Broken.OpenCommand Virus

Broken.OpenCommand Virus

Guten Tag,
Leider habe ich auf meinen PC auch ein Virus bekommen, endeckt durch Malwarebytes. Name wie im Titel "Broken.OpenCommand" ist in der Registry drin und merhmalige versuchen auch mit Ordner löschen haben nicht geholfen, erstellt sich danach wieder.

Mein Virusprogramm Avast gibt keine Meldung, Spybot ebenso nicht, Ad-Aware zeigt nur Cookies an und Secure Banking gibt auch keine Rückmeldung.

Das Programm "Gmer" hat viren erkannt, einige davon sind allerdings das Programm selber oder Secure Banking, können also ignoriert werden.
Hab danach alle Programme ausgeschaltet.

Logfiles befinden sich im Anhang.

Vielen dank schonmal im Vorraus!



Broken.OpenCommand Virus

Broken.OpenCommand Virus

Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

 hier steht das Log


Broken.OpenCommand Virus

Broken.OpenCommand Virus

Wie es aussieht bin ich sehr beliebt bei Virenentwickler.

Malwarebytes Anti-Malware

Datenbank Version: v2012.02.29.04

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Gast :: MEDICO-PC [limitiert]

06.03.2012 22:41:49
mbam-log-2012-03-06 (22-41-49).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 188124
Laufzeit: 13 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: ("%1" /S) -> Löschen bei Neustart.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: (regedit.exe "%1") -> Löschen bei Neustart.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=45344496915d7a45b7caec32b14db4b7
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-06 11:53:05
# local_time=2012-03-07 12:53:05 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT 
# compatibility_mode=768 16777215 100 0 57743389 57743389 0 0
# compatibility_mode=5893 16776573 100 94 5967 82701321 0 0
# compatibility_mode=8192 67108863 100 0 1081 1081 0 0
# scanned=76705
# found=12
# cleaned=0
# scan_time=6515
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe	probably a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe	a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll	a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)	00000000000000000000000000000000	I
C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbarIE.dll	a variant of Win32/Adware.Toolbar.Dealio application (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa2.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa3.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa6.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\ProgramData\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa7.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa2.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa3.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa6.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
C:\Users\All Users\Spybot - Search & Destroy\Recovery\FraudAVSJhorwPa7.zip	Win32/Bagle.gen.zip worm (unable to clean)	00000000000000000000000000000000	I
Habe bei 94 Prozent gestoppt mach morgen nochmal ein Scan, hatte nicht mehr die zeit.

Habe außerdem eine Toolbar namens Conduit auf den IE, wo sofort auch eine Meldung kommt, das dieses ein Link aufrufen möchte.

Vielen Dank nochmal!


Broken.OpenCommand Virus

Broken.OpenCommand Virus

Da liegt ja auch einiges in der Q von Spybot. Hast du die Logs davon noch?
Logfiles bitte immer in CODE-Tags posten

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Bestimmt, muss ich nach der Arbeit mal nachsehen

Alt 07.03.2012, 21:16   #6
Broken.OpenCommand Virus

Broken.OpenCommand Virus

Wo sind die Logs? Habe mal nachgesehen. Google sagt die wären unter AppData aber ich finde den Spybot ordner nicht?



Broken.OpenCommand Virus

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Gast :: MEDICO-PC [limitiert]

08.03.2012 17:03:07
mbam-log-2012-03-08 (19-39-05).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 410567
Laufzeit: 2 Stunde(n), 26 Minute(n), 8 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: ("%1" /S) -> Keine Aktion durchgeführt.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: (regedit.exe "%1") -> Keine Aktion durchgeführt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

Hab ich gemacht, kam gleiches Ergebnis raus.

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Sorry, wusste ich nicht, hier nochmal:

 Malwarebytes Anti-Malware  (Test)

Datenbank Version: v2012.03.08.06

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Medico :: MEDICO-PC [Administrator]

Schutz: Aktiviert

08.03.2012 20:43:49
mbam-log-2012-03-08 (20-43-49).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 462288
Laufzeit: 2 Stunde(n), 13 Minute(n), 42 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: ("%1" /S) -> Löschen bei Neustart.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bösartig: () Gut: (regedit.exe "%1") -> Löschen bei Neustart.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)


Broken.OpenCommand Virus

Broken.OpenCommand Virus

Broken.OpenCommand Virus

Kann den Bericht nur als Anhang verschicken und den auch nur als Teil.

