Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Achtung! Windows wurde aus Sicherheitsgründen blockiert.

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 31.01.2012, 10:06   #1
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Hallo Liebe Forum gemeinde,
meine Desktop wuerde gestern mit dem "Achtung! Windows wurde aus Sicherheitsgründen blockiert " Trojaner infiziert. Zum glueck hatte ich zwei login Konto mit Admin rechte. Ich koennte ganz normal mit meine andere konto anloggen. Ich habe mit Malwarebytes gescannt und es hat eine Trojaner gefunden und habe ich "loschen" taste gedruckt. Denn habe ich wieder in den infizierte Benutzer konto eingelogged. Der Trojaner war immer noch da.
Und habe ich einfach den Benutzer konto geloescht und eine neues Konto hingelegt.
Jetzt habe ich wieder 2 kontos ( eine fuer mich und eine fuer mine Frau) und beides funktionern ganz normal. Ich habe angst dass meine PC immer noch infiziert ist. Ich will sicher gehen dass ich kann wieder ganz normal ohne Trojaner/Virus meine Email, Online Banking usw. benutzen kann.

Momentan habe ich Malwarebytes und Bitdefender Internet Security 2012 auf meine PC installiert.

Ich bitte um hilfe... Was soll ich machen? Ich habe mit beide Antivurs program Voll Scan gemacht und wueder nix gefunden.

Vielen Dank im Voraus
Kancha

ps. Deutsch ist nicht meine Mutter sprache, daher ich bitte um Verstaendnis.

Alt 31.01.2012, 15:13   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Ohne die Logs von Malwarebytes und Co wird das hier nichts.
Alles von Malwarebytes (und evtl. anderen Scannern) muss hier gepostet werden.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:
ATTFilter
 hier steht das Log
         
__________________

__________________

Alt 31.01.2012, 16:40   #3
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Malwarebytes Log.

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.30.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
simon :: ADMIN-PC [administrator]

Protection: Enabled

30.01.2012 17:00:03
mbam-log-2012-01-30 (17-00-03).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 591733
Time elapsed: 2 hour(s), 26 minute(s), 

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
         
__________________

Alt 31.01.2012, 16:51   #4
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



OLTs hier:

OLT.txt

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 31.01.2012 16:48:31 - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\simon\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,98 Gb Total Physical Memory | 3,60 Gb Available Physical Memory | 60,20% Memory free
11,96 Gb Paging File | 8,44 Gb Available in Paging File | 70,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449,79 Gb Total Space | 346,15 Gb Free Space | 76,96% Space Free | Partition Type: NTFS
Drive D: | 80,00 Gb Total Space | 79,81 Gb Free Space | 99,76% Space Free | Partition Type: NTFS
Drive E: | 100,00 Gb Total Space | 88,20 Gb Free Space | 88,19% Space Free | Partition Type: NTFS
Drive F: | 261,99 Gb Total Space | 246,65 Gb Free Space | 94,15% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: simon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\simon\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Bitdefender\Bitdefender 2012\Antispam32\bdimguiaux.exe (Bitdefender)
PRC - C:\Program Files (x86)\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\VoipCheapCom.com\VoipCheapCom\VoipCheapCom.exe (VoipCheapCom)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\UMonit.exe ()
PRC - C:\Program Files (x86)\jmesoft\hotkey.exe (JME)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b559a471eef00081f0b5c2719d1d9623\System.Runtime.Remoting.ni.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\Antispam32\connector.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\Antispam32\framework.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2012\Antispam32\txmlutil.dll ()
MOD - C:\Program Files (x86)\Java\jre6\bin\jp2native.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files (x86)\jmesoft\hidhook.dll ()
MOD - C:\Windows\SysWOW64\UMonit.exe ()
MOD - C:\Windows\SysWOW64\ustor.dll ()
MOD - C:\Program Files (x86)\jmesoft\KeyHook.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (VSSERV) -- C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe (Bitdefender)
SRV:64bit: - (UPDATESRV) -- C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe (Bitdefender)
SRV:64bit: - (Printer Control) -- C:\Windows\SysNative\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Mobile Partner. RunOuc) -- C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe ()
SRV - (Update Server) -- C:\Programme\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NeroMediaHomeService.4) -- C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (oem-drv64) OEM-SLP2.1 Driver (HPD64) -- C:\Windows\SysNative\drivers\oem-drv64.sys (secr9tos)
DRV:64bit: - (ewusbnet) -- C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (ew_hwusbdev) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_enumerator) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (avchv) -- C:\Windows\SysNative\drivers\avchv.sys (BitDefender)
DRV:64bit: - (avc3) -- C:\Windows\SysNative\drivers\avc3.sys (BitDefender)
DRV:64bit: - (avckf) -- C:\Windows\SysNative\drivers\avckf.sys (BitDefender)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (trufos) -- C:\Windows\SysNative\drivers\trufos.sys (BitDefender S.R.L.)
DRV:64bit: - (bdsandbox) -- C:\Windows\SysNative\drivers\bdsandbox.sys (BitDefender SRL)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bdfsfltr) -- C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (e1cexpress) Intel(R) -- C:\Windows\SysNative\drivers\e1c62x64.sys (Intel Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8192Ce) -- C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation                           )
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (USTOR2K) -- C:\Windows\SysNative\drivers\ustor2k.sys (Genesys Logic)
DRV:64bit: - (BDVEDISK) -- C:\Windows\SysNative\drivers\bdvedisk.sys (BitDefender)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SSPORT) -- C:\Windows\SysNative\drivers\SSPORT.SYS (Samsung Electronics)
DRV:64bit: - (DgiVecp) -- C:\Windows\SysNative\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (bdfwfpf) -- C:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys (BitDefender LLC)
DRV - (BdfNdisf) -- c:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys (BitDefender LLC)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1927487744-2472533838-3505975869-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1927487744-2472533838-3505975869-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1927487744-2472533838-3505975869-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1927487744-2472533838-3505975869-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D5 E6 C1 03 FF DF CC 01  [binary data]
IE - HKU\S-1-5-21-1927487744-2472533838-3505975869-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2012\BDTBEXT\ [2011.12.15 17:19:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.14 10:39:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.05 11:58:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Program Files\Bitdefender\Bitdefender 2012\bdtbext\ [2011.12.15 17:19:09 | 000,000,000 | ---D | M]
 
