Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Security Shield - Virus eingefangen (https://www.trojaner-board.de/118030-security-shield-virus-eingefangen.html)

PuritySH 26.06.2012 18:07

Security Shield - Virus eingefangen
 
Hallo da draussen,

ich habe mir gestern den Security Shild Virus eingefangen. Nachdem ich ein wenig im Forum rumgeschaut habe und überall steht, dass man solche Probleme individuell lösen muss habe ich nun also das Thema eröffnet.

Der Security Shield meldet sich heute nicht zu Wort, aber wie ich gelesen habe, ist er wohl immer noch da, auch wenn er keine Meldung gibt.

Anbei die Logs die ich gestern abend noch erstellt habe:

OTL.txt:OTL Logfile:
Code:

OTL logfile created on: 25.06.2012 22:31:26 - Run 1
OTL by OldTimer - Version 3.2.53.0    Folder = C:\Users\***\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,24 Gb Available Physical Memory | 58,12% Memory free
7,71 Gb Paging File | 5,65 Gb Available in Paging File | 73,23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,29 Gb Total Space | 353,30 Gb Free Space | 78,11% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 465,66 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
 
Computer Name: EURONICS-VAIO | User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.25 22:22:22 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
PRC - [2012.06.25 20:10:50 | 000,442,368 | ---- | M] () -- C:\Users\***\AppData\Local\jsswnnqxb.exe
PRC - [2012.06.21 23:34:35 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe
PRC - [2011.03.04 14:36:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.06.09 00:55:16 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2010.06.01 04:01:54 | 000,600,928 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2010.05.31 20:18:32 | 000,120,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2010.05.31 18:01:52 | 000,673,136 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.05.26 11:08:08 | 000,055,152 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\VAIO Care\VCSpt.exe
PRC - [2010.05.18 14:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Programme\Sony\VAIO Care\listener.exe
PRC - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010.03.04 05:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.25 20:10:50 | 000,442,368 | ---- | M] () -- C:\Users\***\AppData\Local\jsswnnqxb.exe
MOD - [2012.06.21 23:34:34 | 002,042,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.06.14 10:56:19 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\009c50fb69919b90fb233cb4c35d0ad7\System.Windows.Forms.ni.dll
MOD - [2012.06.14 10:56:13 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebefde27b0ef7f39bb49c493b34a602c\System.Drawing.ni.dll
MOD - [2012.05.10 18:46:46 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\73baa23d28d21c7c01e334211330a84e\IAStorUtil.ni.dll
MOD - [2012.05.10 18:44:35 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll
MOD - [2012.05.10 18:43:59 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b68fdf2c95b93fc5006a092c11eed07c\WindowsBase.ni.dll
MOD - [2012.05.10 18:43:55 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll
MOD - [2012.05.10 18:43:52 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll
MOD - [2012.05.10 18:43:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll
MOD - [2012.05.10 18:43:47 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll
MOD - [2011.07.24 16:34:57 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.11.25 18:09:26 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.25 18:09:23 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.06.24 22:06:19 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.05.25 06:23:52 | 000,252,416 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV - [2012.06.21 23:34:35 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe -- (MySQL)
SRV - [2010.11.25 09:27:27 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.10.12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.06.21 19:00:52 | 000,575,856 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV - [2010.06.20 22:47:18 | 000,108,400 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2010.06.20 22:47:16 | 000,067,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2010.06.18 08:07:12 | 000,423,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2010.06.17 13:44:10 | 000,851,824 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2010.06.09 16:57:16 | 000,101,232 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV - [2010.06.09 16:56:02 | 000,384,880 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV - [2010.06.09 16:55:00 | 000,537,456 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2010.06.09 00:55:14 | 000,952,096 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2010.06.08 18:00:04 | 000,836,608 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV - [2010.06.06 23:13:46 | 000,304,496 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV - [2010.06.01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010.05.31 19:25:48 | 001,250,160 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.09 06:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.07 20:26:48 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.01.07 20:26:48 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.06.28 19:53:20 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.28 19:53:20 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.03.11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.06.24 22:34:53 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.06.24 22:33:43 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.06.24 22:06:24 | 006,107,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.06.23 22:04:45 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010.06.23 22:04:43 | 000,342,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010.06.23 22:04:43 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.06.23 22:04:43 | 000,102,952 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010.06.23 22:04:09 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010.06.23 22:03:07 | 000,078,848 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsne64.sys -- (risdsnpe)
DRV:64bit: - [2010.06.23 22:02:59 | 000,094,208 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2010.05.31 23:36:54 | 000,299,568 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2010.05.31 23:36:48 | 000,402,720 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2010.05.31 23:36:41 | 001,573,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.05.31 22:10:13 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2010.05.28 22:03:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.05.28 22:02:36 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2010.04.26 22:20:29 | 000,012,032 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.26 15:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2008.06.16 04:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEE&bmod=SVEE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{26722C1C-238C-4F45-9235-0FF35F364C09}: "URL" = hxxp://de.shopping.com/?linkin_id=8056363
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\..\SearchScopes\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011.04.15 23:33:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012.04.01 21:33:10 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.11.10 20:13:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.06.25 18:06:52 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-1.xml
[2012.03.20 13:37:33 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-10.xml
[2012.04.06 12:12:54 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-11.xml
[2012.05.05 17:11:30 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-12.xml
[2012.05.08 18:20:34 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-13.xml
[2012.06.18 20:45:17 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-14.xml
[2012.06.25 22:29:58 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-15.xml
[2011.07.03 01:06:11 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-2.xml
[2011.08.17 22:01:39 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-3.xml
[2011.09.01 19:08:43 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-4.xml
[2011.09.11 22:45:17 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-5.xml
[2011.09.19 20:41:27 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-6.xml
[2011.10.05 20:49:18 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:51:31 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-8.xml
[2011.11.17 19:44:05 | 000,000,950 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-9.xml
[2011.06.21 12:46:50 | 000,001,056 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin.xml
[2012.04.30 19:33:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.04.16 07:59:17 | 000,330,316 | ---- | M] () (No name found) -- C:\USERS\***\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
[2012.06.21 23:34:35 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.21 23:34:33 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.21 23:34:33 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.21 23:34:33 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.21 23:34:33 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.21 23:34:33 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.21 23:34:33 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\***\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\***\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [EPSON SX210 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFDE.EXE /FU "C:\Users\***\AppData\Local\Temp\E_S95C9.tmp" /EF "HKCU" File not found
O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{423D4F55-13A2-4D2E-BBDA-A1774A136043}: DhcpNameServer = 172.16.16.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3593B11-7940-4EF9-BF6F-C86A919D5698}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.25 22:22:16 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2012.06.25 22:02:49 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2012.06.25 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.25 22:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.25 22:02:40 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.25 22:02:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.25 20:24:46 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira
[2012.06.23 20:55:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\V5 Play
[2012.06.23 20:54:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\V5Play
[2012.06.23 17:55:59 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\V5 Play
[2012.06.21 20:17:28 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Little Worlds Online
[2012.06.18 22:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Fugazo
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\JollyBear
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\ProgramData\JollyBear
[2012.06.16 13:22:59 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\LegacyInteractive
[2012.06.16 12:55:00 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\WildTangent
[2012.06.06 19:24:17 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\17.03.2012
[2012.06.05 21:43:59 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Marcel
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.25 22:35:29 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.25 22:35:29 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.25 22:30:42 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable
[2012.06.25 22:28:06 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.25 22:27:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.25 22:27:35 | 3106,480,128 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.25 22:26:32 | 000,050,477 | ---- | M] () -- C:\Users\***\Desktop\Defogger.exe
[2012.06.25 22:22:22 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.25 21:47:01 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.25 20:10:50 | 000,442,368 | ---- | M] () -- C:\Users\***\AppData\Local\jsswnnqxb.exe
[2012.06.23 20:55:44 | 000,001,172 | ---- | M] () -- C:\Users\***\Desktop\May's Mystery.lnk
[2012.06.23 12:01:18 | 000,002,698 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk
[2012.06.19 19:08:01 | 000,492,004 | ---- | M] () -- C:\test.xml
[2012.06.14 10:54:24 | 000,323,192 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 01:09:20 | 001,522,286 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.14 01:09:20 | 000,654,852 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.14 01:09:20 | 000,616,694 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.14 01:09:20 | 000,130,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.14 01:09:20 | 000,106,816 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.05 21:44:19 | 003,085,853 | ---- | M] () -- C:\Users\***\Desktop\Tim Bendzko-Soundcheck-ESC Sag einfach Ja-Live 25.05.12.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.25 22:30:42 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable
[2012.06.25 22:26:31 | 000,050,477 | ---- | C] () -- C:\Users\***\Desktop\Defogger.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.25 20:10:50 | 000,442,368 | ---- | C] () -- C:\Users\***\AppData\Local\jsswnnqxb.exe
[2012.06.23 20:55:44 | 000,001,172 | ---- | C] () -- C:\Users\***\Desktop\May's Mystery.lnk
[2012.06.05 21:32:02 | 003,085,853 | ---- | C] () -- C:\Users\***\Desktop\Tim Bendzko-Soundcheck-ESC Sag einfach Ja-Live 25.05.12.mp3
[2012.04.07 18:05:04 | 000,000,416 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.04.07 18:05:04 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD5240.DAT
[2012.04.07 18:04:52 | 000,014,496 | ---- | C] () -- C:\Windows\HL-5240.INI
[2012.04.07 18:04:52 | 000,000,151 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012.04.07 18:04:52 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\brlmw03a.ini
[2012.04.07 18:04:52 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012.04.07 18:04:18 | 000,000,091 | ---- | C] () -- C:\Windows\Brownie.ini
[2011.05.04 16:46:50 | 001,527,912 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.12 19:30:23 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.10.12 19:30:22 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.10.12 19:30:22 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.10.12 19:30:21 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.10.12 19:30:20 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.10.12 19:30:13 | 000,028,732 | ---- | C] () -- C:\Windows\SysWow64\ativvsny.dat
[2010.10.12 19:30:13 | 000,026,936 | ---- | C] () -- C:\Windows\SysWow64\ativvsnl.dat
[2010.10.12 19:27:41 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== LOP Check ==========
 
[2011.04.19 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Acreon
[2011.10.20 19:28:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Alawar
[2011.08.14 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Canneverbe Limited
[2012.01.01 19:41:08 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Colibri Games
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Complitly
[2011.11.10 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoft
[2011.11.10 20:13:44 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.06 13:22:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\elsterformular
[2012.06.16 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Frogwares
[2011.12.30 18:15:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\GameHouse
[2012.03.25 21:42:56 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\ICQ
[2012.06.16 13:22:59 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\LegacyInteractive
[2012.06.21 20:17:28 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Little Worlds Online
[2011.07.24 16:35:21 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\OpenOffice.org
[2011.09.21 19:58:43 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\pdfforge
[2011.11.22 23:24:47 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PeaceCraft2
[2011.11.24 23:48:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PeaceCraft3
[2011.04.28 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PhotoScape
[2012.02.16 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\SoftGrid Client
[2011.05.04 16:47:54 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\TP
[2012.04.30 19:27:21 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\TS3Client
[2012.01.07 22:57:40 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Ubisoft
[2012.01.07 14:32:14 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\V-Games
[2012.06.23 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\V5 Play
[2011.10.20 18:43:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\VC 2 Paradise Resort
[2012.06.18 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\WildTangent
[2012.01.01 23:51:26 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2011.05.11 16:43:58 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—
[2011.05.11 16:43:58 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—

< End of report >

--- --- ---


Und nun der Extras.txt:OTL Logfile:
Code:

OTL Extras logfile created on: 25.06.2012 22:31:26 - Run 1
OTL by OldTimer - Version 3.2.53.0    Folder = C:\Users\***\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,24 Gb Available Physical Memory | 58,12% Memory free
7,71 Gb Paging File | 5,65 Gb Available in Paging File | 73,23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,29 Gb Total Space | 353,30 Gb Free Space | 78,11% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 465,66 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
 
