Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   "wssetup.exe Perion Network Ltd." bei PC start (https://www.trojaner-board.de/136589-wssetup-exe-perion-network-ltd-pc-start.html)

Ruhrpottler 14.06.2013 15:11

"wssetup.exe Perion Network Ltd." bei PC start
 
Guten Tag!

Mein Problem sieht wie folgt aus: immer wenn ich meinen PC starte, bekomme ich die Meldung "wssetup.exe installieren"

Was mein PC wissen angeht, sieht es eher mager aus. Ich habe auch schon mal auf "Ja" geklickt, weil ich dachte, es gehört zu Windows.

Nun taucht die Meldung aber immer wieder nach einem Start auf, woraus ich mal schließen
möchte, dass es nicht zu Windows gehört.

Der PC ist langsamer geworden und Antivira startet keinen Scan mehr.

Im Zip Ordner sind die Logfiles von OTL und Gmer

markusg 14.06.2013 15:12

Hi,
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Ruhrpottler 14.06.2013 16:56

Ok, die letzten Fenster waren nicht wie in der Anleitung :)

Ich hoffe das ich trotzdem alles richtig gemacht habe.

Danke für die schnelle Antwort, die Logfiles hab ich wieder in den Anhang gepackt.
Bin erst mal ein paar stunden nicht da, trotzdem schon mal vielen dank für die schnelle Bearbeitung!

markusg 14.06.2013 17:53

Passt.
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Ruhrpottler 15.06.2013 12:42

Ganz großer Mist.......Panik/Hilfe

Der Internetexplorer geht nicht mehr, hab mehrmals einen Neustart gemacht, nichts ging.
Hab jetzt Google als Startseite angelegt und konnte so wieder ins Forum gelangen.
Wenn ich eine Seite in der Adressleiste anwählen will, bleibt alles weiß und nichts passiert.

Das ist jetzt alles passiert, nachdem ich Combofix laufen lassen habe.

Der Log von Combofix
Code:

