Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Externe Festplatte infiziert? wscript.exe

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 24.08.2013, 18:57   #1
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Liebe Community,

ich habe mir wohl einen Virus auf meiner externen Festplatte eingefangen. Das befürchte ich zumindest.
Meine Ordner werden alle als Verknüpfungen dargestellt. Verkünpfungsziel ist eine Datei im "system32"-Ordner - wscript.exe. Mein Virenscanner (avast) bestätigt auch, dass er einen solchen Trojaner gefunden hätte.
Trotz Löschung des Trojaners mit dem Scanner ändert sich das Problem nicht.
Ein Scan mit Anti-Malwarebytes ergab einige Treffer, darunter aber nicht den. Ich habe alle Treffer beseitigt. Das Problem existiert weiter.
Ich bin ratlos...

Danke schonmal!

Alt 24.08.2013, 19:01   #2
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Hallo,

kannst du bitte die genaue Fundmeldung von avast posten?
Steck die externe Festplatte bitte an und teile mir ihren Laufwerksbuchstaben mit.


Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
  • Doppelklick auf die OTL.exe.
  • Unter Extra Registry, wähle bitte Use SafeList.
  • Setze den Haken bei Scan all Users.
  • Klicke nun auf Run Scan.
  • Wenn der Scan beendet ist, werden 2 Logfiles (OTL.txt und Extras.txt) erstellt.
  • Poste den Inhalt dieser Logfiles hier in den Thread.
__________________

__________________

Alt 24.08.2013, 19:12   #3
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Die Benachrichtigung von avast hab ich leider nicht mehr.

Meine Festplatte ist angeschlossen, Laufwerk E:!

Scan mit OTL läuft.

OTL-Logfile OTL.txt

Code:
ATTFilter
OTL logfile created on: 24.08.2013 20:04:02 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Matthias\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,02 Gb Available Physical Memory | 34,92% Memory free
11,57 Gb Paging File | 7,55 Gb Available in Paging File | 65,27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 318,92 Gb Free Space | 71,97% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 437,63 Gb Free Space | 46,99% Space Free | Partition Type: FAT32
 
Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.08.24 20:02:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Matthias\Downloads\OTL.exe
PRC - [2013.08.17 15:14:18 | 000,276,376 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.08.06 01:30:06 | 000,164,816 | ---- | M] (APN LLC.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
PRC - [2013.08.06 01:29:59 | 001,601,488 | ---- | M] (APN) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
PRC - [2013.07.25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013.07.21 13:52:03 | 001,861,512 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
PRC - [2013.05.16 10:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013.05.16 10:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013.05.15 13:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.04.04 14:50:32 | 000,887,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012.05.30 13:55:26 | 001,112,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
PRC - [2012.05.02 01:03:44 | 002,279,304 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
PRC - [2012.04.25 06:18:10 | 000,784,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
PRC - [2012.04.06 12:17:04 | 002,796,112 | ---- | M] (Samsung Electronics CO., LTD.) -- C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
PRC - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () -- C:\Program Files (x86)\XSManager\WTGService.exe
PRC - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2012.02.21 12:55:16 | 000,936,272 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
PRC - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
PRC - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\irstrtsv.exe
PRC - [2012.01.31 08:56:48 | 001,640,328 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
PRC - [2012.01.28 07:38:52 | 004,466,256 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2012.01.04 20:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2010.07.08 23:05:12 | 000,160,992 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\starter4g.exe
PRC - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\service4g.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.08.17 15:14:17 | 003,551,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.07.21 13:52:02 | 016,166,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
MOD - [2013.05.16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013.05.16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2013.04.21 21:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013.04.21 21:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.09.08 12:40:10 | 001,645,056 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2011.02.16 18:03:20 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2012.03.30 05:54:10 | 000,079,664 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe -- (ExpressCache)
SRV:64bit: - [2012.02.02 15:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2011.12.08 03:44:04 | 000,594,704 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:64bit: - [2011.12.08 03:43:56 | 000,273,168 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.12.08 03:43:48 | 000,618,256 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.12.08 03:43:44 | 000,148,752 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.12.05 02:30:50 | 000,659,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.12.05 01:55:36 | 000,135,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV - [2013.08.22 21:53:23 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.08.17 15:14:17 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.08.06 01:30:06 | 000,164,816 | ---- | M] (APN LLC.) [Auto | Running] -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe -- (APNMCP)
SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.11.23 10:20:45 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\XSManager\WTGService.exe -- (WTGService)
SRV - [2012.03.12 01:46:40 | 000,274,200 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe -- (SamsungDeviceConfigurationWinService)
SRV - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R)
SRV - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysWOW64\irstrtsv.exe -- (irstrtsv)
SRV - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\Windows\service4g.exe -- (XS Stick Service)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013.06.28 00:54:02 | 001,030,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.06.28 00:54:02 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013.06.28 00:54:02 | 000,189,936 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013.05.09 10:59:07 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013.05.09 10:59:07 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013.05.09 10:59:07 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013.05.09 10:59:06 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013.05.09 10:59:06 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013.01.22 22:32:33 | 000,117,888 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV:64bit: - [2012.12.13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.30 05:54:16 | 000,095,024 | ---- | M] (Diskeeper Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\excsd.sys -- (excsd)
DRV:64bit: - [2012.03.30 05:54:16 | 000,023,344 | ---- | M] (Diskeeper Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\excfs.sys -- (excfs)
DRV:64bit: - [2012.03.14 12:49:20 | 000,242,512 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.16 15:08:26 | 000,031,216 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2012.02.14 05:38:56 | 000,060,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (ibtfltcoex)
DRV:64bit: - [2012.02.07 02:49:04 | 000,026,504 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irstrtdv.sys -- (irstrtdv)
DRV:64bit: - [2012.01.09 12:49:26 | 000,225,920 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UBDA.sys -- (RTL2832UBDA)
DRV:64bit: - [2012.01.09 12:49:26 | 000,049,152 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832U_IRHID.sys -- (RTL2832U_IRHID)
DRV:64bit: - [2012.01.09 12:49:26 | 000,039,680 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UUSB.sys -- (RTL2832UUSB)
DRV:64bit: - [2012.01.05 13:36:54 | 014,652,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012.01.04 20:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012.01.04 20:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012.01.04 20:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011.12.20 10:38:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2011.12.20 10:38:36 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.12.20 10:38:36 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.12.05 21:23:08 | 000,331,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.12.01 15:51:00 | 011,417,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.11.30 04:19:48 | 000,747,008 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.11.30 04:19:46 | 000,094,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.11.29 12:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.11.23 16:02:20 | 000,648,808 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.11.10 11:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.11.05 14:04:42 | 000,513,600 | ---- | M] (ITETech                  ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF15BDA.sys -- (AF9035BDA)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.28 08:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=119816&tt=gc_&babsrc=HP_ss&mntrId=4CA7C48508CCFD54
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_din2g&mntrId=4CA7C48508CCFD54&affID=119357&tt=180613_ndt6&tsp=4921
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=6362549110274455&q={searchTerms}
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com.anonymize-me.de/?anonymto=687474703A2F2F6D7973746172742E696E63726564696261722E636F6D2F6D623230312F3F7365617263683D7B7365617263685465726D737D266C6F633D49425F445326613D3650515178665374586A26693D3236&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "hxxp://www.domradio.de/"
FF - prefs.js..extensions.enabledAddons: gmailwatcher%40sonthakit:1.61
FF - prefs.js..extensions.enabledAddons: addon%40codecs.com:1.0
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17
FF - prefs.js..extensions.enabledAddons: toolbar_ORJ-V7%40apn.ask.com:21.51433
FF - prefs.js..extensions.enabledAddons: %7B74fa6b20-2ae6-4584-a4fd-4ac734f8d210%7D:3.3
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40delta.com:1.5.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.18 21:40:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\ht66y4t0.default\extensions\firejump@firejump.net
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2013.06.04 01:49:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\Extensions
[2013.08.24 19:46:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions
[2013.08.23 19:16:57 | 000,000,000 | ---D | M] (BargainJoy) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}
[2013.07.20 10:34:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.06.22 12:22:49 | 000,000,000 | ---D | M] ("Safe ads") -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\addon@codecs.com
[2013.08.24 19:38:25 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\ffxtlbr@delta.com
[2013.06.22 12:21:23 | 000,000,000 | ---D | M] (WebCake) -- C:\Users\Matthias\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\plugin@getwebcake.com
[2013.03.21 10:23:42 | 000,226,606 | ---- | M] () (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\gmailwatcher@sonthakit.xpi
[2013.08.12 02:31:09 | 000,454,970 | ---- | M] () (No name found) -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\toolbar_ORJ-V7@apn.ask.com.xpi
[2013.07.13 08:41:45 | 000,002,545 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\ask-search.xml
[2013.03.21 13:05:26 | 000,002,308 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\askcom.xml
[2013.06.22 12:21:24 | 000,006,546 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\babylon.xml
[2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\BrowserProtect.xml
[2013.06.22 12:21:39 | 000,001,294 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\delta.xml
[2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\googlede.xml
[2013.05.27 15:56:30 | 000,001,304 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\holasearch.xml
[2013.04.02 21:54:32 | 000,002,683 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\Search_Results.xml
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (Recorder Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{10743931-94DF-476f-A987-4391233C17A2}
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.08.17 15:14:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013.04.02 21:54:32 | 000,002,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {120A8821-2BEE-4C29-BCDA-62C577781992} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL File not found
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.5\bh\delta.dll (Delta-search.com)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.5\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKLM..\Run: [ApnTBMon] C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (APN)
O4 - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files (x86)\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [starter4g] C:\Windows\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DelayedDesktopSwitchTimeout = 0
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4750731-9CEA-48CB-B383-6C430621A66D}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN64C~1.DLL) - C:\ProgramData\Wincert\win64cert.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN32C~1.DLL) - C:\ProgramData\Wincert\win32cert.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{98c6118b-3358-11e2-9bc4-c48508ccfd57}\Shell - "" = AutoRun
O33 - MountPoints2\{98c6118b-3358-11e2-9bc4-c48508ccfd57}\Shell\AutoRun\command - "" = D:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.08.24 19:38:29 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\BabSolution
[2013.08.24 19:38:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta
[2013.08.24 19:38:23 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Delta
[2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Simply Super Software
[2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Simply Super Software
[2013.08.24 19:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2013.08.24 18:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2013.08.24 18:58:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013.08.24 18:58:27 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\windows\SysNative\sdnclean64.exe
[2013.08.24 18:58:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013.08.24 18:17:01 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\Malwarebytes
[2013.08.24 18:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.08.24 18:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.08.24 18:16:38 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2013.08.24 18:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.08.24 13:34:32 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle
[2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2013.08.22 21:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2013.08.22 21:49:57 | 000,000,000 | -HSD | C] -- C:\Users\Matthias\AppData\Roaming\750
[2013.08.22 21:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013.08.22 21:47:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2013.08.22 21:45:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2013.08.22 21:45:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013.08.22 21:45:20 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2013.08.22 21:43:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys
[2013.08.22 19:38:33 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\DAEMON Tools Lite
[2013.08.22 19:38:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2013.08.22 19:37:53 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2013.08.22 19:22:30 | 000,000,000 | -HSD | C] -- C:\74b36
[2013.08.17 15:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.08.12 22:21:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2013.08.11 22:10:35 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Schlag den Raab - Das 3. Spiel
[2013.08.11 22:10:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer
[2013.08.11 22:10:19 | 000,000,000 | ---D | C] -- C:\Users\Matthias\AppData\Roaming\ProtectDISC
[2013.08.11 22:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
[2013.08.11 22:02:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bitComposer Games
[2013.08.04 07:23:18 | 000,000,000 | ---D | C] -- C:\windows\SysNative\MRT
[2013.07.31 16:32:59 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Desktop\Libori-Dienstag
 
========== Files - Modified Within 30 Days ==========
 
[2013.08.24 19:53:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013.08.24 19:48:51 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.08.24 19:48:51 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.08.24 19:48:09 | 001,498,742 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013.08.24 19:48:09 | 000,654,400 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2013.08.24 19:48:09 | 000,616,242 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013.08.24 19:48:09 | 000,130,240 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2013.08.24 19:48:09 | 000,106,622 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013.08.24 19:43:52 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2013.08.24 19:43:51 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.08.24 19:41:34 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013.08.24 19:32:00 | 000,001,114 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.08.24 19:21:00 | 000,000,298 | ---- | M] () -- C:\windows\tasks\DSite.job
[2013.08.24 19:14:11 | 000,462,896 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013.08.24 18:37:59 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2013.08.24 17:47:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2013.08.24 10:48:39 | 000,000,320 | ---- | M] () -- C:\windows\tasks\MT66 Software Update.job
[2013.08.23 19:16:42 | 000,000,005 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\WBPU-TTL.DAT
[2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys
[2013.08.22 21:35:21 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2013.08.20 22:24:25 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00003553.LCS
[2013.07.31 17:01:43 | 000,000,072 | ---- | M] () -- C:\Users\Matthias\AppData\Roaming\WB.CFG
 