[2012.01.30 16:54:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\simon\AppData\Roaming\mozilla\Extensions
[2012.01.31 08:50:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\simon\AppData\Roaming\mozilla\Firefox\Profiles\i26v9f8f.default\extensions
[2011.09.11 08:52:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.01.03 10:21:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.09.11 08:52:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\SIMON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I26V9F8F.DEFAULT\EXTENSIONS\NOSQUINT@URANDOM.CA.XPI
() (No name found) -- C:\USERS\SIMON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I26V9F8F.DEFAULT\EXTENSIONS\XPIRFTOOLBAR@ROBOFORM.COM.XPI
[2011.11.14 10:39:54 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.28 05:32:48 | 000,176,952 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files (x86)\mozilla firefox\plugins\npatgpc.dll
[2011.11.14 10:39:52 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.09.11 08:51:29 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2011.11.14 10:39:52 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll File not found
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll File not found
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe (Bitdefender)
O4:64bit: - HKLM..\Run: [PrintDisp] C:\Windows\SysNative\PrintDisp.exe (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UMonit] C:\Windows\SysWOW64\UMonit.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [jmekey] C:\Program Files (x86)\jmesoft\hotkey.exe (JME)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1927487744-2472533838-3505975869-1002..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1927487744-2472533838-3505975869-1005..\Run: [VoipCheapCom] C:\Program Files (x86)\VoipCheapCom.com\VoipCheapCom\VoipCheapCom.exe (VoipCheapCom)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1927487744-2472533838-3505975869-1002..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}  (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{073B2E8B-BED0-4331-92D3-BCF87B40F9DB}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C64F63B-71CF-4815-9856-2717D8D0FDAC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE50F38C-4708-457B-9E1B-145E45A43690}: NameServer = 193.189.244.225 193.189.244.206
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.31 16:25:32 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\Tickets
[2012.01.31 10:29:02 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\VoipCheapCom
[2012.01.31 09:47:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.01.31 09:38:05 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Yahoo!
[2012.01.30 19:02:24 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\Adobe
[2012.01.30 18:58:22 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\Zeugnisse
[2012.01.30 18:58:22 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\Sushil_scan
[2012.01.30 18:58:21 | 000,000,000 | R--D | C] -- C:\Users\simon\Documents\Scanned Documents
[2012.01.30 18:58:20 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\SamsungSoftware
[2012.01.30 18:58:20 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\Phone Backup
[2012.01.30 18:58:19 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\PhoenixRC
[2012.01.30 18:58:19 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\My Received Files
[2012.01.30 18:58:16 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\Hari_AuPair
[2012.01.30 17:15:26 | 000,000,000 | R--D | C] -- C:\Users\simon\Music
[2012.01.30 16:59:19 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Malwarebytes
[2012.01.30 16:57:17 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Adobe
[2012.01.30 16:56:10 | 000,000,000 | ---D | C] -- C:\Users\simon\Documents\My RoboForm Data
[2012.01.30 16:55:56 | 000,000,000 | R--D | C] -- C:\Users\simon\Documents
[2012.01.30 16:55:16 | 000,000,000 | R--D | C] -- C:\Users\simon\Pictures
[2012.01.30 16:55:04 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\worldtop400511
[2012.01.30 16:54:59 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\S.A.D.Europa-Fuehrerschein.2011.German-PLZ
[2012.01.30 16:54:58 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\pokharaphotos
[2012.01.30 16:54:35 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\Nepal_Katrin
[2012.01.30 16:54:21 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\katm
[2012.01.30 16:54:08 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\German_Top_100_Single_Charts_07.11.2011
[2012.01.30 16:53:54 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Mozilla
[2012.01.30 16:53:54 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\Mozilla
[2012.01.30 16:53:52 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\German_TOP50_ODC_07_11_2011-MCG
[2012.01.30 16:53:50 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\Ebay_Bilder
[2012.01.30 16:53:50 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\burosch_hd_testbilder
[2012.01.30 16:53:49 | 000,000,000 | ---D | C] -- C:\Users\simon\Desktop\2011-11-15
[2012.01.30 16:53:44 | 000,000,000 | R--D | C] -- C:\Users\simon\Desktop
[2012.01.30 16:52:46 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Intel Corporation
[2012.01.30 16:52:34 | 000,000,000 | R--D | C] -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.01.30 16:52:33 | 000,000,000 | R--D | C] -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.01.30 16:52:33 | 000,000,000 | R--D | C] -- C:\Users\simon\Searches
[2012.01.30 16:52:26 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Identities
[2012.01.30 16:52:24 | 000,000,000 | R--D | C] -- C:\Users\simon\Contacts
[2012.01.30 16:52:22 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\VirtualStore
