AdwCleaner Code:
# AdwCleaner v2.114 - Datei am 15/03/2013 um 13:49:17 erstellt
# Aktualisiert am 05/03/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzer : JEEZY - JEEZY1
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\JEEZY\Downloads\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\searchplugins\babylon1.xml
Datei Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\searchplugins\icqplugin.xml
Datei Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\searchplugins\icqplugin-1.xml
Ordner Gelöscht : C:\Program Files\ICQ6Toolbar
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\Users\JEEZY\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\JEEZY\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\JEEZY\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
Ordner Gelöscht : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\extensions\firejump@firejump.net
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\5d538bdeb43dee43
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\StartSearch
Schlüssel Gelöscht : HKLM\SOFTWARE\5d538bdeb43dee43
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\extensions [firejump@firejump.net]
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16470
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=114026&tt=0113_6&babsrc=HP_ss&mntrId=6ee7012200000000000000ff5ef94524 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0 (de)
Datei : C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\prefs.js
C:\Users\JEEZY\AppData\Roaming\Mozilla\Firefox\Profiles\m5697o37.default\user.js ... Gelöscht !
Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_v[...]
Gelöscht : user_pref("extensions.BabylonToolbar.admin", false);
Gelöscht : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Gelöscht : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Gelöscht : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Gelöscht : user_pref("extensions.BabylonToolbar.bbDpng", "6");
Gelöscht : user_pref("extensions.BabylonToolbar.cntry", "DE");
Gelöscht : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Gelöscht : user_pref("extensions.BabylonToolbar.dpkLst", "");
Gelöscht : user_pref("extensions.BabylonToolbar.excTlbr", false);
Gelöscht : user_pref("extensions.BabylonToolbar.hdrMd5", "C28CDA6402C30E77190DB37385B548D2");
Gelöscht : user_pref("extensions.BabylonToolbar.id", "6ee7012200000000000000ff5ef94524");
Gelöscht : user_pref("extensions.BabylonToolbar.instlDay", "15709");
Gelöscht : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Gelöscht : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.8.7.21:01:29");
Gelöscht : user_pref("extensions.BabylonToolbar.pnu_base", "{\"newVrsn\":\"59\",\"lastVrsn\":\"59\",\"vrsnLoad\[...]
Gelöscht : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Gelöscht : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Gelöscht : user_pref("extensions.BabylonToolbar.rvrt", "false");
Gelöscht : user_pref("extensions.BabylonToolbar.sg", "czb");
Gelöscht : user_pref("extensions.BabylonToolbar.smplGrp", "czb");
Gelöscht : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Gelöscht : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]
Gelöscht : user_pref("extensions.BabylonToolbar.vrsn", "1.8.7.2");
Gelöscht : user_pref("extensions.BabylonToolbar.vrsni", "1.8.7.2");
Gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", "");
Gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=114026&tt=0113_6");
Gelöscht : user_pref("extensions.BabylonToolbar_i.excTlbr", false);
Gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", false);
Gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.7.21:01:30");
Gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Gelöscht : user_pref("icqtoolbar.engineVerified", false);
Gelöscht : user_pref("icqtoolbar.facebookSmilesAddonShowedPopup", true);
Gelöscht : user_pref("icqtoolbar.firstTbRun", false);
Gelöscht : user_pref("icqtoolbar.geolastmodified", 1361607618);
Gelöscht : user_pref("icqtoolbar.history", "horkruks||asg||0%3A1%3A29454366||Cam'Ron%20-%20Get%20'Em%20Girls||h[...]
Gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Gelöscht : user_pref("icqtoolbar.installTime", "1343363667");
Gelöscht : user_pref("icqtoolbar.installsource", "1");
Gelöscht : user_pref("icqtoolbar.newtab_most_visited_state", "1");
Gelöscht : user_pref("icqtoolbar.newtab_recently_closed_state", "1");
Gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Gelöscht : user_pref("icqtoolbar.previousFFVersion", "7.0.1");
Gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Gelöscht : user_pref("icqtoolbar.suggestions", false);
Gelöscht : user_pref("icqtoolbar.uniqueID", "132052132013205213201320521531323");
Gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1361558949);
Gelöscht : user_pref("icqtoolbar.userHpApproved", true);
Gelöscht : user_pref("icqtoolbar.version", "1.5.3");
Gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
Gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
Gelöscht : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", false);
Gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
-\\ Google Chrome v25.0.1364.172
Datei : C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
-\\ Chromium v directory_upgrade: true
}
Datei : C:\Users\JEEZY\AppData\Local\Chromium\User Data\Default\Preferences
[OK] Die Datei ist sauber.