========== Files Created - No Company Name ==========
 
[2013.08.24 18:58:38 | 000,001,355 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013.08.24 13:34:32 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2013.08.11 22:10:22 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00003553.LCS
[2013.07.27 00:21:11 | 000,000,072 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WB.CFG
[2013.07.22 21:20:00 | 000,010,455 | ---- | C] () -- C:\Users\Matthias\Friebe_elster_2048.pfx
[2013.06.28 11:27:50 | 000,000,005 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WBPU-Q2-TTL.DAT
[2013.06.22 13:21:04 | 000,000,005 | ---- | C] () -- C:\Users\Matthias\AppData\Roaming\WBPU-TTL.DAT
[2013.06.22 12:22:31 | 000,079,360 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2013.06.22 12:22:17 | 000,645,632 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2013.06.22 12:22:17 | 000,240,640 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2013.06.22 12:22:06 | 000,715,038 | ---- | C] () -- C:\windows\unins000.exe
[2013.06.22 12:22:06 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll
[2013.06.22 12:22:06 | 000,002,000 | ---- | C] () -- C:\windows\unins000.dat
[2013.06.22 12:16:53 | 000,376,832 | ---- | C] () -- C:\windows\SysWow64\xvid.dll
[2013.06.21 22:56:26 | 000,000,218 | ---- | C] () -- C:\Users\Matthias\.recently-used.xbel
[2013.05.27 15:54:57 | 000,178,688 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2013.03.04 20:08:50 | 000,007,168 | ---- | C] () -- C:\Users\Matthias\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.12.01 00:42:45 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll
[2012.11.23 10:20:48 | 000,338,432 | ---- | C] () -- C:\windows\SysWow64\sqlite36_engine.dll
[2012.06.30 13:44:34 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2012.06.30 12:37:45 | 000,003,586 | ---- | C] () -- C:\windows\HotFixList.ini
[2012.03.13 04:59:22 | 000,963,912 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2012.03.13 04:59:22 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin
[2012.03.13 04:59:19 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin
[2012.03.13 04:59:19 | 000,261,208 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2012.03.13 04:59:16 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012.03.13 04:59:14 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll
[2012.03.13 04:59:14 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2012.03.13 04:59:13 | 013,184,512 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll
[2012.02.02 15:08:26 | 000,001,536 | ---- | C] () -- C:\windows\SysWow64\IusEventLog.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.08.22 21:49:57 | 000,000,000 | -HSD | M] -- C:\Users\Matthias\AppData\Roaming\750
[2013.07.07 21:38:34 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Audacity
[2013.03.05 00:52:41 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\avidemux
[2013.08.24 19:38:29 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\BabSolution
[2013.03.04 23:49:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Babylon
[2013.04.02 21:47:05 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Canneverbe Limited
[2013.06.22 12:22:09 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\CDXReader
[2013.08.22 21:44:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DAEMON Tools Lite
[2013.06.22 12:21:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DealPly
[2013.08.24 19:38:23 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Delta
[2013.03.04 23:49:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DesktopIconForAmazon
[2013.08.24 19:15:14 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Dropbox
[2013.06.22 12:21:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DSite
[2013.04.02 22:38:01 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DVDVideoSoft
[2013.04.02 22:27:41 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.03.09 01:42:25 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\elsterformular
[2012.11.23 09:59:39 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Engelmann Media
[2013.07.30 16:07:03 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FileZilla
[2012.12.01 00:42:56 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FreeAudioPack
[2013.04.02 21:54:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\FreeFLVConverter
[2013.06.21 22:56:26 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Gaupol
[2013.06.21 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\gtk-2.0
[2013.07.20 00:59:27 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\ICQ
[2013.08.22 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\IrfanView
[2013.06.22 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\LavFilters
[2013.01.09 16:51:45 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\MAY Computer
[2013.05.11 19:55:57 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\MusE
[2012.11.23 10:20:45 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\OCS
[2013.03.24 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\OpenOffice.org
[2012.11.23 10:20:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Opera
[2013.01.12 15:40:50 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Origin
[2013.05.27 15:59:34 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\PerformerSoft
[2013.08.11 22:10:19 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\ProtectDISC
[2013.01.18 16:33:32 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Scribus
[2013.08.24 19:06:20 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Simply Super Software
[2013.07.01 20:29:04 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Subtitle Edit
[2012.12.28 01:03:59 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\TerraTec
[2013.06.22 12:22:15 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Ultimate Codec Packages
[2013.04.02 22:22:35 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Video DVD Maker FREE
[2012.11.17 22:09:46 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\Visan
[2013.03.01 10:17:13 | 000,000,000 | ---D | M] -- C:\Users\Matthias\AppData\Roaming\XSManager
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:CB0AACC9

< End of report >
         
OTL-Logfile Extras.txt

Code:
ATTFilter
OTL Extras logfile created on: 24.08.2013 20:04:02 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Matthias\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,02 Gb Available Physical Memory | 34,92% Memory free
11,57 Gb Paging File | 7,55 Gb Available in Paging File | 65,27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 318,92 Gb Free Space | 71,97% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 437,63 Gb Free Space | 46,99% Space Free | Partition Type: FAT32
 
Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0436CEA9-698E-430E-BB1F-09C80EC35353}" = rport=445 | protocol=6 | dir=out | app=system | 
"{2223CF43-4B6C-464E-95D5-87BD29B7BD99}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{241D0DCC-2DDF-419B-8BE3-BB38F3116349}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2E3C6DD4-847E-4FED-BA6C-FC9ADDB6A283}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{387AA4CE-D36B-4095-8E21-0EE33291AE69}" = rport=139 | protocol=6 | dir=out | app=system | 
"{4563C9C8-F97B-44C2-9C72-0ECDECD44806}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{4E104AC3-404C-4FE7-BAD4-534AD76A327E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{57DDE9F5-0E20-4066-8D5E-87E7219E7CE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{58229A73-E337-47EF-8DFB-4D2394B740B9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{586B5219-FA5E-48A8-B7D2-5E8569AF6828}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{73A80D95-D754-471F-B96B-A447112F05CB}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{779648A7-8399-4D24-9244-A1E83021E7E0}" = rport=137 | protocol=17 | dir=out | app=system | 
"{78C841EF-F0C0-42D5-8013-75FCEF706F71}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{7D7B7F00-C187-40C7-9018-041EE1028310}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{7E47EF18-E911-444D-AA49-339B68BB6AA6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{8A98285A-CDDE-425A-966D-4D4B314CBED4}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | 
"{930D0493-BCFB-4EEE-AF4C-3D216119D30A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{93A83531-FDD6-4584-AC3A-3A11D9170305}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{9BD29CBC-0ACB-49A4-9ECD-FC798377B76A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{9E88BC59-8DB5-4920-A329-5EEC34462AAA}" = lport=138 | protocol=17 | dir=in | app=system | 
"{9EFC8579-2987-4E44-820C-AE17499A5C3A}" = lport=137 | protocol=17 | dir=in | app=system | 
"{AD768F5D-B99C-4CEC-BB46-9AAE7FDCCE79}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B1744E19-BE6C-4CF0-A48D-D5F299233371}" = lport=139 | protocol=6 | dir=in | app=system | 
"{B6C64B38-9574-488E-B6B5-169DDBCC822E}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{B87E108D-46A8-4D4A-8BB8-7ED899FB4800}" = lport=445 | protocol=6 | dir=in | app=system | 
"{C1675484-5844-40DF-8CE9-ED048B4EC999}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C287B71D-60A8-4136-A44C-3DB32AC18009}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{C2EBCC5B-7A36-4B70-AB77-658A409599F3}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{CF50AD87-6DD7-496E-8836-5C7A82B929DF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{F17A45E0-B598-4C3D-AC77-9F45A3FF97B7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{F2882A53-5A64-443D-84F8-C4F66CF5A83B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{F3312CE5-78E4-4186-A6AC-4403312B87C2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{F521DB80-92E7-4261-B7A8-B0866A409782}" = rport=138 | protocol=17 | dir=out | app=system | 
"{FF8B6CEE-7C21-4173-8A4E-75F3C11D307C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01641C9D-49C5-4FDE-B1B4-475B3C231116}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{06AD03B2-E7C3-4DF6-9485-F5E1B73B3B07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{0FB3C0B7-A94A-486A-AA6E-9DC0E21BE9CA}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | 
"{19AAC066-F4BF-40E9-8381-A311040607DE}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | 
"{1EAFC354-C540-4593-8176-686CD1F16040}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{233491A6-87B6-4ACD-883D-585AC173F445}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{240AFACA-886B-4369-A43D-31C36D6E4B35}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | 
"{24F33176-70B0-47E8-968E-9FBA6925D002}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{264EE886-100A-46EA-AA21-9F9968300A20}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe | 
"{28197DE6-8E5E-4B6E-AA3D-E088A8EC07EF}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | 
"{33F5B46E-D0F7-4631-82A9-C1965BF1DE6F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{347EDD06-238D-4147-B351-118BA3E622A3}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | 
"{3496B250-99E7-4043-B5E3-CA98D7A57000}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | 
"{378356E6-85AE-48C8-92A7-6A03C9B46F7D}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | 
"{3A2D54B9-1180-4929-BC7F-530D13FED6C3}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | 
"{3C27AD16-779C-4CAE-89B2-C939400A896F}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | 
"{401EA2B1-0323-45BF-9BDB-68CF4FB608A2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{460297C1-3816-4B33-A5C1-3AA01F6B77D0}" = protocol=6 | dir=out | app=system | 
"{4B3DAEE9-7164-4459-B7D9-B852F79178AD}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\videospin.exe | 
"{544750CB-19C4-4508-BDDF-20FE8A8D0D57}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{599FFCA2-1F30-44DA-8CD7-2DA8634D64AE}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | 
"{5E858310-0E4A-4628-922B-78B0C2E6AAC9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{63170B9B-C412-43E6-B9C6-1BDB4C64FA30}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | 
"{6341CDE1-DDF0-4322-960B-6B2C6D2F19A1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{65B9BD46-F9C5-4755-B839-3D7AF1872101}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{674E1A3A-0FE8-4F3D-A678-8780C1994485}" = protocol=6 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | 
"{6761AD54-38A7-4F93-80BB-7DEFC3D8B394}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{756EFEE2-BEBC-4F44-A064-2D0D99295DF0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{7AD77024-60F2-4216-913F-AEFC8FC944FA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{84B97CEE-C7C6-46D4-AB7A-E50A077AF052}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{855637EF-E060-430A-AB73-36512B38B93C}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | 
"{88B16A89-57F7-4F39-9F5F-99DEB1D90397}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{99215DB0-E3EF-4A08-B0C9-E10648EB17EC}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{A0E448D2-620A-42EB-BC45-980FD520F178}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{A3DDED73-CD7E-491F-BEFC-4D0AEC69C18B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BBB76FB6-0A16-46AF-9ACA-68FDB78D753E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C03A4322-16D7-470C-9318-334E0A28155B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C0FB93F2-E787-469F-8F09-FAB16C3B31E6}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | 
"{C56AB1E6-C319-4241-9761-80666D2510DE}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | 
"{C9CC4DC7-73A2-4E4D-8151-4F7F9986A749}" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\umi.exe | 
"{D601ECD8-BED2-492F-9967-E177D7044DBB}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | 
"{D9135861-BC13-4453-BF8B-0A3D1EE6B203}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | 
"{DA7B6BCF-AEE0-4A14-90CD-EA7B55D1153E}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe | 
"{DD02B452-C91B-47C5-9562-E85E14B9F310}" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\videospin\programs\rm.exe | 
"{DD8E06E0-2832-480A-8DFE-19857E416C84}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{DDBD7845-C6DD-48B2-8731-601F03419C87}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7m\icq.exe | 
"{E0FFCA86-31D7-47F0-99C1-BFDC4A29DC36}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\insttool.exe | 
"{E10CEE13-CEB5-44E0-8021-09E6FCDE89F3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{E3E98352-A3C7-440C-952A-581FFD71396B}" = protocol=17 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | 
"{E55E3451-BAFC-4076-9C6C-BA7EB806C269}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe | 
"{E6418CE4-8820-4EB7-89EF-51D09F6A6764}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | 
"{E6461C57-A902-4519-AB8E-60996004BDFF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{E90254D6-94F5-4D30-AC92-672AB2BB75B8}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe | 
"{EAAE70F4-723F-47EA-8CB0-D775C93289E8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{EB7EC6C7-544C-4A35-9E36-AB1363D4C5AD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{EF409194-6CBE-4535-A5F0-1CAEAD0DB336}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe | 
"{FE4B1515-F2F3-4809-95B0-5EB4450DD4C3}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\insttool.exe | 
"{FED98362-9B95-4659-8CF9-4B8B59DF2023}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"TCP Query User{33F7A501-8820-4A41-8EC1-0476E68FF8C9}C:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | 
"TCP Query User{6280D4BC-5F2C-4B10-B398-A2938BB36E10}C:\program files (x86)\origin games\fifa 12\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | 
"TCP Query User{75274A09-3E10-4C7E-8672-B6E184938F22}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | 
"TCP Query User{A1BA3AD1-0BD6-45EA-A854-57BBF45CE1C1}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | 
"UDP Query User{6D93E194-5F39-4467-9399-B966897609EB}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | 
"UDP Query User{D43E0A68-C01B-44BF-9AE3-16F98CCD6678}C:\program files (x86)\origin games\fifa 12\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | 
"UDP Query User{D6DC1BF3-C301-403B-9855-77B2F6007C1B}C:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\matthias\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{F8EEF5E8-3AAC-4BEE-AE7F-3A6F40B5AF41}C:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\versioncheck\versioncheck.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}" = Easy Support Center
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
"{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}" = Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed
"{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}" = ExpressCache
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{3C28BFD4-90C7-3138-87EF-418DC16E9598}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4ED70939-4D42-48E4-B573-13E3B8B13ADF}" = gs_x64
"{520C4DD4-2BC7-409B-BA48-E1A4F832662D}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{76FF0F03-B707-4332-B5D1-A56C8303514E}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0017-0407-1000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (German) 2010
"{90140000-0017-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{D3646908-5C00-4C50-B9A5-9F1D1A83B452}" = Microsoft SharePoint Designer 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0000-1000-0000000FF1CE}" = Microsoft Office Publisher 2010
"{90140000-0019-0000-1000-0000000FF1CE}_Office14.PUBLISHER_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.OMUI.de-de_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.OMUI.de-de_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PUBLISHER_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-1000-0000000FF1CE}_Office14.OMUI.de-de_{3013A793-10A7-4D1F-B8B4-2FAA82F4D259}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PUBLISHER_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{98782D5D-A9EE-43C6-88AD-B50AD8530E78}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PUBLISHER_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010
"{90140000-0043-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{8DFD91C7-66AE-4E54-9901-5D5F401AD329}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-0044-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{8299B64F-1537-4081-974C-033EAB8F098E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{90140000-00BA-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{BBBD3986-9A9D-402A-BA73-CCDE3EF0ED77}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0100-0407-1000-0000000FF1CE}" = Microsoft Office O MUI (German) 2010
"{90140000-0100-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{E2D2FA5C-6353-4F7B-9ABF-F548759A5D35}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-0101-0407-1000-0000000FF1CE}" = Microsoft Office X MUI (German) 2010
"{90140000-0101-0407-1000-0000000FF1CE}_Office14.OMUI.de-de_{EA7ED796-796A-4C86-8BCB-88A55C89E32C}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PUBLISHER_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}" = WebCake 3.00
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DF7756DD-656A-45C3-BA71-74673E8259A9}" = Intel® PROSet/Wireless WiFi Software
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F76C9B9E-8F61-461D-B4AE-EC926C3A8D46}" = eDocPrintPro
"DesktopIconAmazon" = Desktop Icon für Amazon
"Elantech" = ETDWare PS/2-X64 10.7.13.1_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Office14.OMUI.de-de" = Microsoft Office Language Pack 2010 - German/Deutsch
"Office14.PUBLISHER" = Microsoft Publisher 2010
"ProInst" = Intel PROSet Wireless
"Scribus 1.4.2" = Scribus 1.4.2 (64bit)
"SearchAnonymizer" = SearchAnonymizer
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03CC9D58-B132-4CC0-A521-4F3660AA43C7}" = Movie Maker
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{12F81925-F3C1-40DB-91F7-777817974319}" = Easy File Share
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Settings
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9.6
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20B1B020-DEAE-48D1-9960-D4C3185D758B}" = Phase 5 HTML-Editor
"{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3CBD94C1-BA15-488C-888B-D8DD296CC6DC}" = Fotogalerie
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{40F4FF7A-B214-4453-B973-080B09CED019}" = Absolute Reminder
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5
"{4F524A2D-5637-006A-76A7-A758B70C0300}" = Ask Toolbar
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74D5F45B-EC9F-4083-9493-364D159FFFBE}_is1" = DivXLand Media Subtitler 2.1.0
"{770103E9-E1C3-48C9-812B-2982C7070575}_is1" = Pazera Free MOV to AVI Converter 1.4
"{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}" = ICQ7M
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{93F34C5C-ACAA-48F3-9B26-70359A117F12}" = Intel(R) WiDi
"{94CDEFC5-D87D-4122-8F06-275AC30B1314}" = Fast Flash Sleep Resume
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Deutsch
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B654E683-93ED-4B4F-BED8-4CE9C0B8D3ED}" = Multimedia POP
"{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack
"{B750B5C2-CC17-4967-905B-29F4EB986131}" = Software Launcher
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{cb41fc68-4442-4f7f-b22f-8f31c74897ac}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106
"{D848E062-BA12-4855-0001-E7C196D614BE}" = MyTube Bigpack HD Free
"{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1" = FireJump
"{DE256D8B-D971-456D-BC02-CB64DA24F115}" = Easy Software Manager
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common
"{E630D30A-79EE-407A-8F51-9D57D1F45230}" = gs_x86
"{EA8ADAA9-6671-4839-A51E-0C6792B78F3E}" = FIFA 12
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EDE7A262-DB20-4432-A630-2ACEE186C416}" = Easy Migration
"{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}" = E-POP
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5212949-60B3-43FC-A178-4A7B0BEDAD69}" = eDocPrintPro v3.17.0
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27)
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) OpenCL CPU Runtime
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin
"3D073343-CEEB-4ce7-85AC-A69A7631B5D6" = Intel(R) Rapid Start Technology
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ANSTOSS 3_is1" = ANSTOSS 3
"Audacity_is1" = Audacity 2.0.2
"avast" = avast! Free Antivirus
"Cinergy T Stick RC" = Cinergy T Stick RC V86.001.1129.2011
"Cinergy T-Stick MKII" = Cinergy T-Stick MKII V9.06.3.01
"codecs" = codecs
"DAEMON Tools Lite" = DAEMON Tools Lite
"DC-Bass Source" = DC-Bass Source 1.3.0
"delta" = Delta toolbar  
"Disketch" = Disketch Disc Label Software
"Doxillion" = Doxillion Document Converter
"EasyCash&Tax_is1" = EasyCash&Tax 1.57
"ECTPlugAnlagenverzeichnis_is1" = ECTPlugAnlagenverzeichnis 1.5
"Elster-Export Plugin für EasyCash&Tax_is1" = Elster-Export 1.13
"ElsterFormular" = ElsterFormular
"ffdshow_is1" = ffdshow v1.1.4399 [2012-03-22]
"FileZilla Client" = FileZilla Client 3.6.0.1
"Free FLV Converter_is1" = Free FLV Converter V 7.5.0
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 7.2
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2
"Freemake Video Converter_is1" = Freemake Video Converter Version 4.0.1
"Google Chrome" = Google Chrome
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.9.0 (Standard)
"LAME_is1" = LAME v3.99.3 (for Windows)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Mozilla Firefox 23.0.1 (x86 de)" = Mozilla Firefox 23.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MuseScore" = MuseScore 1.3
"OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5
"Origin" = Origin
"Passbild-Generator_is1" = Bewerbungsfoto-/Passbild-Generator v3.5a
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"SDR3" = Schlag den Raab - Das 3. Spiel
"Searchqu Toolbar" = Windows Searchqu Toolbar
"SubtitleCreator" = SubtitleCreator
"SubtitleEdit_is1" = Subtitle Edit 3.3.6
"Trojan Remover_is1" = Trojan Remover 6.8.8
"VLC media player" = VLC media player 2.0.6
"WinLiveSuite" = Windows Live Essentials
"XSManager" = XSManager
"Xvid Video Codec 1.3.2" = Xvid Video Codec
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"DSite" = Update for Ultimate Codec
"Ultimate Codec Packages" = Ultimate Codec Packages
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 03.08.2013 16:26:21 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2059
 
Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6383514
 
Error - 03.08.2013 18:12:43 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6383514
 
Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6384513
 
Error - 03.08.2013 18:12:44 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6384513
 
Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6385527
 
Error - 03.08.2013 18:12:45 | Computer Name = Matthias_Friebe | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6385527
 
[ System Events ]
Error - 24.06.2013 14:26:38 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003
Description = 
 
Error - 25.06.2013 12:28:39 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003
Description = 
 
Error - 25.06.2013 13:35:07 | Computer Name = Matthias_Friebe | Source = DCOM | ID = 10010
Description = 
 
Error - 25.06.2013 13:37:02 | Computer Name = Matthias_Friebe | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   cdrom
 
Error - 25.06.2013 13:43:47 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003
Description = 
 
Error - 25.06.2013 18:28:37 | Computer Name = Matthias_Friebe | Source = DCOM | ID = 10005
Description = 
 
Error - 25.06.2013 18:28:37 | Computer Name = Matthias_Friebe | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden
 Fehlers nicht gestartet:   %%109
 
Error - 25.06.2013 18:59:17 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003
Description = 
 
Error - 26.06.2013 17:04:58 | Computer Name = Matthias_Friebe | Source = bowser | ID = 8003
Description = 
 
Error - 26.06.2013 19:30:31 | Computer Name = Matthias_Friebe | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR6 gefunden.
 
 
< End of report >
         
__________________

Alt 24.08.2013, 19:33   #4
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Ok, Platte angesteckt lassen.


Schritt 1

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.




Schritt 2
  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:
ATTFilter
dir /a /b "E:\" /c
         
  • Schliesse bitte alle anderen Programme.
  • Klicke nun auf None (deutsch "Nichts") und danach auf den Scan Button.
  • Kopiere danach den Inhalt der OTL.txt hier in deinen Thread.



Bitte poste in deiner nächsten Antwort:
  • Log von Combofix
  • Log von OTL
__________________
cheers,
Leo