Der Rest vom Anhang ist hier:

O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (InnoGames Toolbar) - {c7478d43-2bd5-4844-98b8-c2a6aa9ed677} - C:\Program Files (x86)\InnoGames\prxtbInn0.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (InnoGames Toolbar) - {c7478d43-2bd5-4844-98b8-c2a6aa9ed677} - C:\Program Files (x86)\InnoGames\prxtbInn0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001\..\Toolbar\WebBrowser: (InnoGames Toolbar) - {C7478D43-2BD5-4844-98B8-C2A6AA9ED677} - C:\Program Files (x86)\InnoGames\prxtbInn0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-501\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-501\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-501\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-775227719-1777431515-2653404987-501\..\Toolbar\WebBrowser: (InnoGames Toolbar) - {C7478D43-2BD5-4844-98B8-C2A6AA9ED677} - C:\Program Files (x86)\InnoGames\prxtbInn0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001..\Run: [AutoStart-Manager 2006] C:\Program Files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe (Wirth New Media Sarl )
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001..\Run: [SecureBanking] C:\Program Files (x86)\Secure Banking\v1.3\SecureBanking.exe (Secure Banking)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [GameXN] C:\ProgramData\GameXN\GameXNGO.exe (EasyBits Software AS)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [GameXN (news)] C:\ProgramData\GameXN\GameXNGO.exe (EasyBits Software AS)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [GameXN (update)] C:\ProgramData\GameXN\GameXNGO.exe (EasyBits Software AS)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [SecureBanking] C:\Program Files (x86)\Secure Banking\v1.3\SecureBanking.exe (Secure Banking)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-775227719-1777431515-2653404987-501..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start Freenet.lnk =  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-775227719-1777431515-2653404987-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20F130E6-D7BD-4225-A82C-168B851A9B7B}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A0EA15C1-C840-4214-AB96-A1EFDE080614}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4E56C8D-6D85-4C3E-A324-7D00022F8D22}: DhcpNameServer =
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Air Mouse.lnk - C:\PROGRA~2\AIRMOU~1\AIRMOU~1\AIRMOU~1.EXE - ()
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVer HID Receiver.lnk - C:\PROGRA~2\COMMON~1\AVERME~1\AVERQU~1\AVERHI~1.EXE - ()
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVerQuick.lnk - C:\PROGRA~2\COMMON~1\AVERME~1\AVERQU~1\AVERQU~1.EXE - (AVerMedia TECHNOLOGIES, Inc.)
MsConfig:64bit - StartUpFolder: C:^Users^Medico^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^setup_9.0.0.722_14.04.2011_20-50.lnk -  - File not found
MsConfig:64bit - StartUpFolder: C:^Users^Medico^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wipe tray agent 2011.lnk -  - File not found
MsConfig:64bit - StartUpReg: Aim - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: ArcadeDeluxeAgent - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: BackupManagerTray - hkey= - key= - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
MsConfig:64bit - StartUpReg: CanonMyPrinter - hkey= - key= - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
MsConfig:64bit - StartUpReg: Comrade.exe - hkey= - key= - C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe (IGN Entertainment Inc.)
MsConfig:64bit - StartUpReg: DivX Download Manager - hkey= - key= - C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
MsConfig:64bit - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MsConfig:64bit - StartUpReg: Duden Korrektor SysTray - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: EA Core - hkey= - key= - C:\Program Files (x86)\Electronic Arts\EADM\Core.exe (Electronic Arts)
MsConfig:64bit - StartUpReg: EgisTecLiveUpdate - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: iolo Startup - hkey= - key= - C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: KiesTrayAgent - hkey= - key= - C:\Program Files (x86)\Samsung\Kies\/\KiesTrayAgent.exe ()
MsConfig:64bit - StartUpReg: LManager - hkey= - key= - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
MsConfig:64bit - StartUpReg: Malwarebytes' Anti-Malware - hkey= - key= - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
MsConfig:64bit - StartUpReg: mwlDaemon - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: NortonOnlineBackupReminder - hkey= - key= - C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
MsConfig:64bit - StartUpReg: PlayMovie - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: RGSC - hkey= - key= - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
MsConfig:64bit - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
MsConfig:64bit - StartUpReg: StartCCC - hkey= - key= - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
MsConfig:64bit - State: "services" - Reg Error: Key error.

ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2012.03.07 23:13:05 | 000,000,000 | ---D | C] -- C:\Users\Medico\AppData\Roaming\gnupg
[2012.03.06 22:46:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.03.05 20:09:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012.03.05 18:07:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secure Banking
[2012.02.26 20:20:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2012.02.26 20:20:33 | 000,231,376 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2012.02.26 20:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2012.02.26 16:40:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tools&More
[2012.02.26 16:40:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tools&More
[2012.02.26 10:39:54 | 000,053,080 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.02.24 23:53:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.02.24 23:45:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.02.24 22:55:31 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012.02.21 12:31:48 | 002,135,552 | ---- | C] (iolo technologies, LLC) -- C:\Windows\SysNative\Incinerator64.dll
[2012.02.21 12:31:45 | 002,077,184 | ---- | C] (iolo technologies, LLC) -- C:\Windows\SysWow64\Incinerator32.dll
[2012.02.21 01:23:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.02.19 17:29:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
[2012.02.19 17:29:42 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2012.02.19 16:03:28 | 000,023,464 | ---- | C] (EldoS Corporation) -- C:\Windows\SysNative\drivers\ElRawDsk.sys
[2012.02.19 16:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Mechanic
[2012.02.19 16:02:40 | 000,091,136 | ---- | C] (iolo technologies, LLC) -- C:\Windows\SysNative\IncContxMenu.dll
[2012.02.19 16:02:25 | 000,015,360 | ---- | C] (iolo technologies, LLC) -- C:\Windows\SysNative\smrgdf.exe
[2012.02.19 16:02:24 | 000,046,080 | ---- | C] (iolo technologies, LLC) -- C:\Windows\SysNative\iolobtdfg.exe
[2012.02.19 16:01:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iolo
[2012.02.19 15:55:38 | 000,000,000 | ---D | C] -- C:\Users\Medico\AppData\Roaming\iolo
[2012.02.19 15:55:38 | 000,000,000 | ---D | C] -- C:\ProgramData\iolo
[2012.02.16 00:37:19 | 000,000,000 | ---D | C] -- C:\Users\Medico\AppData\Roaming\Malwarebytes
[2012.02.16 00:36:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.02.16 00:36:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.02.16 00:36:54 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.02.16 00:36:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.05.02 23:06:17 | 017,143,210 | ---- | C] (JonDos GmbH) -- C:\ProgramData\JonDoFox.paf.exe
========== Files - Modified Within 30 Days ==========
[2012.03.10 12:11:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.10 11:58:47 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.03.10 11:04:46 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.10 11:04:46 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.10 10:55:34 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr
[2012.03.10 10:54:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.10 10:53:32 | 3219,935,232 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.08 23:14:15 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.08 23:14:14 | 002,308,096 | ---- | M] () -- C:\Windows\SysNative\jscript9.dll
[2012.03.08 23:14:14 | 000,267,776 | ---- | M] () -- C:\Windows\SysNative\ieaksie.dll
[2012.03.08 23:14:14 | 000,163,840 | ---- | M] () -- C:\Windows\SysNative\ieakui.dll
[2012.03.08 23:14:14 | 000,114,176 | ---- | M] () -- C:\Windows\SysNative\admparse.dll
[2012.03.08 23:14:14 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.08 23:14:14 | 000,012,288 | ---- | M] () -- C:\Windows\SysNative\mshta.exe
[2012.03.08 22:13:58 | 000,002,344 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.03.08 19:36:19 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012.03.08 19:36:19 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012.03.05 20:42:55 | 000,000,000 | ---- | M] () -- C:\Users\Medico\defogger_reenable
[2012.02.26 20:20:50 | 000,000,879 | ---- | M] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.02.26 20:20:34 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2012.02.26 17:03:43 | 553,785,881 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.02.26 16:40:30 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\Autostart-Manager 2006.lnk
[2012.02.26 10:39:53 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.02.23 17:49:07 | 000,001,262 | ---- | M] () -- C:\Users\Medico\Desktop\Spybot - Search & Destroy.lnk