ComboFix 13-06-13.01 - *** 15.06.2013  12:50:54.1.6 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.8188.6574 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\windows\SysWow64\tmp4C89.tmp
c:\windows\SysWow64\tmp4C8A.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-05-15 bis 2013-06-15  ))))))))))))))))))))))))))))))
.
.
2013-06-15 10:54 . 2013-06-15 10:54        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2013-06-15 10:54 . 2013-06-15 10:54        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-06-14 12:03 . 2013-06-14 12:03        --------        d-----w-        c:\programdata\Solidshield
2013-06-14 11:41 . 2013-05-13 06:37        9460464        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{38D67761-B52B-455A-A2CD-E1B295648B0F}\mpengine.dll
2013-06-13 09:25 . 2013-05-08 06:39        1910632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-06-13 09:25 . 2013-04-26 05:51        751104        ----a-w-        c:\windows\system32\win32spl.dll
2013-06-13 09:25 . 2013-04-26 04:55        492544        ----a-w-        c:\windows\SysWow64\win32spl.dll
2013-06-13 09:25 . 2013-05-13 05:51        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-06-13 09:25 . 2013-05-13 05:51        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2013-06-13 09:25 . 2013-05-13 05:51        139776        ----a-w-        c:\windows\system32\cryptnet.dll
2013-06-13 09:25 . 2013-05-13 05:50        52224        ----a-w-        c:\windows\system32\certenc.dll
2013-06-13 09:25 . 2013-05-13 04:45        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2013-06-13 09:25 . 2013-05-13 04:45        1160192        ----a-w-        c:\windows\SysWow64\crypt32.dll
2013-06-13 09:25 . 2013-05-13 04:45        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2013-06-13 09:25 . 2013-05-13 03:43        1192448        ----a-w-        c:\windows\system32\certutil.exe
2013-06-13 09:25 . 2013-05-13 03:08        903168        ----a-w-        c:\windows\SysWow64\certutil.exe
2013-06-13 09:25 . 2013-05-13 03:08        43008        ----a-w-        c:\windows\SysWow64\certenc.dll
2013-06-08 13:30 . 2013-06-13 13:04        75825640        ----a-w-        c:\windows\system32\MRT.exe
2013-06-05 13:31 . 2013-06-05 13:31        --------        d-----w-        c:\users\***\AppData\Local\EA Games
2013-06-05 13:05 . 2013-06-05 13:07        --------        d-----w-        c:\users\***\AppData\Roaming\DAEMON Tools Lite
2013-06-05 13:03 . 2013-06-05 13:07        --------        d-----w-        c:\programdata\DAEMON Tools Lite
2013-06-05 06:26 . 2013-06-14 12:08        --------        d-----w-        c:\windows\SysWow64\WNLT
2013-06-05 06:26 . 2013-06-05 06:26        --------        d-----w-        c:\windows\SysWow64\jmdp
2013-06-05 06:26 . 2013-06-05 06:26        --------        d-----w-        c:\windows\SysWow64\ARFC
2013-06-05 06:26 . 2013-05-21 13:31        1447728        ----a-w-        c:\windows\system32\dmwu.exe
2013-06-05 06:26 . 2013-05-21 13:30        33792        ----a-w-        c:\windows\system32\ImHttpComm.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-13 21:01 . 2012-04-01 19:12        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-13 21:01 . 2012-03-25 09:44        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-27 22:13 . 2012-03-31 00:09        291088        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2013-05-27 22:13 . 2012-03-27 16:03        291088        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2013-05-27 22:13 . 2012-03-27 16:03        280904        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2013-05-02 00:06 . 2010-11-21 03:27        278800        ------w-        c:\windows\system32\MpSigStub.exe
2013-04-12 14:45 . 2013-04-23 17:16        1656680        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-15 17:47        265064        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 17:47        983400        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 17:47        3153920        ----a-w-        c:\windows\system32\win32k.sys
2013-04-04 03:35 . 2013-04-26 10:35        95648        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-23 01:58 . 2013-03-23 01:58        719360        ----a-w-        c:\windows\SysWow64\mshtmlmedia.dll
2013-03-23 01:58 . 2013-03-23 01:58        226304        ----a-w-        c:\windows\system32\elshyph.dll
2013-03-23 01:58 . 2013-03-23 01:58        185344        ----a-w-        c:\windows\SysWow64\elshyph.dll
2013-03-23 01:58 . 2013-03-23 01:58        158720        ----a-w-        c:\windows\SysWow64\msls31.dll
2013-03-23 01:58 . 2013-03-23 01:58        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2013-03-23 01:58 . 2013-03-23 01:58        138752        ----a-w-        c:\windows\SysWow64\wextract.exe
2013-03-23 01:58 . 2013-03-23 01:58        1054720        ----a-w-        c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-23 01:57 . 2013-03-23 01:57        97280        ----a-w-        c:\windows\system32\mshtmled.dll
2013-03-23 01:57 . 2013-03-23 01:57        92160        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2013-03-23 01:57 . 2013-03-23 01:57        905728        ----a-w-        c:\windows\system32\mshtmlmedia.dll
2013-03-23 01:57 . 2013-03-23 01:57        81408        ----a-w-        c:\windows\system32\icardie.dll
2013-03-23 01:57 . 2013-03-23 01:57        77312        ----a-w-        c:\windows\system32\tdc.ocx
2013-03-23 01:57 . 2013-03-23 01:57        762368        ----a-w-        c:\windows\system32\ieapfltr.dll
2013-03-23 01:57 . 2013-03-23 01:57        73728        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2013-03-23 01:57 . 2013-03-23 01:57        62976        ----a-w-        c:\windows\system32\pngfilt.dll
2013-03-23 01:57 . 2013-03-23 01:57        61952        ----a-w-        c:\windows\SysWow64\tdc.ocx
2013-03-23 01:57 . 2013-03-23 01:57        599552        ----a-w-        c:\windows\system32\vbscript.dll
2013-03-23 01:57 . 2013-03-23 01:57        523264        ----a-w-        c:\windows\SysWow64\vbscript.dll
2013-03-23 01:57 . 2013-03-23 01:57        52224        ----a-w-        c:\windows\system32\msfeedsbs.dll
2013-03-23 01:57 . 2013-03-23 01:57        51200        ----a-w-        c:\windows\system32\imgutil.dll
2013-03-23 01:57 . 2013-03-23 01:57        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2013-03-23 01:57 . 2013-03-23 01:57        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2013-03-23 01:57 . 2013-03-23 01:57        452096        ----a-w-        c:\windows\system32\dxtmsft.dll
2013-03-23 01:57 . 2013-03-23 01:57        441856        ----a-w-        c:\windows\system32\html.iec
2013-03-23 01:57 . 2013-03-23 01:57        38400        ----a-w-        c:\windows\SysWow64\imgutil.dll
2013-03-23 01:57 . 2013-03-23 01:57        361984        ----a-w-        c:\windows\SysWow64\html.iec
2013-03-23 01:57 . 2013-03-23 01:57        281600        ----a-w-        c:\windows\system32\dxtrans.dll
2013-03-23 01:57 . 2013-03-23 01:57        27648        ----a-w-        c:\windows\system32\licmgr10.dll
2013-03-23 01:57 . 2013-03-23 01:57        270848        ----a-w-        c:\windows\system32\iedkcs32.dll
2013-03-23 01:57 . 2013-03-23 01:57        247296        ----a-w-        c:\windows\system32\webcheck.dll
2013-03-23 01:57 . 2013-03-23 01:57        235008        ----a-w-        c:\windows\system32\url.dll
2013-03-23 01:57 . 2013-03-23 01:57        23040        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2013-03-23 01:57 . 2013-03-23 01:57        216064        ----a-w-        c:\windows\system32\msls31.dll
2013-03-23 01:57 . 2013-03-23 01:57        197120        ----a-w-        c:\windows\system32\msrating.dll
2013-03-23 01:57 . 2013-03-23 01:57        173568        ----a-w-        c:\windows\system32\ieUnatt.exe
2013-03-23 01:57 . 2013-03-23 01:57        167424        ----a-w-        c:\windows\system32\iexpress.exe
2013-03-23 01:57 . 2013-03-23 01:57        1509376        ----a-w-        c:\windows\system32\inetcpl.cpl
2013-03-23 01:57 . 2013-03-23 01:57        149504        ----a-w-        c:\windows\system32\occache.dll
2013-03-23 01:57 . 2013-03-23 01:57        144896        ----a-w-        c:\windows\system32\wextract.exe
2013-03-23 01:57 . 2013-03-23 01:57        1441280        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2013-03-23 01:57 . 2013-03-23 01:57        1400416        ----a-w-        c:\windows\system32\ieapfltr.dat
2013-03-23 01:57 . 2013-03-23 01:57        13824        ----a-w-        c:\windows\system32\mshta.exe
2013-03-23 01:57 . 2013-03-23 01:57        137216        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2013-03-23 01:57 . 2013-03-23 01:57        136192        ----a-w-        c:\windows\system32\iepeers.dll
2013-03-23 01:57 . 2013-03-23 01:57        135680        ----a-w-        c:\windows\system32\IEAdvpack.dll
2013-03-23 01:57 . 2013-03-23 01:57        12800        ----a-w-        c:\windows\SysWow64\mshta.exe
2013-03-23 01:57 . 2013-03-23 01:57        12800        ----a-w-        c:\windows\system32\msfeedssync.exe
2013-03-23 01:57 . 2013-03-23 01:57        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2013-03-23 01:57 . 2013-03-23 01:57        102912        ----a-w-        c:\windows\system32\inseng.dll
2013-03-23 01:56 . 2013-03-23 01:56        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        9728        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        648192        ----a-w-        c:\windows\system32\d3d10level9.dll
2013-03-23 01:56 . 2013-03-23 01:56        604160        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2013-03-23 01:56 . 2013-03-23 01:56        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        522752        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2013-03-23 01:56 . 2013-03-23 01:56        465920        ----a-w-        c:\windows\system32\WMPhoto.dll
2013-03-23 01:56 . 2013-03-23 01:56        417792        ----a-w-        c:\windows\SysWow64\WMPhoto.dll
2013-03-23 01:56 . 2013-03-23 01:56        4096        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        4096        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3928064        ----a-w-        c:\windows\system32\d2d1.dll
2013-03-23 01:56 . 2013-03-23 01:56        364544        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2013-03-23 01:56 . 2013-03-23 01:56        363008        ----a-w-        c:\windows\system32\dxgi.dll
2013-03-23 01:56 . 2013-03-23 01:56        3584        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3584        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3419136        ----a-w-        c:\windows\SysWow64\d2d1.dll
2013-03-23 01:56 . 2013-03-23 01:56        333312        ----a-w-        c:\windows\system32\d3d10_1core.dll
2013-03-23 01:56 . 2013-03-23 01:56        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        296960        ----a-w-        c:\windows\system32\d3d10core.dll
2013-03-23 01:56 . 2013-03-23 01:56        293376        ----a-w-        c:\windows\SysWow64\dxgi.dll
2013-03-23 01:56 . 2013-03-23 01:56        2776576        ----a-w-        c:\windows\system32\msmpeg2vdec.dll
2013-03-23 01:56 . 2013-03-23 01:56        2565120        ----a-w-        c:\windows\system32\d3d10warp.dll
2013-03-23 01:56 . 2013-03-23 01:56        2560        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        2560        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-03-23 01:56 . 2013-03-23 01:56        249856        ----a-w-        c:\windows\SysWow64\d3d10_1core.dll
2013-03-23 01:56 . 2013-03-23 01:56        245248        ----a-w-        c:\windows\system32\WindowsCodecsExt.dll
2013-03-23 01:56 . 2013-03-23 01:56        2284544        ----a-w-        c:\windows\SysWow64\msmpeg2vdec.dll
2013-03-23 01:56 . 2013-03-23 01:56        221184        ----a-w-        c:\windows\system32\UIAnimation.dll
2013-03-23 01:56 . 2013-03-23 01:56        220160        ----a-w-        c:\windows\SysWow64\d3d10core.dll
2013-03-23 01:56 . 2013-03-23 01:56        207872        ----a-w-        c:\windows\SysWow64\WindowsCodecsExt.dll
2013-03-23 01:56 . 2013-03-23 01:56        1988096        ----a-w-        c:\windows\SysWow64\d3d10warp.dll
2013-03-23 01:56 . 2013-03-23 01:56        194560        ----a-w-        c:\windows\system32\d3d10_1.dll
2013-03-23 01:56 . 2013-03-23 01:56        1887232        ----a-w-        c:\windows\system32\d3d11.dll
2013-03-23 01:56 . 2013-03-23 01:56        187392        ----a-w-        c:\windows\SysWow64\UIAnimation.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-07-04 14:03        1310040        ----a-r-        c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GAINWARD"="c:\program files (x86)\EXPERTool\TBPanel.exe" [2011-08-02 2273608]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2012-03-25 4942336]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195]
"VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-07-28 348664]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2012-10-04 115032]
"Sweetpacks Communicator"="c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-08-15 231768]
"WinampAgent"="d:\programme\Winamp\winampa.exe" [2012-06-28 74752]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;d:\programme\Skype\Updater\Updater.exe;d:\programme\Skype\Updater\Updater.exe [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [x]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynUSB64.sys;c:\windows\SYSNATIVE\drivers\SynUSB64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe;c:\windows\SYSNATIVE\dmwu.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 21:01]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-05 11474024]
"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.facebook.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to MP3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-ASRockXTU - (no file)
Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-06-15  12:55:36
ComboFix-quarantined-files.txt  2013-06-15 10:55
.
Vor Suchlauf: 7 Verzeichnis(se), 10.434.842.624 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 11.092.008.960 Bytes frei
.
- - End Of File - - 327A23DE3BE577F0352B4EE41E4A77C4
A36C5E4F47E84449FF07ED3517B43A31