Alt 24.08.2013, 20:14   #5
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Combofix
Combofix Logfile:
Code:
ATTFilter
ComboFix 13-08-22.01 - Matthias 24.08.2013  20:43:31.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.5926.2861 [GMT 2:00]
ausgeführt von:: c:\users\Matthias\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Delta\delta\1.8.24.5\deltaApp.dll
c:\program files (x86)\Delta\delta\1.8.24.5\deltaEng.dll
c:\program files (x86)\Windows Searchqu Toolbar
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\BrowserConnection.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\css\new-tab.css
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_amazon.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ebay.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_facebook.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_fantastigames.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ftalk.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_youtube.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\IDR_WEBSTORE_ICON.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png__
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\new-tab.html
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\analytics.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\constant.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config - Copy.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\jquery.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\localStorage.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\new-tab.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\preferences.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\manifest.json
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\OurLocalPage.html
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngr.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\DnsBHO.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest.alt
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlp.xpt
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF10.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF11.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF12.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF13.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF14.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF15.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF3.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF4.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF5.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF6.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF7.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF8.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF9.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DataMngr.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DnsBHO.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Error404BHO.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\NewTabBHO.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.xul
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RelatedSearch.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RequestPreserver.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SearchBHO.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SettingManager.js
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Settings.xml
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\install.rdf
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\IEBHO.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\installhelper.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngr.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngrUI.exe
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\DnsBHO.dll
c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\IEBHO.dll
c:\program files (x86)\Windows Searchqu Toolbar\sysid.ini
c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe
c:\programdata\BrowserDefender
c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings
c:\programdata\Roaming
c:\programdata\Wincert\WIN32C~1.DLL
c:\users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
c:\users\Matthias\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E76258EF-35BE-48ED-890A-B5D99C1B8BFC}.xps
c:\users\Matthias\AppData\Roaming\750
c:\users\Matthias\AppData\Roaming\750\6312.js
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-07-24 bis 2013-08-24  ))))))))))))))))))))))))))))))
.
.
2013-08-24 18:57 . 2013-08-24 18:57	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-08-24 18:46 . 2013-08-24 18:46	76232	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\offreg.dll
2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\users\Matthias\AppData\Roaming\BabSolution
2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\program files (x86)\Delta
2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Delta
2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Simply Super Software
2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\program files (x86)\Trojan Remover
2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\programdata\Simply Super Software
2013-08-24 16:58 . 2013-08-24 17:03	--------	d-----w-	c:\programdata\Spybot - Search & Destroy
2013-08-24 16:58 . 2013-08-24 18:42	--------	d-----w-	c:\program files (x86)\Spybot - Search & Destroy 2
2013-08-24 16:17 . 2013-08-24 16:17	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Malwarebytes
2013-08-24 16:16 . 2013-08-24 16:16	--------	d-----w-	c:\programdata\Malwarebytes
2013-08-24 16:16 . 2013-08-24 16:16	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-24 16:16 . 2013-04-04 12:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2013-08-24 14:20 . 2013-08-24 14:20	--------	d-----w-	c:\users\Default\AppData\Local\Microsoft Help
2013-08-23 17:30 . 2013-08-06 08:58	9515512	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\mpengine.dll
2013-08-22 19:54 . 2013-08-22 19:54	--------	d-----w-	c:\program files\Microsoft Analysis Services
2013-08-22 19:54 . 2013-08-22 19:54	--------	d-----w-	c:\program files (x86)\Microsoft Analysis Services
2013-08-22 19:54 . 2013-08-22 19:55	--------	d-----w-	c:\program files (x86)\Microsoft Visual Studio 8
2013-08-22 19:47 . 2013-08-22 19:47	--------	d-----w-	c:\program files\Common Files\DESIGNER
2013-08-22 19:45 . 2013-08-22 19:55	--------	d-----w-	c:\program files\Microsoft Office
2013-08-22 19:45 . 2013-08-22 19:45	--------	d-----r-	C:\MSOCache
2013-08-22 19:43 . 2013-08-22 19:43	283200	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-22 17:38 . 2013-08-22 19:44	--------	d-----w-	c:\users\Matthias\AppData\Roaming\DAEMON Tools Lite
2013-08-22 17:38 . 2013-08-22 19:43	--------	d-----w-	c:\program files (x86)\DAEMON Tools Lite
2013-08-22 17:37 . 2013-08-22 19:44	--------	d-----w-	c:\programdata\DAEMON Tools Lite
2013-08-22 17:22 . 2013-08-22 17:22	--------	d-----w-	C:\74b36
2013-08-15 06:10 . 2013-07-26 03:35	2706432	----a-w-	c:\windows\system32\mshtml.tlb
2013-08-15 06:10 . 2013-07-26 02:49	2706432	----a-w-	c:\windows\SysWow64\mshtml.tlb
2013-08-14 15:17 . 2013-07-09 05:52	224256	----a-w-	c:\windows\system32\wintrust.dll
2013-08-12 20:21 . 2013-08-12 20:21	--------	d--h--w-	c:\programdata\CanonBJ
2013-08-12 20:21 . 2009-07-14 01:40	84992	----a-w-	c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL
2013-08-11 20:10 . 2013-08-11 20:10	--------	d-----w-	c:\program files (x86)\ProtectDisc Driver Installer
2013-08-11 20:10 . 2013-08-11 20:10	--------	d-----w-	c:\users\Matthias\AppData\Roaming\ProtectDISC
2013-08-11 20:02 . 2013-08-11 20:02	--------	d-----w-	c:\program files (x86)\bitComposer Games
2013-08-04 05:23 . 2013-08-15 06:06	--------	d-----w-	c:\windows\system32\MRT
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-22 19:53 . 2012-11-17 16:09	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-22 19:53 . 2012-11-17 16:09	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-15 06:04 . 2012-11-30 07:34	78161360	----a-w-	c:\windows\system32\MRT.exe
2013-07-12 18:48 . 2013-07-12 18:48	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-12 18:48 . 2012-11-22 22:28	789416	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-07-12 18:48 . 2012-11-22 22:28	867240	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2013-07-09 04:45 . 2013-08-14 15:17	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2013-06-27 22:54 . 2013-03-22 18:33	189936	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2013-06-27 22:54 . 2012-11-19 23:20	378944	----a-w-	c:\windows\system32\drivers\aswSP.sys
2013-06-27 22:54 . 2012-11-19 23:20	1030952	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2013-06-22 10:22 . 2013-06-22 10:22	715038	----a-w-	c:\windows\unins000.exe
2013-06-22 10:16 . 2013-06-22 10:16	376832	----a-w-	c:\windows\SysWow64\xvid.dll
2013-06-05 03:34 . 2013-07-11 19:23	3153920	----a-w-	c:\windows\system32\win32k.sys
2013-06-04 06:00 . 2013-07-11 19:23	624128	----a-w-	c:\windows\system32\qedit.dll
2013-06-04 04:53 . 2013-07-11 19:23	509440	----a-w-	c:\windows\SysWow64\qedit.dll
2013-06-04 01:11 . 2013-06-04 01:11	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-06-04 01:11 . 2013-06-04 01:11	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-06-04 01:11 . 2013-06-04 01:11	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-06-04 01:11 . 2013-06-04 01:11	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-06-04 01:11 . 2013-06-04 01:11	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-06-04 01:11 . 2013-06-04 01:11	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-06-04 01:11 . 2013-06-04 01:11	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-06-04 01:11 . 2013-06-04 01:11	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-06-04 01:11 . 2013-06-04 01:11	81408	----a-w-	c:\windows\system32\icardie.dll
2013-06-04 01:11 . 2013-06-04 01:11	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-06-04 01:11 . 2013-06-04 01:11	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-06-04 01:11 . 2013-06-04 01:11	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-06-04 01:11 . 2013-06-04 01:11	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-06-04 01:11 . 2013-06-04 01:11	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-06-04 01:11 . 2013-06-04 01:11	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-06-04 01:11 . 2013-06-04 01:11	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-06-04 01:11 . 2013-06-04 01:11	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-06-04 01:11 . 2013-06-04 01:11	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-06-04 01:11 . 2013-06-04 01:11	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-06-04 01:11 . 2013-06-04 01:11	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-06-04 01:11 . 2013-06-04 01:11	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-06-04 01:11 . 2013-06-04 01:11	441856	----a-w-	c:\windows\system32\html.iec
2013-06-04 01:11 . 2013-06-04 01:11	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-06-04 01:11 . 2013-06-04 01:11	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-06-04 01:11 . 2013-06-04 01:11	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-06-04 01:11 . 2013-06-04 01:11	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-06-04 01:11 . 2013-06-04 01:11	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-06-04 01:11 . 2013-06-04 01:11	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-06-04 01:11 . 2013-06-04 01:11	235008	----a-w-	c:\windows\system32\url.dll
2013-06-04 01:11 . 2013-06-04 01:11	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-06-04 01:11 . 2013-06-04 01:11	216064	----a-w-	c:\windows\system32\msls31.dll
2013-06-04 01:11 . 2013-06-04 01:11	197120	----a-w-	c:\windows\system32\msrating.dll
2013-06-04 01:11 . 2013-06-04 01:11	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-06-04 01:11 . 2013-06-04 01:11	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-06-04 01:11 . 2013-06-04 01:11	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-06-04 01:11 . 2013-06-04 01:11	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-06-04 01:11 . 2013-06-04 01:11	149504	----a-w-	c:\windows\system32\occache.dll
2013-06-04 01:11 . 2013-06-04 01:11	144896	----a-w-	c:\windows\system32\wextract.exe
2013-06-04 01:11 . 2013-06-04 01:11	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-06-04 01:11 . 2013-06-04 01:11	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-06-04 01:11 . 2013-06-04 01:11	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-06-04 01:11 . 2013-06-04 01:11	13824	----a-w-	c:\windows\system32\mshta.exe
2013-06-04 01:11 . 2013-06-04 01:11	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-06-04 01:11 . 2013-06-04 01:11	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-06-04 01:11 . 2013-06-04 01:11	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-06-04 01:11 . 2013-06-04 01:11	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-06-04 01:11 . 2013-06-04 01:11	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-06-04 01:11 . 2013-06-04 01:11	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-06-04 01:11 . 2013-06-04 01:11	102912	----a-w-	c:\windows\system32\inseng.dll
2013-06-04 01:02 . 2013-06-04 01:02	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	648192	----a-w-	c:\windows\system32\d3d10level9.dll
2013-06-04 01:02 . 2013-06-04 01:02	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll
2013-06-04 01:02 . 2013-06-04 01:02	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-06-04 01:02 . 2013-06-04 01:02	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-06-04 01:02 . 2013-06-04 01:02	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3928064	----a-w-	c:\windows\system32\d2d1.dll
2013-06-04 01:02 . 2013-06-04 01:02	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll
2013-06-04 01:02 . 2013-06-04 01:02	363008	----a-w-	c:\windows\system32\dxgi.dll
2013-06-04 01:02 . 2013-06-04 01:02	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2013-06-04 01:02 . 2013-06-04 01:02	333312	----a-w-	c:\windows\system32\d3d10_1core.dll
2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	296960	----a-w-	c:\windows\system32\d3d10core.dll
2013-06-04 01:02 . 2013-06-04 01:02	293376	----a-w-	c:\windows\SysWow64\dxgi.dll
2013-06-04 01:02 . 2013-06-04 01:02	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2013-06-04 01:02 . 2013-06-04 01:02	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2013-06-04 01:02 . 2013-06-04 01:02	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-04 01:02 . 2013-06-04 01:02	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2013-06-04 01:02 . 2013-06-04 01:02	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll
2013-06-04 01:02 . 2013-06-04 01:02	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2013-06-04 01:02 . 2013-06-04 01:02	221184	----a-w-	c:\windows\system32\UIAnimation.dll
2013-06-04 01:02 . 2013-06-04 01:02	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll
2013-06-04 01:02 . 2013-06-04 01:02	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"starter4g"="c:\windows\starter4g.exe" [2010-07-08 160992]
"ApplyEsf-eDocPrintPro"="c:\program files (x86)\Common Files\MAYComputer\eDocPrintPro\\ApplyEsf.exe" [2010-11-25 315392]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-08-05 1601488]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-07-19 1655568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"DelayedDesktopSwitchTimeout"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AF9035BDA;Cinergy T-Stick service;c:\windows\system32\DRIVERS\AF15BDA.sys;c:\windows\SYSNATIVE\DRIVERS\AF15BDA.sys [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmnsusbser.sys [x]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RTL2832U_IRHID;Cinergy T Stick HID;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys;c:\windows\SYSNATIVE\DRIVERS\RTL2832U_IRHID.sys [x]
R3 RTL2832UBDA;Cinergy T Stick RC BDA service;c:\windows\system32\drivers\RTL2832UBDA.sys;c:\windows\SYSNATIVE\drivers\RTL2832UBDA.sys [x]
R3 RTL2832UUSB;Cinergy T Stick RC USB service;c:\windows\system32\Drivers\RTL2832UUSB.sys;c:\windows\SYSNATIVE\Drivers\RTL2832UUSB.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 excsd;ExpressCache Storage Filter Driver;c:\windows\system32\DRIVERS\excsd.sys;c:\windows\SYSNATIVE\DRIVERS\excsd.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 excfs;ExpressCache File System Filter Driver;c:\windows\system32\DRIVERS\excfs.sys;c:\windows\SYSNATIVE\DRIVERS\excfs.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
S2 ExpressCache;ExpressCache;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 irstrtsv;Intel(R) Rapid Start Technology Service;c:\windows\SysWOW64\irstrtsv.exe;c:\windows\SysWOW64\irstrtsv.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 SamsungDeviceConfigurationWinService;SamsungDeviceConfiguration;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [x]
S2 SearchAnonymizer;SearchAnonymizer;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 WTGService;WTGService;c:\program files (x86)\XSManager\WTGService.exe;c:\program files (x86)\XSManager\WTGService.exe [x]
S2 XS Stick Service;XS Stick Service;c:\windows\service4g.exe;c:\windows\service4g.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 irstrtdv;Intel(R) Rapid Start Technology Driver;c:\windows\system32\DRIVERS\irstrtdv.sys;c:\windows\SYSNATIVE\DRIVERS\irstrtdv.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-01 20:22	1173456	----a-w-	c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-17 19:53]
.
2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20]
.
2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20]
.
2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41]
.
2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58	133840	----a-w-	c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ocs_SM"="c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-11-23 106496]
"ApplyEsf-eDocPrintPro"="c:\program files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe" [2013-01-03 443392]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.domradio.de/
FF - ExtSQL: 2013-08-23 19:16; {74fa6b20-2ae6-4584-a4fd-4ac734f8d210}; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}
FF - ExtSQL: 2013-08-24 19:38; ffxtlbr@delta.com; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\ffxtlbr@delta.com
FF - user.js: extensions.autoDisableScopes - 0 
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extentions.webcake.installId - 6af63b99-f003-4ded-9bce-6c00089258b8
FF - user.js: extentions.webcake.defaultEnableAppsList - layers,brain/features,newOffers/wc
FF - user.js: extensions.delta.tlbrSrchUrl - 
FF - user.js: extensions.delta.id - 4ca70e72000000000000c48508ccfd54
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15941
FF - user.js: extensions.delta.vrsn - 1.8.24.5
FF - user.js: extensions.delta.vrsni - 1.8.24.5
FF - user.js: extensions.delta.vrsnTs - 1.8.24.519:38
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - orgnl
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=121115&tt=200813_245&tsp=4984 srcExt=def
FF - user.js: extensions.delta_i.babExt - 
FF - user.js: extensions.delta_i.srcExt - 
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
AddRemove-Searchqu Toolbar - c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-24  21:10:29
ComboFix-quarantined-files.txt  2013-08-24 19:10
.
Vor Suchlauf: 9 Verzeichnis(se), 342.258.233.344 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 342.203.432.960 Bytes frei
.
- - End Of File - - 77EE78F3313385B4E95767CBFADB502C
         
--- --- ---


OTL
Code:
ATTFilter
OTL logfile created on: 24.08.2013 21:13:21 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Matthias\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,59 Gb Available Physical Memory | 44,79% Memory free
11,57 Gb Paging File | 8,37 Gb Available in Paging File | 72,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 318,80 Gb Free Space | 71,94% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32
 
Computer Name: MATTHIAS_FRIEBE | User Name: Matthias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.LAGS - lagarith.dll ( )
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.LAGS - C:\windows\SysWow64\lagarith.dll ( )
Drivers32: vidc.mjpg - C:\windows\SysWow64\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: vidc.XVID - C:\windows\SysWow64\xvidvfw.dll ()
 
========== Custom Scans ==========
 
<Combofix Logfile:
Code:
ATTFilter
ComboFix 13-08-22.01 - Matthias 24.08.2013  20:43:31.1.4 - x64 >
         
Code:
ATTFilter
 
< Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.5926.2861 [GMT 2:00] >
 
< ausgeführt von:: c:\users\Matthias\Downloads\ComboFix.exe >
 
< AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} >
Invalid Switch: Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
 
< SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} >
Invalid Switch: Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
 
< SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} >
Invalid Switch: Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
 
< SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} >
Invalid Switch: Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
< . >
 