[2012.02.23 17:23:26 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.02.23 17:23:21 | 000,201,352 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.02.23 17:23:10 | 000,258,520 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.02.23 17:12:43 | 000,817,496 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.02.23 17:12:42 | 000,335,704 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.02.23 17:11:04 | 000,053,080 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.02.23 17:10:43 | 000,059,224 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.02.23 17:10:38 | 000,069,976 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.02.23 17:10:19 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.02.22 21:46:22 | 000,061,440 | ---- | M] () -- C:\Windows\SysWow64\drivers\yaduktlx.sys
[2012.02.21 12:31:52 | 000,002,223 | ---- | M] () -- C:\Users\Medico\Desktop\System Mechanic.lnk
[2012.02.21 11:15:39 | 000,000,386 | ---- | M] () -- C:\Windows\SysWow64\ioloBootDefrag.cfg
[2012.02.21 01:23:28 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.02.19 17:29:49 | 000,001,662 | ---- | M] () -- C:\Users\Public\Desktop\Recuva.lnk
[2012.02.19 15:55:51 | 000,074,703 | ---- | M] () -- C:\Windows\SysWow64\mfc45.dll
[2012.02.16 13:15:47 | 000,455,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.02.16 01:45:30 | 001,557,816 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.02.16 01:45:30 | 000,668,250 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.02.16 01:45:30 | 000,627,786 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.02.16 01:45:30 | 000,135,886 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.02.16 01:45:30 | 000,111,364 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.02.16 00:36:58 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
========== Files Created - No Company Name ==========
[2012.03.10 10:55:34 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr
[2012.03.08 23:14:15 | 017,790,464 | ---- | C] () -- C:\Windows\SysNative\mshtml.dll
[2012.03.08 23:14:15 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.08 23:14:14 | 002,308,096 | ---- | C] () -- C:\Windows\SysNative\jscript9.dll
[2012.03.08 23:14:14 | 000,267,776 | ---- | C] () -- C:\Windows\SysNative\ieaksie.dll
[2012.03.08 23:14:14 | 000,163,840 | ---- | C] () -- C:\Windows\SysNative\ieakui.dll
[2012.03.08 23:14:14 | 000,114,176 | ---- | C] () -- C:\Windows\SysNative\admparse.dll
[2012.03.08 23:14:14 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.08 23:14:14 | 000,012,288 | ---- | C] () -- C:\Windows\SysNative\mshta.exe
[2012.03.05 20:40:40 | 000,000,000 | ---- | C] () -- C:\Users\Medico\defogger_reenable
[2012.02.26 20:20:50 | 000,000,879 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.02.26 16:40:30 | 000,001,088 | ---- | C] () -- C:\Users\Public\Desktop\Autostart-Manager 2006.lnk
[2012.02.24 22:11:21 | 553,785,881 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.02.23 20:00:21 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2012.02.22 21:46:21 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\yaduktlx.sys
[2012.02.21 01:23:28 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.02.19 17:29:49 | 000,001,662 | ---- | C] () -- C:\Users\Public\Desktop\Recuva.lnk
[2012.02.19 16:04:33 | 000,000,386 | ---- | C] () -- C:\Windows\SysWow64\ioloBootDefrag.cfg
[2012.02.19 16:02:51 | 000,002,223 | ---- | C] () -- C:\Users\Medico\Desktop\System Mechanic.lnk
[2012.02.19 15:55:51 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dll
[2012.02.16 00:36:58 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2011.06.10 23:38:31 | 000,000,000 | ---- | C] () -- C:\Users\Medico\AppData\Local\{3166108E-828C-47C6-AB03-041022BA93FB}
[2011.06.03 15:33:43 | 000,000,000 | ---- | C] () -- C:\Users\Medico\AppData\Local\{1218B187-6CFC-4BFD-AC41-6A84FA68BD90}
[2011.06.03 10:46:20 | 000,000,000 | ---- | C] () -- C:\Users\Medico\AppData\Local\{07DBA7D4-7535-4FCE-9946-9B7CE3C54D5D}
[2011.06.02 23:27:30 | 000,000,000 | ---- | C] () -- C:\Users\Medico\AppData\Local\{90C8A9EE-7C11-4FD8-B742-B2DA53431435}
[2011.05.18 22:15:09 | 000,143,360 | R--- | C] () -- C:\Windows\Vmix108.dll
[2011.05.18 22:15:00 | 000,000,410 | ---- | C] () -- C:\Windows\Cm108.ini.cfl
[2011.05.18 22:14:10 | 000,002,029 | R--- | C] () -- C:\Windows\Cm108.ini.cfg
[2011.05.18 22:14:10 | 000,000,740 | ---- | C] () -- C:\Windows\Cm108.ini.imi
[2011.04.25 22:51:41 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011.04.25 22:51:41 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011.04.14 19:06:49 | 000,000,137 | ---- | C] () -- C:\ProgramData\avalon2.2.ini
[2011.04.14 19:06:36 | 000,219,136 | ---- | C] () -- C:\Windows\sqlite3_engine.dll