Anderes Thema
Warum sind im OTL und den anderen logs, ordner/spiele/Explorer drin, die ich garnicht auf dem rechner habe?
Firefox z.B., habe ich nie gehabt, den Ordner GAME gibt's auch nicht mehr
Das war jetzt nur so am rande :/

ACHTUNG, EDITIERE VIA HANDY
Nachdem ich die Antwort verfasst hatte,und ANTWORTEN geklickt hab, hat der Internetexprer nicht mehr reagiert. Wie ich aber über Handy sehe, hat er trotzdem gepostet

markusg 15.06.2013 13:10

keine Aufregung, ist doch wochenendeund das Problem bekommen wir gelöst.
Zurücksetzen der Internet Explorer 7-Einstellungen
Internet explorer auf standard, dann gehts.
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

Ruhrpottler 15.06.2013 14:44

Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.06.15.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16618
Mark :: ***-PC [Administrator]

15.06.2013 14:59:34
mbam-log-2013-06-15 (14-59-34).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 325994
Laufzeit: 31 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


markusg 15.06.2013 15:08

Hi,

lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

Ruhrpottler 15.06.2013 15:28

Ich hoffe das ich alles richtig habe, weil ich auch nicht immer weiß ob es Treiber sind oder nicht :D

Code:

Acrobat.com        Adobe Systems Incorporated        25.03.2012                1.1.377 notwendig

Adobe AIR        Adobe Systems Inc.        25.03.2012                1.0.4990 notwendig