< . >
 
< ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) >
 
< . >
 
< . >
 
< c:\program files (x86)\Delta\delta\1.8.24.5\deltaApp.dll >
 
< c:\program files (x86)\Delta\delta\1.8.24.5\deltaEng.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\BrowserConnection.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\css\new-tab.css >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_amazon.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ebay.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_facebook.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_fantastigames.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_ftalk.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\fav_youtube.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\IDR_WEBSTORE_ICON.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\images\imesh_logo_128.png__ >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\config\skin\new-tab.html >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\analytics.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\constant.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config - Copy.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\default-config.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\jquery.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\localStorage.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\new-tab.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\lib\preferences.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\manifest.json >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\ChromeExtension\OurLocalPage.html >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngr.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\DnsBHO.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\chrome.manifest.alt >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlp.xpt >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF10.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF11.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF12.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF13.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF14.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF15.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF3.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF4.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF5.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF6.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF7.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF8.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF9.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DataMngr.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\DnsBHO.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Error404BHO.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\NewTabBHO.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\overlay.xul >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RelatedSearch.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\RequestPreserver.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SearchBHO.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\SettingManager.js >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\content\Settings.xml >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\FirefoxExtension\install.rdf >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\IEBHO.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\installhelper.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngr.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\datamngrUI.exe >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\DnsBHO.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\Datamngr\x64\IEBHO.dll >
 
< c:\program files (x86)\Windows Searchqu Toolbar\sysid.ini >
 
< c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe >
 
< c:\programdata\BrowserDefender >
 
< c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe >
 
< c:\programdata\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings >
 
< c:\programdata\Roaming >
 
< c:\programdata\Wincert\WIN32C~1.DLL >
 
< c:\users\Matthias\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage >
 
< c:\users\Matthias\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E76258EF-35BE-48ED-890A-B5D99C1B8BFC}.xps >
 
< c:\users\Matthias\AppData\Roaming\750 >
 
< c:\users\Matthias\AppData\Roaming\750\6312.js >
 
< c:\windows\wininit.ini >
 
< . >
 
< . >
 
< (((((((((((((((((((((((   Dateien erstellt von 2013-07-24 bis 2013-08-24  )))))))))))))))))))))))))))))) >
 
< . >
 
< . >
 
< 2013-08-24 18:57 . 2013-08-24 18:57	--------	d-----w-	c:\users\Default\AppData\Local\temp >
 
< 2013-08-24 18:46 . 2013-08-24 18:46	76232	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\offreg.dll >
 
< 2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\users\Matthias\AppData\Roaming\BabSolution >
 
< 2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\program files (x86)\Delta >
 
< 2013-08-24 17:38 . 2013-08-24 17:38	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Delta >
 
< 2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Simply Super Software >
 
< 2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\program files (x86)\Trojan Remover >
 
< 2013-08-24 17:06 . 2013-08-24 17:06	--------	d-----w-	c:\programdata\Simply Super Software >
 
< 2013-08-24 16:58 . 2013-08-24 17:03	--------	d-----w-	c:\programdata\Spybot - Search & Destroy >
 
< 2013-08-24 16:58 . 2013-08-24 18:42	--------	d-----w-	c:\program files (x86)\Spybot - Search & Destroy 2 >
 
< 2013-08-24 16:17 . 2013-08-24 16:17	--------	d-----w-	c:\users\Matthias\AppData\Roaming\Malwarebytes >
 
< 2013-08-24 16:16 . 2013-08-24 16:16	--------	d-----w-	c:\programdata\Malwarebytes >
 
< 2013-08-24 16:16 . 2013-08-24 16:16	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware >
 
< 2013-08-24 16:16 . 2013-04-04 12:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys >
 
< 2013-08-24 14:20 . 2013-08-24 14:20	--------	d-----w-	c:\users\Default\AppData\Local\Microsoft Help >
 
< 2013-08-23 17:30 . 2013-08-06 08:58	9515512	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{097DAD02-6DC1-4877-860F-5D345C4E16B2}\mpengine.dll >
 
< 2013-08-22 19:54 . 2013-08-22 19:54	--------	d-----w-	c:\program files\Microsoft Analysis Services >
 
< 2013-08-22 19:54 . 2013-08-22 19:54	--------	d-----w-	c:\program files (x86)\Microsoft Analysis Services >
 
< 2013-08-22 19:54 . 2013-08-22 19:55	--------	d-----w-	c:\program files (x86)\Microsoft Visual Studio 8 >
 
< 2013-08-22 19:47 . 2013-08-22 19:47	--------	d-----w-	c:\program files\Common Files\DESIGNER >
 
< 2013-08-22 19:45 . 2013-08-22 19:55	--------	d-----w-	c:\program files\Microsoft Office >
 
< 2013-08-22 19:45 . 2013-08-22 19:45	--------	d-----r-	C:\MSOCache >
 
< 2013-08-22 19:43 . 2013-08-22 19:43	283200	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys >
 
< 2013-08-22 17:38 . 2013-08-22 19:44	--------	d-----w-	c:\users\Matthias\AppData\Roaming\DAEMON Tools Lite >
 
< 2013-08-22 17:38 . 2013-08-22 19:43	--------	d-----w-	c:\program files (x86)\DAEMON Tools Lite >
 
< 2013-08-22 17:37 . 2013-08-22 19:44	--------	d-----w-	c:\programdata\DAEMON Tools Lite >
 
< 2013-08-22 17:22 . 2013-08-22 17:22	--------	d-----w-	C:\74b36 >
 
< 2013-08-15 06:10 . 2013-07-26 03:35	2706432	----a-w-	c:\windows\system32\mshtml.tlb >
 
< 2013-08-15 06:10 . 2013-07-26 02:49	2706432	----a-w-	c:\windows\SysWow64\mshtml.tlb >
 
< 2013-08-14 15:17 . 2013-07-09 05:52	224256	----a-w-	c:\windows\system32\wintrust.dll >
 
< 2013-08-12 20:21 . 2013-08-12 20:21	--------	d--h--w-	c:\programdata\CanonBJ >
 
< 2013-08-12 20:21 . 2009-07-14 01:40	84992	----a-w-	c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL >
 
< 2013-08-11 20:10 . 2013-08-11 20:10	--------	d-----w-	c:\program files (x86)\ProtectDisc Driver Installer >
 
< 2013-08-11 20:10 . 2013-08-11 20:10	--------	d-----w-	c:\users\Matthias\AppData\Roaming\ProtectDISC >
 
< 2013-08-11 20:02 . 2013-08-11 20:02	--------	d-----w-	c:\program files (x86)\bitComposer Games >
 
< 2013-08-04 05:23 . 2013-08-15 06:06	--------	d-----w-	c:\windows\system32\MRT >
 
< . >
 
< . >
 
< . >
 
< ((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) >
 
< . >
 
< 2013-08-22 19:53 . 2012-11-17 16:09	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl >
 
< 2013-08-22 19:53 . 2012-11-17 16:09	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe >
 
< 2013-08-15 06:04 . 2012-11-30 07:34	78161360	----a-w-	c:\windows\system32\MRT.exe >
 
< 2013-07-12 18:48 . 2013-07-12 18:48	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll >
 
< 2013-07-12 18:48 . 2012-11-22 22:28	789416	----a-w-	c:\windows\SysWow64\deployJava1.dll >
 
< 2013-07-12 18:48 . 2012-11-22 22:28	867240	----a-w-	c:\windows\SysWow64\npDeployJava1.dll >
 
< 2013-07-09 04:45 . 2013-08-14 15:17	44032	----a-w-	c:\windows\apppatch\acwow64.dll >
 
< 2013-06-27 22:54 . 2013-03-22 18:33	189936	----a-w-	c:\windows\system32\drivers\aswVmm.sys >
 
< 2013-06-27 22:54 . 2012-11-19 23:20	378944	----a-w-	c:\windows\system32\drivers\aswSP.sys >
 
< 2013-06-27 22:54 . 2012-11-19 23:20	1030952	----a-w-	c:\windows\system32\drivers\aswSnx.sys >
 
< 2013-06-22 10:22 . 2013-06-22 10:22	715038	----a-w-	c:\windows\unins000.exe >
 
< 2013-06-22 10:16 . 2013-06-22 10:16	376832	----a-w-	c:\windows\SysWow64\xvid.dll >
 
< 2013-06-05 03:34 . 2013-07-11 19:23	3153920	----a-w-	c:\windows\system32\win32k.sys >
 
< 2013-06-04 06:00 . 2013-07-11 19:23	624128	----a-w-	c:\windows\system32\qedit.dll >
 
< 2013-06-04 04:53 . 2013-07-11 19:23	509440	----a-w-	c:\windows\SysWow64\qedit.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	226304	----a-w-	c:\windows\system32\elshyph.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	185344	----a-w-	c:\windows\SysWow64\elshyph.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	158720	----a-w-	c:\windows\SysWow64\msls31.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	97280	----a-w-	c:\windows\system32\mshtmled.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	81408	----a-w-	c:\windows\system32\icardie.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	77312	----a-w-	c:\windows\system32\tdc.ocx >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	762368	----a-w-	c:\windows\system32\ieapfltr.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	62976	----a-w-	c:\windows\system32\pngfilt.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	61952	----a-w-	c:\windows\SysWow64\tdc.ocx >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	599552	----a-w-	c:\windows\system32\vbscript.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	523264	----a-w-	c:\windows\SysWow64\vbscript.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	52224	----a-w-	c:\windows\system32\msfeedsbs.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	51200	----a-w-	c:\windows\system32\imgutil.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	48640	----a-w-	c:\windows\system32\mshtmler.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	452096	----a-w-	c:\windows\system32\dxtmsft.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	441856	----a-w-	c:\windows\system32\html.iec >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	38400	----a-w-	c:\windows\SysWow64\imgutil.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	361984	----a-w-	c:\windows\SysWow64\html.iec >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	281600	----a-w-	c:\windows\system32\dxtrans.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	27648	----a-w-	c:\windows\system32\licmgr10.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	270848	----a-w-	c:\windows\system32\iedkcs32.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	247296	----a-w-	c:\windows\system32\webcheck.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	235008	----a-w-	c:\windows\system32\url.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	216064	----a-w-	c:\windows\system32\msls31.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	197120	----a-w-	c:\windows\system32\msrating.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	173568	----a-w-	c:\windows\system32\ieUnatt.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	167424	----a-w-	c:\windows\system32\iexpress.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	1509376	----a-w-	c:\windows\system32\inetcpl.cpl >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	150528	----a-w-	c:\windows\SysWow64\iexpress.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	149504	----a-w-	c:\windows\system32\occache.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	144896	----a-w-	c:\windows\system32\wextract.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	1400416	----a-w-	c:\windows\system32\ieapfltr.dat >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	138752	----a-w-	c:\windows\SysWow64\wextract.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	13824	----a-w-	c:\windows\system32\mshta.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	136192	----a-w-	c:\windows\system32\iepeers.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	135680	----a-w-	c:\windows\system32\IEAdvpack.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	12800	----a-w-	c:\windows\SysWow64\mshta.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	12800	----a-w-	c:\windows\system32\msfeedssync.exe >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll >
 
< 2013-06-04 01:11 . 2013-06-04 01:11	102912	----a-w-	c:\windows\system32\inseng.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	648192	----a-w-	c:\windows\system32\d3d10level9.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	465920	----a-w-	c:\windows\system32\WMPhoto.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3928064	----a-w-	c:\windows\system32\d2d1.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	363008	----a-w-	c:\windows\system32\dxgi.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	333312	----a-w-	c:\windows\system32\d3d10_1core.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	296960	----a-w-	c:\windows\system32\d3d10core.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	293376	----a-w-	c:\windows\SysWow64\dxgi.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	2565120	----a-w-	c:\windows\system32\d3d10warp.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	221184	----a-w-	c:\windows\system32\UIAnimation.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll >
 
< 2013-06-04 01:02 . 2013-06-04 01:02	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll >
 
< . >
 
< . >
 
< ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) >
 
< . >
 
< . >
 
< *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  >
 
< REGEDIT4 >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] >
 
< @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] >
 
< @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] >
 
< @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	130736	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] >
 
< "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] >
 
< "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] >
 
< "starter4g"="c:\windows\starter4g.exe" [2010-07-08 160992] >
 
< "ApplyEsf-eDocPrintPro"="c:\program files (x86)\Common Files\MAYComputer\eDocPrintPro\\ApplyEsf.exe" [2010-11-25 315392] >
 
< "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] >
 
< "ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-08-05 1601488] >
 
< "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] >
 
< "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] >
 
< "TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-07-19 1655568] >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] >
 
< "ConsentPromptBehaviorAdmin"= 5 (0x5) >
 
< "ConsentPromptBehaviorUser"= 3 (0x3) >
 
< "EnableUIADesktopToggle"= 0 (0x0) >
 
< "DelayedDesktopSwitchTimeout"= 0 (0x0) >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] >
 
< "LoadAppInit_DLLs"=1 (0x1) >
 
< . >
 
< "mixer3"=wdmaud.drv >
 
< . >
 
< [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] >
 
< BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe >
 
< . >
 
< R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] >
 
< R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] >
 
< R3 AF9035BDA;Cinergy T-Stick service;c:\windows\system32\DRIVERS\AF15BDA.sys;c:\windows\SYSNATIVE\DRIVERS\AF15BDA.sys [x] >
 
< R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] >
 
< R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmnsusbser.sys [x] >
 
< R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x] >
 
< R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] >
 
< R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] >
 
< R3 RTL2832U_IRHID;Cinergy T Stick HID;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys;c:\windows\SYSNATIVE\DRIVERS\RTL2832U_IRHID.sys [x] >
 
< R3 RTL2832UBDA;Cinergy T Stick RC BDA service;c:\windows\system32\drivers\RTL2832UBDA.sys;c:\windows\SYSNATIVE\drivers\RTL2832UBDA.sys [x] >
 