Computer Name: EURONICS-VAIO | User Name: ***| Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{040F656B-F0D5-4F65-925B-16246B1464B7}" = rport=137 | protocol=17 | dir=out | app=system |
"{24883A1E-3C90-46AC-AFD0-F6C89989B73A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{29DF35AC-ACDB-423C-847F-8F9D04734833}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2F642A2D-AD3E-426B-A32F-19291409471A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{569C39EA-1FED-46CA-B683-F71A8F9C4493}" = lport=137 | protocol=17 | dir=in | app=system |
"{6BA63B88-8EDB-4FFD-B6B4-C81F6463F486}" = lport=139 | protocol=6 | dir=in | app=system |
"{74615106-DF0E-4B26-934D-E9D8001FA003}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8727D5A4-D2A8-40EE-BB08-BB414672D214}" = rport=445 | protocol=6 | dir=out | app=system |
"{8DCCD82D-3DA5-4EF2-85D9-EC099BB9D34E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9B9BCCF8-71D4-4C62-93F1-857F00E58CDA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A017B8E1-DAAB-48D2-AB49-CF37CB885055}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B06BF5C8-482F-4008-B6CC-19F3F7CEBEF0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B3D56847-DE9B-40B0-B3A3-1BCB394B03B4}" = rport=139 | protocol=6 | dir=out | app=system |
"{D2DE2666-53BF-4246-B295-AD5223417403}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DF4F2114-A924-4A99-B6AB-27156799C724}" = lport=138 | protocol=17 | dir=in | app=system |
"{E620D9C8-328B-41C2-A5A3-AFBEF555A37A}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{E7117E3E-BFDC-4D0B-B232-26950AF7A5F1}" = rport=138 | protocol=17 | dir=out | app=system |
"{ED88903D-22B6-4F5F-B4C5-FCC4530744A0}" = lport=445 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1260BE6D-6D8F-42BE-BC21-C5A1CABCF8A2}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"{1294652E-CFCD-4956-99AC-D799C43B7193}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
"{12EB41D6-5CC5-44E5-A0E8-9CDC8DDE7306}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"{1BA9156D-64B5-4C37-878F-2AEECFDA47AB}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{1D0D38B4-44A2-446F-BD59-44772C8BC482}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{2532E276-7F82-4B66-B901-B015A0B9F2BC}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"{474D1C3C-3364-4BCF-94CA-9B3B68819B9E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{71BAF76B-AFBC-4358-9F7D-1D80557A0B7A}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"{727FE888-49DF-4170-AAB7-28213305BDA9}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
"{744EAB95-5BF1-4CAB-B00D-F019EB09636D}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
"{7534C4CB-3EBD-44C3-9D90-6185247B67F0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7596710C-3E80-4E2F-BC2B-FD9EEA9AAD08}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
"{86235500-CEED-4DF7-91CC-3516D4A1C04A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A80875FF-4BF0-492A-B44D-89A28F8AAC00}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{CD7DAB54-87AE-4938-91A6-140A17089F5A}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
"{CE4E96EB-B854-4598-A32A-C4C1EF3B5EEE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404\anno4.exe |
"{D5FFD150-EA38-42D8-80A2-02B9AE262DA4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{ECF4B88F-891B-4FCB-99DF-8D6F793467D9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{F23F80D4-7C1C-435C-B5AF-2A7286641B54}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\related designs\anno 1404\anno4.exe |
"{F49A1682-1C7D-4BDC-B6D7-1F17444F8514}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{F91D52BE-85EC-49D9-BE23-17835CD92B82}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.4\icq.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{10E14C74-0638-4996-ABAD-BBF7A6CF1FAA}" = PMB VAIO Edition plug-in (Click to Disc)
"{115B60D5-BBDB-490E-AF2E-064D37A3CE01}" = Media Gallery
"{1E37FC84-799E-481B-9462-3489861E36C9}" = PMB VAIO Edition plug-in (Click to Disc)
"{202B76AB-1B21-434E-A289-788D767D3A7C}" = Media Gallery
"{26A24AE4-039D-4CA4-87B4-2F86416020FF}" = Java(TM) 6 Update 20 (64-bit)
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4DABD2B3-B67A-41B0-86FE-C11AAF5D158A}" = PMB VAIO Edition plug-in (VAIO Movie Story)
"{5AC18E2C-7EAB-4F9E-BEEC-07FD722B28E3}" = PMB VAIO Edition plug-in (VAIO Movie Story)
"{5AFD1F5C-8FDA-413C-AF38-F1E7BD10D72F}" = VAIO Media plus
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{687C26DE-9A70-B256-170A-717DFA8B360E}" = ATI Catalyst Install Manager
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A3D964A6-411A-4817-9D58-5CB8808F494E}" = VAIO Media plus
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{E0156F98-8990-09B0-FCEC-1914C3281283}" = ccc-utility64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"EPSON SX210 Series" = Druckerdeinstallation für EPSON SX210 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{01BA7349-0270-8D01-279E-0960D158B9B0}" = Catalyst Control Center Graphics Full Existing
"{0513EE35-E0FB-4166-B663-BD1AE3A803DE}" = Anno 1404
"{07441A52-E208-478A-92B7-5C337CA8C131}" = Remote Play mit PlayStation®3
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{09BF3083-B76F-B5A0-2446-CDCA707F5918}" = CCC Help Russian
"{0D0F662B-EBEA-4075-819E-74798AD42CDE}" = VAIO Care
"{0F73537E-25F5-81B7-7CD8-517083B1F48D}" = CCC Help Chinese Traditional
"{16E107BF-24A3-28A5-91C9-556A0AA4875D}" = CCC Help Italian
"{177AF091-7854-4615-8327-AC7518F62782}" = VAIO Media plus
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{1873FFC1-FDCB-47E1-B7C7-F418211E3530}" = PMB VAIO Edition plug-in (VAIO Image Optimizer)
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20536917-E2DF-45D9-B41F-9AC0CAFFE48A}" = Media Gallery
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{2105804E-14A1-1B5C-DF13-FB04C4059972}" = CCC Help Thai
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23CFDAC8-5CCE-1A02-581A-753B0A6BEEE1}" = CCC Help Spanish
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{275EA703-F9BD-0F41-F004-DB89011ED5A7}" = CCC Help Dutch
"{2B72AF5B-EC2D-25BD-2A38-5F3C0A727DA8}" = CCC Help Greek
"{2F9D63BE-A891-4E39-AFB3-7402D486800C}" = VAIO Hardware Diagnostics
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}" = VAIO Care
"{3B887224-2336-0699-917A-B38B5B99A254}" = CCC Help French
"{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404
"{3DB5EA77-4A14-4EC9-8BFC-73BC848BDE73}" = Media Gallery
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{4106D232-7B04-4431-9E0B-79B83AFDD25E}" = MySQL Server 5.5
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9DA746-5AE1-4BA0-9087-BDB162242890}" = VAIO Media plus
"{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = PMB VAIO Edition plug-in (Click to Disc)
"{4F527211-4FDF-76EA-61A5-91EE3161980B}" = Catalyst Control Center Core Implementation
"{4FFBB818-B13C-11E0-931D-B2664824019B}_is1" = Complitly
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{52F9CDDA-26F6-4499-90E0-6DDDE6D2259C}" = VAIO Media plus
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{547C9EB4-4CA6-402F-9D1B-8BD30DC71E44}" = VAIO Sample Contents
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}" = VAIO DVD Menu Data
"{5A92468F-3ED8-4F96-A9E1-4F176C80EC29}" = VAIO Quick Web Access
"{5BEE8F1F-BD32-4553-8107-500439E43BD7}" = VAIO Update
"{5D279843-4635-85CA-9201-3BD9E179E749}" = CCC Help Chinese Standard
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO-Support für Übertragungen
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65B138AE-F636-4D4C-BA5D-A06E21E47C53}" = Remote-Tastatur mit PlayStation 3
"{6B4E92B0-6691-E4A1-A86B-6600BD6972D4}" = CCC Help Turkish
"{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{734B6C6C-4740-476F-BB0C-F7AF469EDBB2}" = Remote Play with PlayStation 3
"{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4
"{74B81E20-730A-F440-FB01-C7B3716CB80A}" = Catalyst Control Center Graphics Previews Common
"{77F38281-1BAC-80B3-D99E-AE11CE3A0924}" = Catalyst Control Center Graphics Full New
"{7BB90344-0647-468E-925A-7F69F7983421}" = ArcSoft Magic-i Visual Effects 2
"{7D793D3E-C37E-4C1D-4ACF-D05878F5D480}" = CCC Help Japanese
"{7FC454AE-6857-215B-33FF-D50835C32EF9}" = CCC Help Danish
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{80EC2233-C9E0-4B7E-B45A-2AD35702B0B5}" = Brother HL-5240
"{8211C280-5B02-4E7E-B55F-845A207249BA}" = VAIO Data Restore Tool
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{88C252C8-A7EE-4B60-BF74-8E5919A8048F}" = PMB VAIO Edition Guide
"{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}" = VAIO Media plus
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F2DAC3B-E040-1B90-D882-EEF8033AA0A5}" = Catalyst Control Center Graphics Previews Vista
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{919FBC0E-93A3-445A-2055-BCB23AED1641}" = Catalyst Control Center Localization All
"{9238E8A4-BEBA-43A3-B926-769BDBF194C5}" = VAIO Media plus Opening Movie
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0E583D1-23F7-4C35-9620-B169D7715E4B}" = Adobe Premiere Elements 8.0
"{A20548C1-4B08-C41D-A3A8-FE8C933C2A00}" = Catalyst Control Center InstallProxy
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" =
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3 - Deutsch
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B19E486A-59E8-5585-CB2F-4DCB1B230368}" = CCC Help Czech
"{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = PMB VAIO Edition plug-in (VAIO Movie Story)
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B941F34C-F36A-4A6F-A97C-50B5948E451F}" = VAIO Media plus
"{B945DDC0-3213-4850-8B20-F2DA67FDFE9E}" = CCC Help Norwegian
"{BA1CA03B-8F13-12C6-BCE6-46C422B357AE}" = CCC Help German
"{BBF0B71F-F8F3-70FD-B558-7835894F40A5}" = CCC Help Portuguese
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO-Handbuch
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" =
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CFB66DB0-00AC-4CBC-B99D-99EFEB03743C}" = PMB VAIO Edition plug-in (Click to Disc)
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D4CE65B8-23C1-A51B-6739-AE6686DD6C6D}" = CCC Help Korean
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel(R) Turbo Boost Technology Driver
"{D7F08B1C-A956-3A0A-E891-83173A2F73BA}" = Catalyst Control Center Graphics Light
"{D8FF4505-5977-4116-8DE4-2AF7174E70AC}" = Media Gallery
"{D9D30D77-E0E2-6B2F-3C7B-0D8C9A82C8DB}" = CCC Help English
"{DBE88A57-BD7B-E315-C07D-D203E514BB58}" = CCC Help Finnish
"{DD256151-9EAC-9D83-8D60-A475F092CF03}" = CCC Help Hungarian
"{DD88F979-FA58-41AC-980C-A6E1A82B61D9}" = VAIO - Media Gallery
"{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}" = ArcSoft WebCam Companion 3
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F572C0E3-90D1-CC46-C163-4C4E50D3C220}" = ccc-core-static
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F93A233E-59A6-CBD2-68D3-4446D710EDA5}" = CCC Help Polish
"{FB33CE0D-D26D-86C3-9BD5-F58631EAE3C2}" = CCC Help Swedish
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FBB4411F-1328-4E36-A5B3-16AA8CFA8F9C}" = PMB VAIO Edition plug-in (VAIO Movie Story)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Art of Murder 2/DE-German_is1" = Die Kunst des Mordens: Der Marionettenspieler
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Das Geheimnis von Dragonville: May's Mystery_is1" = May's Mystery 1.0
"Diablo III" = Diablo III
"EdnaSE" = Edna Bricht Aus - Sammler Edition
"ElsterFormular für Privatanwender 12.3.2.6814p" = ElsterFormular für Privatanwender
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
"Freecorder5.07" = Freecorder 5
"Google Chrome" = Google Chrome
"ICQToolbar" = ICQ Toolbar
"InstallShield_{1873FFC1-FDCB-47E1-B7C7-F418211E3530}" = VAIO - PMB VAIO Edition plug-in (VAIO Image Optimizer)
"InstallShield_{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = VAIO - PMB VAIO Edition plug-in (Click to Disc)
"InstallShield_{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"InstallShield_{88C252C8-A7EE-4B60-BF74-8E5919A8048F}" = VAIO - PMB VAIO Edition Guide
"InstallShield_{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = VAIO - PMB VAIO Edition plug-in (VAIO Movie Story)
"Magic Encyclopedia" = Magic Encyclopedia
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PhotoScape" = PhotoScape
"PremElem80" = Adobe Premiere Elements 8.0
"splashtop" = VAIO Quick Web Access
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VAIO Help and Support" =
"VAIO screensaver" = VAIO screensaver
"WildTangent wildgames Master Uninstall" = WildTangent-Spiele
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"WTA-1a5731ac-9a01-4b80-a96f-0d0cdd06b97e" = Hidden World
"WTA-24ca87c5-cbf7-482e-9951-9f1e9825dde3" = The Tiny Bang Story
"WTA-2803f5de-785c-4056-afd6-1973cd5a680f" = Campfire Legends - The Last Act Premium Edition
"WTA-28a93869-60ec-480d-9c2e-ead46143ff83" = May's Mysteries: The Secret of Dragonville
"WTA-333cdf7f-1d1b-4b90-8982-743bb672b1c9" = Sherlock Holmes and the Hound of the Baskervilles
"WTA-34221cd8-20d9-4701-8ee7-0f0ba5dd792b" = My Kingdom for the Princess 3
"WTA-515a0244-6112-475d-b772-c976dd01cbc1" = The Lost Cases of Sherlock Holmes 2
"WTA-7630414f-3994-4677-82fc-21faa19cc69e" = My Kingdom for the Princess 2
"WTA-7b8d23de-82ff-4f9c-b965-4262b1e3c334" = Virtual City 2: Paradise Resort!
"WTA-7bdc972b-9308-4aea-b529-ee8c1c53214f" = World Mosaics
"WTA-8e6dad77-68aa-4755-92a7-e3527df999de" = World Riddles 3
"WTA-91192237-90a7-4bf6-857c-63882fe20558" = Nancy Drew: Shadow at the Water's Edge
"WTA-9280cbd9-b5b7-4c6e-9944-dd45be6bc563" = Nancy Drew: Ransom of the Seven Ships
"WTA-96a4038b-157e-44d6-8da5-668259059c43" = Sherlock Holmes: Mystery of the Persian Carpet
"WTA-a412c9ce-0083-4361-b71f-3173e1f3d493" = Big City Adventure: London Story
"WTA-d3f778e8-2406-44f0-8204-e8b54b6c872c" = Nancy Drew: Secret of the Old Clock
"WTA-e0c8e4b3-0e08-44d7-8cab-0ce2296adb81" = Color Cross
"WTA-e1e5086b-fc94-43b8-8870-01bb152303d5" = World Mosaics 2
"WTA-f858da1a-63f7-4106-83d0-e0abf7372a98" = Roads of Rome 2
"WTA-fb46e5a3-5686-425a-afda-6606f88c339c" = Nancy Drew: Secrets Can Kill Remastered
"xampp" = XAMPP 1.7.4
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 22.04.2012 11:20:23 | Computer Name = EURONICS-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 25.04.2012 13:27:16 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 29.04.2012 09:26:16 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 06.05.2012 12:13:27 | Computer Name = Euronics-VAIO | Source = CVHSVC | ID = 100
Description = Nur zur Information.  (Patch task for {90140011-0066-0407-0000-0000000FF1CE}):
 DownloadLatest Failed: HTTP-Status 304: Die Serverantwort ist ungültig. Der Server
 verwendet nicht das definierte Protokoll. Setzen Sie den Auftrag fort. Der Vorgang
 wird von BITS wiederholt. 
 
Error - 10.05.2012 14:22:33 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 19.05.2012 10:40:58 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 23.05.2012 12:27:04 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 25.05.2012 13:09:31 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 01.06.2012 08:18:43 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 08.06.2012 14:46:35 | Computer Name = Euronics-VAIO | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
[ System Events ]
Error - 31.05.2012 17:17:30 | Computer Name = Euronics-VAIO | Source = Service Control Manager | ID = 7038
Description = Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService"
 mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:  %%1352    Vergewissern
 Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
 Management Console (MMC).
 
Error - 31.05.2012 17:17:30 | Computer Name = Euronics-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht
 gestartet:  %%1069
 
Error - 04.06.2012 16:44:26 | Computer Name = Euronics-VAIO | Source = DCOM | ID = 10010
Description =
 
Error - 13.06.2012 19:01:42 | Computer Name = Euronics-VAIO | Source = DCOM | ID = 10010
Description =
 
Error - 15.06.2012 05:38:42 | Computer Name = Euronics-VAIO | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?15.?06.?2012 um 02:31:21 unerwartet heruntergefahren.
 
Error - 15.06.2012 05:39:16 | Computer Name = Euronics-VAIO | Source = WMPNetworkSvc | ID = 866300
Description =
 
Error - 17.06.2012 17:15:29 | Computer Name = Euronics-VAIO | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Intel(R) Rapid Storage Technology erreicht.
 
Error - 17.06.2012 17:15:29 | Computer Name = Euronics-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Intel(R) Rapid Storage Technology" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%1053
 
Error - 21.06.2012 14:09:22 | Computer Name = Euronics-VAIO | Source = DCOM | ID = 10010
Description =
 
Error - 25.06.2012 16:27:42 | Computer Name = Euronics-VAIO | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?25.?06.?2012 um 22:26:43 unerwartet heruntergefahren.
 
 
< End of report >

--- --- ---

Ich hoffe, das diese Logs vorerst reichen.


Vielen Dank für eure Hilfe im Voraus.

Greetz

Janina

cosinus 29.06.2012 16:02

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

PuritySH 02.07.2012 21:03

Hallo,

vielen Dank für die Antwort schonmal, war leider übers WE verreist und kann nun erst antworten... Avira hat neulich was gefunden was ich daraufhin entfernt habe, ob es nun das Security Shild... Ding war, weiß ich leider nicht. :stirn:

Also, hier schonmal der Malware Log:

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.02.03

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

02.07.2012 20:00:51
mbam-log-2012-07-02 (20-00-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 410754
Laufzeit: 37 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Gefunden hat Malware leider nichts.


Hier nun ESET:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=9a9daff810967e479c3222f34caf8084
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-02 07:59:42
# local_time=2012-07-02 09:59:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=1797 16775165 100 94 250028 77794930 0 0
# compatibility_mode=5893 16776573 100 94 249698 92884359 0 0
# compatibility_mode=8192 67108863 100 0 110 110 0 0
# scanned=222482
# found=4
# cleaned=0
# scan_time=4673
C:\Program Files (x86)\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\WildGames\World Riddles 3\TimeTravel.exe        a variant of Win32/Kryptik.BCY trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\3ad21bf4-7e589e3b        a variant of Java/Exploit.CVE-2012-0507.CD trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Euronics\Downloads\PDFCreator-1_2_3_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I

So, ich hoffe das verrät etwas über den Zustand von meinem Vaio :/

Vielen Dank im Voraus!

Greetz

Janina

cosinus 03.07.2012 13:10

Zitat:

Avira hat neulich was gefunden was ich daraufhin entfernt habe, ob es nun das Security Shild...
Schön und wo sind die Logs dazu?
Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

PuritySH 04.07.2012 20:37

Hallo,

entschuldige bitte, ich hab das alles noch nicht so auf dem Zettel...

Hier also der Log von Avira bzgl des Virus Fundes:

Code:



Avira AntiVir Personal
Erstellungsdatum der Reportdatei: Mittwoch, 27. Juni 2012  19:37

Es wird nach 3874966 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (plain)  [6.1.7600]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : EURONICS-VAIO

Versionsinformationen:
BUILD.DAT      : 10.2.0.707    36070 Bytes  25.01.2012 12:53:00
AVSCAN.EXE    : 10.3.0.7      484008 Bytes  28.06.2011 17:53:19
AVSCAN.DLL    : 10.0.5.0      57192 Bytes  28.06.2011 17:53:19
LUKE.DLL      : 10.3.0.5      45416 Bytes  28.06.2011 17:53:20
LUKERES.DLL    : 10.0.0.0      13672 Bytes  14.01.2010 09:59:47
AVSCPLR.DLL    : 10.3.0.7      119656 Bytes  28.06.2011 17:53:21
AVREG.DLL      : 10.3.0.9      88833 Bytes  12.07.2011 16:48:55
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 07:05:36
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 12:36:27
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 21:28:19
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 19:30:19
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 16:23:47
VBASE005.VDF  : 7.11.29.136  2166272 Bytes  10.05.2012 17:02:20
VBASE006.VDF  : 7.11.29.137    2048 Bytes  10.05.2012 17:02:21
VBASE007.VDF  : 7.11.29.138    2048 Bytes  10.05.2012 17:02:21
VBASE008.VDF  : 7.11.29.139    2048 Bytes  10.05.2012 17:02:21
VBASE009.VDF  : 7.11.29.140    2048 Bytes  10.05.2012 17:02:21
VBASE010.VDF  : 7.11.29.141    2048 Bytes  10.05.2012 17:02:21
VBASE011.VDF  : 7.11.29.142    2048 Bytes  10.05.2012 17:02:21
VBASE012.VDF  : 7.11.29.143    2048 Bytes  10.05.2012 17:02:21
VBASE013.VDF  : 7.11.29.144    2048 Bytes  10.05.2012 17:02:21
VBASE014.VDF  : 7.11.30.3    198144 Bytes  14.05.2012 17:36:00
VBASE015.VDF  : 7.11.30.69    186368 Bytes  17.05.2012 17:34:57
VBASE016.VDF  : 7.11.30.143  223744 Bytes  21.05.2012 17:54:26
VBASE017.VDF  : 7.11.30.207  287744 Bytes  23.05.2012 16:19:47
VBASE018.VDF  : 7.11.31.57    188416 Bytes  28.05.2012 18:23:07
VBASE019.VDF  : 7.11.31.111  214528 Bytes  30.05.2012 18:47:19
VBASE020.VDF  : 7.11.31.151  116736 Bytes  31.05.2012 18:47:19
VBASE021.VDF  : 7.11.31.205  134144 Bytes  03.06.2012 18:47:20
VBASE022.VDF  : 7.11.32.9    169472 Bytes  05.06.2012 16:53:51
VBASE023.VDF  : 7.11.32.85    155648 Bytes  08.06.2012 17:46:04
VBASE024.VDF  : 7.11.32.133  127488 Bytes  11.06.2012 21:14:54
VBASE025.VDF  : 7.11.32.171  182784 Bytes  12.06.2012 21:14:54
VBASE026.VDF  : 7.11.32.251  119296 Bytes  14.06.2012 21:14:55
VBASE027.VDF  : 7.11.33.83    159232 Bytes  18.06.2012 18:11:24
VBASE028.VDF  : 7.11.33.195  200192 Bytes  22.06.2012 21:32:24
VBASE029.VDF  : 7.11.34.57    187904 Bytes  27.06.2012 17:27:42
VBASE030.VDF  : 7.11.34.58      2048 Bytes  27.06.2012 17:27:42
VBASE031.VDF  : 7.11.34.60      2048 Bytes  27.06.2012 17:27:42
Engineversion  : 8.2.10.96
AEVDF.DLL      : 8.1.2.8      106867 Bytes  05.06.2012 18:47:24
AESCRIPT.DLL  : 8.1.4.28      455035 Bytes  21.06.2012 18:13:35
AESCN.DLL      : 8.1.8.2      131444 Bytes  21.03.2012 19:30:26
AESBX.DLL      : 8.2.5.12      606578 Bytes  17.06.2012 21:15:00
AERDL.DLL      : 8.1.9.15      639348 Bytes  11.09.2011 20:05:55
AEPACK.DLL    : 8.2.16.22    807288 Bytes  21.06.2012 18:13:29
AEOFFICE.DLL  : 8.1.2.38      201083 Bytes  21.06.2012 18:13:17
AEHEUR.DLL    : 8.1.4.52    4923767 Bytes  21.06.2012 18:13:15
AEHELP.DLL    : 8.1.21.0      254326 Bytes  12.05.2012 17:02:29
AEGEN.DLL      : 8.1.5.30      422261 Bytes  17.06.2012 21:14:56
AEEXP.DLL      : 8.1.0.54      82293 Bytes  21.06.2012 18:13:35
AEEMU.DLL      : 8.1.3.0      393589 Bytes  04.03.2011 12:36:01
AECORE.DLL    : 8.1.25.10    201080 Bytes  05.06.2012 18:47:22
AEBB.DLL      : 8.1.1.0        53618 Bytes  04.03.2011 12:36:00
AVWINLL.DLL    : 10.0.0.0      19304 Bytes  04.03.2011 12:36:13
AVPREF.DLL    : 10.0.3.2      44904 Bytes  28.06.2011 17:53:19
AVREP.DLL      : 10.0.0.10    174120 Bytes  18.05.2011 08:47:20
AVARKT.DLL    : 10.0.26.1    255336 Bytes  28.06.2011 17:53:19
AVEVTLOG.DLL  : 10.0.0.9      203112 Bytes  28.06.2011 17:53:19
SQLITE3.DLL    : 3.6.19.0      355688 Bytes  17.06.2010 12:27:02
AVSMTP.DLL    : 10.0.0.17      63848 Bytes  04.03.2011 12:36:12
NETNT.DLL      : 10.0.0.0      11624 Bytes  17.06.2010 12:27:01
RCIMAGE.DLL    : 10.0.0.35    2589544 Bytes  28.06.2011 17:53:19
RCTEXT.DLL    : 10.0.64.0      98664 Bytes  28.06.2011 17:53:19

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: avguard_async_scan
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_50187700\guard_slideup.avp
Protokollierung.......................: standard
Primäre Aktion........................: reparieren
Sekundäre Aktion......................: quarantäne
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: aus
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: vollständig

Beginn des Suchlaufs: Mittwoch, 27. Juni 2012  19:37

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'listener.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamservice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorDataMgrSvc.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avnotify.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'BluetoothHeadsetProxy.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'RunDll32.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamgui.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBVolumeWatcher.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'AdobeARM.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ISBMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorIcon.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.bin' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'msnmsgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VCSpt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgrSub.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'DllHost.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'uCamMonitor.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBDeviceInfoProvider.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mysqld.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ICQ Service.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht

Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\Users\Euronics\AppData\Local\jsswnnqxb.exe'
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
C:\Users\Euronics\AppData\Local\jsswnnqxb.exe
  [FUND]      Ist das Trojanische Pferd TR/FakeAV.nfiv
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '55f6efaf.qua' verschoben!