[2012.01.30 16:52:18 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Bitdefender
[2012.01.30 16:52:15 | 000,000,000 | --SD | C] -- C:\Users\simon\AppData\Roaming\Microsoft
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\Videos
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\Saved Games
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\Links
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\Favorites
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\Downloads
[2012.01.30 16:52:15 | 000,000,000 | R--D | C] -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Vorlagen
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\AppData\Local\Verlauf
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\AppData\Local\Temporary Internet Files
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Startmenü
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\SendTo
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Recent
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Netzwerkumgebung
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Lokale Einstellungen
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Eigene Dateien
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Druckumgebung
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Cookies
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\AppData\Local\Anwendungsdaten
[2012.01.30 16:52:15 | 000,000,000 | -HSD | C] -- C:\Users\simon\Anwendungsdaten
[2012.01.30 16:52:15 | 000,000,000 | -H-D | C] -- C:\Users\simon\AppData
[2012.01.30 16:52:15 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\Temp
[2012.01.30 16:52:15 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\Microsoft Help
[2012.01.30 16:52:15 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Local\Microsoft
[2012.01.30 16:52:15 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Media Center Programs
[2012.01.30 16:52:15 | 000,000,000 | ---D | C] -- C:\Users\simon\AppData\Roaming\Macromedia
[2012.01.30 15:29:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.01.30 15:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.01.30 15:29:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012.01.30 15:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.30 15:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.30 15:00:39 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.01.30 15:00:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.01.25 22:14:47 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012.01.25 22:14:47 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2012.01.25 22:14:47 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2012.01.25 22:14:47 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012.01.25 22:14:47 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012.01.25 22:14:47 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012.01.24 11:44:37 | 000,030,200 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll
[2012.01.24 11:44:37 | 000,018,424 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui2.dll
[2012.01.24 11:44:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF
[2012.01.24 11:31:32 | 000,901,120 | ---- | C] (ActMask hxxp://www.all2pdf.com) -- C:\Windows\SysWow64\SaveTo.dll
[2012.01.24 11:31:20 | 002,650,112 | ---- | C] (DynaForms GmbH) -- C:\Windows\SysWow64\CPDF.dll
[2012.01.24 11:31:20 | 000,826,368 | ---- | C] (ActMask Co.,Ltd - hxxp://www.all2pdf.com) -- C:\Windows\SysNative\PrintDisp.exe
[2012.01.24 11:31:20 | 000,077,824 | ---- | C] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\SysNative\PrintCtrl.exe
[2012.01.24 11:31:15 | 000,369,152 | ---- | C] (ActMask Co.,Ltd) -- C:\Windows\SysNative\ActPub.exe
[2012.01.24 11:31:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2012.01.24 11:31:10 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdiplus.dll
[2012.01.24 11:31:10 | 001,171,456 | ---- | C] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\SysNative\PrtClient.exe
[2012.01.24 11:31:10 | 000,828,416 | ---- | C] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\SysNative\SetupDrv.exe
[2012.01.24 11:31:10 | 000,740,864 | ---- | C] (ActMask - hxxp://www.all2pdf.com) -- C:\Windows\SysNative\PrtTools.exe
[2012.01.24 11:31:10 | 000,377,344 | ---- | C] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\SysWow64\SetPrinter.exe
[2012.01.24 11:31:10 | 000,377,344 | ---- | C] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) -- C:\Windows\SysNative\SetPrinter.exe
[2012.01.20 07:40:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Vodafone
[2012.01.20 07:40:38 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2012.01.20 07:40:18 | 000,008,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SpOrder.dll
[2012.01.19 17:35:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
[2012.01.19 17:35:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero
[2012.01.19 17:35:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2012.01.19 17:35:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero
[2012.01.17 11:34:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2012.01.17 11:34:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImgBurn
[2012.01.11 09:53:48 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2012.01.11 09:53:47 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012.01.11 09:53:47 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2012.01.11 09:53:47 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012.01.11 09:53:47 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012.01.11 09:53:45 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012.01.11 09:53:45 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2012.01.05 14:47:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner
[2012.01.05 14:47:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Mobile Partner
[2012.01.05 14:47:03 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01007.dll
[2012.01.05 14:47:03 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfCoInstaller01007.dll
[2012.01.05 14:47:03 | 000,196,608 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys
[2012.01.05 14:47:03 | 000,093,696 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys
[2012.01.05 14:47:03 | 000,085,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys
[2012.01.05 14:47:03 | 000,055,296 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcecm.sys
[2012.01.05 14:47:03 | 000,029,184 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_juextctrl.sys
[2012.01.05 14:47:00 | 000,999,936 | ---- | C] (DiBcom SA) -- C:\Windows\SysNative\drivers\mod7700.sys
[2012.01.05 14:47:00 | 000,256,000 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbnet.sys
[2012.01.05 14:47:00 | 000,121,600 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbmdm.sys
[2012.01.05 14:47:00 | 000,032,768 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\SysNative\drivers\ewdcsc.sys
[2012.01.05 14:47:00 | 000,013,952 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys
[2012.01.05 14:46:56 | 000,117,248 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys
[2012.01.05 14:46:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobile Partner
[2012.01.05 14:46:11 | 000,000,000 | ---D | C] -- C:\ProgramData\DatacardService
[2012.01.03 10:21:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.31 09:39:20 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.31 09:39:20 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.31 09:36:47 | 001,498,642 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.01.31 09:36:47 | 000,654,126 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.01.31 09:36:47 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.01.31 09:36:47 | 000,129,998 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.01.31 09:36:47 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.01.31 09:30:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.31 09:30:30 | 523,141,119 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.31 09:30:27 | 000,042,496 | ---- | M] (secr9tos) -- C:\Windows\SysNative\drivers\oem-drv64.sys
[2012.01.31 09:29:50 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.01.27 14:36:10 | 000,091,554 | ---- | M] () -- C:\Users\simon\Desktop\E-Ticket.pdf
[2012.01.26 13:34:38 | 001,069,075 | ---- | M] () -- C:\Users\simon\Desktop\VBG.PDF
[2012.01.24 11:31:31 | 001,218,627 | ---- | M] () -- C:\Windows\unins000.exe
[2012.01.24 11:31:31 | 000,020,718 | ---- | M] () -- C:\Windows\unins000.dat
[2012.01.21 17:50:29 | 000,140,798 | ---- | M] () -- C:\Users\simon\Desktop\LG 55lw5590_3D.pdf
[2012.01.20 07:48:00 | 000,000,350 | ---- | M] () -- C:\Windows\SysNative\checkdnsid.xml
[2012.01.20 07:40:18 | 000,008,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SpOrder.dll
[2012.01.19 22:14:13 | 000,574,733 | ---- | M] () -- C:\Users\simon\Desktop\LG LED TV 55LW5600 Spec Sheet.pdf
[2012.01.19 22:14:02 | 000,354,744 | ---- | M] () -- C:\Users\simon\Desktop\55LW5590.pdf
[2012.01.19 17:23:09 | 000,009,696 | ---- | M] () -- C:\Users\simon\Desktop\LG 55lw5590.pdf
[2012.01.16 08:43:46 | 000,018,424 | ---- | M] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui2.dll
[2012.01.16 08:43:44 | 000,030,200 | ---- | M] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll
[2012.01.13 14:24:19 | 004,056,018 | ---- | M] () -- C:\Users\simon\Desktop\WAVE XXL.pdf
[2012.01.13 12:41:09 | 000,201,326 | ---- | M] () -- C:\Users\simon\Desktop\eurodns_inv_650355-1.pdf
[2012.01.13 12:33:06 | 000,592,782 | ---- | M] () -- C:\Users\simon\Desktop\Gutschriftanzeige.PDF
[2012.01.11 11:39:16 | 000,000,000 | -H-- | M] () -- C:\Users\simon\Documents\Default.rdp
[2012.01.09 10:17:33 | 000,622,614 | ---- | M] () -- C:\Users\simon\Desktop\Frau_Junge.PDF
[2012.01.06 12:18:00 | 009,826,270 | ---- | M] () -- C:\Users\simon\Desktop\iPod_nano_6thgen_Benutzerhandbuch.pdf
[2012.01.05 14:47:04 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2012.01.05 14:46:40 | 001,490,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01007.dll
[2012.01.05 14:46:40 | 001,490,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfCoInstaller01007.dll
[2012.01.05 14:46:40 | 000,999,936 | ---- | M] (DiBcom SA) -- C:\Windows\SysNative\drivers\mod7700.sys
[2012.01.05 14:46:40 | 000,256,000 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbnet.sys
[2012.01.05 14:46:40 | 000,196,608 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys
[2012.01.05 14:46:40 | 000,121,600 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbmdm.sys
[2012.01.05 14:46:40 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys
[2012.01.05 14:46:40 | 000,093,696 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys
[2012.01.05 14:46:40 | 000,085,504 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys
[2012.01.05 14:46:40 | 000,055,296 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcecm.sys
[2012.01.05 14:46:40 | 000,032,768 | ---- | M] (Huawei Tech. Co., Ltd.) -- C:\Windows\SysNative\drivers\ewdcsc.sys
[2012.01.05 14:46:40 | 000,029,184 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_juextctrl.sys
[2012.01.05 14:46:40 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys
[2012.01.03 11:53:23 | 002,368,783 | ---- | M] () -- C:\Users\simon\Desktop\CV_KC.rtf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.31 09:22:33 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.01.30 18:58:16 | 000,196,811 | ---- | C] () -- C:\Users\simon\Documents\Sushil_Resume.pdf
[2012.01.30 18:58:16 | 000,035,929 | ---- | C] () -- C:\Users\simon\Documents\SushilKC.pdf