[2011.04.14 19:06:33 | 000,340,992 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.12.31 15:26:13 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2010.08.03 17:06:03 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010.08.03 17:06:02 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010.05.07 06:54:16 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2010.05.07 06:54:16 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2010.05.07 06:54:16 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2010.05.07 06:54:16 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2010.04.24 00:35:08 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010.04.24 00:35:08 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2010.03.13 21:57:46 | 000,000,064 | ---- | C] () -- C:\Windows\AVerText.ini
[2010.03.13 21:43:30 | 000,049,152 | R--- | C] () -- C:\Windows\SysWow64\AVerIO.dll
[2010.03.13 21:43:30 | 000,003,456 | R--- | C] () -- C:\Windows\SysWow64\AVerIO.sys
[2010.03.13 21:43:02 | 000,598,016 | R--- | C] () -- C:\Windows\SysWow64\sptlib21.dll
[2010.03.13 21:43:02 | 000,294,912 | R--- | C] () -- C:\Windows\SysWow64\sptlib11.dll
[2010.03.13 21:43:02 | 000,290,816 | R--- | C] () -- C:\Windows\SysWow64\sptlib22.dll
[2010.03.13 21:43:02 | 000,249,856 | R--- | C] () -- C:\Windows\SysWow64\sptlib03.dll
[2010.03.13 21:43:02 | 000,249,856 | R--- | C] () -- C:\Windows\SysWow64\sptlib01.dll
[2010.03.13 21:43:02 | 000,225,280 | R--- | C] () -- C:\Windows\SysWow64\sptlib02.dll
[2010.03.13 21:43:02 | 000,135,168 | R--- | C] () -- C:\Windows\SysWow64\sptlib12.dll
[2011.03.02 18:28:16 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\26337
[2011.04.11 22:11:18 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Canneverbe Limited
[2011.04.17 17:56:57 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Canon
[2010.07.19 19:40:31 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.10.13 20:06:09 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\FileZilla
[2011.03.06 21:50:13 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\GetRightToGo
[2012.03.10 11:02:53 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\go
[2012.02.19 16:28:23 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\iolo
[2011.12.01 22:36:19 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\JonDo
[2010.05.11 18:40:43 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Notepad++
[2010.09.05 20:03:46 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\OpenOffice.org
[2011.04.26 21:33:42 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Opera
[2010.05.29 00:00:32 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\PC Suite
[2012.02.19 17:33:47 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\PMCallCenter
[2011.07.23 14:37:11 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\PROject MT
[2011.07.23 14:58:13 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\PROMT
[2010.05.29 00:00:39 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Samsung
[2010.11.26 16:10:08 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\TeamViewer
[2010.04.28 20:41:45 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Template
[2011.11.23 23:15:35 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Thunderbird
[2012.02.27 14:12:49 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\TrueCrypt
[2011.07.26 09:35:44 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\WFDS
[2010.08.10 00:05:01 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Wimpomat2
[2012.01.17 00:02:27 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\WIPE
[2009.12.03 22:42:42 | 000,000,000 | -HSD | M] -- C:\Users\Medico\AppData\Roaming\.#
[2010.08.08 19:29:49 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\acccore
[2009.12.28 01:38:56 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\FileZilla
[2009.11.26 14:06:40 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\GameConsole
[2012.03.07 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\gnupg
[2012.02.19 16:18:27 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\iolo
[2011.06.12 21:06:42 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\JonDo
[2011.08.22 16:23:13 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\OpenCandy
[2010.01.15 20:34:45 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Opera
[2010.06.19 12:47:21 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\PC Suite
[2010.05.28 23:57:02 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Samsung
[2009.12.01 18:23:18 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\TeamViewer
[2010.01.24 12:33:19 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Thunderbird
[2009.12.29 01:16:50 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Trillian
[2011.04.16 11:47:02 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\WFDS
[2011.04.14 19:06:49 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\WIPE
[2010.04.30 19:45:57 | 000,000,000 | ---D | M] -- C:\Users\sdasd\AppData\Roaming\Notepad++