Ende des Suchlaufs: Mittwoch, 27. Juni 2012  19:37
Benötigte Zeit: 00:05 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      0 Verzeichnisse wurden überprüft
    34 Dateien wurden geprüft
      1 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      1 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
    33 Dateien ohne Befall
      0 Archive wurden durchsucht
      0 Warnungen
      1 Hinweise

So, mehr habe ich aber nicht durchlaufen lassen....

Viele Grüße

Janina

cosinus 05.07.2012 10:12

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

PuritySH 05.07.2012 21:25

Hallo,

okidoki, ich poste dann mal alles was dort steht:

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.25.09

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

25.06.2012 22:03:22
mbam-log-2012-06-25 (22-03-22).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 206222
Laufzeit: 2 Minute(n), 51 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.02.03

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

02.07.2012 19:53:46
mbam-log-2012-07-02 (19-53-46).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 67942
Laufzeit: 6 Minute(n), 27 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.02.03

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

02.07.2012 20:00:51
mbam-log-2012-07-02 (20-00-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 410754
Laufzeit: 37 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

2012/06/25 22:03:17 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/25 22:03:19 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/25 22:03:22 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/25 22:03:24 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/06/25 22:09:04 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/06/25 22:09:04 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database already up-to-date
2012/06/25 22:28:38 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/25 22:28:42 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/25 22:28:45 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/25 22:28:47 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/06/26 18:50:44 +0200        EURONICS-VAIO        (null)        MESSAGE        Executing scheduled update:  Daily
2012/06/26 18:50:51 +0200        EURONICS-VAIO        (null)        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.25.09 to version v2012.06.26.07
2012/06/26 19:01:22 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/26 19:01:24 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/26 19:01:27 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/26 19:01:30 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/06/26 19:01:30 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/06/26 19:01:30 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/06/26 19:03:29 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/06/26 19:03:31 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/06/26 19:03:31 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/26 19:03:32 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/06/27 19:27:59 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/27 19:28:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/27 19:28:04 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/27 19:28:06 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/06/27 19:38:44 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/06/27 19:38:55 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.26.07 to version v2012.06.27.08
2012/06/27 19:38:55 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/06/27 19:38:55 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/06/27 19:40:54 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/06/27 19:40:56 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/06/27 19:40:56 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/27 19:40:57 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/06/28 23:46:23 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/28 23:46:24 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/06/28 23:46:25 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/28 23:46:28 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/28 23:46:30 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/06/28 23:46:39 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/06/28 23:46:39 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.27.08 to version v2012.06.28.12
2012/06/28 23:46:39 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/06/28 23:48:31 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/06/28 23:48:33 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/06/28 23:48:33 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/28 23:48:34 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/06/29 23:17:09 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/06/29 23:17:10 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/06/29 23:17:11 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/06/29 23:17:14 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/29 23:17:15 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/06/29 23:17:21 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.28.12 to version v2012.06.29.10
2012/06/29 23:17:21 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/06/29 23:17:21 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/06/29 23:19:04 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/06/29 23:19:06 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/06/29 23:19:06 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/06/29 23:19:08 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/07/02 19:50:42 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/07/02 19:50:43 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/07/02 19:50:44 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/07/02 19:50:47 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/02 19:50:49 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/07/02 19:50:53 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/07/02 19:50:53 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.06.29.10 to version v2012.07.02.03
2012/07/02 19:50:53 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/07/02 19:52:48 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/07/02 19:52:50 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/07/02 19:52:50 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/02 19:52:51 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/07/04 21:33:48 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/07/04 21:33:50 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/07/04 21:33:51 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/07/04 21:33:54 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/04 21:33:55 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/07/04 21:34:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.07.02.03 to version v2012.07.04.06
2012/07/04 21:34:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/07/04 21:34:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/07/04 21:35:59 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/07/04 21:36:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/07/04 21:36:01 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/04 21:36:02 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully

Code:

2012/07/05 22:18:03 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting protection
2012/07/05 22:18:04 +0200        EURONICS-VAIO        Euronics        MESSAGE        Executing scheduled update:  Daily
2012/07/05 22:18:05 +0200        EURONICS-VAIO        Euronics        MESSAGE        Protection started successfully
2012/07/05 22:18:08 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/05 22:18:10 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully
2012/07/05 22:18:12 +0200        EURONICS-VAIO        Euronics        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.07.04.06 to version v2012.07.05.07
2012/07/05 22:18:12 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting database refresh
2012/07/05 22:18:12 +0200        EURONICS-VAIO        Euronics        MESSAGE        Stopping IP protection
2012/07/05 22:20:10 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection stopped
2012/07/05 22:20:11 +0200        EURONICS-VAIO        Euronics        MESSAGE        Database refreshed successfully
2012/07/05 22:20:11 +0200        EURONICS-VAIO        Euronics        MESSAGE        Starting IP protection
2012/07/05 22:20:13 +0200        EURONICS-VAIO        Euronics        MESSAGE        IP Protection started successfully


Puh, sorry für die Mehrarbeit...

Danke und viele Grüße

Janina

cosinus 05.07.2012 21:39

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

PuritySH 05.07.2012 21:47

1) Also bei Windows selber habe ich überhaupt nichts gemerkt. Allgemein wäre mir der Virus nicht aufgefallen, wenn er sich nicht selbst durch Pop-Ups gemeldet hätte.

2) Ich habe die Ordner grade mal durchgeschaut, da ist ebenfalls nichts merkwürdiges. Leere ORdner sind keine da und auf Anhieb würde mir jetzt nicht einfallen, was dort fehlen sollte. Scheint also alles oke zu sein.

cosinus 05.07.2012 21:51

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


PuritySH 05.07.2012 22:19

Okay, hier die Textdatei:

[code]0OTL Logfile:
Code:

OTL logfile created on: 05.07.2012 22:57:56 - Run 2
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Users\Euronics\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 67,56% Memory free
7,71 Gb Paging File | 5,80 Gb Available in Paging File | 75,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,29 Gb Total Space | 352,32 Gb Free Space | 77,90% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 465,66 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
 
Computer Name: EURONICS-VAIO | User Name: Euronics | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.05 22:56:29 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe
PRC - [2011.03.04 14:36:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.06.09 00:55:16 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2010.06.01 04:01:54 | 000,600,928 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2010.05.31 20:18:32 | 000,120,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2010.05.31 18:01:52 | 000,673,136 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.05.26 11:08:08 | 000,055,152 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\VAIO Care\VCSpt.exe
PRC - [2010.05.18 14:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Programme\Sony\VAIO Care\listener.exe
PRC - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010.03.04 05:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.14 10:56:19 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\009c50fb69919b90fb233cb4c35d0ad7\System.Windows.Forms.ni.dll
MOD - [2012.06.14 10:56:13 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebefde27b0ef7f39bb49c493b34a602c\System.Drawing.ni.dll
MOD - [2012.05.10 18:46:46 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\73baa23d28d21c7c01e334211330a84e\IAStorUtil.ni.dll
MOD - [2012.05.10 18:44:35 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll
MOD - [2012.05.10 18:43:59 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b68fdf2c95b93fc5006a092c11eed07c\WindowsBase.ni.dll
MOD - [2012.05.10 18:43:55 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll
MOD - [2012.05.10 18:43:52 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll
MOD - [2012.05.10 18:43:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll
MOD - [2012.05.10 18:43:47 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll
MOD - [2011.07.24 16:34:57 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.11.25 18:09:26 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.25 18:09:23 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.06.24 22:06:19 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.05.25 06:23:52 | 000,252,416 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV - [2012.06.21 23:34:35 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe -- (MySQL)
SRV - [2010.11.25 09:27:27 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.10.12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.06.21 19:00:52 | 000,575,856 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV - [2010.06.20 22:47:18 | 000,108,400 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2010.06.20 22:47:16 | 000,067,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2010.06.18 08:07:12 | 000,423,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2010.06.17 13:44:10 | 000,851,824 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2010.06.09 16:57:16 | 000,101,232 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV - [2010.06.09 16:56:02 | 000,384,880 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV - [2010.06.09 16:55:00 | 000,537,456 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2010.06.09 00:55:14 | 000,952,096 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2010.06.08 18:00:04 | 000,836,608 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV - [2010.06.06 23:13:46 | 000,304,496 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV - [2010.06.01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010.05.31 19:25:48 | 001,250,160 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Programme\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.09 06:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.07 20:26:48 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.01.07 20:26:48 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.06.28 19:53:20 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.28 19:53:20 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.03.11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.06.24 22:34:53 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.06.24 22:33:43 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.06.24 22:06:24 | 006,107,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.06.23 22:04:45 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010.06.23 22:04:43 | 000,342,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010.06.23 22:04:43 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.06.23 22:04:43 | 000,102,952 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010.06.23 22:04:09 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010.06.23 22:03:07 | 000,078,848 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsne64.sys -- (risdsnpe)
DRV:64bit: - [2010.06.23 22:02:59 | 000,094,208 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2010.05.31 23:36:54 | 000,299,568 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2010.05.31 23:36:48 | 000,402,720 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2010.05.31 23:36:41 | 001,573,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.05.31 22:10:13 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2010.05.28 22:03:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.05.28 22:02:36 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2010.04.26 22:20:29 | 000,012,032 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.26 15:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2008.06.16 04:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEE&bmod=SVEE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{26722C1C-238C-4F45-9235-0FF35F364C09}: "URL" = hxxp://de.shopping.com/?linkin_id=8056363
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\..\SearchScopes\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011.04.15 23:33:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Euronics\AppData\Roaming\mozilla\Extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012.04.01 21:33:10 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.11.10 20:13:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.07.02 19:51:28 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-1.xml
[2012.03.20 13:37:33 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-10.xml
[2012.04.06 12:12:54 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-11.xml
[2012.05.05 17:11:30 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-12.xml
[2012.05.08 18:20:34 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-13.xml
[2012.06.18 20:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-14.xml
[2012.06.25 22:29:58 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-15.xml
[2011.07.03 01:06:11 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-2.xml
[2011.08.17 22:01:39 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-3.xml
[2011.09.01 19:08:43 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-4.xml
[2011.09.11 22:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-5.xml
[2011.09.19 20:41:27 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-6.xml
[2011.10.05 20:49:18 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-8.xml
[2011.11.17 19:44:05 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-9.xml
[2011.06.21 12:46:50 | 000,001,056 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin.xml
[2012.04.30 19:33:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.04.16 07:59:17 | 000,330,316 | ---- | M] () (No name found) -- C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
[2012.06.21 23:34:35 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.21 23:34:33 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.21 23:34:33 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.21 23:34:33 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.21 23:34:33 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.21 23:34:33 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.21 23:34:33 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [EPSON SX210 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFDE.EXE /FU "C:\Users\Euronics\AppData\Local\Temp\E_S95C9.tmp" /EF "HKCU" File not found
O4 - Startup: C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{423D4F55-13A2-4D2E-BBDA-A1774A136043}: DhcpNameServer = 172.16.16.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3593B11-7940-4EF9-BF6F-C86A919D5698}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MCODS - Reg Error: Value error.
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: MCODS - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} -
ActiveX:64bit: >{F65A5BD6-CBD5-44BB-92EE-7CD500DC5948} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.05 22:56:28 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
[2012.07.02 20:39:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.02 20:39:43 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Euronics\Desktop\esetsmartinstaller_enu.exe
[2012.06.25 22:02:49 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Malwarebytes
[2012.06.25 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.25 22:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.25 22:02:40 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.25 22:02:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.25 20:24:46 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Avira
[2012.06.23 20:55:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\V5 Play
[2012.06.23 20:54:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\V5Play
[2012.06.23 17:55:59 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2012.06.21 20:17:28 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2012.06.18 22:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Fugazo
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Local\JollyBear
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\ProgramData\JollyBear
[2012.06.16 13:22:59 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.16 12:55:00 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\WildTangent
[2012.06.06 19:24:17 | 000,000,000 | ---D | C] -- C:\Users\Euronics\Desktop\17.03.2012
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.05 22:56:29 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
[2012.07.05 22:47:01 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.05 22:23:15 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 22:23:15 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.05 22:15:53 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.05 22:15:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.05 22:15:34 | 3106,480,128 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.02 20:39:46 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Euronics\Desktop\esetsmartinstaller_enu.exe
[2012.06.25 22:30:42 | 000,000,000 | ---- | M] () -- C:\Users\Euronics\defogger_reenable
[2012.06.25 22:26:32 | 000,050,477 | ---- | M] () -- C:\Users\Euronics\Desktop\Defogger.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.23 20:55:44 | 000,001,172 | ---- | M] () -- C:\Users\Euronics\Desktop\May's Mystery.lnk
[2012.06.23 12:01:18 | 000,002,698 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk
[2012.06.19 19:08:01 | 000,492,004 | ---- | M] () -- C:\test.xml
[2012.06.14 10:54:24 | 000,323,192 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 01:09:20 | 001,522,286 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.14 01:09:20 | 000,654,852 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.14 01:09:20 | 000,616,694 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.14 01:09:20 | 000,130,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.14 01:09:20 | 000,106,816 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.25 22:30:42 | 000,000,000 | ---- | C] () -- C:\Users\Euronics\defogger_reenable
[2012.06.25 22:26:31 | 000,050,477 | ---- | C] () -- C:\Users\Euronics\Desktop\Defogger.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.23 20:55:44 | 000,001,172 | ---- | C] () -- C:\Users\Euronics\Desktop\May's Mystery.lnk
[2012.04.07 18:05:04 | 000,000,416 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.04.07 18:05:04 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD5240.DAT
[2012.04.07 18:04:52 | 000,014,496 | ---- | C] () -- C:\Windows\HL-5240.INI
[2012.04.07 18:04:52 | 000,000,151 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012.04.07 18:04:52 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\brlmw03a.ini
[2012.04.07 18:04:52 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012.04.07 18:04:18 | 000,000,091 | ---- | C] () -- C:\Windows\Brownie.ini
[2011.05.04 16:46:50 | 001,527,912 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.12 19:30:23 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.10.12 19:30:22 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.10.12 19:30:22 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.10.12 19:30:21 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.10.12 19:30:20 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.10.12 19:30:13 | 000,028,732 | ---- | C] () -- C:\Windows\SysWow64\ativvsny.dat
[2010.10.12 19:30:13 | 000,026,936 | ---- | C] () -- C:\Windows\SysWow64\ativvsnl.dat
[2010.10.12 19:27:41 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== LOP Check ==========
 
[2011.04.19 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Acreon
[2011.10.20 19:28:41 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Alawar
[2011.08.14 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Canneverbe Limited
[2012.01.01 19:41:08 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Colibri Games
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Complitly
[2011.11.10 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoft
[2011.11.10 20:13:44 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.06 13:22:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\elsterformular
[2012.06.16 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Frogwares
[2011.12.30 18:15:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\GameHouse
[2012.03.25 21:42:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ICQ
[2012.06.16 13:22:59 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.21 20:17:28 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2011.07.24 16:35:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\OpenOffice.org
[2011.09.21 19:58:43 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\pdfforge
[2011.11.22 23:24:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft2
[2011.11.24 23:48:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft3
[2011.04.28 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PhotoScape
[2012.02.16 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\SoftGrid Client
[2011.05.04 16:47:54 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TP
[2012.04.30 19:27:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TS3Client
[2012.01.07 22:57:40 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Ubisoft
[2012.01.07 14:32:14 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V-Games
[2012.06.23 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2011.10.20 18:43:12 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\VC 2 Paradise Resort
[2012.06.18 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\WildTangent
[2012.06.29 23:14:50 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.04.19 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Acreon
[2011.04.19 17:56:05 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Adobe
[2011.10.20 19:28:41 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Alawar
[2011.04.30 22:12:55 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ArcSoft
[2011.04.05 18:14:09 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ATI
[2012.06.25 20:24:46 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Avira
[2011.08.14 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Canneverbe Limited
[2012.01.01 19:41:08 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Colibri Games
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Complitly
[2011.11.10 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoft
[2011.11.10 20:13:44 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.06 13:22:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\elsterformular
[2012.06.16 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Frogwares
[2011.12.30 18:15:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\GameHouse
[2012.03.25 21:42:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ICQ
[2011.04.05 18:13:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Identities
[2011.04.05 18:14:20 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Intel Corporation
[2012.06.16 13:22:59 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.21 20:17:28 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2010.11.25 09:24:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Macromedia
[2012.06.25 22:02:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Malwarebytes
[2010.10.13 00:58:02 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Media Center Programs
[2012.05.18 19:39:52 | 000,000,000 | --SD | M] -- C:\Users\Euronics\AppData\Roaming\Microsoft
[2011.04.15 23:33:51 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Mozilla
[2011.07.24 16:35:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\OpenOffice.org
[2011.09.21 19:58:43 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\pdfforge
[2011.11.22 23:24:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft2
[2011.11.24 23:48:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft3
[2011.04.28 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PhotoScape
[2011.11.20 22:37:17 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Realore_Whiterra Roads Of Rome 2
[2012.02.16 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\SoftGrid Client
[2011.04.05 17:15:25 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Sony Corporation
[2011.05.04 16:47:54 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TP
[2012.04.30 19:27:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TS3Client
[2012.01.07 22:57:40 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Ubisoft
[2012.01.07 14:32:14 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V-Games
[2012.06.23 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2011.10.20 18:43:12 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\VC 2 Paradise Resort
[2012.06.18 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\WildTangent
 
< %APPDATA%\*.exe /s >
[2011.04.19 10:52:48 | 000,272,384 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Acreon\WowMatrix\Modules\curl.exe
[2011.10.16 16:56:00 | 000,091,128 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Complitly\KeepMeUpdated.exe
[2011.10.16 16:56:00 | 000,091,128 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Complitly\64\KeepMeUpdated.exe
[2010.11.25 09:24:32 | 000,038,784 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.09.28 20:54:04 | 000,415,432 | ---- | M] (WildTangent, Inc.) -- C:\Users\Euronics\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\nancydrewtrailofthetwister\nancydrewtrailofthetwister-wildgames.exe
[2012.05.22 03:34:34 | 000,571,040 | ---- | M] (WildTangent, Inc.) -- C:\Users\Euronics\AppData\Roaming\WildTangent\WildTangent Games\App\Update\Updater.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2009.12.20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Files - Unicode (All) ==========
[2011.05.11 16:43:58 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—
[2011.05.11 16:43:58 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—

< End of report >

--- --- ---


Wahnsinn das man da überhaupt was draus erkennen kann :confused:

Grüße

cosinus 06.07.2012 09:34

Code:

Scan Mode: Current user
Haken bei alle Benutzer vergessen!

PuritySH 06.07.2012 16:39

Hallo,

... nun in richtig. (Hoffe ich...)