-\\ Opera v12.14.1738.0
Datei : C:\Users\JEEZY\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [8757 octets] - [15/03/2013 13:49:17]
########## EOF - C:\AdwCleaner[S1].txt - [8817 octets] ##########
OTL
OTL Logfile: Code:
OTL logfile created on: 15.03.2013 13:55:41 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JEEZY\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,49 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 60,93% Memory free
6,98 Gb Paging File | 5,52 Gb Available in Paging File | 79,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 59,53 Gb Total Space | 10,03 Gb Free Space | 16,85% Space Free | Partition Type: NTFS
Drive D: | 1397,26 Gb Total Space | 1273,62 Gb Free Space | 91,15% Space Free | Partition Type: NTFS
Computer Name: JEEZY1 | User Name: JEEZY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.03.13 18:40:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\JEEZY\Desktop\OTL.exe
PRC - [2013.03.09 15:33:09 | 001,808,392 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe
PRC - [2013.03.08 18:47:49 | 000,917,400 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013.02.23 02:36:04 | 000,545,576 | ---- | M] (AnchorFree Inc.) -- C:\Programme\Hotspot Shield\bin\openvpnas.exe
PRC - [2013.02.23 02:33:26 | 000,389,928 | ---- | M] () -- C:\Programme\Hotspot Shield\bin\hsswd.exe
PRC - [2013.02.23 02:29:46 | 000,453,928 | ---- | M] (AnchorFree Inc.) -- C:\Programme\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2013.02.21 19:48:23 | 000,213,384 | ---- | M] (Google Inc.) -- C:\Programme\Google\Update\1.3.21.135\GoogleCrashHandler.exe
PRC - [2012.12.17 11:39:02 | 000,615,440 | ---- | M] () -- D:\Program Files\EslWire\service\WireHelperSvc.exe
PRC - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.12.14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.12.14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012.11.23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.10.02 20:29:14 | 000,864,616 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2012.10.02 20:28:55 | 001,820,520 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011.09.05 10:04:54 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.07.12 15:29:00 | 000,552,960 | ---- | M] (ROCCAT GmbH) -- D:\Program Files\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe
PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.12.20 18:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.20 18:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.11.20 13:29:22 | 000,101,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 02:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
========== Modules (No Company Name) ==========
MOD - [2013.03.09 15:33:08 | 014,586,888 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_146.dll
MOD - [2013.03.08 18:47:49 | 003,069,848 | ---- | M] () -- D:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.01.08 14:41:12 | 000,093,696 | ---- | M] () -- D:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2010.06.22 13:50:52 | 000,061,440 | ---- | M] () -- D:\Program Files\ROCCAT\Kone[+] Mouse\hiddriver.dll
========== Services (SafeList) ==========
SRV - [2013.03.09 15:33:09 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.02.25 07:39:32 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.02.23 02:36:04 | 000,545,576 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Programme\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2013.02.23 02:33:26 | 000,389,928 | ---- | M] () [Auto | Running] -- C:\Programme\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2013.02.23 02:29:46 | 000,453,928 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Programme\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2013.02.22 02:54:48 | 000,078,512 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2013.02.16 01:34:06 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.01.08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.12.17 11:39:02 | 000,615,440 | ---- | M] () [Auto | Running] -- D:\Program Files\EslWire\service\WireHelperSvc.exe -- (EslWireHelper)
SRV - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.12.14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012.10.10 21:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.03.09 18:06:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011.09.05 10:04:54 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.08.07 22:40:00 | 003,804,120 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011.03.02 15:28:56 | 000,361,216 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\avp.exe -- (AVP)