< R3 RTL2832UUSB;Cinergy T Stick RC USB service;c:\windows\system32\Drivers\RTL2832UUSB.sys;c:\windows\SYSNATIVE\Drivers\RTL2832UUSB.sys [x] >
 
< R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] >
 
< R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] >
 
< R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] >
 
< S0 aswRvrt;aswRvrt; [x] >
 
< S0 aswVmm;aswVmm; [x] >
 
< S0 excsd;ExpressCache Storage Filter Driver;c:\windows\system32\DRIVERS\excsd.sys;c:\windows\SYSNATIVE\DRIVERS\excsd.sys [x] >
 
< S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] >
 
< S1 aswSnx;aswSnx; [x] >
 
< S1 aswSP;aswSP; [x] >
 
< S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] >
 
< S1 excfs;ExpressCache File System Filter Driver;c:\windows\system32\DRIVERS\excfs.sys;c:\windows\SYSNATIVE\DRIVERS\excfs.sys [x] >
 
< S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x] >
 
< S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] >
 
< S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] >
 
< S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] >
 
< S2 aswFsBlk;aswFsBlk; [x] >
 
< S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] >
 
< S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] >
 
< S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] >
 
< S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] >
 
< S2 ExpressCache;ExpressCache;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe;c:\program files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [x] >
 
< S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] >
 
< S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] >
 
< S2 irstrtsv;Intel(R) Rapid Start Technology Service;c:\windows\SysWOW64\irstrtsv.exe;c:\windows\SysWOW64\irstrtsv.exe [x] >
 
< S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] >
 
< S2 SamsungDeviceConfigurationWinService;SamsungDeviceConfiguration;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe;c:\program files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [x] >
 
< S2 SearchAnonymizer;SearchAnonymizer;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe;c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [x] >
 
< S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] >
 
< S2 WTGService;WTGService;c:\program files (x86)\XSManager\WTGService.exe;c:\program files (x86)\XSManager\WTGService.exe [x] >
 
< S2 XS Stick Service;XS Stick Service;c:\windows\service4g.exe;c:\windows\service4g.exe [x] >
 
< S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] >
Invalid Switch: Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
 
< S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] >
 
< S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] >
 
< S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] >
 
< S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] >
 
< S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] >
 
< S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] >
Invalid Switch: 2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
 
< S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] >
 
< S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] >
 
< S3 irstrtdv;Intel(R) Rapid Start Technology Driver;c:\windows\system32\DRIVERS\irstrtdv.sys;c:\windows\SYSNATIVE\DRIVERS\irstrtdv.sys [x] >
 
< S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] >
 
< S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] >
 
< S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x] >
 
< S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] >
 
< S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x] >
 
< . >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] >
 
< 2013-08-01 20:22	1173456	----a-w-	c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe >
 
< . >
 
< Inhalt des "geplante Tasks" Ordners >
 
< . >
 
< 2013-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job >
 
< - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-17 19:53] >
 
< . >
 
< 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job >
 
< - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20] >
 
< . >
 
< 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job >
 
< - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-19 23:20] >
 
< . >
 
< 2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job >
 
< - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41] >
 
< . >
 
< 2013-08-24 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job >
 
< - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 04:41] >
 
< . >
 
< . >
 
< --------- X64 Entries ----------- >
 
< . >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] >
 
< @="{472083B0-C522-11CF-8763-00608CC02F24}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] >
 
< 2013-05-09 08:58	133840	----a-w-	c:\program files\AVAST Software\Avast\ashShA64.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] >
 
< @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] >
 
< @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] >
 
< @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] >
 
< @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" >
 
< [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] >
 
< 2013-05-25 00:36	164016	----a-w-	c:\users\Matthias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] >
 
< "Ocs_SM"="c:\users\Matthias\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-11-23 106496] >
 
< "ApplyEsf-eDocPrintPro"="c:\program files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe" [2013-01-03 443392] >
 
< . >
 
< ------- Zusätzlicher Suchlauf ------- >
 
< . >
 
< uLocal Page = c:\windows\system32\blank.htm >
 
< mLocal Page = c:\windows\SysWOW64\blank.htm >
 
< IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe >
 
< TCP: DhcpNameServer = 192.168.2.1 >
 
< FF - ProfilePath - c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\ >
 
< FF - prefs.js: browser.search.selectedEngine - Google >
 
< FF - prefs.js: browser.startup.homepage - hxxp://www.domradio.de/ >
Invalid Switch: 
 
< FF - ExtSQL: 2013-08-23 19:16; {74fa6b20-2ae6-4584-a4fd-4ac734f8d210}; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210} >
 
< FF - ExtSQL: 2013-08-24 19:38; ffxtlbr@delta.com; c:\users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\ffxtlbr@delta.com >
 
< FF - user.js: extensions.autoDisableScopes - 0  >
 
< FF - user.js: extensions.shownSelectionUI - true >
 
< FF - user.js: extentions.webcake.installId - 6af63b99-f003-4ded-9bce-6c00089258b8 >
 
< FF - user.js: extentions.webcake.defaultEnableAppsList - layers,brain/features,newOffers/wc >
Invalid Switch: wc
 
< FF - user.js: extensions.delta.tlbrSrchUrl -  >
 
< FF - user.js: extensions.delta.id - 4ca70e72000000000000c48508ccfd54 >
 
< FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} >
 
< FF - user.js: extensions.delta.instlDay - 15941 >
 
< FF - user.js: extensions.delta.vrsn - 1.8.24.5 >
 
< FF - user.js: extensions.delta.vrsni - 1.8.24.5 >
 
< FF - user.js: extensions.delta.vrsnTs - 1.8.24.519:38 >
 
< FF - user.js: extensions.delta.prtnrId - delta >
 
< FF - user.js: extensions.delta.prdct - delta >
 
< FF - user.js: extensions.delta.aflt - orgnl >
 
< FF - user.js: extensions.delta.smplGrp - none >
 
< FF - user.js: extensions.delta.tlbrId - base >
 
< FF - user.js: extensions.delta.instlRef - sst >
 
< FF - user.js: extensions.delta.dfltLng - de >
 
< FF - user.js: extensions.delta.excTlbr - false >
 
< FF - user.js: extensions.delta.ffxUnstlRst - true >
 
< FF - user.js: extensions.delta.admin - false >
 
< FF - user.js: extensions.delta_i.babTrack - affID=121115&tt=200813_245&tsp=4984 srcExt=def >
 
< FF - user.js: extensions.delta_i.babExt -  >
 
< FF - user.js: extensions.delta_i.srcExt -  >
 
< FF - user.js: extensions.delta.autoRvrt - false >
 
< FF - user.js: extensions.delta.rvrt - false >
 
< FF - user.js: extensions.delta.newTab - false >
 
< . >
 
< - - - - Entfernte verwaiste Registrierungseinträge - - - - >
 
< . >
 
< Toolbar-Locked - (no file) >
 
< Toolbar-10 - (no file) >
 
< Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe >
 
< HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start >
 
< Toolbar-Locked - (no file) >
 
< Toolbar-10 - (no file) >
 
< AddRemove-Searchqu Toolbar - c:\program files (x86)\Windows Searchqu Toolbar\uninstall.exe >
 
< . >
 
< . >
 
< . >
 
< --------------------- Gesperrte Registrierungsschluessel --------------------- >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="FlashBroker" >
 
< "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] >
 
< "Enabled"=dword:00000001 >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] >
 
< @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] >
 
< @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="IFlashBroker5" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] >
 
< @="{00020424-0000-0000-C000-000000000046}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] >
 
< @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" >
 
< "Version"="1.0" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="FlashBroker" >
 
< "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] >
 
< "Enabled"=dword:00000001 >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] >
 
< @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] >
 
< @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="Shockwave Flash Object" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] >
 
< @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" >
 
< "ThreadingModel"="Apartment" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] >
 
< @="0" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] >
 
< @="ShockwaveFlash.ShockwaveFlash.11" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] >
 
< @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] >
 
< @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] >
 
< @="1.0" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] >
 
< @="ShockwaveFlash.ShockwaveFlash" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="Macromedia Flash Factory Object" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] >
 
< @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" >
 
< "ThreadingModel"="Apartment" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] >
 
< @="FlashFactory.FlashFactory.1" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] >
 
< @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] >
 
< @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] >
 
< @="1.0" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] >
 
< @="FlashFactory.FlashFactory" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] >
 
< @Denied: (A 2) (Everyone) >
 
< @="IFlashBroker5" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] >
 
< @="{00020424-0000-0000-C000-000000000046}" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] >
 
< @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" >
 
< "Version"="1.0" >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] >
 
< @Denied: (A) (Users) >
 
< @Denied: (A) (Everyone) >
 
< @Allowed: (B 1 2 3 4 5) (S-1-5-20) >
 
< "BlindDial"=dword:00000000 >
 
< . >
 
< [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] >
 
< @Denied: (Full) (Everyone) >
 
< . >
 
< Zeit der Fertigstellung: 2013-08-24  21:10:29 >
 
< ComboFix-quarantined-files.txt  2013-08-24 19:10 >
 
< . >
 
< Vor Suchlauf: 9 Verzeichnis(se), 342.258.233.344 Bytes frei >
 
< Nach Suchlauf: 14 Verzeichnis(se), 342.203.432.960 Bytes frei >
 
< . >
 
< - - End Of File - - 77EE78F3313385B4E95767CBFADB502C >
         
--- --- --- < End of report >


Alt 24.08.2013, 20:31   #6
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Das sieht irgendwie so aus, als hättest du das Combofix-Logfile bei OTL in die Textbox eingegeben...
Kannst du den Schritt 2 (OTL) bitte nochmals wiederholen, so wie er angegeben ist?
__________________
--> Externe Festplatte infiziert? wscript.exe

Alt 24.08.2013, 20:33   #7
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Verzeihung, mein Fehler.

hier das neue OTL-File

Code:
ATTFilter
OTL logfile created on: 24.08.2013 21:33:02 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\*****\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 43,18% Memory free
11,57 Gb Paging File | 8,24 Gb Available in Paging File | 71,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 317,48 Gb Free Space | 71,65% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32
 
Computer Name: ***** | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
========== Custom Scans ==========
 
< dir /a /b "E:\" /c >
FOUND.000
Medien
System Volume Information
Recycled
Daten
Programme
$RECYCLE.BIN
202
Medien.lnk
Daten.lnk
Programme.lnk
7575

< End of report >
         

Geändert von PKos (24.08.2013 um 21:18 Uhr)

Alt 24.08.2013, 20:37   #8
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Ok, und grad nochmals:

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:
ATTFilter
dir /a/s/b "E:\Recycled" /c
dir /a/s/b "E:\202" /c
dir /a/s/b "E:\7575" /c
         
  • Schliesse bitte alle anderen Programme.
  • Klicke nun auf None (deutsch "Nichts") und danach auf den Scan Button.
  • Kopiere danach den Inhalt der OTL.txt hier in deinen Thread.
__________________
cheers,
Leo

Alt 24.08.2013, 20:40   #9
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Neues OTL-File

Code:
ATTFilter
OTL logfile created on: 24.08.2013 21:39:51 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\****\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 40,71% Memory free
11,57 Gb Paging File | 8,04 Gb Available in Paging File | 69,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 317,48 Gb Free Space | 71,65% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 442,38 Gb Free Space | 47,50% Space Free | Partition Type: FAT32
 
Computer Name: ***** | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
========== Custom Scans ==========
 
< dir /a/s/b "E:\Recycled" /c >
 
< dir /a/s/b "E:\202" /c >
E:\202\i3d3.js
E:\202\g31.js
 
< dir /a/s/b "E:\7575" /c >
E:\7575\i686.js
E:\7575\g64106.js

< End of report >
         

Geändert von PKos (24.08.2013 um 21:17 Uhr)

Alt 24.08.2013, 20:57   #10
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Ok, dann mach bitte diesen Fix.
Wie ist der Zustand danach auf der externen Platte?


Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:
ATTFilter
:files
C:\74b36
E:\202
E:\Medien.lnk
E:\Daten.lnk
E:\Programme.lnk
E:\7575
dir /a/b "C:\" /c
attrib -h -s "E:\*" /s /d /c

:commands
[emptytemp]
         
  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread
__________________
cheers,
Leo

Alt 24.08.2013, 21:11   #11
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Die Verknüpfungen sind alle weg, die Dateiordner wieder ganz normal da. Dafür noch neue Ordner: "Found.000", "Recycled", "System Volume Information"

Code:
ATTFilter
All processes killed
========== FILES ==========
File\Folder C:\74b36 not found.
File\Folder E:\202 not found.
File\Folder E:\Medien.lnk not found.
File\Folder E:\Daten.lnk not found.
File\Folder E:\Programme.lnk not found.
File\Folder E:\7575 not found.
< dir /a/b "C:\" /c >
$RECYCLE.BIN
30d7a25614e5d95791
ComboFix.txt
Cyanide
Documents and Settings
hiberfil.sys
Intel
msdia80.dll
MSOCache
pagefile.sys
PerfLogs
Program Files
Program Files (x86)
ProgramData
Qoobox
Recovery
RHDSetup.log
setup.log
System Volume Information
user.js
Users
Windows
_OTL
C:\Users\*****\Downloads\cmd.bat deleted successfully.
C:\Users\*****\Downloads\cmd.txt deleted successfully.
< attrib -h -s "E:\*" /s /d /c >
C:\Users\*****\Downloads\cmd.bat deleted successfully.
C:\Users\*****\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: *****
->Temp folder emptied: 1125 bytes
->Temporary Internet Files folder emptied: 55170 bytes
->Java cache emptied: 4758840 bytes
->FireFox cache emptied: 6371899 bytes
->Google Chrome cache emptied: 447051005 bytes
->Flash cache emptied: 64497 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2682 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42304315 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 477,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 08242013_220612

Files\Folders moved on Reboot...
C:\Users\*****\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
         

Geändert von PKos (24.08.2013 um 21:19 Uhr)

Alt 25.08.2013, 01:52   #12
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Gut. Bei diesen 3 neuen Ordnern kannst du das Attribut "versteckt" wieder aktivieren, denn dieses hab ich im Fix für alle rausgenommen (denn die Malware hat deine bestehenden Ordner versteckt und Verknüpfungen gleichen Namens erstellt, welche auf Malwarefiles gezeigt haben).