Code:

OTL logfile created on: 06.07.2012 17:04:59 - Run 3
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Users\Euronics\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 59,09% Memory free
7,71 Gb Paging File | 5,71 Gb Available in Paging File | 73,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,29 Gb Total Space | 352,96 Gb Free Space | 78,04% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 465,66 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
 
Computer Name: EURONICS-VAIO | User Name: Euronics | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.06 17:03:39 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe
PRC - [2011.03.04 14:36:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.06.09 00:55:16 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2010.06.01 04:01:54 | 000,600,928 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2010.05.31 20:18:32 | 000,120,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2010.05.31 18:01:52 | 000,673,136 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.05.26 11:08:08 | 000,055,152 | ---- | M] (Sony Corporation) -- C:\Programme\Sony\VAIO Care\VCSpt.exe
PRC - [2010.05.18 14:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Programme\Sony\VAIO Care\listener.exe
PRC - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010.03.04 05:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.14 10:56:19 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\009c50fb69919b90fb233cb4c35d0ad7\System.Windows.Forms.ni.dll
MOD - [2012.06.14 10:56:13 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebefde27b0ef7f39bb49c493b34a602c\System.Drawing.ni.dll
MOD - [2012.05.10 18:46:46 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\73baa23d28d21c7c01e334211330a84e\IAStorUtil.ni.dll
MOD - [2012.05.10 18:44:35 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll
MOD - [2012.05.10 18:43:59 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b68fdf2c95b93fc5006a092c11eed07c\WindowsBase.ni.dll
MOD - [2012.05.10 18:43:55 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll
MOD - [2012.05.10 18:43:52 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll
MOD - [2012.05.10 18:43:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll
MOD - [2012.05.10 18:43:47 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll
MOD - [2011.07.24 16:34:57 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2010.11.25 18:09:26 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.11.25 18:09:23 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.06.24 22:06:19 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.05.25 06:23:52 | 000,252,416 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV - [2012.06.21 23:34:35 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011.06.28 19:53:19 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.27 11:09:10 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.11 15:02:28 | 008,142,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe -- (MySQL)
SRV - [2010.11.25 09:27:27 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.10.12 19:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.06.21 19:00:52 | 000,575,856 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV - [2010.06.20 22:47:18 | 000,108,400 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2010.06.20 22:47:16 | 000,067,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2010.06.18 08:07:12 | 000,423,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2010.06.17 13:44:10 | 000,851,824 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2010.06.09 16:57:16 | 000,101,232 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV - [2010.06.09 16:56:02 | 000,384,880 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV - [2010.06.09 16:55:00 | 000,537,456 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2010.06.09 00:55:14 | 000,952,096 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2010.06.08 18:00:04 | 000,836,608 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV - [2010.06.06 23:13:46 | 000,304,496 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV - [2010.06.01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.06.01 04:01:56 | 000,367,456 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2010.05.31 20:18:32 | 000,217,968 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010.05.31 19:25:48 | 001,250,160 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2010.05.28 22:02:57 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.05.28 22:02:38 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.03.04 05:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.09 06:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.09.18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.07 20:26:48 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.01.07 20:26:48 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.06.28 19:53:20 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.28 19:53:20 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.03.11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.06.24 22:34:53 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.06.24 22:33:43 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.06.24 22:06:24 | 006,107,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.06.23 22:04:45 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010.06.23 22:04:43 | 000,342,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010.06.23 22:04:43 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.06.23 22:04:43 | 000,102,952 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010.06.23 22:04:09 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010.06.23 22:03:07 | 000,078,848 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsne64.sys -- (risdsnpe)
DRV:64bit: - [2010.06.23 22:02:59 | 000,094,208 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2010.05.31 23:36:54 | 000,299,568 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2010.05.31 23:36:48 | 000,402,720 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2010.05.31 23:36:41 | 001,573,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.05.31 22:10:13 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2010.05.28 22:03:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.05.28 22:02:36 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2010.04.26 22:20:29 | 000,012,032 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.26 15:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2008.06.16 04:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEE&bmod=SVEE
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{26722C1C-238C-4F45-9235-0FF35F364C09}: "URL" = hxxp://de.shopping.com/?linkin_id=8056363
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.21 23:34:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011.04.15 23:33:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Euronics\AppData\Roaming\mozilla\Extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012.04.01 21:33:10 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.11.10 20:13:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.07.02 19:51:28 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-1.xml
[2012.03.20 13:37:33 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-10.xml
[2012.04.06 12:12:54 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-11.xml
[2012.05.05 17:11:30 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-12.xml
[2012.05.08 18:20:34 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-13.xml
[2012.06.18 20:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-14.xml
[2012.06.25 22:29:58 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-15.xml
[2011.07.03 01:06:11 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-2.xml
[2011.08.17 22:01:39 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-3.xml
[2011.09.01 19:08:43 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-4.xml
[2011.09.11 22:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-5.xml
[2011.09.19 20:41:27 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-6.xml
[2011.10.05 20:49:18 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-8.xml
[2011.11.17 19:44:05 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-9.xml
[2011.06.21 12:46:50 | 000,001,056 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin.xml
[2012.04.30 19:33:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.04.16 07:59:17 | 000,330,316 | ---- | M] () (No name found) -- C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
[2012.06.21 23:34:35 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.21 23:34:33 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.21 23:34:33 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.21 23:34:33 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.21 23:34:33 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.21 23:34:33 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.21 23:34:33 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-183073535-2217135185-3241308808-1000..\Run: [EPSON SX210 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFDE.EXE /FU "C:\Users\Euronics\AppData\Local\Temp\E_S95C9.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{423D4F55-13A2-4D2E-BBDA-A1774A136043}: DhcpNameServer = 172.16.16.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3593B11-7940-4EF9-BF6F-C86A919D5698}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MCODS - Reg Error: Value error.
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: MCODS - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} -
ActiveX:64bit: >{F65A5BD6-CBD5-44BB-92EE-7CD500DC5948} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.06 17:03:38 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
[2012.07.02 20:39:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.02 20:39:43 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Euronics\Desktop\esetsmartinstaller_enu.exe
[2012.06.25 22:02:49 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Malwarebytes
[2012.06.25 22:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.25 22:02:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.25 22:02:40 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.25 22:02:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.25 20:24:46 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Avira
[2012.06.23 20:55:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\V5 Play
[2012.06.23 20:54:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\V5Play
[2012.06.23 17:55:59 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2012.06.21 20:17:28 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2012.06.18 22:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Fugazo
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Local\JollyBear
[2012.06.18 20:49:28 | 000,000,000 | ---D | C] -- C:\ProgramData\JollyBear
[2012.06.16 13:22:59 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.16 12:55:00 | 000,000,000 | ---D | C] -- C:\Users\Euronics\AppData\Roaming\WildTangent
[2012.06.06 19:24:17 | 000,000,000 | ---D | C] -- C:\Users\Euronics\Desktop\17.03.2012
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.06 17:09:05 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.06 17:09:05 | 000,013,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.06 17:03:39 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Euronics\Desktop\OTL.exe
[2012.07.06 17:01:50 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.06 17:01:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.06 17:01:31 | 3106,480,128 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.05 22:47:01 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.02 20:39:46 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Euronics\Desktop\esetsmartinstaller_enu.exe
[2012.06.25 22:30:42 | 000,000,000 | ---- | M] () -- C:\Users\Euronics\defogger_reenable
[2012.06.25 22:26:32 | 000,050,477 | ---- | M] () -- C:\Users\Euronics\Desktop\Defogger.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.23 20:55:44 | 000,001,172 | ---- | M] () -- C:\Users\Euronics\Desktop\May's Mystery.lnk
[2012.06.23 12:01:18 | 000,002,698 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk
[2012.06.19 19:08:01 | 000,492,004 | ---- | M] () -- C:\test.xml
[2012.06.14 10:54:24 | 000,323,192 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 01:09:20 | 001,522,286 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.14 01:09:20 | 000,654,852 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.14 01:09:20 | 000,616,694 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.14 01:09:20 | 000,130,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.14 01:09:20 | 000,106,816 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.25 22:30:42 | 000,000,000 | ---- | C] () -- C:\Users\Euronics\defogger_reenable
[2012.06.25 22:26:31 | 000,050,477 | ---- | C] () -- C:\Users\Euronics\Desktop\Defogger.exe
[2012.06.25 22:02:42 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.23 20:55:44 | 000,001,172 | ---- | C] () -- C:\Users\Euronics\Desktop\May's Mystery.lnk
[2012.04.07 18:05:04 | 000,000,416 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.04.07 18:05:04 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD5240.DAT
[2012.04.07 18:04:52 | 000,014,496 | ---- | C] () -- C:\Windows\HL-5240.INI
[2012.04.07 18:04:52 | 000,000,151 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012.04.07 18:04:52 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\brlmw03a.ini
[2012.04.07 18:04:52 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012.04.07 18:04:18 | 000,000,091 | ---- | C] () -- C:\Windows\Brownie.ini
[2011.05.04 16:46:50 | 001,527,912 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.10.12 19:30:23 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.10.12 19:30:22 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.10.12 19:30:22 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.10.12 19:30:21 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.10.12 19:30:20 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.10.12 19:30:13 | 000,028,732 | ---- | C] () -- C:\Windows\SysWow64\ativvsny.dat
[2010.10.12 19:30:13 | 000,026,936 | ---- | C] () -- C:\Windows\SysWow64\ativvsnl.dat
[2010.10.12 19:27:41 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== LOP Check ==========
 
[2011.04.19 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Acreon
[2011.10.20 19:28:41 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Alawar
[2011.08.14 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Canneverbe Limited
[2012.01.01 19:41:08 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Colibri Games
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Complitly
[2011.11.10 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoft
[2011.11.10 20:13:44 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.06 13:22:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\elsterformular
[2012.06.16 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Frogwares
[2011.12.30 18:15:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\GameHouse
[2012.03.25 21:42:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ICQ
[2012.06.16 13:22:59 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.21 20:17:28 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2011.07.24 16:35:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\OpenOffice.org
[2011.09.21 19:58:43 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\pdfforge
[2011.11.22 23:24:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft2
[2011.11.24 23:48:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft3
[2011.04.28 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PhotoScape
[2012.02.16 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\SoftGrid Client
[2011.05.04 16:47:54 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TP
[2012.04.30 19:27:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TS3Client
[2012.01.07 22:57:40 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Ubisoft
[2012.01.07 14:32:14 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V-Games
[2012.06.23 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2011.10.20 18:43:12 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\VC 2 Paradise Resort
[2012.06.18 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\WildTangent
[2012.06.29 23:14:50 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.04.19 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Acreon
[2011.04.19 17:56:05 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Adobe
[2011.10.20 19:28:41 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Alawar
[2011.04.30 22:12:55 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ArcSoft
[2011.04.05 18:14:09 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ATI
[2012.06.25 20:24:46 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Avira
[2011.08.14 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Canneverbe Limited
[2012.01.01 19:41:08 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Colibri Games
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Complitly
[2011.11.10 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoft
[2011.11.10 20:13:44 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.06 13:22:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\elsterformular
[2012.06.16 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Frogwares
[2011.12.30 18:15:38 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\GameHouse
[2012.03.25 21:42:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\ICQ
[2011.04.05 18:13:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Identities
[2011.04.05 18:14:20 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Intel Corporation
[2012.06.16 13:22:59 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\LegacyInteractive
[2012.06.21 20:17:28 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Little Worlds Online
[2010.11.25 09:24:56 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Macromedia
[2012.06.25 22:02:49 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Malwarebytes
[2010.10.13 00:58:02 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Media Center Programs
[2012.05.18 19:39:52 | 000,000,000 | --SD | M] -- C:\Users\Euronics\AppData\Roaming\Microsoft
[2011.04.15 23:33:51 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Mozilla
[2011.07.24 16:35:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\OpenOffice.org
[2011.09.21 19:58:43 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\pdfforge
[2011.11.22 23:24:47 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft2
[2011.11.24 23:48:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PeaceCraft3
[2011.04.28 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\PhotoScape
[2011.11.20 22:37:17 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Realore_Whiterra Roads Of Rome 2
[2012.02.16 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\SoftGrid Client
[2011.04.05 17:15:25 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Sony Corporation
[2011.05.04 16:47:54 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TP
[2012.04.30 19:27:21 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\TS3Client
[2012.01.07 22:57:40 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\Ubisoft
[2012.01.07 14:32:14 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V-Games
[2012.06.23 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\V5 Play
[2011.10.20 18:43:12 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\VC 2 Paradise Resort
[2012.06.18 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\Euronics\AppData\Roaming\WildTangent
 
< %APPDATA%\*.exe /s >
[2011.04.19 10:52:48 | 000,272,384 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Acreon\WowMatrix\Modules\curl.exe
[2011.10.16 16:56:00 | 000,091,128 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Complitly\KeepMeUpdated.exe
[2011.10.16 16:56:00 | 000,091,128 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Complitly\64\KeepMeUpdated.exe
[2010.11.25 09:24:32 | 000,038,784 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.09.28 20:54:04 | 000,415,432 | ---- | M] (WildTangent, Inc.) -- C:\Users\Euronics\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\nancydrewtrailofthetwister\nancydrewtrailofthetwister-wildgames.exe
[2012.05.22 03:34:34 | 000,571,040 | ---- | M] (WildTangent, Inc.) -- C:\Users\Euronics\AppData\Roaming\WildTangent\WildTangent Games\App\Update\Updater.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2009.12.20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Files - Unicode (All) ==========
[2011.05.11 16:43:58 | 000,000,040 | ---- | M] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—
[2011.05.11 16:43:58 | 000,000,040 | ---- | C] ()(C:\Windows\SysNative\??) -- C:\Windows\SysNative\ꋀ—

< End of report >

Viele Grüße

Janina

cosinus 09.07.2012 07:59

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{26722C1C-238C-4F45-9235-0FF35F364C09}: "URL" = http://de.shopping.com/?linkin_id=8056363
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}: "URL" = http://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
IE - HKU\S-1-5-21-183073535-2217135185-3241308808-1000\..\SearchScopes\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}: "URL" = http://services.zinio.com/search?s={searchTerms}&rf=sonyslices
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.de/"
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q="
[2012.05.30 21:07:18 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011.11.10 20:06:37 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012.04.01 21:33:10 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.11.10 20:13:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.07.02 19:51:28 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-1.xml
[2012.03.20 13:37:33 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-10.xml
[2012.04.06 12:12:54 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-11.xml
[2012.05.05 17:11:30 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-12.xml
[2012.05.08 18:20:34 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-13.xml
[2012.06.18 20:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-14.xml
[2012.06.25 22:29:58 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-15.xml
[2011.07.03 01:06:11 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-2.xml
[2011.08.17 22:01:39 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-3.xml
[2011.09.01 19:08:43 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-4.xml
[2011.09.11 22:45:17 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-5.xml
[2011.09.19 20:41:27 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-6.xml
[2011.10.05 20:49:18 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-7.xml
[2011.10.11 19:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-8.xml
[2011.11.17 19:44:05 | 000,000,950 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-9.xml
[2011.06.21 12:46:50 | 000,001,056 | ---- | M] () -- C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin.xml
O2:64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Euronics\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4 - HKU\S-1-5-21-183073535-2217135185-3241308808-1000..\Run: [EPSON SX210 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFDE.EXE /FU "C:\Users\Euronics\AppData\Local\Temp\E_S95C9.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
:Files
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

PuritySH 10.07.2012 19:00

Hallo,

vielen Dank für die Antwort.

Hier also das Logfile:

Code:

All processes killed
========== OTL ==========
HKU\S-1-5-21-183073535-2217135185-3241308808-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\ not found.
Registry value HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll moved successfully.
HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\{26722C1C-238C-4F45-9235-0FF35F364C09}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26722C1C-238C-4F45-9235-0FF35F364C09}\ not found.
Registry key HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCE6CB67-8AFF-4BB8-BA2E-9E3D90C2F1A9}\ not found.
Registry key HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA73A74D-67BB-4413-A6E6-DF95D35295F1}\ not found.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=" removed from browser.search.defaulturl
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: "hxxp://www.google.de/" removed from browser.startup.homepage
Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q=" removed from keyword.URL
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\searchplugin folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\Plugins folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\modules folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\META-INF folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\defaults folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\chrome folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}\defaults\preferences folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}\defaults folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}\chrome\content folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}\chrome folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516} folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully.
C:\Users\Euronics\AppData\Roaming\mozilla\Firefox\Profiles\yhxmh8xv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-10.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-11.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-12.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-13.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-14.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-15.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-7.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-8.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin-9.xml moved successfully.
C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\searchplugins\icqplugin.xml moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
C:\Users\Euronics\AppData\Roaming\Complitly\64\Complitly64.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
C:\Users\Euronics\AppData\Roaming\Complitly\Complitly.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
File C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_USERS\S-1-5-21-183073535-2217135185-3241308808-1000\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON SX210 Series deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
========== FILES ==========
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Euronics\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Euronics
->Temp folder emptied: 134348881 bytes
->Temporary Internet Files folder emptied: 87264932 bytes
->FireFox cache emptied: 62030824 bytes
->Google Chrome cache emptied: 7110668 bytes
->Flash cache emptied: 63840 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 775028175 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84962 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.017,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Euronics
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.53.1 log created on 07102012_195241

Files\Folders moved on Reboot...
C:\Users\Euronics\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF06C697C3352B3C6A.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF0A36C7D00D24C896.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF25DDBE75611EE815.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF30B706257DFB2508.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF333B0845D91C8375.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF37A568223A347AFF.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF419E4A0C0793CE75.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF5A38AD1B3CDF3D21.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF64180ACF7666AD91.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF77D21A56CDEDC3D7.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DF90FC7B889F52F35F.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DFDA7299590DE1B135.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DFE9E4D494B547E83A.TMP not found!
File\Folder C:\Users\Euronics\AppData\Local\Temp\~DFFACB1F7D57A1A44B.TMP not found!

PendingFileRenameOperations files...
File C:\Users\Euronics\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF06C697C3352B3C6A.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF0A36C7D00D24C896.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF25DDBE75611EE815.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF30B706257DFB2508.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF333B0845D91C8375.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF37A568223A347AFF.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF419E4A0C0793CE75.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF5A38AD1B3CDF3D21.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF64180ACF7666AD91.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF77D21A56CDEDC3D7.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DF90FC7B889F52F35F.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DFDA7299590DE1B135.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DFE9E4D494B547E83A.TMP not found!
File C:\Users\Euronics\AppData\Local\Temp\~DFFACB1F7D57A1A44B.TMP not found!

Registry entries deleted on Reboot...