Adobe Flash Player 11 ActiveX        Adobe Systems Incorporated        13.06.2013        6,00MB        11.7.700.224 notwendig

Adobe Reader 9        Adobe Systems Incorporated        25.03.2012        202MB        9.0.0 notwendig

Apple Application Support        Apple Inc.        04.01.2013        65,0MB        2.3.2 unnötig

Apple Mobile Device Support        Apple Inc.        04.01.2013        25,1MB        6.0.1.3 unnötig

Apple Software Update        Apple Inc.        27.03.2012        2,38MB        2.1.3.127 unnötig

ASRock App Charger v1.0.4        ASRock Inc.        25.03.2012        1,34MB notwendig       

ASRock eXtreme Tuner v0.1.66                25.03.2012        15,3MB notwendig       

ASRock InstantBoot v1.26                25.03.2012 notwendig               

Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver        Atheros Communications Inc.        25.03.2012                1.0.0.35 notwendig

ATI Catalyst Install Manager        ATI Technologies, Inc.        25.03.2012        22,1MB        3.0.765.0 notwendig

Avira Free Antivirus        Avira        15.11.2012        109MB        12.1.9.1236 notwendig

Battlefield 3™        Electronic Arts        06.09.2012                1.4.0.0 notwendig

Battlelog Web Plugins        EA Digital Illusions CE AB        27.05.2013                2.1.4 notwendig

Bonjour        Apple Inc.        27.03.2012        2,00MB        3.0.0.10 unnötig

CCleaner        Piriform        24.05.2013                4.02

ESN Sonar        ESN Social Software AB        27.05.2013                0.70.4 notwendig

Etron USB3.0 Host Controller        Etron Technology        25.03.2012        5,12MB        0.96 notwendig

EXPERTool 7.21        Gainward Co., Ltd        25.03.2012        11,2MB notwendig

Futuremark SystemInfo        Futuremark Corporation        04.10.2012                3.54.1.1 unbekannt

Guild Wars 2        NCsoft Corporation, Ltd.        07.10.2012 notwendig               

IB Updater Service                05.06.2013                3.0.5.4 unbekannt

Internet Explorer Toolbar 4.6 by SweetPacks        SweetIM Technologies Ltd.        08.11.2012        4,27MB        4.6.0004 unnötig?

Java 7 Update 21        Oracle        05.03.2013        129MB        7.0.210 notwendig

Malwarebytes Anti-Malware Version 1.75.0.1300        Malwarebytes Corporation        15.06.2013        19,2MB        1.75.0.1300 unnötig

Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        04.10.2012        38,8MB        4.0.30319 (Denk mal die Microsoft und Nvidia sachen brauch ich ?)

Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        08.11.2012        348KB        8.0.59193

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148        Microsoft Corporation        25.03.2012        788KB        9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        27.03.2012        240KB        9.0.30729

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148        Microsoft Corporation        25.03.2012        596KB        9.0.30729.4148

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219        Microsoft Corporation        27.03.2012        13,8MB        10.0.40219

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219        Microsoft Corporation        25.03.2012        11,1MB        10.0.40219

NVIDIA 3D Vision Controller-Treiber 296.10        NVIDIA Corporation        31.03.2012                296.10

NVIDIA 3D Vision Treiber 311.06        NVIDIA Corporation        16.04.2013                311.06

NVIDIA Grafiktreiber 311.06        NVIDIA Corporation        16.04.2013                311.06

NVIDIA HD-Audiotreiber 1.3.12.0        NVIDIA Corporation        31.03.2012                1.3.12.0

NVIDIA PhysX-Systemsoftware 9.12.0213        NVIDIA Corporation        31.03.2012                9.12.0213

NVIDIA Update 1.11.3        NVIDIA Corporation        16.04.2013                1.11.3

Origin        Electronic Arts, Inc.        27.03.2012                8.5.0.4554 notwendig

PunkBuster Services        Even Balance, Inc.        27.03.2012                0.991 notwendig

Realtek High Definition Audio Driver        Realtek Semiconductor Corp.        25.03.2012                6.0.1.6215 notwendig

Skype™ 6.3        Skype Technologies S.A.        29.03.2013        21,0MB        6.3.105 unnötig

Sound Blaster X-Fi MB        Creative Technology Limited        25.03.2012                1.0 unnötig

Steinberg Cubase LE 4        Steinberg Media Technologies GmbH        19.11.2012        87,1MB        4.1.2.851 unnötig

Steinberg HALionOne        Steinberg Media Technologies GmbH        19.11.2012        117MB        1.1.0.457 unnötig

Steinberg HALionOne Essential Set        Steinberg Media Technologies GmbH        19.11.2012        101MB        1.0.1.457 unnötig

SweetIM for Messenger 3.7        SweetIM Technologies Ltd.        08.11.2012        5,12MB        3.7.0007 unbekannt

SweetPacks bundle uninstaller        SweetIM Technologies Ltd.        08.11.2012        2,46MB        1.0.0000 unbekannt

Syncrosoft Lizenz Kontrolle        SIA Syncrosoft        19.11.2012 unbekannt               

Update Manager for SweetPacks 1.1        SweetIM Technologies Ltd.        08.11.2012        2,76MB        1.1.0008 unbekannt

Winamp        Nullsoft, Inc        26.01.2013                5.63 nötig

Winamp Erkennungs-Plug-in        Nullsoft, Inc        26.01.2013        63,0KB        1.0.0.1 unnötig

WinRAR 4.20 (64-Bit)        win.rar GmbH        08.11.2012                4.20.0 notwendig

XFastUsb                25.03.2012 unnötig


markusg 15.06.2013 15:31

deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen
bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok

deinstaliere:
Futuremark
IB Updater
Internet Explorer Toolbar
Steinberg : alle
SweetIM
SweetPacks
Update Manager
XFastUsb
Öffne CCleaner, analysieren, starten, PC neustarten
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Ruhrpottler 16.06.2013 18:18