[2012.01.30 18:58:15 | 032,243,712 | ---- | C] () -- C:\Users\simon\Documents\ROM_backup.nb1
[2012.01.30 18:58:15 | 000,493,797 | ---- | C] () -- C:\Users\simon\Documents\Jayanta-Taxcard.PDF
[2012.01.30 18:58:15 | 000,358,301 | ---- | C] () -- C:\Users\simon\Documents\Jayanta.PDF
[2012.01.30 18:58:15 | 000,212,692 | ---- | C] () -- C:\Users\simon\Documents\Jayanta1.PDF
[2012.01.30 18:58:15 | 000,117,830 | ---- | C] () -- C:\Users\simon\Documents\Invoice.pdf
[2012.01.30 18:58:14 | 002,368,760 | ---- | C] () -- C:\Users\simon\Documents\CV_KC.rtf
[2012.01.30 18:58:14 | 000,543,645 | ---- | C] () -- C:\Users\simon\Documents\Gold_Card_Fernabsatzbedingungen.pdf
[2012.01.30 18:58:14 | 000,337,482 | ---- | C] () -- C:\Users\simon\Documents\handytranporter.jpg
[2012.01.30 18:58:14 | 000,196,745 | ---- | C] () -- C:\Users\simon\Documents\CV_KC.pdf
[2012.01.30 18:58:14 | 000,088,691 | ---- | C] () -- C:\Users\simon\Documents\CV_Sushil_KC.pdf
[2012.01.30 18:58:14 | 000,000,000 | -H-- | C] () -- C:\Users\simon\Documents\Default.rdp
[2012.01.30 16:53:49 | 004,056,018 | ---- | C] () -- C:\Users\simon\Desktop\WAVE XXL.pdf
[2012.01.30 16:53:49 | 001,069,075 | ---- | C] () -- C:\Users\simon\Desktop\VBG.PDF
[2012.01.30 16:53:49 | 001,054,199 | ---- | C] () -- C:\Users\simon\Desktop\Menu.PDF
[2012.01.30 16:53:49 | 000,574,733 | ---- | C] () -- C:\Users\simon\Desktop\LG LED TV 55LW5600 Spec Sheet.pdf
[2012.01.30 16:53:49 | 000,196,880 | ---- | C] () -- C:\Users\simon\Desktop\Sushil_CV.pdf
[2012.01.30 16:53:49 | 000,196,798 | ---- | C] () -- C:\Users\simon\Desktop\Resume_Sushil_KC.pdf
[2012.01.30 16:53:49 | 000,054,548 | ---- | C] () -- C:\Users\simon\Desktop\TravelTrex.pdf
[2012.01.30 16:53:49 | 000,002,080 | ---- | C] () -- C:\Users\simon\Desktop\S.A.D.-Europa-Führerschein 2011.lnk
[2012.01.30 16:53:48 | 009,826,270 | ---- | C] () -- C:\Users\simon\Desktop\iPod_nano_6thgen_Benutzerhandbuch.pdf
[2012.01.30 16:53:48 | 000,592,782 | ---- | C] () -- C:\Users\simon\Desktop\Gutschriftanzeige.PDF
[2012.01.30 16:53:48 | 000,140,798 | ---- | C] () -- C:\Users\simon\Desktop\LG 55lw5590_3D.pdf
[2012.01.30 16:53:48 | 000,009,696 | ---- | C] () -- C:\Users\simon\Desktop\LG 55lw5590.pdf
[2012.01.30 16:53:48 | 000,001,272 | ---- | C] () -- C:\Users\simon\Desktop\Führerschein Trainer 2012.lnk
[2012.01.30 16:53:48 | 000,000,121 | ---- | C] () -- C:\Users\simon\Desktop\LEYK.com
[2012.01.30 16:53:44 | 127,598,592 | ---- | C] () -- C:\Users\simon\Desktop\Fuehrerschein.iso
[2012.01.30 16:53:44 | 002,401,262 | ---- | C] () -- C:\Users\simon\Desktop\Finanzamt.PDF
[2012.01.30 16:53:44 | 002,368,783 | ---- | C] () -- C:\Users\simon\Desktop\CV_KC.rtf
[2012.01.30 16:53:44 | 001,596,719 | ---- | C] () -- C:\Users\simon\Desktop\DomainContract.PDF
[2012.01.30 16:53:44 | 000,704,611 | ---- | C] () -- C:\Users\simon\Desktop\CIB Program.pdf
[2012.01.30 16:53:44 | 000,652,551 | ---- | C] () -- C:\Users\simon\Desktop\Anschreiben_Pro7Sat1.PDF
[2012.01.30 16:53:44 | 000,622,614 | ---- | C] () -- C:\Users\simon\Desktop\Frau_Junge.PDF
[2012.01.30 16:53:44 | 000,436,987 | ---- | C] () -- C:\Users\simon\Desktop\coverletter0002.PDF
[2012.01.30 16:53:44 | 000,354,744 | ---- | C] () -- C:\Users\simon\Desktop\55LW5590.pdf
[2012.01.30 16:53:44 | 000,201,326 | ---- | C] () -- C:\Users\simon\Desktop\eurodns_inv_650355-1.pdf
[2012.01.30 16:53:44 | 000,091,554 | ---- | C] () -- C:\Users\simon\Desktop\E-Ticket.pdf
[2012.01.30 16:53:44 | 000,055,132 | ---- | C] () -- C:\Users\simon\Desktop\Anschreiben_HostEurope.pdf
[2012.01.30 16:53:44 | 000,052,903 | ---- | C] () -- C:\Users\simon\Desktop\Anschreiben.pdf
[2012.01.30 16:52:38 | 000,001,409 | ---- | C] () -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.01.30 16:52:35 | 000,001,403 | ---- | C] () -- C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.01.24 11:31:20 | 001,391,616 | ---- | C] () -- C:\Windows\SysWow64\ActPDF.dll
[2012.01.24 11:31:15 | 001,218,627 | ---- | C] () -- C:\Windows\unins000.exe
[2012.01.24 11:31:15 | 000,020,718 | ---- | C] () -- C:\Windows\unins000.dat
[2012.01.24 11:31:10 | 000,691,200 | ---- | C] () -- C:\Windows\SysNative\PrintLog.exe
[2012.01.24 11:31:10 | 000,524,288 | ---- | C] () -- C:\Windows\SysNative\PrtPass.exe
[2012.01.20 07:47:50 | 000,000,350 | ---- | C] () -- C:\Windows\SysNative\checkdnsid.xml
[2012.01.17 11:34:45 | 000,001,881 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
[2012.01.05 14:47:04 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2011.12.15 17:20:13 | 000,182,652 | ---- | C] () -- C:\ProgramData\1323965837.bdinstall.bin
[2011.12.15 17:09:49 | 000,033,174 | ---- | C] () -- C:\ProgramData\1323965383.bdinstall.bin
[2011.12.15 17:04:31 | 000,001,556 | ---- | C] () -- C:\ProgramData\1323965071.bdinstall.bin
[2011.12.15 17:04:23 | 000,108,046 | ---- | C] () -- C:\ProgramData\1323965044.bdinstall.bin
[2011.12.15 16:27:48 | 000,181,662 | ---- | C] () -- C:\ProgramData\1323962640.bdinstall.bin
[2011.09.10 15:15:50 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\ustor.dll
[2011.09.10 15:15:50 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\UMonit.exe
[2011.09.10 15:15:42 | 000,001,393 | ---- | C] () -- C:\Windows\SysWow64\IconCfg0.ini
[2011.09.10 15:15:42 | 000,000,722 | ---- | C] () -- C:\Windows\SysWow64\ProductName.ini
[2011.09.10 15:13:21 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2011.09.10 15:09:56 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009.07.13 22:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009.07.13 22:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009.07.13 22:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2005.01.03 11:10:44 | 000,319,488 | ---- | C] () -- C:\Windows\SysWow64\DLXAPI32.DLL
 