Viele Grüße

cosinus 10.07.2012 22:06

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

PuritySH 11.07.2012 21:21

Hallo,

hier die Datei:

Code:

# AdwCleaner v1.701 - Logfile created 07/11/2012 at 22:20:08
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium  (64 bits)
# User : Euronics - EURONICS-VAIO
# Running from : C:\Users\Euronics\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Euronics\AppData\Local\Conduit
Folder Found : C:\Users\Euronics\AppData\LocalLow\Conduit
Folder Found : C:\Users\Euronics\AppData\Roaming\Complitly
Folder Found : C:\Users\Euronics\AppData\Roaming\pdfforge
Folder Found : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\ConduitCommon
Folder Found : C:\Program Files (x86)\Complitly
Folder Found : C:\Program Files (x86)\Conduit

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Found : HKCU\Software\Ask&Record
Key Found : HKCU\Software\Complitly
Key Found : HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
[x64] Key Found : HKCU\Software\Ask&Record
[x64] Key Found : HKCU\Software\Complitly
[x64] Key Found : HKCU\Software\Conduit
[x64] Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
[x64] Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
[x64] Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\prefs.js

Found : user_pref("CT1060933..clientLogIsEnabled", false);
Found : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129633202291172081", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129652058719725628", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Found : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Found : user_pref("CT1060933.CTID", "CT1060933");
Found : user_pref("CT1060933.CurrentServerDate", "10-7-2012");
Found : user_pref("CT1060933.DSInstall", false);
Found : user_pref("CT1060933.DialogsAlignMode", "LTR");
Found : user_pref("CT1060933.DialogsGetterLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.DownloadReferralCookieData", "");
Found : user_pref("CT1060933.EnableClickToSearchBox", false);
Found : user_pref("CT1060933.EnableSearchHistory", false);
Found : user_pref("CT1060933.EnableSearchSuggest", false);
Found : user_pref("CT1060933.FirstServerDate", "10-11-2011");
Found : user_pref("CT1060933.FirstTime", true);
Found : user_pref("CT1060933.FirstTimeFF3", true);
Found : user_pref("CT1060933.FixPageNotFoundErrors", false);
Found : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Found : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT1060933.HPInstall", false);
Found : user_pref("CT1060933.HasUserGlobalKeys", true);
Found : user_pref("CT1060933.HomePageProtectorEnabled", false);
Found : user_pref("CT1060933.HomepageBeforeUnload", "hxxp://www.google.de/");
Found : user_pref("CT1060933.Initialize", true);
Found : user_pref("CT1060933.InitializeCommonPrefs", true);
Found : user_pref("CT1060933.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT1060933.InstallationId", "ConduitStubGeneric");
Found : user_pref("CT1060933.InstallationType", "ConduitStubIntegration");
Found : user_pref("CT1060933.InstalledDate", "Thu Nov 10 2011 19:06:42 GMT+0100");
Found : user_pref("CT1060933.InvalidateCache", false);
Found : user_pref("CT1060933.IsAlertDBUpdated", true);
Found : user_pref("CT1060933.IsGrouping", false);
Found : user_pref("CT1060933.IsInitSetupIni", true);
Found : user_pref("CT1060933.IsMulticommunity", false);
Found : user_pref("CT1060933.IsOpenThankYouPage", false);
Found : user_pref("CT1060933.IsOpenUninstallPage", true);
Found : user_pref("CT1060933.LanguagePackLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT1060933.LastLogin_3.12.0.7", "Thu Apr 26 2012 19:22:06 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.12.2.3", "Wed May 30 2012 18:23:36 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.13.0.6", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.LastLogin_3.8.0.8", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CT1060933.LatestVersion", "3.13.0.6");
Found : user_pref("CT1060933.Locale", "en-us");
Found : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Found : user_pref("CT1060933.MCDetectTooltipShow", false);
Found : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Found : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT1060933.OriginalFirstVersion", "3.8.0.8");
Found : user_pref("CT1060933.RadioIsPodcast", false);
Found : user_pref("CT1060933.RadioLastCheckTime", "Thu Nov 10 2011 19:06:44 GMT+0100");
Found : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Found : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Found : user_pref("CT1060933.RadioMediaID", "21504191");
Found : user_pref("CT1060933.RadioMediaType", "Media Player");
Found : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Found : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Found : user_pref("CT1060933.RadioStationName", "KFOG");
Found : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Found : user_pref("CT1060933.SHRINK_TOOLBAR", 1);
Found : user_pref("CT1060933.SearchBackToDefaultEngine", false);
Found : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Found : user_pref("CT1060933.SearchEngineBeforeUnload", "ICQ Search");
Found : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Found : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Found : user_pref("CT1060933.SearchInNewTabEnabled", true);
Found : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Found : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT1060933.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Found : user_pref("CT1060933.SearchInNewTabUserEnabled", false);
Found : user_pref("CT1060933.SearchProtectorEnabled", false);
Found : user_pref("CT1060933.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Found : user_pref("CT1060933.ServiceMapLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.SettingsLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Found : user_pref("CT1060933.SettingsLastUpdate", "1341409951");
Found : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Found : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Thu Nov 10 2011 19:06:42 GMT+0100");
Found : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Found : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT1060933.UserID", "UN04397635592770677");
Found : user_pref("CT1060933.ValidationData_Search", 0);
Found : user_pref("CT1060933.ValidationData_Toolbar", 2);
Found : user_pref("CT1060933.alertChannelId", "15651");
Found : user_pref("CT1060933.appApproved.129272674122038321", true);
Found : user_pref("CT1060933.approveUntrustedApps", false);
Found : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Found : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Found : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F726A706D736E6F");
Found : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737578707673797475242F4B4947[...]
Found : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Found : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Found : user_pref("CT1060933.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...]
Found : user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Found : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Found : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Found : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Found : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Found : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Found : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Found : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Found : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Found : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Found : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Found : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Found : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Found : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g>d", "6C6C6D3D3D4175447A78754648207D4C797925507D50242A28[...]
Found : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT1060933.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Found : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Found : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Found : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Found : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "3D676C71707471447A7043777A7A487C784D4E227A");
Found : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F726A706D727773787474");
Found : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT1060933.components.1000082", false);
Found : user_pref("CT1060933.components.129032145384800518", false);
Found : user_pref("CT1060933.components.129032148247613461", false);
Found : user_pref("CT1060933.components.129032152822456983", false);
Found : user_pref("CT1060933.components.129032154330894193", false);
Found : user_pref("CT1060933.components.129032155426050046", false);
Found : user_pref("CT1060933.components.129032157011675027", false);
Found : user_pref("CT1060933.components.129032162642925076", false);
Found : user_pref("CT1060933.components.129078058382649592", false);
Found : user_pref("CT1060933.components.129272674122038321", false);
Found : user_pref("CT1060933.components.129633202291172081", false);
Found : user_pref("CT1060933.components.129639980260409734", false);
Found : user_pref("CT1060933.components.129652058719725628", false);
Found : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Fri Nov 11 2011 03:06:43 GMT+0100");
Found : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Found : user_pref("CT1060933.initDone", true);
Found : user_pref("CT1060933.isAppTrackingManagerOn", true);
Found : user_pref("CT1060933.isFirstRadioInstallation", false);
Found : user_pref("CT1060933.isSearchProtectorNotifyChanges", false);
Found : user_pref("CT1060933.myStuffEnabled", true);
Found : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Found : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT1060933.oldAppsList", "128346981843587669,128280995260143876,111,129272674122038321,129[...]
Found : user_pref("CT1060933.revertSettingsEnabled", true);
Found : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Found : user_pref("CT1060933.testingCtid", "");
Found : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Found : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CT1060933.usageEnabled", false);
Found : user_pref("CT1060933.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/15651/15317/DE", "\"0\"");
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT1060933&octid=[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Euronics\\AppData\\Roaming\\Mozilla[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://freecorder.com/fc6/gadget/video.html", "833x3[...]
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Found : user_pref("CommunityToolbar.globalUserId", "96545c57-4b65-4045-b007-ac128590f878");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Nov 10 2011 19:06:4[...]
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 10 2011 20:06:56 GMT+010[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "2492309d-1eb1-45f4-9456-e80b40798fae");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Found : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search");

-\\ Google Chrome v20.0.1132.47

File : C:\Users\Euronics\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [23109 octets] - [11/07/2012 22:20:08]

########## EOF - C:\AdwCleaner[R1].txt - [23238 octets] ##########

:dankeschoen:

cosinus 12.07.2012 10:11

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

PuritySH 12.07.2012 20:10

Guten Abend,

hier die Textdatei:

Code:

# AdwCleaner v1.701 - Logfile created 07/12/2012 at 19:49:59
# Updated 02/07/2012 by Xplode
# Operating system : Windows 7 Home Premium  (64 bits)
# User : Euronics - EURONICS-VAIO
# Running from : C:\Users\Euronics\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Euronics\AppData\Local\Conduit
Folder Deleted : C:\Users\Euronics\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Euronics\AppData\Roaming\Complitly
Folder Deleted : C:\Users\Euronics\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\ConduitCommon
Folder Deleted : C:\Program Files (x86)\Complitly
Folder Deleted : C:\Program Files (x86)\Conduit

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Key Deleted : HKCU\Software\Ask&Record
Key Deleted : HKCU\Software\Complitly
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\prefs.js

C:\Users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\user.js ... Deleted !

Deleted : user_pref("CT1060933..clientLogIsEnabled", false);
Deleted : user_pref("CT1060933..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT1060933..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT1060933.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129633202291172081", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129652058719725628", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true);
Deleted : user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true);
Deleted : user_pref("CT1060933.CTID", "CT1060933");
Deleted : user_pref("CT1060933.CurrentServerDate", "10-7-2012");
Deleted : user_pref("CT1060933.DSInstall", false);
Deleted : user_pref("CT1060933.DialogsAlignMode", "LTR");
Deleted : user_pref("CT1060933.DialogsGetterLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.DownloadReferralCookieData", "");
Deleted : user_pref("CT1060933.EnableClickToSearchBox", false);
Deleted : user_pref("CT1060933.EnableSearchHistory", false);
Deleted : user_pref("CT1060933.EnableSearchSuggest", false);
Deleted : user_pref("CT1060933.FirstServerDate", "10-11-2011");
Deleted : user_pref("CT1060933.FirstTime", true);
Deleted : user_pref("CT1060933.FirstTimeFF3", true);
Deleted : user_pref("CT1060933.FixPageNotFoundErrors", false);
Deleted : user_pref("CT1060933.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT1060933.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT1060933.HPInstall", false);
Deleted : user_pref("CT1060933.HasUserGlobalKeys", true);
Deleted : user_pref("CT1060933.HomePageProtectorEnabled", false);
Deleted : user_pref("CT1060933.HomepageBeforeUnload", "hxxp://www.google.de/");
Deleted : user_pref("CT1060933.Initialize", true);
Deleted : user_pref("CT1060933.InitializeCommonPrefs", true);
Deleted : user_pref("CT1060933.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT1060933.InstallationId", "ConduitStubGeneric");
Deleted : user_pref("CT1060933.InstallationType", "ConduitStubIntegration");
Deleted : user_pref("CT1060933.InstalledDate", "Thu Nov 10 2011 19:06:42 GMT+0100");
Deleted : user_pref("CT1060933.InvalidateCache", false);
Deleted : user_pref("CT1060933.IsAlertDBUpdated", true);
Deleted : user_pref("CT1060933.IsGrouping", false);
Deleted : user_pref("CT1060933.IsInitSetupIni", true);
Deleted : user_pref("CT1060933.IsMulticommunity", false);
Deleted : user_pref("CT1060933.IsOpenThankYouPage", false);
Deleted : user_pref("CT1060933.IsOpenUninstallPage", true);
Deleted : user_pref("CT1060933.LanguagePackLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT1060933.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT1060933.LastLogin_3.12.0.7", "Thu Apr 26 2012 19:22:06 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.12.2.3", "Wed May 30 2012 18:23:36 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.13.0.6", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.LastLogin_3.8.0.8", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CT1060933.LatestVersion", "3.13.0.6");
Deleted : user_pref("CT1060933.Locale", "en-us");
Deleted : user_pref("CT1060933.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT1060933.MCDetectTooltipShow", false);
Deleted : user_pref("CT1060933.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT1060933.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT1060933.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT1060933.OriginalFirstVersion", "3.8.0.8");
Deleted : user_pref("CT1060933.RadioIsPodcast", false);
Deleted : user_pref("CT1060933.RadioLastCheckTime", "Thu Nov 10 2011 19:06:44 GMT+0100");
Deleted : user_pref("CT1060933.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000");
Deleted : user_pref("CT1060933.RadioMediaID", "21504191");
Deleted : user_pref("CT1060933.RadioMediaType", "Media Player");
Deleted : user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191");
Deleted : user_pref("CT1060933.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.RadioStationName", "KFOG");
Deleted : user_pref("CT1060933.RadioStationURL", "hxxp://live.cumulusstreaming.com/KFOG-FM");
Deleted : user_pref("CT1060933.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT1060933.SearchBackToDefaultEngine", false);
Deleted : user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search");
Deleted : user_pref("CT1060933.SearchEngineBeforeUnload", "ICQ Search");
Deleted : user_pref("CT1060933.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106[...]
Deleted : user_pref("CT1060933.SearchInNewTabEnabled", true);
Deleted : user_pref("CT1060933.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT1060933.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Deleted : user_pref("CT1060933.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT1060933.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Deleted : user_pref("CT1060933.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT1060933.SearchProtectorEnabled", false);
Deleted : user_pref("CT1060933.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT1060933.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT1060933.ServiceMapLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.SettingsLastCheckTime", "Tue Jul 10 2012 19:46:21 GMT+0200");
Deleted : user_pref("CT1060933.SettingsLastUpdate", "1341409951");
Deleted : user_pref("CT1060933.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13");
Deleted : user_pref("CT1060933.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Thu Nov 10 2011 19:06:42 GMT+0100");
Deleted : user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT1060933.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT1060933.TrusteLinkUrl", "hxxp://trust.conduit.com/CT1060933");
Deleted : user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT1060933.UserID", "UN04397635592770677");
Deleted : user_pref("CT1060933.ValidationData_Search", 0);
Deleted : user_pref("CT1060933.ValidationData_Toolbar", 2);
Deleted : user_pref("CT1060933.alertChannelId", "15651");
Deleted : user_pref("CT1060933.appApproved.129272674122038321", true);
Deleted : user_pref("CT1060933.approveUntrustedApps", false);
Deleted : user_pref("CT1060933.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e.:2z527", "2423");
Deleted : user_pref("CT1060933.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D6F726A706D736E6F");
Deleted : user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737578707673797475242F4B4947[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Deleted : user_pref("CT1060933.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g>d", "6C6C6D3D3D4175447A78754648207D4C797925507D50242A28[...]
Deleted : user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT1060933.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Deleted : user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
Deleted : user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Deleted : user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Deleted : user_pref("CT1060933.backendstorage./9b5ba==9cjag", "3D676C71707471447A7043777A7A487C784D4E227A");
Deleted : user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F726A706D727773787474");
Deleted : user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT1060933.components.1000082", false);
Deleted : user_pref("CT1060933.components.129032145384800518", false);
Deleted : user_pref("CT1060933.components.129032148247613461", false);
Deleted : user_pref("CT1060933.components.129032152822456983", false);
Deleted : user_pref("CT1060933.components.129032154330894193", false);
Deleted : user_pref("CT1060933.components.129032155426050046", false);
Deleted : user_pref("CT1060933.components.129032157011675027", false);
Deleted : user_pref("CT1060933.components.129032162642925076", false);
Deleted : user_pref("CT1060933.components.129078058382649592", false);
Deleted : user_pref("CT1060933.components.129272674122038321", false);
Deleted : user_pref("CT1060933.components.129633202291172081", false);
Deleted : user_pref("CT1060933.components.129639980260409734", false);
Deleted : user_pref("CT1060933.components.129652058719725628", false);
Deleted : user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Fri Nov 11 2011 03:06:43 GMT+0100");
Deleted : user_pref("CT1060933.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.initDone", true);
Deleted : user_pref("CT1060933.isAppTrackingManagerOn", true);
Deleted : user_pref("CT1060933.isFirstRadioInstallation", false);
Deleted : user_pref("CT1060933.isSearchProtectorNotifyChanges", false);
Deleted : user_pref("CT1060933.myStuffEnabled", true);
Deleted : user_pref("CT1060933.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT1060933.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT1060933.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT1060933.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT1060933.oldAppsList", "128346981843587669,128280995260143876,111,129272674122038321,129[...]
Deleted : user_pref("CT1060933.revertSettingsEnabled", true);
Deleted : user_pref("CT1060933.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT1060933.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT1060933.testingCtid", "");
Deleted : user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 19:46:22 GMT+0200");
Deleted : user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CT1060933.usageEnabled", false);
Deleted : user_pref("CT1060933.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/15651/15317/DE", "\"0\"");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT1060933&octid=[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Euronics\\AppData\\Roaming\\Mozilla[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://freecorder.com/fc6/gadget/video.html", "833x3[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1060933");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT1060933");
Deleted : user_pref("CommunityToolbar.globalUserId", "96545c57-4b65-4045-b007-ac128590f878");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Nov 10 2011 19:06:4[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 10 2011 20:06:56 GMT+010[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 10 2011 19:06:43 GMT+0100");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "2492309d-1eb1-45f4-9456-e80b40798fae");
Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.de/");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "ICQ Search");

-\\ Google Chrome v20.0.1132.47

File : C:\Users\Euronics\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [23214 octets] - [11/07/2012 22:20:08]
AdwCleaner[S1].txt - [22714 octets] - [12/07/2012 19:49:59]

########## EOF - C:\AdwCleaner[S1].txt - [22843 octets] ##########

:dankeschoen:

cosinus 12.07.2012 21:17

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

PuritySH 13.07.2012 17:29

Schönen Freitag Abend :)

hier das Log:

Code:

