B9BE-298718E1487A}
[2012.06.30 03:14:14 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{174829FC-6683-44C9-8A49-96378AC0BCE8}
[2012.06.30 03:13:51 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{A70B47C6-AD0C-4AAE-9C50-0377105BB3E3}
[2012.06.29 16:22:20 | 000,319,488 | ---- | C] (GigaTwin/Unicam Team) -- C:\Users\Max\Desktop\UniCam Loader 1.1.exe
[2012.06.29 16:04:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012.06.29 16:04:38 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2012.06.29 15:13:25 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{73C14D43-6E81-433B-9C23-79F3FE6B44A9}
[2012.06.29 15:13:01 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{99E2C589-6C29-4BDD-A300-152B593DA21E}
[2012.06.29 03:12:48 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{C176DE92-9C1F-48B9-BD89-BFFF23A52A8B}
[2012.06.29 03:12:25 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{EF2E0394-27CB-4D21-84C6-0D549A51EC28}
[2012.06.28 15:12:12 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{3EDABFF5-B522-4949-8714-5774D9267C63}
[2012.06.28 15:11:48 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{67381B56-5811-4822-AD65-B22EB7453AB7}
[2012.06.28 03:11:35 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{72D5DD88-9330-4BC9-B995-3549DE6C72D3}
[2012.06.28 03:11:12 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{4824C93D-094F-48EC-9C8B-DE3CC8001E93}
[2012.06.27 15:10:59 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{986109CB-193F-493A-AAAC-BCE25DDEFB3A}
[2012.06.27 15:10:36 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{E1494694-0EA9-4C3D-AA3A-D2E87621023D}
[2012.06.27 03:10:21 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{8D346E41-4FF3-4AEB-8163-09BAB802E505}
[2012.06.27 03:09:58 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{80E87279-1B71-4C0C-A495-904BEF980736}
[2012.06.26 20:45:16 | 000,627,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.06.26 20:45:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.06.26 20:45:14 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.06.26 20:45:14 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.06.26 20:45:14 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.06.26 20:44:56 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2012.06.26 20:44:49 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.06.26 20:42:36 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.06.26 20:42:36 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.06.26 20:42:36 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.06.26 20:26:05 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\Desktop 7
[2012.06.26 15:09:10 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{ABDA9D84-74E5-4210-8196-3CCCC9FCB9BE}
[2012.06.26 15:08:24 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{27A9F340-9B5D-4FFB-899F-A6A25C17341F}
[2012.06.26 03:07:59 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{2B667E3F-3C10-46F8-85FC-DA95F8A0A3D2}
[2012.06.26 03:07:27 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{85434D36-8106-494F-BB2A-FEA720A5C621}
[2012.06.25 15:07:00 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{5809E706-C244-4DF1-BD1C-D29AE6D80634}
[2012.06.25 15:06:32 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\{EB83DDB9-6BD2-4A63-B851-F8C4BF0A60C2}
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.07.25 11:26:49 | 000,020,864 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.25 11:26:48 | 000,020,864 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.25 11:19:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.25 11:18:54 | 2414,710,784 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.24 14:56:10 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe
[2012.07.24 10:36:19 | 004,503,728 | ---- | M] () -- C:\ProgramData\piz_0ef.pad
[2012.07.23 23:02:35 | 000,001,879 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012.07.23 22:44:41 | 000,656,040 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.07.23 22:44:41 | 000,616,546 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.23 22:44:41 | 000,130,640 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.07.23 22:44:41 | 000,106,926 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.23 19:00:53 | 021,849,912 | ---- | M] () -- C:\Users\Max\Desktop\bdp7500bl_12_fus_deu.zip
[2012.07.19 17:02:16 | 146,876,696 | ---- | M] () -- C:\Users\Max\Desktop\47pfl6877k_12_fus_deu_NEW.zip
[2012.07.19 12:49:34 | 146,511,599 | ---- | M] () -- C:\Users\Max\Desktop\6xx7_7XX7_8xx7_132.5.1.zip
[2012.07.18 18:59:09 | 002,404,360 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.17 10:18:14 | 145,224,603 | ---- | M] () -- C:\Users\Max\Desktop\47pfl6877k_12_fus_deu_108_008.zip
[2012.07.16 19:39:34 | 000,002,047 | ---- | M] () -- C:\Users\Public\Desktop\Nokia Suite.lnk
[2012.07.11 12:12:44 | 000,142,909 | ---- | M] () -- C:\Users\Max\Desktop\2012-07-08-415.jpg
[2012.07.11 12:12:44 | 000,116,759 | ---- | M] () -- C:\Users\Max\Desktop\2012-07-08-416.jpg
[2012.07.11 12:12:44 | 000,114,337 | ---- | M] () -- C:\Users\Max\Desktop\2012-07-08-410.jpg
[2012.07.07 12:33:17 | 000,001,884 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2012.07.01 17:14:25 | 094,925,071 | ---- | M] () -- C:\Users\Max\Desktop\bdp7700_12_fus_deu.zip
[2012.06.29 16:22:05 | 000,549,280 | ---- | M] () -- C:\Users\Max\Desktop\max_5.27.uns