SRV - [2010.12.20 18:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010.12.20 18:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva392.sys -- (XDva392)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\CM106.sys -- (USBMULCD)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2013.02.22 02:50:36 | 000,037,064 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss6.sys -- (taphss6)
DRV - [2013.02.22 02:37:16 | 000,040,136 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\hssdrv6.sys -- (HssDRV6)
DRV - [2012.12.17 11:38:54 | 000,867,344 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ESLWireACD.sys -- (ESLWireAC)
DRV - [2012.12.14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.10.10 21:14:28 | 010,837,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.04.08 02:51:30 | 000,050,728 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm)
DRV - [2012.04.06 19:15:10 | 000,033,512 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2011.11.06 03:06:37 | 000,488,536 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2011.08.03 09:58:14 | 000,024,504 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ESLvnic.sys -- (ESLvnic1)
DRV - [2011.06.02 10:32:50 | 000,317,416 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\asmtxhci.sys -- (asmtxhci)
DRV - [2011.06.02 10:32:50 | 000,101,352 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\asmthub3.sys -- (asmthub3)
DRV - [2011.03.03 16:59:19 | 000,139,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.10.19 16:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2010.07.01 14:21:14 | 000,034,896 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2010.06.09 16:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010.06.09 16:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (KL1)
DRV - [2010.04.22 18:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2010.01.14 21:27:02 | 000,025,376 | R--- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan60.sys -- (VLAN)
DRV - [2010.01.14 21:27:02 | 000,025,376 | R--- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan60.sys -- (RTVLANPT)
DRV - [2010.01.14 21:26:46 | 000,040,736 | R--- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (TEAM)
DRV - [2010.01.14 21:26:46 | 000,040,736 | R--- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV - [2010.01.14 21:26:34 | 000,033,056 | R--- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2009.11.02 19:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.07.14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2005.01.02 04:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FF 36 37 4F F0 9B CC 01 [binary data]
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1221864313-813813898-1403309165-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.7
FF - prefs.js..extensions.enabledAddons: toolbar%40web.de:2.4
FF - prefs.js..extensions.enabledAddons: %7Bdd3d7613-0246-469d-bc65-2a3cc1668adc%7D:0.7.1.1
FF - prefs.js..extensions.enabledAddons: %7Bef4e370e-d9f0-4e00-b93e-a4f274cfdd5a%7D:1.4.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..network.proxy.type: 2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\JEEZY\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2013.03.08 18:47:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2013.03.08 18:47:49 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins
[2011.11.05 20:24:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\Extensions
[2013.03.15 13:49:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\Firefox\Profiles\m5697o37.default\extensions
[2013.03.06 18:05:33 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\JEEZY\AppData\Roaming\mozilla\Firefox\Profiles\m5697o37.default\extensions\ich@maltegoetz.de
[2013.02.23 09:37:18 | 000,000,000 | ---D | M] (WEB.DE MailCheck) -- C:\Users\JEEZY\AppData\Roaming\mozilla\Firefox\Profiles\m5697o37.default\extensions\toolbar@web.de
[2012.11.02 14:56:01 | 000,077,464 | ---- | M] () (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\firefox\profiles\m5697o37.default\extensions\ciuvo-extension@billiger.de.xpi
[2012.08.26 18:58:28 | 000,101,863 | ---- | M] () (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\firefox\profiles\m5697o37.default\extensions\ciuvo-extension@icq.de.xpi
[2012.12.30 19:54:44 | 000,016,192 | ---- | M] () (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\firefox\profiles\m5697o37.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi
[2013.02.20 16:59:09 | 000,685,671 | ---- | M] () (No name found) -- C:\Users\JEEZY\AppData\Roaming\mozilla\firefox\profiles\m5697o37.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Enabled) = D:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\JEEZY\AppData\Local\Facebook\Messenger\2.1.4651.0\npFbDesktopPlugin.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: Google Docs = C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google Mail = C:\Users\JEEZY\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012.10.06 08:09:09 | 000,001,297 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 255.255.255.255 easyanticheat.se # misleading site
O1 - Hosts: 255.255.255.255 www.easyanticheat.se # misleading site
O1 - Hosts: 255.255.255.255 easyanticheat.com # misleading site
O1 - Hosts: 255.255.255.255 www.easyanticheat.com # misleading site
O1 - Hosts: 255.255.255.255 easyanticheat.info # misleading site
O1 - Hosts: 255.255.255.255 www.easyanticheat.info # misleading site
O1 - Hosts: 255.255.255.255 easyanticheat.org # misleading site
O1 - Hosts: 255.255.255.255 www.easyanticheat.org # misleading site
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [RoccatKone+] D:\Program Files\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.EXE (ROCCAT GmbH)
O4 - HKLM..\Run: [speedvid] C:\Programme\SpeedVID\SpeedVID Accelerator\SpeedVidA.exe (SpeedVID Accelerator)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-1221864313-813813898-1403309165-1000..\Run: [Facebook Update] C:\Users\JEEZY\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-1221864313-813813898-1403309165-1000..\Run: [ICQ] D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1221864313-813813898-1403309165-1000..\Run: [Irsacu] C:\Users\JEEZY\AppData\Roaming\Doelna\zaesw.exe File not found
O4 - HKU\S-1-5-21-1221864313-813813898-1403309165-1000..\Run: [Steam] D:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\JEEZY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JEEZY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\JEEZY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk = C:\Users\JEEZY\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5EF94524-B58F-4D8C-AEA3-40728AEDA34B}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7072BE6F-DBB1-44D3-B0BB-C77C59CD5E1D}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll) - c:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (c:\progra~1\kasper~1\kasper~1\kloehk.dll) - c:\Programme\Kaspersky Lab\Kaspersky Internet Security Special Ferrari Edition\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.15 13:52:05 | 002,417,863 | ---- | C] (Swearware) -- C:\Users\JEEZY\Desktop\ComboFix.exe
[2013.03.15 13:41:52 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{98C7E03C-DDC9-4CFD-9D91-2735BD785193}
[2013.03.15 06:34:48 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{C4F6228A-EA4A-4E3E-8D64-81B83E9CAF36}
[2013.03.14 22:04:21 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\JEEZY\Desktop\tdsskiller.exe
[2013.03.14 20:57:16 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\JEEZY\Desktop\aswMBR.exe
[2013.03.14 16:57:32 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{A7BB5671-C546-4027-8C28-F39537B0CC00}
[2013.03.14 03:18:05 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{0950DA9E-A647-4C58-8CDB-33DE61F13E70}
[2013.03.13 18:40:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\JEEZY\Desktop\OTL.exe
[2013.03.13 18:33:54 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Roaming\Malwarebytes
[2013.03.13 18:33:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.03.13 18:33:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.03.13 18:33:33 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.13 18:06:08 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Roaming\Hotspot Shield
[2013.03.13 06:20:17 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{848EEA9D-93E2-43B9-9066-7E75167CACD3}
[2013.03.12 16:58:51 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{32E2F4BE-C239-4610-90D5-DB1C2B5192F5}
[2013.03.11 17:42:28 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{B6D04BA0-AFD9-49C5-BF6C-1027C06748DC}
[2013.03.10 18:20:29 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{282767F1-8AD9-4C73-8EBB-2D15A43576FF}
[2013.03.10 04:52:03 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{5479D843-A6C6-499F-B831-8439DC0343F0}
[2013.03.09 17:40:04 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\Documents\ManiaPlanet
[2013.03.09 17:40:04 | 000,000,000 | ---D | C] -- C:\ProgramData\ManiaPlanet
[2013.03.09 16:24:21 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\Macromedia
[2013.03.09 15:32:34 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\Documents\My Games
[2013.03.09 08:58:48 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{13270695-25BD-405A-8774-D38B516E5E83}
[2013.03.08 18:45:49 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{59F27150-C4D8-4104-AA02-4031C255E7E1}