18:25:18.0570 4000        TDSS rootkit removing tool 2.7.45.0 Jul  9 2012 12:46:35
18:25:19.0038 4000        ============================================================
18:25:19.0038 4000        Current date / time: 2012/07/13 18:25:19.0038
18:25:19.0038 4000        SystemInfo:
18:25:19.0038 4000       
18:25:19.0038 4000        OS Version: 6.1.7600 ServicePack: 0.0
18:25:19.0038 4000        Product type: Workstation
18:25:19.0038 4000        ComputerName: EURONICS-VAIO
18:25:19.0038 4000        UserName: Euronics
18:25:19.0038 4000        Windows directory: C:\Windows
18:25:19.0038 4000        System windows directory: C:\Windows
18:25:19.0038 4000        Running under WOW64
18:25:19.0038 4000        Processor architecture: Intel x64
18:25:19.0038 4000        Number of processors: 4
18:25:19.0038 4000        Page size: 0x1000
18:25:19.0038 4000        Boot type: Normal boot
18:25:19.0038 4000        ============================================================
18:25:21.0550 4000        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:25:21.0659 4000        Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:25:21.0659 4000        ============================================================
18:25:21.0659 4000        \Device\Harddisk0\DR0:
18:25:21.0659 4000        MBR partitions:
18:25:21.0659 4000        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1ABF000, BlocksNum 0x32000
18:25:21.0659 4000        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1AF1000, BlocksNum 0x38894830
18:25:21.0659 4000        \Device\Harddisk1\DR1:
18:25:21.0659 4000        MBR partitions:
18:25:21.0846 4000        \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x1000, BlocksNum 0x3A384800
18:25:21.0846 4000        ============================================================
18:25:21.0909 4000        C: <-> \Device\Harddisk0\DR0\Partition1
18:25:21.0940 4000        D: <-> \Device\Harddisk1\DR1\Partition0
18:25:21.0940 4000        ============================================================
18:25:21.0940 4000        Initialize success
18:25:21.0940 4000        ============================================================
18:26:06.0603 4640        ============================================================
18:26:06.0603 4640        Scan started
18:26:06.0603 4640        Mode: Manual; SigCheck; TDLFS;
18:26:06.0603 4640        ============================================================
18:26:07.0320 4640        1394ohci        (969c91060cbb5d17cb8440b5f78b4c51) C:\Windows\system32\drivers\1394ohci.sys
18:26:07.0414 4640        1394ohci - ok
18:26:07.0523 4640        ACDaemon        (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
18:26:07.0820 4640        ACDaemon - ok
18:26:07.0882 4640        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\drivers\ACPI.sys
18:26:07.0898 4640        ACPI - ok
18:26:07.0929 4640        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\drivers\acpipmi.sys
18:26:08.0038 4640        AcpiPmi - ok
18:26:08.0116 4640        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
18:26:08.0132 4640        AdobeActiveFileMonitor8.0 - ok
18:26:08.0210 4640        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
18:26:08.0225 4640        adp94xx - ok
18:26:08.0303 4640        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
18:26:08.0319 4640        adpahci - ok
18:26:08.0366 4640        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
18:26:08.0366 4640        adpu320 - ok
18:26:08.0412 4640        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
18:26:08.0568 4640        AeLookupSvc - ok
18:26:08.0646 4640        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
18:26:08.0709 4640        AFD - ok
18:26:08.0756 4640        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
18:26:08.0756 4640        agp440 - ok
18:26:08.0787 4640        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
18:26:08.0849 4640        ALG - ok
18:26:08.0896 4640        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
18:26:08.0912 4640        aliide - ok
18:26:08.0958 4640        AMD External Events Utility (27429a457fca8f50923863a965fe0c6c) C:\Windows\system32\atiesrxx.exe
18:26:08.0990 4640        AMD External Events Utility - ok
18:26:08.0990 4640        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
18:26:09.0005 4640        amdide - ok
18:26:09.0052 4640        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
18:26:09.0130 4640        AmdK8 - ok
18:26:09.0177 4640        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
18:26:09.0239 4640        AmdPPM - ok
18:26:09.0302 4640        amdsata        (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
18:26:09.0317 4640        amdsata - ok
18:26:09.0348 4640        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
18:26:09.0364 4640        amdsbs - ok
18:26:09.0395 4640        amdxata        (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
18:26:09.0395 4640        amdxata - ok
18:26:09.0504 4640        AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
18:26:09.0504 4640        AntiVirSchedulerService - ok
18:26:09.0551 4640        AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
18:26:09.0567 4640        AntiVirService - ok
18:26:09.0629 4640        ApfiltrService  (2d45f2dfbc3d8f53df7ebeffa8c9bc38) C:\Windows\system32\drivers\Apfiltr.sys
18:26:09.0645 4640        ApfiltrService - ok
18:26:09.0676 4640        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
18:26:09.0770 4640        AppID - ok
18:26:09.0816 4640        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
18:26:09.0879 4640        AppIDSvc - ok
18:26:09.0941 4640        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
18:26:09.0972 4640        Appinfo - ok
18:26:10.0019 4640        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
18:26:10.0035 4640        arc - ok
18:26:10.0050 4640        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
18:26:10.0066 4640        arcsas - ok
18:26:10.0082 4640        ArcSoftKsUFilter (c130bc4a51b1382b2be8e44579ec4c0a) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
18:26:10.0097 4640        ArcSoftKsUFilter - ok
18:26:10.0113 4640        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
18:26:10.0175 4640        AsyncMac - ok
18:26:10.0222 4640        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
18:26:10.0238 4640        atapi - ok
18:26:10.0362 4640        athr            (cca705cdf038d5bc243203ce4416b345) C:\Windows\system32\DRIVERS\athrx.sys
18:26:10.0440 4640        athr - ok
18:26:10.0971 4640        atikmdag        (eaea2ce49de0cca80beb9134107e5dd7) C:\Windows\system32\DRIVERS\atikmdag.sys
18:26:11.0142 4640        atikmdag - ok
18:26:11.0314 4640        atksgt          (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys
18:26:11.0330 4640        atksgt - ok
18:26:11.0408 4640        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
18:26:11.0470 4640        AudioEndpointBuilder - ok
18:26:11.0470 4640        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
18:26:11.0517 4640        AudioSrv - ok
18:26:11.0548 4640        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
18:26:11.0564 4640        avgntflt - ok
18:26:11.0579 4640        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
18:26:11.0595 4640        avipbb - ok
18:26:11.0642 4640        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
18:26:11.0720 4640        AxInstSV - ok
18:26:11.0782 4640        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
18:26:11.0844 4640        b06bdrv - ok
18:26:11.0891 4640        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
18:26:11.0938 4640        b57nd60a - ok
18:26:11.0985 4640        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
18:26:12.0047 4640        BDESVC - ok
18:26:12.0063 4640        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
18:26:12.0125 4640        Beep - ok
18:26:12.0219 4640        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
18:26:12.0281 4640        BFE - ok
18:26:12.0375 4640        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
18:26:12.0468 4640        BITS - ok
18:26:12.0531 4640        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys
18:26:12.0562 4640        blbdrive - ok
18:26:12.0640 4640        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
18:26:12.0702 4640        bowser - ok
18:26:12.0734 4640        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
18:26:12.0765 4640        BrFiltLo - ok
18:26:12.0796 4640        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
18:26:12.0843 4640        BrFiltUp - ok
18:26:12.0921 4640        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
18:26:12.0983 4640        Browser - ok
18:26:13.0030 4640        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
18:26:13.0061 4640        Brserid - ok
18:26:13.0077 4640        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
18:26:13.0108 4640        BrSerWdm - ok
18:26:13.0155 4640        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
18:26:13.0202 4640        BrUsbMdm - ok
18:26:13.0233 4640        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
18:26:13.0264 4640        BrUsbSer - ok
18:26:13.0342 4640        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
18:26:13.0389 4640        BthEnum - ok
18:26:13.0420 4640        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
18:26:13.0451 4640        BTHMODEM - ok
18:26:13.0498 4640        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
18:26:13.0545 4640        BthPan - ok
18:26:13.0670 4640        BTHPORT        (21084ceb85280468c9aca3c805c0f8cf) C:\Windows\System32\Drivers\BTHport.sys
18:26:13.0748 4640        BTHPORT - ok
18:26:13.0779 4640        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
18:26:13.0841 4640        bthserv - ok
18:26:13.0904 4640        BTHUSB          (8504842634dd144c075b6b0c982ccec4) C:\Windows\System32\Drivers\BTHUSB.sys
18:26:13.0935 4640        BTHUSB - ok
18:26:14.0028 4640        btwampfl        (59e3510784548c6939c1b3b985c232e3) C:\Windows\system32\drivers\btwampfl.sys
18:26:14.0044 4640        btwampfl - ok
18:26:14.0075 4640        btwaudio        (1872074ed0a3fb22e3f1e3197b984bfa) C:\Windows\system32\drivers\btwaudio.sys
18:26:14.0091 4640        btwaudio - ok
18:26:14.0153 4640        btwavdt        (691cf076c33ab1c3a5b2fd5450300733) C:\Windows\system32\DRIVERS\btwavdt.sys
18:26:14.0169 4640        btwavdt - ok
18:26:14.0309 4640        btwdins        (8ba6e93a182126781952a7895ec1e4b2) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
18:26:14.0340 4640        btwdins - ok
18:26:14.0372 4640        btwl2cap        (07096d2bc22ccb6cea5a532df0be8a75) C:\Windows\system32\DRIVERS\btwl2cap.sys
18:26:14.0372 4640        btwl2cap - ok
18:26:14.0418 4640        btwrchid        (c9273b20dec8ce38dbce5d29de63c907) C:\Windows\system32\DRIVERS\btwrchid.sys
18:26:14.0418 4640        btwrchid - ok
18:26:14.0450 4640        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
18:26:14.0496 4640        cdfs - ok
18:26:14.0543 4640        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
18:26:14.0590 4640        cdrom - ok
18:26:14.0621 4640        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
18:26:14.0684 4640        CertPropSvc - ok
18:26:14.0730 4640        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
18:26:14.0762 4640        circlass - ok
18:26:14.0824 4640        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
18:26:14.0824 4640        CLFS - ok
18:26:14.0886 4640        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:26:14.0902 4640        clr_optimization_v2.0.50727_32 - ok
18:26:14.0933 4640        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:26:14.0949 4640        clr_optimization_v2.0.50727_64 - ok
18:26:15.0011 4640        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:26:15.0027 4640        clr_optimization_v4.0.30319_32 - ok
18:26:15.0042 4640        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:26:15.0058 4640        clr_optimization_v4.0.30319_64 - ok
18:26:15.0105 4640        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
18:26:15.0136 4640        CmBatt - ok
18:26:15.0167 4640        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
18:26:15.0167 4640        cmdide - ok
18:26:15.0230 4640        CNG            (ca7720b73446fddec5c69519c1174c98) C:\Windows\system32\Drivers\cng.sys
18:26:15.0245 4640        CNG - ok
18:26:15.0261 4640        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
18:26:15.0276 4640        Compbatt - ok
18:26:15.0292 4640        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\drivers\CompositeBus.sys
18:26:15.0339 4640        CompositeBus - ok
18:26:15.0370 4640        COMSysApp - ok
18:26:15.0370 4640        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
18:26:15.0386 4640        crcdisk - ok
18:26:15.0448 4640        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
18:26:15.0510 4640        CryptSvc - ok
18:26:15.0698 4640        cvhsvc          (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
18:26:15.0713 4640        cvhsvc - ok
18:26:15.0776 4640        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
18:26:15.0838 4640        DcomLaunch - ok
18:26:15.0885 4640        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
18:26:15.0947 4640        defragsvc - ok
18:26:16.0025 4640        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
18:26:16.0088 4640        DfsC - ok
18:26:16.0150 4640        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
18:26:16.0212 4640        Dhcp - ok
18:26:16.0244 4640        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
18:26:16.0290 4640        discache - ok
18:26:16.0368 4640        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
18:26:16.0368 4640        Disk - ok
18:26:16.0415 4640        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
18:26:16.0478 4640        Dnscache - ok
18:26:16.0524 4640        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
18:26:16.0587 4640        dot3svc - ok
18:26:16.0618 4640        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
18:26:16.0680 4640        DPS - ok
18:26:16.0727 4640        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
18:26:16.0743 4640        drmkaud - ok
18:26:16.0805 4640        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
18:26:16.0836 4640        DXGKrnl - ok
18:26:16.0868 4640        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
18:26:16.0914 4640        EapHost - ok
18:26:17.0133 4640        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
18:26:17.0226 4640        ebdrv - ok
18:26:17.0367 4640        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
18:26:17.0429 4640        EFS - ok
18:26:17.0507 4640        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
18:26:17.0570 4640        ehRecvr - ok
18:26:17.0616 4640        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
18:26:17.0648 4640        ehSched - ok
18:26:17.0726 4640        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
18:26:17.0741 4640        elxstor - ok
18:26:17.0772 4640        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
18:26:17.0819 4640        ErrDev - ok
18:26:17.0882 4640        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
18:26:17.0944 4640        EventSystem - ok
18:26:17.0975 4640        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
18:26:18.0038 4640        exfat - ok
18:26:18.0069 4640        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
18:26:18.0131 4640        fastfat - ok
18:26:18.0225 4640        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
18:26:18.0287 4640        Fax - ok
18:26:18.0303 4640        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
18:26:18.0350 4640        fdc - ok
18:26:18.0396 4640        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
18:26:18.0459 4640        fdPHost - ok
18:26:18.0474 4640        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
18:26:18.0506 4640        FDResPub - ok
18:26:18.0521 4640        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
18:26:18.0537 4640        FileInfo - ok
18:26:18.0552 4640        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
18:26:18.0584 4640        Filetrace - ok
18:26:18.0677 4640        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:26:18.0708 4640        FLEXnet Licensing Service - ok
18:26:18.0724 4640        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
18:26:18.0740 4640        flpydisk - ok
18:26:18.0771 4640        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
18:26:18.0786 4640        FltMgr - ok
18:26:18.0864 4640        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
18:26:18.0942 4640        FontCache - ok
18:26:19.0020 4640        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:26:19.0036 4640        FontCache3.0.0.0 - ok
18:26:19.0067 4640        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
18:26:19.0083 4640        FsDepends - ok
18:26:19.0130 4640        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
18:26:19.0130 4640        Fs_Rec - ok
18:26:19.0208 4640        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
18:26:19.0223 4640        fvevol - ok
18:26:19.0254 4640        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
18:26:19.0270 4640        gagp30kx - ok
18:26:19.0379 4640        GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
18:26:19.0395 4640        GamesAppService - ok
18:26:19.0473 4640        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
18:26:19.0535 4640        gpsvc - ok
18:26:19.0582 4640        gupdate        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:26:19.0598 4640        gupdate - ok
18:26:19.0613 4640        gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:26:19.0629 4640        gupdatem - ok
18:26:19.0644 4640        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
18:26:19.0691 4640        hcw85cir - ok
18:26:19.0722 4640        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
18:26:19.0769 4640        HdAudAddService - ok
18:26:19.0832 4640        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\drivers\HDAudBus.sys
18:26:19.0863 4640        HDAudBus - ok
18:26:19.0910 4640        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\drivers\HECIx64.sys
18:26:19.0925 4640        HECIx64 - ok
18:26:19.0941 4640        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
18:26:19.0972 4640        HidBatt - ok
18:26:19.0988 4640        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
18:26:20.0034 4640        HidBth - ok
18:26:20.0081 4640        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
18:26:20.0112 4640        HidIr - ok
18:26:20.0144 4640        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
18:26:20.0206 4640        hidserv - ok
18:26:20.0268 4640        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
18:26:20.0300 4640        HidUsb - ok
18:26:20.0331 4640        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
18:26:20.0393 4640        hkmsvc - ok
18:26:20.0424 4640        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
18:26:20.0487 4640        HomeGroupListener - ok
18:26:20.0518 4640        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
18:26:20.0565 4640        HomeGroupProvider - ok
18:26:20.0612 4640        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\drivers\HpSAMD.sys
18:26:20.0612 4640        HpSAMD - ok
18:26:20.0674 4640        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
18:26:20.0721 4640        HTTP - ok
18:26:20.0736 4640        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
18:26:20.0736 4640        hwpolicy - ok
18:26:20.0783 4640        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
18:26:20.0799 4640        i8042prt - ok
18:26:20.0846 4640        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\drivers\iaStor.sys
18:26:20.0861 4640        iaStor - ok
18:26:20.0908 4640        IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
18:26:20.0908 4640        IAStorDataMgrSvc - ok
18:26:20.0971 4640        iaStorV        (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
18:26:20.0986 4640        iaStorV - ok
18:26:21.0080 4640        ICQ Service    (b1a28fa1afde10b95ff9354b15701d70) C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
18:26:21.0095 4640        ICQ Service - ok
18:26:21.0205 4640        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:26:21.0236 4640        idsvc - ok
18:26:21.0985 4640        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
18:26:22.0250 4640        igfx ( UnsignedFile.Multi.Generic ) - warning
18:26:22.0250 4640        igfx - detected UnsignedFile.Multi.Generic (1)
18:26:22.0406 4640        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
18:26:22.0421 4640        iirsp - ok
18:26:22.0484 4640        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
18:26:22.0546 4640        IKEEXT - ok
18:26:22.0624 4640        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\drivers\Impcd.sys
18:26:22.0640 4640        Impcd - ok
18:26:22.0811 4640        IntcAzAudAddService (526e482afb586cb1cdd687869decf686) C:\Windows\system32\drivers\RTKVHD64.sys
18:26:22.0874 4640        IntcAzAudAddService - ok
18:26:22.0999 4640        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
18:26:23.0045 4640        IntcDAud ( UnsignedFile.Multi.Generic ) - warning
18:26:23.0045 4640        IntcDAud - detected UnsignedFile.Multi.Generic (1)
18:26:23.0077 4640        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
18:26:23.0092 4640        intelide - ok
18:26:23.0123 4640        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys
18:26:23.0155 4640        intelppm - ok
18:26:23.0217 4640        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
18:26:23.0248 4640        IPBusEnum - ok
18:26:23.0264 4640        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:26:23.0295 4640        IpFilterDriver - ok
18:26:23.0373 4640        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
18:26:23.0435 4640        iphlpsvc - ok
18:26:23.0467 4640        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\drivers\IPMIDrv.sys
18:26:23.0498 4640        IPMIDRV - ok
18:26:23.0545 4640        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
18:26:23.0623 4640        IPNAT - ok
18:26:23.0638 4640        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
18:26:23.0654 4640        IRENUM - ok
18:26:23.0669 4640        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
18:26:23.0685 4640        isapnp - ok
18:26:23.0716 4640        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\drivers\msiscsi.sys
18:26:23.0732 4640        iScsiPrt - ok
18:26:23.0763 4640        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
18:26:23.0763 4640        kbdclass - ok
18:26:23.0794 4640        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
18:26:23.0825 4640        kbdhid - ok
18:26:23.0872 4640        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:23.0888 4640        KeyIso - ok
18:26:23.0919 4640        KSecDD          (4f4b5fde429416877de7143044582eb5) C:\Windows\system32\Drivers\ksecdd.sys
18:26:23.0935 4640        KSecDD - ok
18:26:23.0950 4640        KSecPkg        (6f40465a44ecdc1731befafec5bdd03c) C:\Windows\system32\Drivers\ksecpkg.sys
18:26:23.0966 4640        KSecPkg - ok
18:26:23.0997 4640        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
18:26:24.0059 4640        ksthunk - ok
18:26:24.0106 4640        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
18:26:24.0169 4640        KtmRm - ok
18:26:24.0231 4640        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
18:26:24.0309 4640        LanmanServer - ok
18:26:24.0340 4640        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
18:26:24.0387 4640        LanmanWorkstation - ok
18:26:24.0465 4640        lirsgt          (156ab2e56dc3ca0b582e3362e07cded7) C:\Windows\system32\DRIVERS\lirsgt.sys
18:26:24.0481 4640        lirsgt - ok
18:26:24.0496 4640        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
18:26:24.0559 4640        lltdio - ok
18:26:24.0605 4640        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
18:26:24.0683 4640        lltdsvc - ok
18:26:24.0715 4640        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
18:26:24.0746 4640        lmhosts - ok
18:26:24.0824 4640        LMS            (3d23191672d83e90d1cf63927ee98136) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:26:24.0839 4640        LMS - ok
18:26:24.0886 4640        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
18:26:24.0902 4640        LSI_FC - ok
18:26:24.0933 4640        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
18:26:24.0949 4640        LSI_SAS - ok
18:26:24.0964 4640        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
18:26:24.0964 4640        LSI_SAS2 - ok
18:26:24.0980 4640        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
18:26:24.0995 4640        LSI_SCSI - ok
18:26:25.0011 4640        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
18:26:25.0073 4640        luafv - ok
18:26:25.0167 4640        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
18:26:25.0183 4640        MBAMProtector - ok
18:26:25.0245 4640        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
18:26:25.0261 4640        MBAMService - ok
18:26:25.0307 4640        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
18:26:25.0339 4640        Mcx2Svc - ok
18:26:25.0370 4640        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
18:26:25.0370 4640        megasas - ok
18:26:25.0417 4640        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
18:26:25.0432 4640        MegaSR - ok
18:26:25.0448 4640        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
18:26:25.0510 4640        MMCSS - ok
18:26:25.0541 4640        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
18:26:25.0588 4640        Modem - ok
18:26:25.0619 4640        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
18:26:25.0651 4640        monitor - ok
18:26:25.0713 4640        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
18:26:25.0713 4640        mouclass - ok
18:26:25.0744 4640        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
18:26:25.0744 4640        mouhid - ok
18:26:25.0760 4640        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
18:26:25.0775 4640        mountmgr - ok
18:26:25.0931 4640        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
18:26:25.0947 4640        MozillaMaintenance - ok
18:26:25.0978 4640        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\drivers\mpio.sys
18:26:25.0994 4640        mpio - ok
18:26:26.0009 4640        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
18:26:26.0041 4640        mpsdrv - ok
18:26:26.0103 4640        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
18:26:26.0181 4640        MpsSvc - ok
18:26:26.0228 4640        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
18:26:26.0259 4640        MRxDAV - ok
18:26:26.0306 4640        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
18:26:26.0337 4640        mrxsmb - ok
18:26:26.0384 4640        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:26:26.0415 4640        mrxsmb10 - ok
18:26:26.0446 4640        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:26:26.0477 4640        mrxsmb20 - ok
18:26:26.0540 4640        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\drivers\msahci.sys
18:26:26.0540 4640        msahci - ok
18:26:26.0571 4640        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\drivers\msdsm.sys
18:26:26.0587 4640        msdsm - ok
18:26:26.0602 4640        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
18:26:26.0618 4640        MSDTC - ok
18:26:26.0649 4640        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
18:26:26.0680 4640        Msfs - ok
18:26:26.0680 4640        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
18:26:26.0743 4640        mshidkmdf - ok
18:26:26.0758 4640        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
18:26:26.0774 4640        msisadrv - ok
18:26:26.0805 4640        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
18:26:26.0867 4640        MSiSCSI - ok
18:26:26.0867 4640        msiserver - ok
18:26:26.0930 4640        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
18:26:26.0977 4640        MSKSSRV - ok
18:26:26.0992 4640        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
18:26:27.0055 4640        MSPCLOCK - ok
18:26:27.0086 4640        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
18:26:27.0148 4640        MSPQM - ok
18:26:27.0195 4640        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
18:26:27.0211 4640        MsRPC - ok
18:26:27.0242 4640        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
18:26:27.0242 4640        mssmbios - ok
18:26:27.0273 4640        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
18:26:27.0320 4640        MSTEE - ok
18:26:27.0351 4640        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
18:26:27.0398 4640        MTConfig - ok
18:26:27.0413 4640        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
18:26:27.0429 4640        Mup - ok
18:26:27.0523 4640        MySQL - ok
18:26:27.0569 4640        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
18:26:27.0647 4640        napagent - ok
18:26:27.0694 4640        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