Schritt 1

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).



Schritt 2

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.



Bitte poste in deiner nächsten Antwort:
  • Log von AdwCleaner
  • Log von OTL
__________________
cheers,
Leo

Alt 25.08.2013, 08:12   #13
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



AdwCleaner
Code:
ATTFilter
# AdwCleaner v3.001 - Report created 25/08/2013 at 08:34:11
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : ***** - *****
# Running from : C:\Users\*****\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : APNMCP
Service Deleted : SearchAnonymizer

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Browser Manager
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\delta
Folder Deleted : C:\Program Files (x86)\Iminent
Folder Deleted : C:\Users\*****\AppData\Local\Temp\apn
Folder Deleted : C:\Users\*****\AppData\Roaming\BabSolution
Folder Deleted : C:\Users\*****\AppData\Roaming\Babylon
Folder Deleted : C:\Users\*****\AppData\Roaming\DealPly
Folder Deleted : C:\Users\*****\AppData\Roaming\delta
Folder Deleted : C:\Users\*****\AppData\Roaming\DesktopIconForAmazon
Folder Deleted : C:\Users\*****\AppData\Roaming\DSite
Folder Deleted : C:\Users\*****\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\*****\AppData\Roaming\OCS
Folder Deleted : C:\Users\*****\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\ffxtlbr@delta.com
Folder Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\plugin@getwebcake.com
File Deleted : C:\windows\System32\roboot64.exe
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Askcom.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\ask-search.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Babylon.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\BrowserProtect.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\delta.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\holasearch.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\searchplugins\Search_Results.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\\invalidprefs.js
File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\user.js
File Deleted : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Deleted : C:\windows\System32\Tasks\Dealply
File Deleted : C:\windows\System32\Tasks\EPUpdater
File Deleted : C:\windows\System32\Tasks\QtraxPlayer

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKCU\Software\5f558fdeb469eb43
Key Deleted : HKLM\SOFTWARE\5f558fdeb469eb43
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_k-lite-codec-pack_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_k-lite-codec-pack_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Conduit
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\XingHaoLyrics
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\BabylonToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\IB Updater
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\SearchquSRTB
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : [x64] HKLM\SOFTWARE\IB Updater
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16660


-\\ Mozilla Firefox v23.0.1 (de)

[ File : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\prefs.js ]

Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", true);
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119828&babsrc=NT_ss&mntrId=4ca70e72000000000000c48508ccfd54");
Line Deleted : user_pref("extensions.ORJ-V7.domain", "\"www.search.ask.com\"");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "orgnl");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.bbDpng", "25");
Line Deleted : user_pref("extensions.delta.cntry", "DE");
Line Deleted : user_pref("extensions.delta.dfltLng", "de");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.hdrMd5", "9809EBCE858AC573C1E1811A43119C3C");
Line Deleted : user_pref("extensions.delta.id", "4ca70e72000000000000c48508ccfd54");
Line Deleted : user_pref("extensions.delta.instlDay", "15941");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.24.519:38:25");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.sg", "azb");
Line Deleted : user_pref("extensions.delta.smplGrp", "azb");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.5");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.519:38:25");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.5");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=180613_ndt6&tsp=4921");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
Line Deleted : user_pref("extensions.enabledAddons", "gmailwatcher%40sonthakit:1.61,addon%40codecs.com:1.0,%7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17,toolbar_ORJ-V7%40apn.ask.com:21.51433,%7B74fa6b20-2ae6-458[...]
Line Deleted : user_pref("extensions.holasearch.admin", false);
Line Deleted : user_pref("extensions.holasearch.aflt", "babsst");
Line Deleted : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}");
Line Deleted : user_pref("extensions.holasearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.holasearch.dfltLng", "en");
Line Deleted : user_pref("extensions.holasearch.excTlbr", false);
Line Deleted : user_pref("extensions.holasearch.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.holasearch.id", "4ca70e72000000000000c48508ccfd54");
Line Deleted : user_pref("extensions.holasearch.instlDay", "15852");
Line Deleted : user_pref("extensions.holasearch.instlRef", "sst");
Line Deleted : user_pref("extensions.holasearch.newTab", false);
Line Deleted : user_pref("extensions.holasearch.prdct", "holasearch");
Line Deleted : user_pref("extensions.holasearch.prtnrId", "holasearch");
Line Deleted : user_pref("extensions.holasearch.rvrt", "false");
Line Deleted : user_pref("extensions.holasearch.smplGrp", "none");
Line Deleted : user_pref("extensions.holasearch.tlbrId", "base");
Line Deleted : user_pref("extensions.holasearch.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.holasearch.vrsn", "1.8.16.16");
Line Deleted : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1615:56:28");
Line Deleted : user_pref("extensions.holasearch.vrsni", "1.8.16.16");
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":136890[...]
Line Deleted : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc");
Line Deleted : user_pref("extentions.webcake.installId", "6af63b99-f003-4ded-9bce-6c00089258b8");

-\\ Google Chrome v28.0.1500.95

[ File : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [22858 octets] - [25/08/2013 08:30:44]
AdwCleaner[S0].txt - [22292 octets] - [25/08/2013 08:34:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [22353 octets] ##########
         
OTL:
Code:
ATTFilter
OTL logfile created on: 25.08.2013 08:41:11 - Run 4
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\*****\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,79 Gb Total Physical Memory | 2,77 Gb Available Physical Memory | 47,83% Memory free
11,57 Gb Paging File | 8,45 Gb Available in Paging File | 73,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 443,13 Gb Total Space | 318,52 Gb Free Space | 71,88% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 443,37 Gb Free Space | 47,61% Space Free | Partition Type: FAT32
 
Computer Name: ***** | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.08.24 20:02:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\*****\Downloads\OTL.exe
PRC - [2013.08.17 15:14:18 | 000,276,376 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.07.21 13:52:03 | 001,861,512 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
PRC - [2013.07.19 17:42:26 | 001,655,568 | ---- | M] (Simply Super Software) -- C:\Program Files (x86)\Trojan Remover\Trjscan.exe
PRC - [2013.05.25 02:47:30 | 027,776,968 | ---- | M] (Dropbox, Inc.) -- C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.05.30 13:55:26 | 001,112,968 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
PRC - [2012.05.02 01:03:44 | 002,279,304 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
PRC - [2012.04.25 06:18:10 | 000,784,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
PRC - [2012.04.06 12:17:04 | 002,796,112 | ---- | M] (Samsung Electronics CO., LTD.) -- C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
PRC - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () -- C:\Program Files (x86)\XSManager\WTGService.exe
PRC - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2012.02.21 12:55:16 | 000,936,272 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
PRC - [2012.02.16 15:08:06 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
PRC - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\irstrtsv.exe
PRC - [2012.01.31 08:56:48 | 001,640,328 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
PRC - [2012.01.28 07:38:52 | 004,466,256 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2012.01.04 20:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2010.07.08 23:05:12 | 000,160,992 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\starter4g.exe
PRC - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\Windows\service4g.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.08.17 15:14:17 | 003,551,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.07.21 13:52:02 | 016,166,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
MOD - [2013.04.21 21:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013.04.21 21:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013.03.13 22:48:52 | 024,978,944 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012.11.14 01:32:50 | 003,558,400 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2011.09.08 12:40:10 | 001,645,056 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2011.02.16 18:03:20 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2012.03.30 05:54:10 | 000,079,664 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe -- (ExpressCache)
SRV:64bit: - [2012.02.02 15:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2011.12.08 03:44:04 | 000,594,704 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:64bit: - [2011.12.08 03:43:56 | 000,273,168 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011.12.08 03:43:48 | 000,618,256 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2011.12.08 03:43:44 | 000,148,752 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2011.12.05 02:30:50 | 000,659,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:64bit: - [2011.12.05 01:55:36 | 000,135,952 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV - [2013.08.22 21:53:23 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.08.17 15:14:17 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.05.11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.04.05 17:35:28 | 000,327,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\XSManager\WTGService.exe -- (WTGService)
SRV - [2012.03.12 01:46:40 | 000,274,200 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012.02.21 12:55:24 | 001,104,208 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2012.02.21 12:55:22 | 001,304,912 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2012.02.21 12:55:18 | 001,014,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2012.02.13 08:02:24 | 000,031,624 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe -- (SamsungDeviceConfigurationWinService)
SRV - [2012.02.08 04:03:36 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012.02.08 04:03:34 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012.02.08 04:03:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R)
SRV - [2012.02.08 04:03:16 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012.02.06 10:49:04 | 000,193,536 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysWOW64\irstrtsv.exe -- (irstrtsv)
SRV - [2010.07.08 23:05:08 | 000,145,120 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\Windows\service4g.exe -- (XS Stick Service)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013.06.28 00:54:02 | 001,030,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.06.28 00:54:02 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013.06.28 00:54:02 | 000,189,936 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013.05.09 10:59:07 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013.05.09 10:59:07 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013.05.09 10:59:07 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013.05.09 10:59:06 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013.05.09 10:59:06 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013.01.22 22:32:33 | 000,117,888 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV:64bit: - [2012.12.13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.30 05:54:16 | 000,095,024 | ---- | M] (Diskeeper Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\excsd.sys -- (excsd)
DRV:64bit: - [2012.03.30 05:54:16 | 000,023,344 | ---- | M] (Diskeeper Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\excfs.sys -- (excfs)
DRV:64bit: - [2012.03.14 12:49:20 | 000,242,512 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.16 15:08:26 | 000,031,216 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2012.02.14 05:38:56 | 000,060,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (ibtfltcoex)
DRV:64bit: - [2012.02.07 02:49:04 | 000,026,504 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irstrtdv.sys -- (irstrtdv)
DRV:64bit: - [2012.01.09 12:49:26 | 000,225,920 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UBDA.sys -- (RTL2832UBDA)
DRV:64bit: - [2012.01.09 12:49:26 | 000,049,152 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832U_IRHID.sys -- (RTL2832U_IRHID)
DRV:64bit: - [2012.01.09 12:49:26 | 000,039,680 | ---- | M] (REALTEK SEMICONDUCTOR Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL2832UUSB.sys -- (RTL2832UUSB)
DRV:64bit: - [2012.01.05 13:36:54 | 014,652,768 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012.01.04 20:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012.01.04 20:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012.01.04 20:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011.12.20 10:38:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2011.12.20 10:38:36 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011.12.20 10:38:36 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011.12.05 21:23:08 | 000,331,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.12.05 02:22:58 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.12.01 15:51:00 | 011,417,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2011.11.30 04:19:48 | 000,747,008 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.11.30 04:19:46 | 000,094,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.11.29 12:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.11.23 16:02:20 | 000,648,808 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.11.10 11:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.11.05 14:04:42 | 000,513,600 | ---- | M] (ITETech                  ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF15BDA.sys -- (AF9035BDA)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.28 08:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 
 
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "hxxp://www.domradio.de/"
FF - prefs.js..extensions.enabledAddons: gmailwatcher%40sonthakit:1.61
FF - prefs.js..extensions.enabledAddons: addon%40codecs.com:1.0
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.17
FF - prefs.js..extensions.enabledAddons: toolbar_ORJ-V7%40apn.ask.com:21.51433
FF - prefs.js..extensions.enabledAddons: %7B74fa6b20-2ae6-4584-a4fd-4ac734f8d210%7D:3.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.18 21:40:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2013.06.04 01:49:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions
[2013.08.25 08:34:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions
[2013.08.23 19:16:57 | 000,000,000 | ---D | M] (BargainJoy) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{74fa6b20-2ae6-4584-a4fd-4ac734f8d210}
[2013.07.20 10:34:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.06.22 12:22:49 | 000,000,000 | ---D | M] ("Safe ads") -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\extensions\addon@codecs.com
[2013.03.21 10:23:42 | 000,226,606 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\gmailwatcher@sonthakit.xpi
[2013.08.12 02:31:09 | 000,454,970 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\extensions\toolbar_ORJ-V7@apn.ask.com.xpi
[2013.01.10 19:39:23 | 000,002,101 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\07q96c0h.default-1357839493735\searchplugins\googlede.xml
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (Recorder Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{10743931-94DF-476f-A987-4391233C17A2}
[2013.08.17 15:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.08.17 15:14:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
 