[2013.03.08 06:45:26 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{D6844212-8BAC-4CC2-9735-62A8FBCC5ADB}
[2013.03.07 15:41:37 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{08EDF804-C6F4-4E91-B1B7-FEB2A8868967}
[2013.03.06 17:57:59 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{BE657D5D-9BF8-48B4-8EDF-F2EA353F52E6}
[2013.03.05 16:59:21 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{62AC2EA0-53FD-4737-A63A-2D3CBC2D942C}
[2013.03.04 12:36:33 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivitizeVPN
[2013.03.04 12:36:31 | 000,000,000 | ---D | C] -- C:\Program Files\PrivitizeVPN
[2013.03.04 07:37:00 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{EF5457BC-169F-4FBC-BC84-B55AF0D3121C}
[2013.03.03 08:24:48 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{F619A86A-58C1-4349-BB29-2E1279B144AC}
[2013.03.02 18:56:13 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\Desktop\xyyy
[2013.03.02 08:28:39 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{088675A9-A353-4668-9545-4C9F27DDA4DE}
[2013.03.01 08:35:24 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{B7476F08-1590-4474-88D9-6B982928F6E2}
[2013.02.28 19:41:13 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{42A4BC10-74EB-45B6-94AE-7C2F6A1C732E}
[2013.02.27 18:40:43 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{34A76B59-87F8-4BFB-B7F4-A8488C42C72E}
[2013.02.27 06:40:19 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{E4C6DE94-3463-445E-954C-08ACC884A93D}
[2013.02.26 07:54:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.02.26 07:54:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013.02.26 07:54:05 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{038F85B3-0437-4E06-A222-A427311832A9}
[2013.02.25 06:50:39 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{91906DC9-2545-42C0-B135-DB8C6D331F1D}
[2013.02.24 08:10:29 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{91FC1C01-7701-4E05-B87C-DD532124857E}
[2013.02.23 09:37:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.02.23 09:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.02.23 09:17:38 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{F851713B-47CA-4933-8BAC-BC98712AC615}
[2013.02.22 16:17:58 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{D49FBA95-891A-425D-8B57-63AC5E26B008}
[2013.02.22 02:50:36 | 000,037,064 | ---- | C] (Anchorfree Inc.) -- C:\Windows\System32\drivers\taphss6.sys
[2013.02.22 02:37:16 | 000,040,136 | ---- | C] (AnchorFree Inc.) -- C:\Windows\System32\drivers\hssdrv6.sys
[2013.02.21 19:38:40 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{343FEAC0-1A8E-41B8-BE61-363F91E05904}
[2013.02.20 16:57:38 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{FA038185-FBE0-49E2-9F3D-FA589DDA95D3}
[2013.02.19 16:57:59 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{6A946F5A-10A0-4379-B8F1-1F78BA520192}
[2013.02.18 18:39:02 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{DAA566C7-8CFD-4C08-B3BE-CBC73A0856BB}
[2013.02.17 16:57:12 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{3E84B599-8ABD-45BA-AB21-FCC2C4A37270}
[2013.02.16 08:36:12 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{324900D5-BD35-480C-B97B-89D6B0664098}
[2013.02.15 08:35:33 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{A40328DD-F743-4E8B-AE67-1EB46DEAB0E3}
[2013.02.14 09:09:16 | 000,000,000 | ---D | C] -- C:\Users\JEEZY\AppData\Local\{4A30E1E7-47CC-4690-84D7-725D630FA3B6}
========== Files - Modified Within 30 Days ==========
[2013.03.15 13:56:16 | 008,010,930 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.15 13:56:16 | 002,766,072 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.15 13:56:16 | 002,414,658 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.15 13:56:16 | 002,159,300 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.15 13:53:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.15 13:52:15 | 002,417,863 | ---- | M] (Swearware) -- C:\Users\JEEZY\Desktop\ComboFix.exe
[2013.03.15 13:50:30 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.15 13:50:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.15 13:50:14 | 2810,097,664 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.15 13:48:41 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.15 13:48:41 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.14 22:16:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.14 22:07:41 | 000,000,512 | ---- | M] () -- C:\Users\JEEZY\Desktop\MBR.dat
[2013.03.14 22:04:24 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\JEEZY\Desktop\tdsskiller.exe
[2013.03.14 20:58:53 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\JEEZY\Desktop\aswMBR.exe