Code:

# AdwCleaner v2.303 - Datei am 16/06/2013 um 19:04:30 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : *** - ***-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\***\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Program Files (x86)\SweetIM
Ordner Gelöscht : C:\ProgramData\DeviceVM
Ordner Gelöscht : C:\Users\***\AppData\Roaming\DeviceVM

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16611

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [2149 octets] - [16/06/2013 19:04:30]

########## EOF - C:\AdwCleaner[S1].txt - [2209 octets] ##########


markusg 16.06.2013 18:20

Hi,
neustarten bitte
HitmanPro - Download - Filepony
lade Hitmanpro, doppelklicken, Scan klicken.
Nichts löschen, auf weiter klicken.
Log speichern und posten, bzw als XML exportieren, packen und anhängenb

Ruhrpottler 16.06.2013 18:23

Doofe frage :) was ist XML? :D

markusg 16.06.2013 18:30

speichere einfach das Log am ende, die schaltflächen solltest du dann sehen

Ruhrpottler 16.06.2013 19:07

So, hat ein bisschen gedauert, musste viel umschreiben :)

Code:

HitmanPro 3.7.6.201
www.hitmanpro.com

  Computer name . . . . : ***-PC
  Windows . . . . . . . : 6.1.1.7601.X64/6
  User name . . . . . . : ***-PC\***
  UAC . . . . . . . . . : Enabled
  License . . . . . . . : Free

  Scan date . . . . . . : 2013-06-16 19:34:38
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 4m 0s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 69

  Objects scanned . . . : 1.042.119
  Files scanned . . . . : 12.092
  Remnants scanned  . . : 217.796 files / 812.231 keys

Suspicious files ____________________________________________________________

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\dll\wc002288.dll
      Size . . . . . . . : 948.118 bytes
      Age  . . . . . . . : 442.7 days (2012-03-31 02:22:17)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 3192353354FE593051B33886088D4C312ACB9A653D874281B2EBF131B80415CB
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\dll\wc002291.dll
      Size . . . . . . . : 965.329 bytes
      Age  . . . . . . . : 437.9 days (2012-04-04 21:05:37)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : CAE3128772295AC4F1179B881A00B061DB00505275CB258F9F0C84CC1DF9B2A5
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\dll\wc002292.dll
      Size . . . . . . . : 956.681 bytes
      Age  . . . . . . . : 436.2 days (2012-04-06 14:55:35)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 7218A15A9890CE82EB25F7AB5AC7AA60B4E3055C5574B70A6CABA4274D6DE493
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\dll\wc002317.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 266.3 days (2012-09-23 12:03:34)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\dll\wc002325.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 115.8 days (2013-02-21 00:44:31)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 19.8 days (2013-05-28 00:13:54)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 23.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Time indicates that the file appeared recently on this computer.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
          0.0s C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbcl.dll

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 442.7 days (2012-03-31 02:09:36)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\***\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 137.992 bytes
      Age  . . . . . . . : 442.7 days (2012-03-31 02:10:06)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 21A3D2E3A063EA2F986EF1BAFD1A71F7FC9EDB3F69E0265E51A18DBC111084F1
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.


markusg 16.06.2013 19:08

sieht gut aus, neues otl log bitte

Ruhrpottler 16.06.2013 19:49

Ich weiß das ich das schon gefragt habe, bis jetzt kam nur keine Antwort.

Warum tauchen in den Logs Dateien/Ordner auf, die schon deinstalliert sind und oder auch nicht mehr vorhanden?

OTL

Code:

OTL logfile created on: 16.06.2013 20:23:10 - Run 4
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\***\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
8,00 Gb Total Physical Memory | 6,47 Gb Available Physical Memory | 80,97% Memory free
15,99 Gb Paging File | 14,40 Gb Available in Paging File | 90,06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,56 Gb Total Space | 11,49 Gb Free Space | 11,78% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 339,73 Gb Free Space | 92,29% Space Free | Partition Type: NTFS
 
Computer Name: ***-PC | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\***\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 (Macrovision Europe Ltd.)
PRC - C:\Users\***\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
PRC - C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Gainward Co.)
PRC - C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\***\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0001\~de6248.tmp ()
MOD - C:\Users\***\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0001\~df394b.tmp ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Program Files (x86)\EXPERTool\TBManage.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- D:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Sound Blaster X-Fi MB Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTAudSvcService) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (EtronXHCI) -- C:\Windows\SysNative\drivers\EtronXHCI.sys (Etron Technology Inc)
DRV:64bit: - (EtronHub3) -- C:\Windows\SysNative\drivers\EtronHub3.sys (Etron Technology Inc)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (AsrAppCharger) -- C:\Windows\SysNative\drivers\AsrAppCharger.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (SynasUSB) -- C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8E 43 79 E3 C6 69 CE 01  [binary data]
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.138.0: C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.4: C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2013.06.15 12:54:25 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] D:\Programme\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000..\Run: [GAINWARD] C:\Program Files (x86)\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82513DB8-D35E-48CA-89A6-E85970EB843F}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.06.16 19:31:54 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.06.16 19:28:17 | 009,833,328 | ---- | C] (SurfRight B.V.) -- C:\Users\***\Desktop\HitmanPro_x64.exe
[2013.06.15 16:43:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2013.06.15 16:40:19 | 000,692,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.06.15 16:40:19 | 000,071,048 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.06.15 16:37:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.06.15 16:12:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.06.15 16:12:10 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.06.15 14:56:30 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2013.06.15 14:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.06.15 14:56:15 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.06.15 14:56:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.06.15 14:56:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.06.15 14:55:52 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Programs
[2013.06.15 13:08:25 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.06.15 13:08:25 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.06.15 12:57:28 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.06.15 12:55:37 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.06.15 12:49:53 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.06.15 12:49:53 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.06.15 12:49:53 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.06.15 12:49:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.06.15 12:49:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.06.15 12:43:07 | 005,080,197 | R--- | C] (Swearware) -- C:\Users\***\Desktop\ComboFix.exe
[2013.06.15 12:40:23 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Logfiles
[2013.06.14 16:54:30 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\***\Desktop\tdsskiller.exe
[2013.06.14 14:15:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2013.06.14 14:03:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Solidshield
[2013.06.13 15:03:52 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.06.13 15:03:52 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.06.13 15:03:52 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.06.13 15:03:52 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.06.13 15:03:52 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.06.13 15:03:52 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.06.13 15:03:52 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.06.13 15:03:52 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.06.13 15:03:52 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.06.13 15:03:51 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.06.13 15:03:50 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.06.13 15:03:50 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.06.13 15:03:50 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.06.13 11:25:49 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2013.06.13 11:25:49 | 000,492,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2013.06.13 11:25:45 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013.06.13 11:25:45 | 001,192,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe
[2013.06.13 11:25:45 | 000,903,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2013.06.13 11:25:45 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2013.06.13 11:25:45 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certenc.dll
[2013.06.13 11:25:45 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certenc.dll
[2013.06.05 15:34:40 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\EA Games
[2013.06.05 15:31:53 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\EA Games
[2013.06.05 15:05:55 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\DAEMON Tools Lite
[2013.06.05 15:03:37 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
 