[2010.03.13 13:10:44 | 000,000,000 | ---D | M] -- C:\Users\sdasd\AppData\Roaming\Opera
[2010.05.18 17:10:23 | 000,000,000 | ---D | M] -- C:\Users\sdasd\AppData\Roaming\Template
[2012.03.06 21:13:59 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2009.12.03 22:42:42 | 000,000,000 | -HSD | M] -- C:\Users\Medico\AppData\Roaming\.#
[2010.08.08 19:29:49 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\acccore
[2010.07.19 19:42:14 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Adobe
[2009.12.24 16:02:32 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Ahead
[2011.12.12 21:05:59 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Apple Computer
[2009.11.26 12:23:16 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\ATI
[2010.08.03 17:03:07 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\DivX
[2009.12.09 20:12:19 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\dvdcss
[2009.12.28 01:38:56 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\FileZilla
[2009.11.26 14:06:40 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\GameConsole
[2012.03.07 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\gnupg
[2009.11.26 12:26:26 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Google
[2009.11.26 12:20:46 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Identities
[2012.02.19 16:18:27 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\iolo
[2011.06.12 21:06:42 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\JonDo
[2009.11.26 12:22:27 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Macromedia
[2012.02.16 00:37:19 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Malwarebytes
[2009.08.22 07:05:58 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Media Center Programs
[2012.01.29 15:45:16 | 000,000,000 | --SD | M] -- C:\Users\Medico\AppData\Roaming\Microsoft
[2009.11.26 12:36:00 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Mozilla
[2011.08.22 16:23:13 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\OpenCandy
[2010.01.15 20:34:45 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Opera
[2010.06.19 12:47:21 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\PC Suite
[2010.05.28 23:57:02 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Samsung
[2009.11.26 14:32:19 | 000,000,000 | RH-D | M] -- C:\Users\Medico\AppData\Roaming\SecuROM
[2012.02.23 22:56:38 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Skype
[2011.01.07 18:06:08 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\skypePM
[2009.12.01 18:23:18 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\TeamViewer
[2010.01.24 12:33:19 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Thunderbird
[2009.12.29 01:16:50 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\Trillian
[2011.06.12 21:13:15 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\vlc
[2011.04.16 11:47:02 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\WFDS
[2009.12.03 17:57:13 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\WinRAR
[2011.04.14 19:06:49 | 000,000,000 | ---D | M] -- C:\Users\Medico\AppData\Roaming\WIPE
< %APPDATA%\*.exe /s >
[2009.12.27 19:35:11 | 000,010,134 | R--- | M] () -- C:\Users\Medico\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\Foren.exe
[2009.12.27 19:35:11 | 000,000,766 | R--- | M] () -- C:\Users\Medico\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\htmledit.exe
[2010.07.23 11:19:56 | 000,010,134 | R--- | M] () -- C:\Users\Medico\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2011.08.22 16:23:14 | 000,416,160 | ---- | M] () -- C:\Users\Medico\AppData\Roaming\OpenCandy\OpenCandy_82A335B3E98045678A61589244799DC2\LatestDLMgr.exe
[2011.08.01 23:38:30 | 001,872,896 | ---- | M] (Speedchecker Limited                                        ) -- C:\Users\Medico\AppData\Roaming\OpenCandy\OpenCandy_82A335B3E98045678A61589244799DC2\pcspeedup.exe
< %SYSTEMDRIVE%\*.exe >
< End of report >



Alt 10.03.2012, 16:35   #13
/// Winkelfunktion
/// TB-Süch-Tiger™
Broken.OpenCommand Virus

Broken.OpenCommand Virus

Das Log zippen und anhängen=> http://www.trojaner-board.de/69886-a...tml#post566999
Logfiles bitte immer in CODE-Tags posten

Alt 10.03.2012, 17:28   #14
Broken.OpenCommand Virus

Broken.OpenCommand Virus

Bitte sehr.

Alt 12.03.2012, 12:52   #15
/// Winkelfunktion
/// TB-Süch-Tiger™
Broken.OpenCommand Virus

Broken.OpenCommand Virus

O2 - BHO: (DivX Plus Web Player HTML5 <video>)
Gehörst du auch zur der Fraktion, die sich Serien und Kinofilme über dubiose Portale anschaut?
Wenn ja: in Zukunft Finger weg, diese illegalen Portale verbreiten Malware und wenn du in Zukunft malwarefrei sein wilst, musst du auf legale Alternativen ausweichen und auf solche riskanten Streamingseiten verzichten!
Logfiles bitte immer in CODE-Tags posten