18:26:27.0710 4640        NativeWifiP - ok
18:26:27.0772 4640        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
18:26:27.0803 4640        NDIS - ok
18:26:27.0819 4640        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
18:26:27.0866 4640        NdisCap - ok
18:26:27.0928 4640        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
18:26:27.0975 4640        NdisTapi - ok
18:26:28.0006 4640        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
18:26:28.0069 4640        Ndisuio - ok
18:26:28.0100 4640        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
18:26:28.0131 4640        NdisWan - ok
18:26:28.0147 4640        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
18:26:28.0178 4640        NDProxy - ok
18:26:28.0209 4640        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
18:26:28.0240 4640        NetBIOS - ok
18:26:28.0271 4640        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
18:26:28.0334 4640        NetBT - ok
18:26:28.0381 4640        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:28.0381 4640        Netlogon - ok
18:26:28.0443 4640        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
18:26:28.0505 4640        Netman - ok
18:26:28.0552 4640        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
18:26:28.0615 4640        netprofm - ok
18:26:28.0708 4640        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:26:28.0724 4640        NetTcpPortSharing - ok
18:26:28.0755 4640        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
18:26:28.0771 4640        nfrd960 - ok
18:26:28.0817 4640        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
18:26:28.0880 4640        NlaSvc - ok
18:26:29.0129 4640        NOBU            (5839a8027d6d324a7cd494051a96628c) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
18:26:29.0192 4640        NOBU - ok
18:26:29.0317 4640        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
18:26:29.0379 4640        Npfs - ok
18:26:29.0410 4640        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
18:26:29.0473 4640        nsi - ok
18:26:29.0488 4640        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
18:26:29.0519 4640        nsiproxy - ok
18:26:29.0675 4640        Ntfs            (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
18:26:29.0722 4640        Ntfs - ok
18:26:29.0847 4640        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
18:26:29.0878 4640        Null - ok
18:26:29.0941 4640        nvraid          (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
18:26:29.0956 4640        nvraid - ok
18:26:29.0972 4640        nvstor          (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
18:26:29.0987 4640        nvstor - ok
18:26:30.0003 4640        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
18:26:30.0019 4640        nv_agp - ok
18:26:30.0050 4640        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
18:26:30.0065 4640        ohci1394 - ok
18:26:30.0143 4640        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:26:30.0159 4640        ose - ok
18:26:30.0471 4640        osppsvc        (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:26:30.0611 4640        osppsvc - ok
18:26:30.0736 4640        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
18:26:30.0799 4640        p2pimsvc - ok
18:26:30.0845 4640        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
18:26:30.0861 4640        p2psvc - ok
18:26:30.0892 4640        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
18:26:30.0908 4640        Parport - ok
18:26:30.0939 4640        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
18:26:30.0939 4640        partmgr - ok
18:26:30.0970 4640        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
18:26:30.0986 4640        PcaSvc - ok
18:26:31.0017 4640        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\drivers\pci.sys
18:26:31.0033 4640        pci - ok
18:26:31.0048 4640        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
18:26:31.0048 4640        pciide - ok
18:26:31.0079 4640        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
18:26:31.0079 4640        pcmcia - ok
18:26:31.0111 4640        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
18:26:31.0111 4640        pcw - ok
18:26:31.0157 4640        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
18:26:31.0235 4640        PEAUTH - ok
18:26:31.0313 4640        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
18:26:31.0360 4640        PerfHost - ok
18:26:31.0469 4640        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
18:26:31.0563 4640        pla - ok
18:26:31.0610 4640        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
18:26:31.0641 4640        PlugPlay - ok
18:26:31.0735 4640        PMBDeviceInfoProvider (80e85394d8cd7f84340b1c6f4b9d698f) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
18:26:31.0750 4640        PMBDeviceInfoProvider - ok
18:26:31.0781 4640        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
18:26:31.0813 4640        PNRPAutoReg - ok
18:26:31.0859 4640        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
18:26:31.0859 4640        PNRPsvc - ok
18:26:31.0922 4640        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
18:26:31.0984 4640        PolicyAgent - ok
18:26:32.0015 4640        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
18:26:32.0078 4640        Power - ok
18:26:32.0156 4640        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
18:26:32.0203 4640        PptpMiniport - ok
18:26:32.0249 4640        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
18:26:32.0281 4640        Processor - ok
18:26:32.0343 4640        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
18:26:32.0359 4640        ProfSvc - ok
18:26:32.0405 4640        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:32.0421 4640        ProtectedStorage - ok
18:26:32.0452 4640        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
18:26:32.0483 4640        Psched - ok
18:26:32.0499 4640        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
18:26:32.0515 4640        PxHlpa64 - ok
18:26:32.0624 4640        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
18:26:32.0671 4640        ql2300 - ok
18:26:32.0811 4640        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
18:26:32.0827 4640        ql40xx - ok
18:26:32.0858 4640        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
18:26:32.0889 4640        QWAVE - ok
18:26:32.0920 4640        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
18:26:32.0951 4640        QWAVEdrv - ok
18:26:32.0983 4640        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
18:26:33.0045 4640        RasAcd - ok
18:26:33.0092 4640        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
18:26:33.0123 4640        RasAgileVpn - ok
18:26:33.0170 4640        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
18:26:33.0217 4640        RasAuto - ok
18:26:33.0248 4640        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
18:26:33.0279 4640        Rasl2tp - ok
18:26:33.0326 4640        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
18:26:33.0388 4640        RasMan - ok
18:26:33.0419 4640        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
18:26:33.0482 4640        RasPppoe - ok
18:26:33.0529 4640        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
18:26:33.0591 4640        RasSstp - ok
18:26:33.0638 4640        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
18:26:33.0669 4640        rdbss - ok
18:26:33.0685 4640        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
18:26:33.0731 4640        rdpbus - ok
18:26:33.0763 4640        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
18:26:33.0794 4640        RDPCDD - ok
18:26:33.0809 4640        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
18:26:33.0856 4640        RDPENCDD - ok
18:26:33.0856 4640        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
18:26:33.0887 4640        RDPREFMP - ok
18:26:33.0934 4640        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
18:26:34.0012 4640        RDPWD - ok
18:26:34.0043 4640        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
18:26:34.0059 4640        rdyboost - ok
18:26:34.0090 4640        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
18:26:34.0137 4640        RemoteAccess - ok
18:26:34.0184 4640        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
18:26:34.0246 4640        RemoteRegistry - ok
18:26:34.0293 4640        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
18:26:34.0324 4640        RFCOMM - ok
18:26:34.0371 4640        rimspci        (fa6abc06b629da29634d31f1fe0347bd) C:\Windows\system32\drivers\rimssne64.sys
18:26:34.0387 4640        rimspci - ok
18:26:34.0433 4640        risdsnpe        (8f8539a7f5c117d4407b2985995671f2) C:\Windows\system32\drivers\risdsne64.sys
18:26:34.0496 4640        risdsnpe - ok
18:26:34.0527 4640        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
18:26:34.0574 4640        RpcEptMapper - ok
18:26:34.0621 4640        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
18:26:34.0636 4640        RpcLocator - ok
18:26:34.0667 4640        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
18:26:34.0699 4640        RpcSs - ok
18:26:34.0730 4640        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
18:26:34.0792 4640        rspndr - ok
18:26:34.0855 4640        RTHDMIAzAudService (d6d381b76056c668679723938f06f16c) C:\Windows\system32\drivers\RtHDMIVX.sys
18:26:34.0870 4640        RTHDMIAzAudService - ok
18:26:34.0901 4640        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:34.0917 4640        SamSs - ok
18:26:34.0964 4640        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\drivers\sbp2port.sys
18:26:34.0964 4640        sbp2port - ok
18:26:35.0011 4640        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
18:26:35.0042 4640        SCardSvr - ok
18:26:35.0057 4640        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
18:26:35.0120 4640        scfilter - ok
18:26:35.0213 4640        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
18:26:35.0291 4640        Schedule - ok
18:26:35.0323 4640        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
18:26:35.0354 4640        SCPolicySvc - ok
18:26:35.0385 4640        sdbus          (2c8d162efaf73abd36d8bcbb6340cae7) C:\Windows\system32\DRIVERS\sdbus.sys
18:26:35.0416 4640        sdbus - ok
18:26:35.0447 4640        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
18:26:35.0510 4640        SDRSVC - ok
18:26:35.0525 4640        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
18:26:35.0588 4640        secdrv - ok
18:26:35.0619 4640        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
18:26:35.0666 4640        seclogon - ok
18:26:35.0697 4640        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
18:26:35.0759 4640        SENS - ok
18:26:35.0822 4640        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
18:26:35.0884 4640        SensrSvc - ok
18:26:35.0915 4640        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
18:26:35.0915 4640        Serenum - ok
18:26:35.0947 4640        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
18:26:35.0978 4640        Serial - ok
18:26:36.0025 4640        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
18:26:36.0071 4640        sermouse - ok
18:26:36.0118 4640        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
18:26:36.0165 4640        SessionEnv - ok
18:26:36.0196 4640        SFEP            (286d3889e6ab5589646ff8a63cb928ae) C:\Windows\system32\drivers\SFEP.sys
18:26:36.0227 4640        SFEP - ok
18:26:36.0259 4640        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
18:26:36.0290 4640        sffdisk - ok
18:26:36.0321 4640        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
18:26:36.0352 4640        sffp_mmc - ok
18:26:36.0383 4640        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\drivers\sffp_sd.sys
18:26:36.0415 4640        sffp_sd - ok
18:26:36.0446 4640        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
18:26:36.0446 4640        sfloppy - ok
18:26:36.0539 4640        Sftfs          (c6cc9297bd53e5229653303e556aa539) C:\Windows\system32\DRIVERS\Sftfslh.sys
18:26:36.0571 4640        Sftfs - ok
18:26:36.0680 4640        sftlist        (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
18:26:36.0695 4640        sftlist - ok
18:26:36.0742 4640        Sftplay        (390aa7bc52cee43f6790cdea1e776703) C:\Windows\system32\DRIVERS\Sftplaylh.sys
18:26:36.0758 4640        Sftplay - ok
18:26:36.0773 4640        Sftredir        (617e29a0b0a2807466560d4c4e338d3e) C:\Windows\system32\DRIVERS\Sftredirlh.sys
18:26:36.0773 4640        Sftredir - ok
18:26:36.0789 4640        Sftvol          (8f571f016fa1976f445147e9e6c8ae9b) C:\Windows\system32\DRIVERS\Sftvollh.sys
18:26:36.0789 4640        Sftvol - ok
18:26:36.0820 4640        sftvsa          (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
18:26:36.0836 4640        sftvsa - ok
18:26:36.0867 4640        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
18:26:36.0929 4640        SharedAccess - ok
18:26:36.0992 4640        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
18:26:37.0023 4640        ShellHWDetection - ok
18:26:37.0085 4640        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
18:26:37.0085 4640        SiSRaid2 - ok
18:26:37.0117 4640        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
18:26:37.0132 4640        SiSRaid4 - ok
18:26:37.0163 4640        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
18:26:37.0226 4640        Smb - ok
18:26:37.0273 4640        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
18:26:37.0304 4640        SNMPTRAP - ok
18:26:37.0382 4640        SOHCImp        (c3e69db0a4e59564230e053232f39ac7) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
18:26:37.0397 4640        SOHCImp - ok
18:26:37.0444 4640        SOHDms          (65cc4779a29c3e82b987bd4961790dff) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
18:26:37.0460 4640        SOHDms - ok
18:26:37.0475 4640        SOHDs          (f47d75cee1844eef4a9ea6ee768828fb) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
18:26:37.0491 4640        SOHDs - ok
18:26:37.0600 4640        SpfService      (5449fc97476f52e027409e703791e6a9) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
18:26:37.0616 4640        SpfService - ok
18:26:37.0647 4640        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
18:26:37.0663 4640        spldr - ok
18:26:37.0741 4640        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
18:26:37.0803 4640        Spooler - ok
18:26:38.0037 4640        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
18:26:38.0099 4640        sppsvc - ok
18:26:38.0209 4640        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
18:26:38.0255 4640        sppuinotify - ok
18:26:38.0333 4640        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
18:26:38.0396 4640        srv - ok
18:26:38.0427 4640        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
18:26:38.0443 4640        srv2 - ok
18:26:38.0458 4640        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
18:26:38.0505 4640        srvnet - ok
18:26:38.0552 4640        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
18:26:38.0614 4640        SSDPSRV - ok
18:26:38.0645 4640        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
18:26:38.0677 4640        SstpSvc - ok
18:26:38.0692 4640        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
18:26:38.0708 4640        stexstor - ok
18:26:38.0755 4640        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
18:26:38.0786 4640        stisvc - ok
18:26:38.0817 4640        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
18:26:38.0817 4640        swenum - ok
18:26:38.0879 4640        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
18:26:38.0942 4640        swprv - ok
18:26:39.0067 4640        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
18:26:39.0129 4640        SysMain - ok
18:26:39.0269 4640        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
18:26:39.0301 4640        TabletInputService - ok
18:26:39.0347 4640        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
18:26:39.0410 4640        TapiSrv - ok
18:26:39.0441 4640        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
18:26:39.0472 4640        TBS - ok
18:26:39.0644 4640        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
18:26:39.0691 4640        Tcpip - ok
18:26:39.0940 4640        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
18:26:39.0971 4640        TCPIP6 - ok
18:26:40.0112 4640        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
18:26:40.0143 4640        tcpipreg - ok
18:26:40.0159 4640        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
18:26:40.0237 4640        TDPIPE - ok
18:26:40.0268 4640        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
18:26:40.0330 4640        TDTCP - ok
18:26:40.0346 4640        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
18:26:40.0408 4640        tdx - ok
18:26:40.0455 4640        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\drivers\termdd.sys
18:26:40.0471 4640        TermDD - ok
18:26:40.0517 4640        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
18:26:40.0595 4640        TermService - ok
18:26:40.0627 4640        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
18:26:40.0658 4640        Themes - ok
18:26:40.0705 4640        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
18:26:40.0736 4640        THREADORDER - ok
18:26:40.0767 4640        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
18:26:40.0814 4640        TrkWks - ok
18:26:40.0861 4640        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
18:26:40.0892 4640        TrustedInstaller - ok
18:26:40.0939 4640        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
18:26:41.0001 4640        tssecsrv - ok
18:26:41.0032 4640        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
18:26:41.0095 4640        tunnel - ok
18:26:41.0095 4640        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
18:26:41.0110 4640        uagp35 - ok
18:26:41.0173 4640        uCamMonitor    (63f6d08c54d5b3c1b12a6172032055c7) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
18:26:41.0173 4640        uCamMonitor - ok
18:26:41.0219 4640        udfs            (0e5e962b5649d544be54e8c90761ea2b) C:\Windows\system32\DRIVERS\udfs.sys
18:26:41.0282 4640        udfs - ok
18:26:41.0313 4640        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
18:26:41.0313 4640        UI0Detect - ok
18:26:41.0360 4640        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
18:26:41.0375 4640        uliagpkx - ok
18:26:41.0391 4640        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
18:26:41.0422 4640        umbus - ok
18:26:41.0469 4640        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
18:26:41.0485 4640        UmPass - ok
18:26:41.0672 4640        UNS            (11a559e0f10cc5e788984023df400a6f) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
18:26:41.0703 4640        UNS - ok
18:26:41.0843 4640        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
18:26:41.0906 4640        upnphost - ok
18:26:41.0968 4640        usbccgp        (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
18:26:42.0031 4640        usbccgp - ok
18:26:42.0062 4640        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
18:26:42.0093 4640        usbcir - ok
18:26:42.0124 4640        usbehci        (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\drivers\usbehci.sys
18:26:42.0140 4640        usbehci - ok
18:26:42.0171 4640        usbhub          (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
18:26:42.0218 4640        usbhub - ok
18:26:42.0265 4640        usbohci        (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
18:26:42.0280 4640        usbohci - ok
18:26:42.0296 4640        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
18:26:42.0311 4640        usbprint - ok
18:26:42.0343 4640        USBSTOR        (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:26:42.0405 4640        USBSTOR - ok
18:26:42.0421 4640        usbuhci        (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
18:26:42.0452 4640        usbuhci - ok
18:26:42.0530 4640        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
18:26:42.0577 4640        usbvideo - ok
18:26:42.0608 4640        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
18:26:42.0639 4640        UxSms - ok
18:26:42.0701 4640        VAIO Event Service (a60605fc66552b421ee1f3d4ebb9a4e0) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
18:26:42.0701 4640        VAIO Event Service - ok
18:26:42.0795 4640        VAIO Power Management (d469be2723f79cf4b384680b1fdc577d) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
18:26:42.0811 4640        VAIO Power Management - ok
18:26:42.0889 4640        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
18:26:42.0889 4640        VaultSvc - ok
18:26:43.0949 4640        VCFw            (96efa2698d6b9e2931609a3ea73fc5dc) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
18:26:43.0965 4640        VCFw - ok
18:26:44.0558 4640        VcmIAlzMgr      (7bebf6a5285ffc03c34a7297a4e177cb) C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
18:26:44.0636 4640        VcmIAlzMgr - ok
18:26:44.0995 4640        VcmINSMgr      (e005b04dfca99f5880c5111933194ca9) C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
18:26:45.0041 4640        VcmINSMgr - ok
18:26:45.0244 4640        VcmXmlIfHelper  (829a32fd1334f72429ca0515760eb7a7) C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
18:26:45.0275 4640        VcmXmlIfHelper - ok
18:26:45.0837 4640        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
18:26:45.0853 4640        vdrvroot - ok
18:26:45.0946 4640        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
18:26:45.0962 4640        vds - ok
18:26:46.0040 4640        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
18:26:46.0071 4640        vga - ok
18:26:46.0102 4640        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
18:26:46.0165 4640        VgaSave - ok
18:26:46.0274 4640        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\drivers\vhdmp.sys
18:26:46.0289 4640        vhdmp - ok
18:26:46.0321 4640        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
18:26:46.0336 4640        viaide - ok
18:26:46.0352 4640        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\drivers\volmgr.sys
18:26:46.0367 4640        volmgr - ok
18:26:46.0445 4640        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
18:26:46.0445 4640        volmgrx - ok
18:26:46.0539 4640        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\drivers\volsnap.sys
18:26:46.0555 4640        volsnap - ok
18:26:46.0601 4640        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
18:26:46.0617 4640        vsmraid - ok
18:26:46.0929 4640        VSNService      (a7eb62c664a03901165290a714bd48d0) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
18:26:46.0960 4640        VSNService ( UnsignedFile.Multi.Generic ) - warning
18:26:46.0960 4640        VSNService - detected UnsignedFile.Multi.Generic (1)
18:26:47.0163 4640        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
18:26:47.0241 4640        VSS - ok
18:26:47.0569 4640        VUAgent        (e55a44d8f9f713d5f5d5bbaef2ba0a34) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
18:26:47.0615 4640        VUAgent - ok
18:26:47.0881 4640        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
18:26:47.0896 4640        vwifibus - ok
18:26:47.0927 4640        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
18:26:47.0974 4640        vwififlt - ok
18:26:48.0037 4640        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
18:26:48.0068 4640        W32Time - ok
18:26:48.0083 4640        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
18:26:48.0099 4640        WacomPen - ok
18:26:48.0146 4640        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
18:26:48.0193 4640        WANARP - ok
18:26:48.0193 4640        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
18:26:48.0224 4640        Wanarpv6 - ok
18:26:48.0395 4640        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
18:26:48.0442 4640        wbengine - ok
18:26:48.0583 4640        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
18:26:48.0598 4640        WbioSrvc - ok
18:26:48.0645 4640        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
18:26:48.0707 4640        wcncsvc - ok
18:26:48.0723 4640        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
18:26:48.0754 4640        WcsPlugInService - ok
18:26:48.0801 4640        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
18:26:48.0817 4640        Wd - ok
18:26:48.0848 4640        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
18:26:48.0879 4640        Wdf01000 - ok
18:26:48.0895 4640        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
18:26:48.0926 4640        WdiServiceHost - ok
18:26:48.0941 4640        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
18:26:48.0957 4640        WdiSystemHost - ok
18:26:49.0004 4640        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
18:26:49.0066 4640        WebClient - ok
18:26:49.0097 4640        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
18:26:49.0160 4640        Wecsvc - ok
18:26:49.0191 4640        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
18:26:49.0253 4640        wercplsupport - ok
18:26:49.0285 4640        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
18:26:49.0363 4640        WerSvc - ok
18:26:49.0425 4640        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
18:26:49.0472 4640        WfpLwf - ok
18:26:49.0487 4640        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
18:26:49.0503 4640        WIMMount - ok
18:26:49.0534 4640        WinDefend - ok
18:26:49.0550 4640        WinHttpAutoProxySvc - ok
18:26:49.0628 4640        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
18:26:49.0690 4640        Winmgmt - ok
18:26:49.0831 4640        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
18:26:49.0909 4640        WinRM - ok
18:26:50.0080 4640        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
18:26:50.0111 4640        Wlansvc - ok
18:26:50.0158 4640        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
18:26:50.0174 4640        WmiAcpi - ok
18:26:50.0236 4640        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
18:26:50.0283 4640        wmiApSrv - ok
18:26:50.0314 4640        WMPNetworkSvc - ok
18:26:50.0345 4640        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
18:26:50.0377 4640        WPCSvc - ok
18:26:50.0392 4640        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
18:26:50.0439 4640        WPDBusEnum - ok
18:26:50.0470 4640        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
18:26:50.0517 4640        ws2ifsl - ok
18:26:50.0564 4640        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
18:26:50.0626 4640        wscsvc - ok
18:26:50.0626 4640        WSearch - ok
18:26:50.0798 4640        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
18:26:50.0845 4640        wuauserv - ok
18:26:50.0985 4640        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
18:26:51.0047 4640        WudfPf - ok
18:26:51.0094 4640        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
18:26:51.0157 4640        WUDFRd - ok
18:26:51.0188 4640        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
18:26:51.0250 4640        wudfsvc - ok
18:26:51.0297 4640        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
18:26:51.0313 4640        WwanSvc - ok
18:26:51.0375 4640        yukonw7        (5250193ef8e173aa7491250f00eb367f) C:\Windows\system32\DRIVERS\yk62x64.sys
18:26:51.0391 4640        yukonw7 - ok
18:26:51.0422 4640        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
18:26:51.0749 4640        \Device\Harddisk0\DR0 - ok
18:26:51.0749 4640        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
18:26:52.0108 4640        \Device\Harddisk1\DR1 - ok
18:26:52.0124 4640        Boot (0x1200)  (7d4ae33e9d84f6d6153ebdececa63ed5) \Device\Harddisk0\DR0\Partition0
18:26:52.0124 4640        \Device\Harddisk0\DR0\Partition0 - ok
18:26:52.0139 4640        Boot (0x1200)  (28d667b0c2107fce1073698932cfdece) \Device\Harddisk0\DR0\Partition1
18:26:52.0139 4640        \Device\Harddisk0\DR0\Partition1 - ok
18:26:52.0139 4640        Boot (0x1200)  (44413b9e435770e9b69b090908e34489) \Device\Harddisk1\DR1\Partition0
18:26:52.0139 4640        \Device\Harddisk1\DR1\Partition0 - ok
18:26:52.0139 4640        ============================================================
18:26:52.0139 4640        Scan finished
18:26:52.0139 4640        ============================================================
18:26:52.0155 3108        Detected object count: 3
18:26:52.0155 3108        Actual detected object count: 3
18:27:42.0746 3108        igfx ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108        igfx ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:27:42.0746 3108        IntcDAud ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108        IntcDAud ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:27:42.0746 3108        VSNService ( UnsignedFile.Multi.Generic ) - skipped by user
18:27:42.0746 3108        VSNService ( UnsignedFile.Multi.Generic ) - User select action: Skip