========== LOP Check ==========
 
[2011.12.31 16:57:10 | 000,000,000 | ---D | M] -- C:\Users\Brina\AppData\Roaming\Bitdefender
[2011.11.30 17:12:02 | 000,000,000 | ---D | M] -- C:\Users\Brina\AppData\Roaming\DAEMON Tools Lite
[2012.01.30 15:08:18 | 000,000,000 | ---D | M] -- C:\Users\Brina\AppData\Roaming\ImgBurn
[2011.09.13 20:59:47 | 000,000,000 | ---D | M] -- C:\Users\Brina\AppData\Roaming\VoipCheapCom
[2012.01.30 16:52:18 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming\Bitdefender
[2012.01.31 10:29:27 | 000,000,000 | ---D | M] -- C:\Users\simon\AppData\Roaming\VoipCheapCom
[2011.12.29 21:30:12 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >
         
--- --- ---
[/code]


Extras.txt

OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 31.01.2012 16:48:31 - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\simon\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,98 Gb Total Physical Memory | 3,60 Gb Available Physical Memory | 60,20% Memory free
11,96 Gb Paging File | 8,44 Gb Available in Paging File | 70,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449,79 Gb Total Space | 346,15 Gb Free Space | 76,96% Space Free | Partition Type: NTFS
Drive D: | 80,00 Gb Total Space | 79,81 Gb Free Space | 99,76% Space Free | Partition Type: NTFS
Drive E: | 100,00 Gb Total Space | 88,20 Gb Free Space | 88,19% Space Free | Partition Type: NTFS
Drive F: | 261,99 Gb Total Space | 246,65 Gb Free Space | 94,15% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: simon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1927487744-2472533838-3505975869-1005\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{2AB9289D-6432-4CC0-8869-A195C3F0CFCC}" = Bitdefender Internet Security 2012
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{EC8A40B2-096A-4EA4-B11A-167F87F293A7}" = iCloud
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Bitdefender" = Bitdefender Internet Security 2012
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel(R) Network Connections Drivers
"Virtual Printer SDK Patch_is1" = 3.3
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1290A3B9-A3E9-4725-8D95-AE37C7AAA3E3}" = LXH-JME8002B Hotkey Driver
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2382cbbd-9625-4b2c-97f0-57c24e48bd41}" = Nero MediaHome 4 Essentials
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java(TM) 6 Update 27
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2B53190C-E53E-4736-9E13-395741415991}" = Netzwerkaufzeichnungs-Player
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5D5509EA-B85A-411E-AB75-59069A411876}" = COMPUTERBILD App-Center
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6395D480-9F3B-4930-8204-B91C8882F967}" = Stata 10
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FC3B9A-4149-43DB-A557-6ED0C8D8BA44}" = Nero MediaHome 4 Help
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
"{90120000-00B2-0407-0000-0000000FF1CE}" = Microsoft – Speichern als PDF oder XPS – Add-In für 2007 Microsoft Office-Programme
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{959B7F35-2819-40C5-A0CD-3C53B5FCC935}" = Genesys USB Mass Storage Device
"{99EF387E-633E-4CFB-BFA3-AB961B685DDF}" = Nero MediaHome 4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4123-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver
"{A73FEB3E-22A7-4507-D8EC-119EE98824B9}" = DAF Desk
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B266E062-D6C5-485B-B426-51B152B041A6}" = Lenovo Tinian FN PS/2 Keyboard Driver
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = CanoScan Toolbox Ver4.9
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"DAEMON Tools Lite" = DAEMON Tools Lite
"de.anleger-fernsehen.dafdesk.C1051E74B3FAE4202E494B14ADD69FC8A349CD49.1" = DAF Desk
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"ffs2011_is1" = Franzis Führerschein Trainer 2012
"ImgBurn" = ImgBurn
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Mobile Partner" = Mobile Partner
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"S.A.D.-Europa-Führerschein 2011" = S.A.D.-Europa-Führerschein 2011 v9.0
"Samsung MFP 560 Series" = Samsung MFP 560 Series
"VLC media player" = VLC media player 1.1.11
"VoipCheapCom_is1" = VoipCheapCom
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 27.01.2012 08:48:40 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 27.01.2012 09:17:32 | Computer Name = Admin-PC | Source = SideBySide | ID = 16842827
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe". Fehler in Manifest-
 oder Richtliniendatei "C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe"
 in Zeile 2.  Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig.
 