[2012.06.28 16:43:46 | 000,319,488 | ---- | M] (GigaTwin/Unicam Team) -- C:\Users\Max\Desktop\UniCam Loader 1.1.exe
[2012.06.27 18:32:25 | 000,127,779 | ---- | M] () -- C:\Users\Max\Desktop\Ablaufprotokoll20120627.pdf
[2012.06.27 15:18:52 | 000,019,072 | ---- | M] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
[2012.06.26 21:39:31 | 000,443,290 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012.06.26 20:36:42 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.06.26 20:36:42 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.07.23 23:02:35 | 004,503,728 | ---- | C] () -- C:\ProgramData\piz_0ef.pad
[2012.07.23 23:02:35 | 000,001,879 | ---- | C] () -- C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012.07.23 19:00:41 | 021,849,912 | ---- | C] () -- C:\Users\Max\Desktop\bdp7500bl_12_fus_deu.zip
[2012.07.19 17:50:25 | 146,876,696 | ---- | C] () -- C:\Users\Max\Desktop\47pfl6877k_12_fus_deu_NEW.zip
[2012.07.19 16:08:42 | 146,511,599 | ---- | C] () -- C:\Users\Max\Desktop\6xx7_7XX7_8xx7_132.5.1.zip
[2012.07.17 10:15:58 | 145,224,603 | ---- | C] () -- C:\Users\Max\Desktop\47pfl6877k_12_fus_deu_108_008.zip
[2012.07.16 19:39:34 | 000,002,047 | ---- | C] () -- C:\Users\Public\Desktop\Nokia Suite.lnk
[2012.07.11 12:13:36 | 000,116,759 | ---- | C] () -- C:\Users\Max\Desktop\2012-07-08-416.jpg
[2012.07.11 12:13:35 | 000,142,909 | ---- | C] () -- C:\Users\Max\Desktop\2012-07-08-415.jpg
[2012.07.11 12:13:35 | 000,114,337 | ---- | C] () -- C:\Users\Max\Desktop\2012-07-08-410.jpg
[2012.07.08 08:33:31 | 2414,710,784 | -HS- | C] () -- C:\hiberfil.sys
[2012.07.01 16:44:57 | 094,925,071 | ---- | C] () -- C:\Users\Max\Desktop\bdp7700_12_fus_deu.zip
[2012.06.29 16:22:15 | 000,549,280 | ---- | C] () -- C:\Users\Max\Desktop\max_5.27.uns
[2012.06.27 18:33:41 | 000,127,779 | ---- | C] () -- C:\Users\Max\Desktop\Ablaufprotokoll20120627.pdf
[2012.05.03 10:02:07 | 000,000,056 | ---- | C] () -- C:\Windows\vidpidfix.INI
[2012.01.18 08:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2012.01.18 08:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2012.01.18 08:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011.11.17 03:40:38 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011.09.20 21:34:52 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011.08.14 15:03:25 | 000,032,256 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2011.08.12 13:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.05.30 18:28:54 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.05.30 18:26:58 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.05.28 02:04:02 | 000,181,724 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011.04.13 19:39:14 | 000,071,168 | ---- | C] () -- C:\Windows\AKDeInstall.exe
[2011.04.13 19:39:05 | 000,000,051 | ---- | C] () -- C:\Windows\TSetup.INI
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.03.26 22:56:45 | 002,336,384 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2011.03.26 22:56:45 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2011.03.26 22:56:45 | 000,014,848 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2011.03.26 22:56:45 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2011.03.26 22:56:45 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2011.03.13 02:49:59 | 000,676,864 | ---- | C] () -- C:\Windows\System32\mxMonecSocket.dll
[2010.11.02 10:43:41 | 000,137,960 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.11.02 10:07:37 | 000,235,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010.11.02 10:07:19 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010.11.02 10:07:18 | 002,373,712 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010.10.08 12:52:13 | 000,000,000 | -H-- | C] () -- C:\Windows\msds.dat
[2010.10.08 12:43:12 | 000,029,574 | ---- | C] () -- C:\Windows\SETUP1.EXE
[2010.09.25 00:32:56 | 000,077,824 | ---- | C] () -- C:\Windows\KMService.exe
[2010.09.25 00:32:56 | 000,008,192 | ---- | C] () -- C:\Windows\System32\srvany.exe
[2010.07.29 19:39:53 | 000,000,149 | ---- | C] () -- C:\Windows\wiso.ini
[2010.05.18 00:27:43 | 000,004,608 | ---- | C] () -- C:\Users\Max\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.04.15 20:46:54 | 000,000,084 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.03.28 02:42:22 | 002,887,680 | ---- | C] () -- C:\Users\Max\s-1-5-21-3619751621-3969484228-3234360931-1000.rrr
[2010.03.06 13:54:38 | 000,001,356 | ---- | C] () -- C:\Users\Max\Windows XP Mode.vmcx
[2010.02.27 18:24:37 | 000,000,484 | RHS- | C] () -- C:\Users\Max\ntuser.pol
[2009.09.04 17:10:16 | 000,007,597 | ---- | C] () -- C:\Users\Max\AppData\Local\Resmon.ResmonCfg
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:D287FACF
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:7631EA83
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:C895616B
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6CC69D3C
< End of report >
Malwarebytes Log: Code:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Datenbank Version: v2012.07.03.05
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Max :: SG [Administrator]
25.07.2012 14:15:27
mbam-log-2012-07-25 (14-25-48).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 235397
Laufzeit: 4 Minute(n), 3 Sekunde(n)
Infizierte Speicherprozesse: 1
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> 2008 -> Keine Aktion durchgeführt.
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Keine Aktion durchgeführt.
(Ende) |