========== Files - Modified Within 30 Days ==========
 
[2013.06.16 20:22:30 | 000,021,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.16 20:22:29 | 000,021,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.16 19:29:57 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.06.16 19:29:57 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.06.16 19:29:57 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.06.16 19:29:57 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.06.16 19:29:57 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.06.16 19:28:52 | 009,833,328 | ---- | M] (SurfRight B.V.) -- C:\Users\Mark\Desktop\HitmanPro_x64.exe
[2013.06.16 19:25:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.16 19:25:30 | 2144,047,103 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.16 19:01:58 | 000,648,201 | ---- | M] () -- C:\Users\***\Desktop\adwcleaner.exe
[2013.06.15 16:40:19 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.06.15 16:40:19 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.06.15 14:56:16 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.06.15 12:54:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.06.15 12:43:19 | 005,080,197 | R--- | M] (Swearware) -- C:\Users\***\Desktop\ComboFix.exe
[2013.06.14 16:54:30 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\***\Desktop\tdsskiller.exe
[2013.06.14 14:24:38 | 000,377,856 | ---- | M] () -- C:\Users\***\Desktop\gmer_2.1.19163.exe
[2013.06.14 14:15:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2013.06.08 16:06:58 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.06.08 13:40:02 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.05.28 23:38:16 | 001,836,893 | ---- | M] () -- C:\Users\***\Documents\Unbenannt.wma
[2013.05.28 00:13:58 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.05.28 00:13:58 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.05.28 00:13:49 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
 
========== Files Created - No Company Name ==========
 
[2013.06.16 19:01:58 | 000,648,201 | ---- | C] () -- C:\Users\***\Desktop\adwcleaner.exe
[2013.06.15 16:43:57 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013.06.15 14:56:16 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.06.15 12:49:53 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.06.15 12:49:53 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.06.15 12:49:53 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.06.15 12:49:53 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.06.15 12:49:53 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.06.14 14:24:37 | 000,377,856 | ---- | C] () -- C:\Users\***\Desktop\gmer_2.1.19163.exe
[2013.05.28 23:38:16 | 001,836,893 | ---- | C] () -- C:\Users\***\Documents\Unbenannt.wma
[2012.11.19 21:02:26 | 000,002,892 | ---- | C] () -- C:\Windows\SysWow64\audcon.sys
[2012.03.27 18:03:49 | 000,291,088 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.03.27 18:03:47 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.03.25 10:38:46 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini
[2012.03.25 10:38:46 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini
[2012.03.25 10:38:46 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini
[2012.03.25 10:38:35 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012.03.25 10:38:35 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011.08.11 04:06:32 | 000,007,764 | ---- | C] () -- C:\Windows\cadx2.ini
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.06.16 18:59:13 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DAEMON Tools Lite
[2013.04.26 23:35:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoft
[2012.11.20 20:00:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Guitar Pro 6
[2012.12.02 19:24:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Origin
[2012.11.19 21:08:18 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Steinberg
 
========== Purity Check ==========
 
 

< End of report >

Extras

Code:

OTL Extras logfile created on: 16.06.2013 20:23:10 - Run 4
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\***\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
8,00 Gb Total Physical Memory | 6,47 Gb Available Physical Memory | 80,97% Memory free
15,99 Gb Paging File | 14,40 Gb Available in Paging File | 90,06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,56 Gb Total Space | 11,49 Gb Free Space | 11,78% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 339,73 Gb Free Space | 92,29% Space Free | Partition Type: NTFS
 