Error - 30.01.2012 03:58:20 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 30.01.2012 06:17:53 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 30.01.2012 06:17:53 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1030
 
Error - 30.01.2012 06:17:53 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1030
 
Error - 30.01.2012 06:17:54 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 30.01.2012 06:17:54 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2028
 
Error - 30.01.2012 06:17:54 | Computer Name = Admin-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2028
 
Error - 30.01.2012 08:54:48 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 30.01.2012 09:42:27 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   AFD  avc3  BdfNdisf  bdfsfltr  bdfwfpf  BDVEDISK  CSC  DfsC  discache  NetBIOS  NetBT  nsiproxy  Psched
rdbss
spldr
tdx
trufos
vwififlt
Wanarpv6
WfpLwf
 
Error - 30.01.2012 09:53:18 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
   %%20
 
Error - 30.01.2012 09:53:32 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Mobile Partner. OUC erreicht.
 
Error - 30.01.2012 09:53:32 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers 
nicht gestartet:   %%1053
 
Error - 30.01.2012 09:54:58 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7022
Description = Der Dienst "Windows-Bilderfassung (WIA)" wurde nicht richtig gestartet.
 
Error - 30.01.2012 09:54:59 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   trufos
 
Error - 30.01.2012 10:15:20 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet:
   %%20
 
Error - 30.01.2012 10:15:21 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Mobile Partner. OUC erreicht.
 
Error - 30.01.2012 10:15:21 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers 
nicht gestartet:   %%1053
 
Error - 30.01.2012 10:15:29 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   trufos
 
 
< End of report >
         
--- --- ---
[/code]

Geändert von kancha (31.01.2012 um 16:58 Uhr)

Alt 31.01.2012, 20:44   #5
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Wieso postest du jetzt ein Log von Mlwarebytes ohne Funde?! Sry das ist sinnfrei
Ich wollte alle sehen, v.a. die mit Funden

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.02.2012, 10:17   #6
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Hallo cosinus,
danke fuer deine Antwort.

Malware hat nur das gefunden was ich gepostet habe.

Was soll ich jetzt posten?

danke

Alt 01.02.2012, 11:31   #7
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Sry aber das ergibt keinen Sinn. Deine erste Aussage:

Zitat:
Ich habe mit Malwarebytes gescannt und es hat eine Trojaner gefunden
es soll also ein Fund von Malwarebytes dagewesen sein. Nun postest du aber ein Log OHNE FUNDE und sagst nun das wäre alles
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.02.2012, 12:33   #8
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Ich hatte eine Demo version von Malwarebytes und jetzt habe ich eine voll version. Ich kann keine alte logfiles sehen.
Jetzt habe ich den infizierte benutzer konto geloscht und beim neue einscannen, findet Malwarebyes keine trojaner.

Gibt es trotzem eine moeglichkeinten?

danker fuer deine Zeit, Arne.

Alt 01.02.2012, 14:18   #9
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Ja wenn du einfach das Benutzerprofil löscht dann sind auch alle Logs mit weg
Weiß du noch was gefunden wurde?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.02.2012, 14:59   #10
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Er hat nur eine Trojaner gefunden der in ordner temp war.
Der folder hat mit (null) 0 angefangen.

Alt 01.02.2012, 15:40   #11
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Ich glaub ich weiß dann was du meinst. Bestimmt sowas in der Art wie 0.4121354306864.exe

Du hast auch schon den ESET Scanner ausgeführt, wo sind die Logs dazu?


Drücke bitte die + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:
ATTFilter
"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
         
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:
ATTFilter
"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
         