O1 HOSTS File: ([2013.08.24 20:57:40 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {120A8821-2BEE-4C29-BCDA-62C577781992} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found
O4 - HKLM..\Run: [ApplyEsf-eDocPrintPro] C:\Program Files (x86)\Common Files\MAYComputer\eDocPrintPro\ApplyEsf.exe (May Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [starter4g] C:\Windows\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - Startup: C:\Users\Matthias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DelayedDesktopSwitchTimeout = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4750731-9CEA-48CB-B383-6C430621A66D}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.08.25 08:30:42 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.08.24 21:58:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.08.24 21:11:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.08.24 21:10:59 | 000,000,000 | ---D | C] -- C:\windows\temp
[2013.08.24 20:39:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2013.08.24 20:39:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2013.08.24 20:39:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2013.08.24 20:38:55 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.08.24 20:38:44 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\*****\Documents\Simply Super Software
[2013.08.24 19:06:20 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Simply Super Software
[2013.08.24 19:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2013.08.24 19:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2013.08.24 18:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2013.08.24 18:17:01 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Malwarebytes
[2013.08.24 18:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.08.24 18:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.08.24 18:16:38 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2013.08.24 18:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.08.24 13:34:32 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle
[2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2013.08.22 21:54:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2013.08.22 21:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2013.08.22 21:48:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013.08.22 21:47:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2013.08.22 21:45:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2013.08.22 21:45:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013.08.22 21:45:20 | 000,000,000 | R--D | C] -- C:\MSOCache
[2013.08.22 21:43:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys
[2013.08.22 19:38:33 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite
[2013.08.22 19:38:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2013.08.22 19:37:53 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2013.08.17 15:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.08.12 22:21:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2013.08.11 22:10:35 | 000,000,000 | ---D | C] -- C:\Users\Matthias\Documents\Schlag den Raab - Das 3. Spiel
[2013.08.11 22:10:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProtectDisc Driver Installer
[2013.08.11 22:10:19 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\ProtectDISC
[2013.08.11 22:09:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
[2013.08.11 22:02:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bitComposer Games
[2013.08.04 07:23:18 | 000,000,000 | ---D | C] -- C:\windows\SysNative\MRT
[2013.07.31 16:32:59 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\Libori-Dienstag
 
========== Files - Modified Within 30 Days ==========
 
[2013.08.25 08:42:44 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.08.25 08:42:44 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.08.25 08:41:40 | 001,498,742 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013.08.25 08:41:40 | 000,654,400 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2013.08.25 08:41:40 | 000,616,242 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013.08.25 08:41:40 | 000,130,240 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2013.08.25 08:41:40 | 000,106,622 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013.08.25 08:35:49 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2013.08.25 08:35:48 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.08.25 08:35:25 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013.08.25 08:32:00 | 000,001,114 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.08.25 08:05:25 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013.08.24 22:05:49 | 000,001,059 | ---- | M] () -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.08.24 20:57:40 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2013.08.24 19:14:11 | 000,462,896 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013.08.24 18:37:59 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2013.08.24 17:47:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2013.08.23 19:16:42 | 000,000,005 | ---- | M] () -- C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
[2013.08.22 21:43:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\windows\SysNative\drivers\dtsoftbus01.sys
[2013.08.22 21:35:21 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2013.08.20 22:24:25 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\00003553.LCS
[2013.07.31 17:01:43 | 000,000,072 | ---- | M] () -- C:\Users\*****\AppData\Roaming\WB.CFG
 
========== Files Created - No Company Name ==========
 
[2013.08.24 22:05:49 | 000,001,059 | ---- | C] () -- C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.08.24 20:39:43 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2013.08.24 20:39:43 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2013.08.24 20:39:43 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2013.08.24 20:39:43 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2013.08.24 20:39:43 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2013.08.24 13:34:32 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2013.08.11 22:10:22 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\00003553.LCS
[2013.07.27 00:21:11 | 000,000,072 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WB.CFG
[2013.07.22 21:20:00 | 000,010,455 | ---- | C] () -- C:\Users\*****\Friebe_elster_2048.pfx
[2013.06.28 11:27:50 | 000,000,005 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WBPU-Q2-TTL.DAT
[2013.06.22 13:21:04 | 000,000,005 | ---- | C] () -- C:\Users\*****\AppData\Roaming\WBPU-TTL.DAT
[2013.06.22 12:22:31 | 000,079,360 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2013.06.22 12:22:17 | 000,645,632 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2013.06.22 12:22:17 | 000,240,640 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2013.06.22 12:22:06 | 000,715,038 | ---- | C] () -- C:\windows\unins000.exe
[2013.06.22 12:22:06 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll
[2013.06.22 12:22:06 | 000,002,000 | ---- | C] () -- C:\windows\unins000.dat
[2013.06.22 12:16:53 | 000,376,832 | ---- | C] () -- C:\windows\SysWow64\xvid.dll
[2013.06.21 22:56:26 | 000,000,218 | ---- | C] () -- C:\Users\*****\.recently-used.xbel
[2013.05.27 15:54:57 | 000,178,688 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2013.03.04 20:08:50 | 000,007,168 | ---- | C] () -- C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.12.01 00:42:45 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll
[2012.11.23 10:20:48 | 000,338,432 | ---- | C] () -- C:\windows\SysWow64\sqlite36_engine.dll
[2012.06.30 13:44:34 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2012.06.30 12:37:45 | 000,003,586 | ---- | C] () -- C:\windows\HotFixList.ini
[2012.03.13 04:59:22 | 000,963,912 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2012.03.13 04:59:22 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin
[2012.03.13 04:59:19 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin
[2012.03.13 04:59:19 | 000,261,208 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2012.03.13 04:59:16 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012.03.13 04:59:14 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll
[2012.03.13 04:59:14 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2012.03.13 04:59:13 | 013,184,512 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll
[2012.02.02 15:08:26 | 000,001,536 | ---- | C] () -- C:\windows\SysWow64\IusEventLog.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.07.07 21:38:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Audacity
[2013.03.05 00:52:41 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\avidemux
[2013.04.02 21:47:05 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Canneverbe Limited
[2013.06.22 12:22:09 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\CDXReader
[2013.08.22 21:44:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DAEMON Tools Lite
[2013.08.25 08:35:58 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Dropbox
[2013.04.02 22:38:01 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DVDVideoSoft
[2013.03.09 01:42:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\elsterformular
[2012.11.23 09:59:39 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Engelmann Media
[2013.07.30 16:07:03 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FileZilla
[2012.12.01 00:42:56 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FreeAudioPack
[2013.04.02 21:54:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\FreeFLVConverter
[2013.06.21 22:56:26 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Gaupol
[2013.06.21 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\gtk-2.0
[2013.07.20 00:59:27 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\ICQ
[2013.08.22 21:33:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\IrfanView
[2013.06.22 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LavFilters
[2013.01.09 16:51:45 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\MAY Computer
[2013.05.11 19:55:57 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\MusE
[2013.03.24 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\OpenOffice.org
[2012.11.23 10:20:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Opera
[2013.01.12 15:40:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Origin
[2013.08.11 22:10:19 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\ProtectDISC
[2013.01.18 16:33:32 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Scribus
[2013.08.24 19:06:20 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Simply Super Software
[2013.07.01 20:29:04 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Subtitle Edit
[2012.12.28 01:03:59 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\TerraTec
[2013.06.22 12:22:15 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Ultimate Codec Packages
[2013.04.02 22:22:35 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Video DVD Maker FREE
[2012.11.17 22:09:46 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Visan
[2013.03.01 10:17:13 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\XSManager
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:CB0AACC9

< End of report >
         

Alt 25.08.2013, 10:47   #14
aharonov
/// TB-Ausbilder
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



Wie läuft der Rechner? Alles in Ordnung?


Schritt 1

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:
ATTFilter
:OTL
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{1263E943-A411-4127-91C8-579383726819}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d41e058b-52aa-4060-a0b5-b90c8a793132&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\..\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=1928513D-F722-409C-A6B5-A78CCEFB3D2A&apn_sauid=B77BD219-3E93-41B2-B71B-84396DA3F76B
FF - prefs.js..browser.search.order.1: "Ask Search"
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe File not found

:commands
[emptytemp]
         
  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread



Schritt 2


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Schritt 3

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.



Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von ESET
  • Log von SecurityCheck
__________________
cheers,
Leo

Alt 25.08.2013, 23:53   #15
PKos
 
Externe Festplatte infiziert? wscript.exe - Standard

Externe Festplatte infiziert? wscript.exe



OTL:

Code:
ATTFilter
All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E9BE2F1-575E-436F-A1D2-567CA3A11446}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1113C54B-0A97-4487-B3A5-D9C3130418EC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1113C54B-0A97-4487-B3A5-D9C3130418EC}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1263E943-A411-4127-91C8-579383726819}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1263E943-A411-4127-91C8-579383726819}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F6C8801-0F24-4027-B6B2-D6069EA7DD25}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9E8595F0-B862-45FC-A057-3284126557BC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E8595F0-B862-45FC-A057-3284126557BC}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B3E73719-337B-46B6-848C-0F584E2BDAF2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3E73719-337B-46B6-848C-0F584E2BDAF2}\ not found.
Registry key HKEY_USERS\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2ECED89-4CE9-4449-9F41-6886A48AE5A9}\ not found.
Prefs.js: "Ask Search" removed from browser.search.order.1
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Matthias
->Temp folder emptied: 3275 bytes
->Temporary Internet Files folder emptied: 7179 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 6236383 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 602 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3290 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 6,00 mb
 
Error: Unable to interpret <    Solltest du d> in the current context!
 
OTL by OldTimer - Version 3.2.69.0 log created on 08252013_233857

Files\Folders moved on Reboot...
C:\Users\*****\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
         
ESET

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3414e2cbed009342b50f2ba92d1c401e
# engine=14899
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-25 10:42:57
# local_time=2013-08-26 12:42:57 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 3913914 154180449 0 0
# compatibility_mode=5893 16776573 100 94 95926 129100427 0 0
# scanned=237310
# found=2
# cleaned=0
# scan_time=3524
sh=529F1CB730B133C2264E3451DCCC7DEEB179C135 ft=1 fh=2c963b952ca2f278 vn="probably a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\_Setupx.dll.vir"
sh=9B7AFC05F48AE3F56DBE1A2114F8FDF50067A187 ft=0 fh=0000000000000000 vn="JS/Adware.Yontoo.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Matthias\AppData\Roaming\Mozilla\Firefox\Profiles\07q96c0h.default-1357839493735\Extensions\plugin@getwebcake.com\content\overlay.js.vir"
         
Securitycheck

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.72  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Trojan Remover 6.8.8   
 Malwarebytes Anti-Malware Version 1.75.0.1300  
 Java 7 Update 25  
 Adobe Flash Player 11.8.800.94  
 Adobe Reader XI  
 Mozilla Firefox (23.0.1) 
 Google Chrome 28.0.1500.72  
 Google Chrome 28.0.1500.95  
 Google Chrome 29.0.1547.57  
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

Antwort

Themen zu Externe Festplatte infiziert? wscript.exe
avast, community, datei, externe, externe festplatte, festplatte, infiziert, liebe, löschung, ordner, platte, problem, scan, scanner, schonmal, system, system32, troja, trojaner, trojaners, verknüpfungen, virenscan, virenscanner, virus, wscript.exe, ändert



Ähnliche Themen: Externe Festplatte infiziert? wscript.exe


  1. Externe Festplatte infiziert?
    Plagegeister aller Art und deren Bekämpfung - 16.09.2015 (16)
  2. “TR/Dropper.Gen” auf Externe Festplatte
    Log-Analyse und Auswertung - 19.08.2014 (5)
  3. Externe Festplatte
    Alles rund um Windows - 04.01.2014 (45)
  4. Dubiose Exe ausgeführt -> System neu aufgesetzt. Externe Festplatte Infiziert?
    Plagegeister aller Art und deren Bekämpfung - 02.07.2013 (9)
  5. externe Festplatte crc-Ptüfung ?
    Netzwerk und Hardware - 15.11.2012 (1)
  6. Externe Festplatte nur Ver.knüpfungen
    Log-Analyse und Auswertung - 28.10.2012 (44)
  7. [Kaufempfehlung] Externe Festplatte
    Netzwerk und Hardware - 09.10.2012 (1)
  8. Datensicherung auf externe Festplatte...
    Diskussionsforum - 10.08.2012 (1)
  9. Externe Festplatte infiziert WORM_VB.DTL / MAL_OTORUN1
    Plagegeister aller Art und deren Bekämpfung - 15.07.2009 (14)
  10. Externe Festplatte
    Netzwerk und Hardware - 14.12.2008 (1)
  11. Externe Festplatte
    Netzwerk und Hardware - 21.05.2008 (2)
  12. Externe Festplatte formatieren?
    Alles rund um Windows - 06.12.2007 (5)
  13. Externe Festplatte
    Netzwerk und Hardware - 26.11.2006 (3)
  14. Externe Festplatte für XP und 98
    Netzwerk und Hardware - 04.12.2005 (1)
  15. externe Festplatte
    Netzwerk und Hardware - 06.08.2005 (1)
  16. Externe Festplatte?
    Netzwerk und Hardware - 19.06.2005 (1)
  17. externe festplatte
    Netzwerk und Hardware - 17.03.2005 (2)

Zum Thema Externe Festplatte infiziert? wscript.exe - Liebe Community, ich habe mir wohl einen Virus auf meiner externen Festplatte eingefangen. Das befürchte ich zumindest. Meine Ordner werden alle als Verknüpfungen dargestellt. Verkünpfungsziel ist eine Datei im "system32"-Ordner - Externe Festplatte infiziert? wscript.exe...
Archiv
Du betrachtest: Externe Festplatte infiziert? wscript.exe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.