Computer Name: ***-PC | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0818AA4A-1078-49FD-9C90-1E97C63F479B}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{139D34DB-32F5-41DD-A45F-62CD7DDABAF3}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{1B4B0D40-96A3-493D-A955-B9EA1A30FE94}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{21FC8DDA-F9EC-44A6-962D-BB3A3D098B92}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{2DF29D61-4B52-4D17-9CA5-F7BFC07113E5}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{389D3A54-0510-4E69-8F08-DCFF73C8E4FC}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{47809E4F-6A2D-42F1-B67F-5692BC401FFA}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{4B73286F-3FAE-417F-AEBF-75ED8DA92C31}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{4D34E443-9990-41B5-9CBA-BE52DAABE118}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{4DF280CD-7664-468C-873E-89E6C0568C27}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{66BFEEAF-2C6A-49FD-9220-89317C167669}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{6E74333F-0166-4307-A785-414FADBFAFB7}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{75A84244-64F3-4EEB-AA1D-E5AEBBFA84C7}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{84EB64C5-0D2D-4037-B8BB-165E38978761}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{869B98C4-AA00-48B7-B216-BF8B8D622ABF}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{8AF93733-AE49-46D3-B2AB-544BBDA5C640}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{8EC53E71-5933-4E37-9746-7BC317313260}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{951D1BE3-4025-458C-B898-BF82AC079BD7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A3F3A18E-5C6D-4A57-9D33-929E228F00D6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{B3371A51-7260-4786-AEE1-33982A6679F6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B6440EED-21E6-4FA6-BB24-0151985859FA}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{CC33DD91-BD29-48B9-B135-669324B48670}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{D357B732-F40B-46C0-A2AF-E8C8FCC23B4E}" = dir=in | app=d:\programme\skype\phone\skype.exe |
"{E29E3FDC-8979-465E-8AFD-1F29330CB40C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{E8B1E4F0-807D-464A-BA4C-4DEC03AA1079}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F093976C-3164-44C6-B806-BAD4EDFAC83A}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{0296F045-C4C3-4AD1-9B70-67CA8B4FD022}D:\game\dead space 2\deadspace2.exe" = protocol=6 | dir=in | app=d:\game\dead space 2\deadspace2.exe |
"TCP Query User{A01F022E-DA0D-45D2-975E-0F08789E50E0}D:\programme\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\programme\winamp\winamp.exe |
"TCP Query User{A5605680-2C17-4D55-9D82-F625DBEE24D4}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{AD45102C-3865-484C-B69C-4A9BD22A8663}C:\users\***\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\***\appdata\local\temp\gw2.exe |
"TCP Query User{EDEE84E8-C42C-4405-A28B-16A6D1C4B727}D:\games\guild wars 2\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=d:\games\guild wars 2\guild wars 2\gw2.exe |
"UDP Query User{31FCC407-B76B-4DF7-87B2-259E9F02BF4F}C:\users\***\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\***\appdata\local\temp\gw2.exe |
"UDP Query User{646533DD-34A5-46EF-8076-82238B5CF1B2}D:\game\dead space 2\deadspace2.exe" = protocol=17 | dir=in | app=d:\game\dead space 2\deadspace2.exe |
"UDP Query User{990CCB4F-5EFB-421E-9245-C91A50AC8CB6}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{BCFBB51C-BDDE-450B-96DA-BC67EFAF1998}D:\programme\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\programme\winamp\winamp.exe |
"UDP Query User{E83D8CFA-D4BC-4266-9F32-CEE98F33B9F3}D:\games\guild wars 2\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=d:\games\guild wars 2\guild wars 2\gw2.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0C798FBB-2BA6-D113-C055-936965550F33}" = ATI Catalyst Install Manager
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 296.10
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.12.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ASRock App Charger_is1" = ASRock App Charger v1.0.4
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Deutsch
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}" = Sound Blaster X-Fi MB
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.66
"ASRock InstantBoot_is1" = ASRock InstantBoot v1.26
"Avira AntiVir Desktop" = Avira Free Antivirus
"Battlelog Web Plugins" = Battlelog Web Plugins
"ESN Sonar-0.70.4" = ESN Sonar
"Guild Wars 2" = Guild Wars 2
"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"MySSID_is1" = EXPERTool 7.21
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"Syncrosoft License Control" = Syncrosoft Lizenz Kontrolle
"Winamp" = Winamp
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1415581796-2093041854-3868926804-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 15.06.2013 07:29:10 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 15.06.2013 08:38:24 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 15.06.2013 08:50:59 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 15.06.2013 09:40:47 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 09:47:43 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 12:44:46 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 12:55:09 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 13:02:04 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 13:09:28 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 16.06.2013 13:27:22 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 19.10.2012 11:11:25 | Computer Name = ***-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597
 (Definition 1.139.124.0)
 
Error - 02.11.2012 12:21:20 | Computer Name = ***-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?01.?11.?2012 um 20:56:34 unerwartet heruntergefahren.
 
Error - 05.11.2012 11:38:54 | Computer Name = ***-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?05.?11.?2012 um 16:37:21 unerwartet heruntergefahren.
 
Error - 08.11.2012 16:47:31 | Computer Name = ***-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?08.?11.?2012 um 21:46:04 unerwartet heruntergefahren.
 
Error - 08.11.2012 16:55:00 | Computer Name = ***-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?08.?11.?2012 um 21:53:14 unerwartet heruntergefahren.
 
Error - 11.11.2012 14:03:30 | Computer Name = ***-PC | Source = Microsoft-Windows-Bits-Client | ID = 16392
Description = Fehler beim Starten des BITS-Dienstes. Fehler: 2147942450.
 
Error - 11.11.2012 14:03:30 | Computer Name = ***-PC | Source = Service Control Manager | ID = 7024
Description = Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit
 folgendem dienstspezifischem Fehler beendet: %%-2147024846.
 
Error - 15.11.2012 18:05:47 | Computer Name = ***-PC | Source = DCOM | ID = 10005
Description =
 
Error - 15.11.2012 18:05:47 | Computer Name = ***-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%50    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 15.11.2012 18:05:47 | Computer Name = ***-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%1069
 
 
< End of report >


markusg 17.06.2013 14:10

Hi,
weil einige deinstalationsroutinen nicht gründlich sind und dann dateien und ordner über lassen


otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
O3 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1415581796-2093041854-3868926804-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread


bitte teste, ob es im Firefox, internet explorer, und sonstigen
evtl. instalierte Browser, irgendwelche ungewollten toolbars, umleitungen oder sonstigen Probleme gibt.
Teste wie pc und programme allgemein laufen.