Poste nun den Inhalt der log.txt.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 01.02.2012, 16:39   #12
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



ok, mache ich heute Abend

Alt 02.02.2012, 12:14   #13
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=5bee99f2648b8c44a72901bdecb1cdc6
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-31 12:51:01
# local_time=2012-01-31 01:51:01 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 4365 79629596 0 0
# compatibility_mode=8192 67108863 100 0 3710 3710 0 0
# scanned=424953
# found=5
# cleaned=0
# scan_time=14514
K:\Jyoti\Desktop\Downloads\SweetImSetup.exe	a variant of Win32/SweetIM.B application (unable to clean)	00000000000000000000000000000000	I
K:\Jyoti\Desktop\Downloads\Unconfirmed 79366.crdownload	a variant of Win32/SweetIM.B application (unable to clean)	00000000000000000000000000000000	I
K:\Jyoti\MyDocuments\Downloads\SweetImSetup.exe	a variant of Win32/SweetIM.B application (unable to clean)	00000000000000000000000000000000	I
K:\Jyoti\MyDocuments\Downloads\Unconfirmed 79366.crdownload	a variant of Win32/SweetIM.B application (unable to clean)	00000000000000000000000000000000	I
K:\Users\Admin\Downloads\55q5jo4lo43yw30\Microsoft.Office.Professional.Plus.2010.x64.SP1.VL.German-Madmax\MadmaxO1064SP1.iso	Win32/HackKMS.C application (unable to clean)	00000000000000000000000000000000	I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=5bee99f2648b8c44a72901bdecb1cdc6
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-02-02 10:51:07
# local_time=2012-02-02 11:51:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 175331 79800562 0 0
# compatibility_mode=8192 67108863 100 0 174676 174676 0 0
# scanned=338889
# found=0
# cleaned=0
# scan_time=9155
         

Alt 02.02.2012, 12:15   #14
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Jyoti\Desktop\Downloads >>> ist von external Harddisk.

Alt 02.02.2012, 16:19   #15
kancha
 
Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Standard

Achtung! Windows wurde aus Sicherheitsgründen blockiert.



Zitat:
Zitat von cosinus Beitrag anzeigen
Ich glaub ich weiß dann was du meinst. Bestimmt sowas in der Art wie 0.4121354306864.exe

.
Ja es war etwas mit Trojan.FakeMS

Antwort

Themen zu Achtung! Windows wurde aus Sicherheitsgründen blockiert.
achtung, achtung!, antivurs, benutzer, bitdefender, blockiert, defender, desktop, deutsch, einfach, email, forum, infiziert., infizierte, internet, konto, login, malwarebytes, neues, online, online banking, security, sprache, tan, trojaner, trojaner gefunden, trojaner/virus, voll, windows



Ähnliche Themen: Achtung! Windows wurde aus Sicherheitsgründen blockiert.


  1. Achtung! Aus Sicherheitsgründen wurde ihr Windows-System blockiert.
    Plagegeister aller Art und deren Bekämpfung - 11.04.2012 (7)
  2. Achtung! Aus Sicherheitsgründen wurde ihr Windowssystem blockiert! Windows 7
    Plagegeister aller Art und deren Bekämpfung - 05.04.2012 (26)
  3. Achtung! Aus Sicherheitsgründen wurde ihr Windows blockiert!
    Plagegeister aller Art und deren Bekämpfung - 29.03.2012 (12)
  4. Achtung aus Sicherheitsgründen wurde ihr Windows blockiert.
    Log-Analyse und Auswertung - 23.02.2012 (3)
  5. Achtung!aus sicherheitsgründen wurde ihr windows system blockiert!
    Log-Analyse und Auswertung - 13.02.2012 (5)
  6. Achtung! Windows wurde aus Sicherheitsgründen blockiert.
    Log-Analyse und Auswertung - 10.02.2012 (48)
  7. Achtung - Aus Sicherheitsgründen wurde Windows blockiert
    Plagegeister aller Art und deren Bekämpfung - 25.01.2012 (18)
  8. Achtung ! Aus Sicherheitsgründen wurde ihr Windows blockiert
    Log-Analyse und Auswertung - 30.12.2011 (3)
  9. Achtung aus Sicherheitsgründen wurde ihr Windows blockiert!
    Log-Analyse und Auswertung - 28.12.2011 (7)
  10. Achtung aus Sicherheitsgründen wurde ihr Windows blockiert!
    Log-Analyse und Auswertung - 28.12.2011 (1)
  11. achtung aus sicherheitsgründen wurde ihr windows system blockiert
    Plagegeister aller Art und deren Bekämpfung - 23.12.2011 (10)
  12. Achtung ! Aus Sicherheitsgründen wurde ihr Windows-System blockiert !!!
    Log-Analyse und Auswertung - 21.12.2011 (3)
  13. Achtung aus Sicherheitsgründen wurde Windows Blockiert - 50€ Zahlungsauffoderung
    Plagegeister aller Art und deren Bekämpfung - 17.12.2011 (2)
  14. Achtung Windows wurde aus Sicherheitsgründen blockiert !
    Plagegeister aller Art und deren Bekämpfung - 08.12.2011 (10)
  15. Achtung Windows wurde aus Sicherheitsgründen blockiert =/
    Plagegeister aller Art und deren Bekämpfung - 08.12.2011 (1)
  16. achtung aus sicherheitsgründen wurde ihr windows system blockiert
    Log-Analyse und Auswertung - 03.12.2011 (24)
  17. Achtung! Aus Sicherheitsgründen wurde ihr Windows System blockiert
    Plagegeister aller Art und deren Bekämpfung - 01.12.2011 (9)

Zum Thema Achtung! Windows wurde aus Sicherheitsgründen blockiert. - Hallo Liebe Forum gemeinde, meine Desktop wuerde gestern mit dem "Achtung! Windows wurde aus Sicherheitsgründen blockiert " Trojaner infiziert. Zum glueck hatte ich zwei login Konto mit Admin rechte. Ich - Achtung! Windows wurde aus Sicherheitsgründen blockiert....
Archiv
Du betrachtest: Achtung! Windows wurde aus Sicherheitsgründen blockiert. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.