[2013.03.14 19:36:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1221864313-813813898-1403309165-1000UA.job
[2013.03.13 22:54:07 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.03.13 18:44:51 | 000,377,856 | ---- | M] () -- C:\Users\JEEZY\Desktop\gmer_2.1.19155.exe
[2013.03.13 18:40:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\JEEZY\Desktop\OTL.exe
[2013.03.13 18:33:34 | 000,000,756 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.11 20:35:38 | 000,082,828 | ---- | M] () -- C:\Users\JEEZY\Desktop\258612_10200208895244234_1837282503_o.jpg
[2013.03.09 16:52:12 | 000,000,216 | ---- | M] () -- C:\Users\JEEZY\Desktop\TrackMania Stadium Open Beta.url
[2013.03.09 16:36:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1221864313-813813898-1403309165-1000Core.job
[2013.03.09 10:38:29 | 000,001,278 | ---- | M] () -- C:\Users\JEEZY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
[2013.03.04 11:28:18 | 000,019,985 | ---- | M] () -- C:\Users\JEEZY\Desktop\581040_606049756076002_496179024_n.jpg
[2013.03.03 10:44:43 | 000,362,063 | ---- | M] () -- C:\Users\JEEZY\Desktop\322763_3035941936707_1353384534_o.jpg
[2013.03.03 10:27:32 | 000,076,290 | ---- | M] () -- C:\Users\JEEZY\Desktop\theaestheticscrewlogo1.jpg
[2013.02.26 16:34:22 | 000,013,359 | ---- | M] () -- C:\Users\JEEZY\Desktop\coco chanel logo.jpg
[2013.02.26 16:32:03 | 000,004,304 | ---- | M] () -- C:\Users\JEEZY\Desktop\bvlgari_logo.jpg
[2013.02.26 16:22:41 | 000,007,573 | ---- | M] () -- C:\Users\JEEZY\Desktop\Louis-Vuitton-logo.jpg
[2013.02.26 16:19:13 | 000,007,185 | ---- | M] () -- C:\Users\JEEZY\Desktop\Yves-Saint-Laurent-Logo.jpeg
[2013.02.26 16:15:23 | 000,014,462 | ---- | M] () -- C:\Users\JEEZY\Desktop\46550_473544462676915_1975152977_n.jpg
[2013.02.23 09:37:02 | 000,000,782 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.02.22 02:50:36 | 000,037,064 | ---- | M] (Anchorfree Inc.) -- C:\Windows\System32\drivers\taphss6.sys
[2013.02.22 02:37:16 | 000,040,136 | ---- | M] (AnchorFree Inc.) -- C:\Windows\System32\drivers\hssdrv6.sys
[2013.02.14 17:53:45 | 029,241,680 | ---- | M] () -- C:\Users\JEEZY\ts3_recording_13_02_14_17_51_12.wav
[2013.02.14 16:53:48 | 008,559,440 | ---- | M] () -- C:\Users\JEEZY\one direction what makes you beautiful.wav
[2013.02.13 15:35:38 | 000,269,680 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013.03.14 22:07:41 | 000,000,512 | ---- | C] () -- C:\Users\JEEZY\Desktop\MBR.dat
[2013.03.13 18:44:50 | 000,377,856 | ---- | C] () -- C:\Users\JEEZY\Desktop\gmer_2.1.19155.exe
[2013.03.13 18:33:34 | 000,000,756 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.11 20:35:38 | 000,082,828 | ---- | C] () -- C:\Users\JEEZY\Desktop\258612_10200208895244234_1837282503_o.jpg
[2013.03.09 16:52:12 | 000,000,216 | ---- | C] () -- C:\Users\JEEZY\Desktop\TrackMania Stadium Open Beta.url
[2013.03.09 15:33:09 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.04 11:28:16 | 000,019,985 | ---- | C] () -- C:\Users\JEEZY\Desktop\581040_606049756076002_496179024_n.jpg
[2013.03.03 10:44:43 | 000,362,063 | ---- | C] () -- C:\Users\JEEZY\Desktop\322763_3035941936707_1353384534_o.jpg
[2013.03.03 10:27:31 | 000,076,290 | ---- | C] () -- C:\Users\JEEZY\Desktop\theaestheticscrewlogo1.jpg
[2013.02.26 16:34:21 | 000,013,359 | ---- | C] () -- C:\Users\JEEZY\Desktop\coco chanel logo.jpg
[2013.02.26 16:32:02 | 000,004,304 | ---- | C] () -- C:\Users\JEEZY\Desktop\bvlgari_logo.jpg
[2013.02.26 16:22:40 | 000,007,573 | ---- | C] () -- C:\Users\JEEZY\Desktop\Louis-Vuitton-logo.jpg
[2013.02.26 16:19:13 | 000,007,185 | ---- | C] () -- C:\Users\JEEZY\Desktop\Yves-Saint-Laurent-Logo.jpeg
[2013.02.26 16:15:21 | 000,014,462 | ---- | C] () -- C:\Users\JEEZY\Desktop\46550_473544462676915_1975152977_n.jpg
[2013.02.23 09:37:02 | 000,000,782 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.02.23 09:37:02 | 000,000,782 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.02.14 17:51:13 | 029,241,680 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_13_02_14_17_51_12.wav
[2013.02.14 16:53:02 | 008,559,440 | ---- | C] () -- C:\Users\JEEZY\one direction what makes you beautiful.wav
[2012.11.25 13:55:11 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2012.11.18 03:01:11 | 003,536,817 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin
[2012.10.12 14:24:53 | 000,944,720 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_10_12_15_24_50.wav
[2012.10.11 19:31:18 | 079,175,120 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_10_11_20_31_10.wav
[2012.08.15 20:48:17 | 038,559,440 | ---- | C] () -- C:\Users\JEEZY\meilenstein nilson.wav
[2012.07.13 21:40:35 | 117,982,160 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_07_13_22_40_33.wav