Ruhrpottler 18.06.2013 10:36

Code:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1415581796-2093041854-3868926804-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-1415581796-2093041854-3868926804-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: ***
->Temp folder emptied: 34967151 bytes
->Temporary Internet Files folder emptied: 36669340 bytes
->Java cache emptied: 479588 bytes
->Flash cache emptied: 602 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5900 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36989081 bytes
RecycleBin emptied: 101884 bytes
 
Total Files Cleaned = 104,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 06182013_112528

Files\Folders moved on Reboot...
C:\Users\***\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


Internetexplorer läuft gut, Videos in HD kann ich schnell vor und zurück spulen. Andere Seiten, bis auf Facebook, gehen schnell auf.
Diverse Programme starten auch wieder schneller. Bei 1-2 geht die CPU Auslastung bis 34%, weiß nicht ob das so normal ist bei einem 6kern.

markusg 18.06.2013 11:40

Hi
geht ja warscheinlich nur für 1 kern auf 36 %.
öffne mal OTL, bereinigen, PC startet neu, Remover werden gelöscht.
Lösche übrig gebliebene Logs, Setups, von uns verwendete Programme.
PC absichern:
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
Computeractive Software Store - Emsisoft Anti-Malware 7 [1-PC] - 63% off RRP
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren.
vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html

sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
http://support.google.com/chrome/bin...&answer=118663
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager
anleitung:
RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten

Ruhrpottler 18.06.2013 12:48

Was spricht denn gegen Antivir? Im Moment ist nichts mit kostenpflichtiger antivieren Software für mich.
Avast sagt schon bei der Installation, das sie Daten von mir speichern.
Mit sowas hab ich schon ein problem!
Was sagst du dazu, was wollen die damit? Hast du noch andere kostenlose im angebot?
Schwerpunkt bei mir ist surfen und zocken, aber selten browserspiele.

markusg 18.06.2013 14:39

wo werden daten gespeichert?
ich kenn nur dieses credit modul, zw diese monatlichen virenstatistiken.
Kredit muss man nicht nutzen und diese Satistiken sind anonymisierte Daten.
Avira nutzt die Ask toolbar und ohne die kannst du avira nicht komplett nutzen, würd daher schon bei Avast bleiben

Ruhrpottler 18.06.2013 15:13

Könntest du bitte mit mir die Einstellung für avast durchgehen?

PS: Ich würde gerne Internet Explorer weiter nutzten, ändere doch bitte dem entsprechend die Anleitung für Windows 7!

markusg 18.06.2013 15:34

avast standard konfig ist ok
auch mal hier gucken:
http://www.trojaner-board.de/127580-...igurieren.html
Schon mal chrome angesehen, ist auf jeden fall mal wesendlich schneller als der ie, und bietet einige Sicherheitsfeatures, die der ie nicht hatt

Ruhrpottler 18.06.2013 16:11

-Nach Google Drive werde ich nicht gefragt (mir egal)
-registrieren tut er sich selber, werde nach nichts gefragt (wie auch immer)
-zwischen Basis- und Vollschutz kann ich nicht wählen (mach automatisch free)^^
-Internet Security tauchte erst im IE auf (hab natürlich ja gesagt) von kosten stand da nichts

Hab ich jetzt kosten am hals?


Seit ich das drauf habe ist wieder alles total langsam. Ich verzweifle :'(

PS: Nein ich habe bis jetzt nur Firefox und IE gehabt. Von Firefox kam ich nicht klar.

markusg 18.06.2013 17:12

du hast aber schon avast free geladen?
das kostet nichts, wenn du die internet security hast, dann deinstalieren und durch avast free ersetzen

Ruhrpottler 18.06.2013 19:56

Hab das neu installiert. Bei mir war es trotzdem anders (hab mal Screens gemacht und in den Anhang gepackt)

Soll ich mir jetzt Chrome laden oder schreibst du die schritte für IE auf?
Wenn du keine lust dazu hast, muss ich mich dir halt beugen :crazy:

markusg 18.06.2013 20:01

Hi,
schau ihn dir doch erst mal an, meckern kann man doch hinterher immernoch :-) vllt gefällt er dir ja
paar erweiterungen bzw einstellungsmöglichkeiten
adblock für chrome:
http://filepony.de/download-adblock_chrome/
damit sollte das leben werbefreier von statten gehen.
ghostery um tracking zu verhindern:
http://filepony.de/download-ghostery_chrome/
HTTPS Everywhere
https://chrome.google.com/webstore/d...jekcdonpmejbdp
wählt, wenn möglich, eine sichere Verbindung
sicher surfen mit chrome:
Sicher surfen mit Google Chrome | Verbraucher sicher online

Ruhrpottler 18.06.2013 20:07

Ich guck mir das morgen mal an. Heute habe ich da keinen nerv mehr zu ^^

markusg 18.06.2013 20:51

immer mit der Ruhe.
bin ab donneerstag für ne gute Woche im Urlaub

Ruhrpottler 27.06.2013 18:20

Weiß nicht ob du noch im Urlaub bist ^^

Lage sieht so aus, das ich alle schritte durchgeführt habe. Chrom hab ich wieder
deinstalliert! Ich gebe zu das er schnell war, aber ich kam mit dem Aufbau einfach nicht klar.

Jetzt hab ich die Einstellungen vom IE vom Admin Konto übernommen, aber er löscht immer alles
und sagt mir das der Explorer nicht sicher ist.
Der verlauf selber ist leer wenn ich drauf gehe, beim öffnen eines neuen Tabs werden mir aber besuchte Seiten angezeigt.
Eingegebene Adressen werden in der Adressleiste gespeichert.


Blick da nicht mehr durch :heulen:

Was mich auch verwirrt ist, das Sachen wie Winamp oder Mediaplayer, wieder neu eingerichtet werden müssen, obwohl sie ja installiert sind und angezeigt werden.

markusg 04.07.2013 14:22

wer ist "er" wer sagt das der ie unsicher ist?


Alle Zeitangaben in WEZ +1. Es ist jetzt 23:24 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131