[2012.07.10 19:26:29 | 000,005,120 | ---- | C] () -- C:\Users\JEEZY\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.01 17:47:15 | 006,754,640 | ---- | C] () -- C:\Users\JEEZY\LORUS.wav
[2012.06.21 22:12:40 | 013,499,600 | ---- | C] () -- C:\Users\JEEZY\snt.wav
[2012.04.24 16:04:48 | 000,716,240 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_04_24_17_4_47.wav
[2012.04.13 17:29:25 | 000,612,560 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_04_13_18_29_23.wav
[2012.04.12 22:16:55 | 001,036,880 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_04_12_23_16_54.wav
[2012.04.09 20:03:07 | 023,005,520 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_04_09_21_3_5.wav
[2012.03.11 16:38:16 | 044,995,280 | ---- | C] () -- C:\Users\JEEZY\singen.wav
[2012.02.20 19:59:46 | 001,772,240 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_02_20_19_59_44.wav
[2012.02.16 21:56:54 | 000,338,432 | ---- | C] () -- C:\Windows\System32\sqlite36_engine.dll
[2012.02.12 19:03:50 | 023,913,680 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_12_02_12_19_3_48.wav
[2011.12.30 04:46:42 | 053,118,764 | ---- | C] () -- C:\Users\JEEZY\ts3_recording_11_12_30_4_46_40.wav
[2011.12.14 19:39:22 | 000,141,032 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.12.14 19:39:22 | 000,138,056 | ---- | C] () -- C:\Users\JEEZY\AppData\Roaming\PnkBstrK.sys
[2011.12.14 19:38:56 | 000,281,200 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.12.14 19:38:55 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.12.10 17:12:41 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011.12.07 18:01:44 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2011.11.06 21:08:31 | 000,265,120 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
[2011.11.06 03:06:54 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011.11.06 03:06:54 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011.11.05 20:54:30 | 000,303,104 | ---- | C] () -- C:\Windows\System32\CmiInstallResAll.dll
[2011.11.05 20:24:04 | 000,008,192 | ---- | C] () -- C:\Windows\System32\drivers\IntelMEFWVer.dll
[2011.11.05 20:21:21 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011.11.05 20:20:17 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011.11.05 20:20:15 | 000,028,578 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011.05.31 07:39:50 | 000,058,368 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2011.05.31 07:38:18 | 000,015,360 | ---- | C] () -- C:\Windows\System32\bdmjpeg.dll
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.08.14 22:12:55 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Alxase
[2011.11.05 20:29:56 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\DAEMON Tools Pro
[2012.08.14 22:13:08 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Doelna
[2013.03.15 13:50:36 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Dropbox
[2012.11.09 22:11:36 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\FileZilla
[2012.07.20 14:18:26 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\fltk.org
[2013.03.14 22:18:50 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\HLSW
[2013.03.13 18:06:08 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Hotspot Shield
[2013.03.14 19:22:46 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\ICQ
[2012.02.20 22:53:20 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\java
[2012.02.18 23:08:21 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\LolClient
[2012.08.14 22:35:32 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Matii
[2012.12.15 23:36:19 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Opera
[2012.08.12 16:53:07 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Publish Providers
[2012.02.09 16:18:16 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Screaming Bee
[2012.08.12 16:53:03 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Sony
[2012.07.27 13:24:08 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\SplitMediaLabs
[2012.02.20 22:26:31 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\TeamViewer
[2012.02.12 11:27:42 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\Teeworlds
[2013.03.13 18:46:08 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\TS3Client
[2011.11.06 02:40:07 | 000,000,000 | ---D | M] -- C:\Users\JEEZY\AppData\Roaming\ts3overlay
========== Purity Check ==========
< End of report > --- --- ---
Bei Combofix bekomme ich folgende Nachricht : Zitat:
NSIS Error
Installer integrity check has failed. Common causes nclude incomplete download and damaged media.
Conttact the installer's authorto obtain a new copy.
More information at:
hxxp://nsis.sf,net/NSIS_Error
| |