:dankeschoen:

Janina

cosinus 13.07.2012 21:27

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

PuritySH 15.07.2012 20:49

Guten Abend,

hier die nächte txt Datei:

Combofix Logfile:
Code:

ComboFix 12-07-14.01 - Euronics 15.07.2012  21:21:56.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.3950.2401 [GMT 2:00]
ausgeführt von:: c:\users\Euronics\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Euronics\AppData\Local\._Revolution_
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-15 bis 2012-07-15  ))))))))))))))))))))))))))))))
.
.
2012-07-15 19:27 . 2012-07-15 19:27        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-07-15 19:26 . 2012-07-15 19:26        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{35ACDFE4-F131-45ED-87A6-670C418DA1C9}\offreg.dll
2012-07-13 15:38 . 2012-05-31 04:04        9013136        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{35ACDFE4-F131-45ED-87A6-670C418DA1C9}\mpengine.dll
2012-07-11 20:28 . 2012-06-12 03:02        3147264        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 20:24 . 2012-06-02 05:37        459216        ----a-w-        c:\windows\system32\drivers\cng.sys
2012-07-11 20:24 . 2012-06-02 05:27        340992        ----a-w-        c:\windows\system32\schannel.dll
2012-07-11 20:24 . 2012-06-02 05:38        95088        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-07-11 20:24 . 2012-06-02 05:38        152432        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2012-07-11 20:24 . 2012-06-02 05:27        307200        ----a-w-        c:\windows\system32\ncrypt.dll
2012-07-11 20:24 . 2012-06-02 04:48        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2012-07-11 20:24 . 2012-06-02 04:48        225280        ----a-w-        c:\windows\SysWow64\schannel.dll
2012-07-11 20:24 . 2012-06-02 04:47        219136        ----a-w-        c:\windows\SysWow64\ncrypt.dll
2012-07-11 20:24 . 2012-06-02 04:42        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2012-07-11 20:23 . 2012-06-06 05:50        2003968        ----a-w-        c:\windows\system32\msxml6.dll
2012-07-11 20:23 . 2012-06-06 05:50        1880064        ----a-w-        c:\windows\system32\msxml3.dll
2012-07-11 20:23 . 2012-06-06 05:09        1389568        ----a-w-        c:\windows\SysWow64\msxml6.dll
2012-07-11 20:23 . 2012-06-06 05:09        1236992        ----a-w-        c:\windows\SysWow64\msxml3.dll
2012-07-11 20:23 . 2012-06-06 05:50        1425408        ----a-w-        c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 20:23 . 2012-06-06 05:09        987136        ----a-w-        c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-10 17:52 . 2012-07-10 17:52        --------        d-----w-        C:\_OTL
2012-07-02 18:39 . 2012-07-02 18:39        --------        d-----w-        c:\program files (x86)\ESET
2012-06-25 20:02 . 2012-06-25 20:02        --------        d-----w-        c:\users\Euronics\AppData\Roaming\Malwarebytes
2012-06-25 20:02 . 2012-06-25 20:02        --------        d-----w-        c:\programdata\Malwarebytes
2012-06-25 20:02 . 2012-04-04 13:56        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-06-25 20:02 . 2012-06-25 20:02        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-25 18:24 . 2012-06-25 18:24        --------        d-----w-        c:\users\Euronics\AppData\Roaming\Avira
2012-06-25 14:04 . 2012-06-25 14:04        1394248        ----a-w-        c:\windows\SysWow64\msxml4.dll
2012-06-23 18:54 . 2012-06-23 18:54        --------        d-----w-        c:\program files (x86)\V5Play
2012-06-23 15:55 . 2012-06-23 18:56        --------        d-----w-        c:\users\Euronics\AppData\Roaming\V5 Play
2012-06-21 18:17 . 2012-06-21 18:17        --------        d-----w-        c:\users\Euronics\AppData\Roaming\Little Worlds Online
2012-06-21 18:12 . 2012-06-02 22:19        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-21 18:12 . 2012-06-02 22:19        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-21 18:12 . 2012-06-02 22:19        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-21 18:12 . 2012-06-02 22:15        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-21 18:12 . 2012-06-02 22:19        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-21 18:12 . 2012-06-02 22:19        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-21 18:12 . 2012-06-02 22:15        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-21 18:12 . 2012-06-02 13:19        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-21 18:12 . 2012-06-02 13:15        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-18 20:19 . 2012-06-21 19:10        --------        d-----w-        c:\programdata\Fugazo
2012-06-18 18:49 . 2012-06-18 18:49        --------        d-----w-        c:\users\Euronics\AppData\Local\JollyBear
2012-06-18 18:49 . 2012-06-18 18:49        --------        d-----w-        c:\programdata\JollyBear
2012-06-16 11:22 . 2012-06-16 11:22        --------        d-----w-        c:\users\Euronics\AppData\Roaming\LegacyInteractive
2012-06-16 10:55 . 2012-06-18 18:31        --------        d-----w-        c:\users\Euronics\AppData\Roaming\WildTangent
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-15 03:56 . 2012-06-13 22:01        1197568        ----a-w-        c:\windows\system32\wininet.dll
2012-05-15 03:08 . 2012-06-13 22:01        981504        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-05-04 10:52 . 2012-06-13 22:01        5505392        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-04 10:08 . 2012-06-13 22:01        3958128        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:08 . 2012-06-13 22:01        3902320        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-05-02 05:32 . 2012-06-13 22:01        208896        ----a-w-        c:\windows\system32\profsvc.dll
2012-04-28 03:50 . 2012-06-13 22:01        204800        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:34 . 2012-06-13 22:01        76288        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-04-26 05:34 . 2012-06-13 22:01        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:28 . 2012-06-13 22:01        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:59 . 2012-06-13 22:01        1460224        ----a-w-        c:\windows\system32\crypt32.dll
2012-04-24 05:59 . 2012-06-13 22:01        182272        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-04-24 05:59 . 2012-06-13 22:01        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-04-24 04:47 . 2012-06-13 22:01        139264        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:47 . 2012-06-13 22:01        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2012-04-24 04:47 . 2012-06-13 22:01        1156608        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-04-20 06:22 . 2012-06-13 22:01        57856        ----a-w-        c:\windows\system32\licmgr10.dll
2012-04-20 05:05 . 2012-06-13 22:01        44544        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2012-04-20 05:00 . 2012-06-13 22:01        482816        ----a-w-        c:\windows\system32\html.iec
2012-04-20 04:15 . 2012-06-13 22:01        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2012-04-20 03:58 . 2012-06-13 22:01        386048        ----a-w-        c:\windows\SysWow64\html.iec
2012-04-20 03:24 . 2012-06-13 22:01        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2010-05-31 673136]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-09 98304]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-06-01 600928]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-6-9 1128224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176]
R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-24 271872]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-21 113120]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2010-06-20 108400]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2010-06-18 423280]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2010-06-20 67952]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2010-06-06 304496]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2010-06-17 851824]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2010-06-09 537456]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-06-09 384880]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2010-06-09 101232]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-06-24 202752]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-06-01 367456]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [2010-06-23 94208]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [2010-06-23 78848]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2010-05-25 252416]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-05-28 2320920]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2010-06-21 575856]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-06-08 836608]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2009-05-26 19968]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-06-23 342056]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-06-23 39464]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [2010-05-28 56344]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-05-28 158976]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2010-04-26 12032]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2010-05-31 1250160]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-05-31 402720]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 07:36]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 07:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-05-31 10775584]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-05-31 2040352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: Free YouTube to MP3 Converter - c:\users\Euronics\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Euronics\AppData\Roaming\Mozilla\Firefox\Profiles\yhxmh8xv.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Freecorder FLV Service - c:\program files (x86)\Freecorder\FLVSrvc.exe
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
AddRemove-Freecorder5.07 - c:\program files (x86)\Freecorder\uninstall.exe
AddRemove-{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 - c:\program files (x86)\Complitly\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=2000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=inteldata\""
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MySQL]
"ImagePath"="\"c:\program files (x86)\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files (x86)\MySQL\MySQL Server 5.5\my.ini\" MySQL"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-07-15  21:30:36
ComboFix-quarantined-files.txt  2012-07-15 19:30
.
Vor Suchlauf: 13 Verzeichnis(se), 378.838.552.576 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 378.938.220.544 Bytes frei
.
- - End Of File - - 517CE895525B577B7DE5FD7F210EB058

--- --- ---


Danke sehr und einen schönen Abend euch noch!

Janina

cosinus 16.07.2012 10:02

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

PuritySH 17.07.2012 20:58

Hallo und schönen Abend euch!

Hier die GMER Datei:

[code]
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-17 21:26:36
Windows 6.1.7600 
Running: 5hjwhmkq.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076a27b11                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf                     
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf@0025676472f6        0xD8 0x0D 0xD6 0xAB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46ae726bf@d8b377838c0e        0xDA 0x4D 0xBF 0xBB ...
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38ed7bd9                     
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076a27b11 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf@0025676472f6            0xD8 0x0D 0xD6 0xAB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46ae726bf@d8b377838c0e            0xDA 0x4D 0xBF 0xBB ...
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38ed7bd9 (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

--- --- ---


Nun das OSAM Log:

Code:

OSAM Logfile:

       
Code:

       
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:52:40 on 17.07.2012

OS: Windows 7 Home Premium Edition (Build 7600), 64-bit
Default Browser: Mozilla Corporation Firefox 13.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"igfxcpl.cpl" - "Intel Corporation" - C:\Windows\system32\igfxcpl.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"igfx" (igfx) - "Intel Corporation" - C:\Windows\System32\DRIVERS\igdkmd64.sys
"Intel(R) Display Audio" (IntcDAud) - "Intel(R) Corporation" - C:\Windows\System32\DRIVERS\IntcDAud.sys
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PxHlpa64" (PxHlpa64) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHlpa64.sys
"Sftfs" (Sftfs) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftfslh.sys
"Sftplay" (Sftplay) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftplaylh.sys
"Sftredir" (Sftredir) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftredirlh.sys
"Sftvol" (Sftvol) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\Sftvollh.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files (x86)\7-Zip\7-zip.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -   (File not found | COM-object registry key not found)
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} "Add to Evernote" - "Evernote Corporation" - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.3.lnk" - ? - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe  (Shortcut exists | File found, but it contains no detailed information | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Bluetooth.lnk" - ? - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File not found)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce )-----
"FlashPlayerUpdate" - "Adobe Systems, Inc." - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_Plugin.exe -update plugin
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"IAStorIcon" - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
"ISBMgr.exe" - ? - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Norton Online Backup" - "Symantec Corporation" - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
"PMBVolumeWatcher" - "Sony Corporation" - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EPSON SX210 Series 64MonitorBE" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\E_ILMFDE.DLL
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Active File Monitor V8" (AdobeActiveFileMonitor8.0) - "Adobe Systems Incorporated" - C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
"Application Virtualization Client" (sftlist) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
"Application Virtualization Service Agent" (sftvsa) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
"ArcSoft Connect Daemon" (ACDaemon) - "ArcSoft Inc." - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
"CamMonitor" (uCamMonitor) - "ArcSoft, Inc." - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
"Client Virtualization Handler" (cvhsvc) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"GamesAppService" (GamesAppService) - "WildTangent, Inc." - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"ICQ Service" (ICQ Service) - ? - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
"Intel(R) Management & Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"MySQL" (MySQL) - ? - C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld.exe
"Norton Online Backup" (NOBU) - "Symantec Corporation" - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"PMBDeviceInfoProvider" (PMBDeviceInfoProvider) - "Sony Corporation" - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
"VAIO Care Performance Service" (SampleCollector) - "Sony Corporation" - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
"VAIO Content Folder Watcher" (VCFw) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
"VAIO Content Metadata Intelligent Analyzing Manager" (VcmIAlzMgr) - "Sony Corporation" - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
"VAIO Content Metadata Intelligent Network Service Manager" (VcmINSMgr) - "Sony Corporation" - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
"VAIO Content Metadata XML Interface" (VcmXmlIfHelper) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
"VAIO Entertainment Common Service" (SpfService) - "Sony Corporation" - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
"VAIO Event Service" (VAIO Event Service) - "Sony Corporation" - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
"VAIO Media plus Content Importer" (SOHCImp) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
"VAIO Media plus Device Searcher" (SOHDs) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
"VAIO Media plus Digital Media Server" (SOHDms) - "Sony Corporation" - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
"VAIO Power Management" (VAIO Power Management) - "Sony Corporation" - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
"VSNService" (VSNService) - "Sony Corporation" - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
"VUAgent" (VUAgent) - "Sony Corporation" - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe

===[ Logfile end ]=========================================[ Logfile end ]===


--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Und zuletzt das aswMBR Log:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-17 21:53:49
-----------------------------
21:53:49.237    OS Version: Windows x64 6.1.7600
21:53:49.238    Number of processors: 4 586 0x2505
21:53:49.238    ComputerName: EURONICS-VAIO  UserName: Euronics
21:53:51.627    Initialize success
21:54:37.901    AVAST engine defs: 12071700
21:56:10.727    The log file has been saved successfully to "C:\Users\Euronics\Desktop\aswMBR.txt"


Vielen Dank mal wieder und schönen Abend noch!

Janina

cosinus 18.07.2012 16:01

aswMBR ist unvollständig
Du musst JEDES Tool per Rechtsklick als Administrator ausführen!

PuritySH 18.07.2012 20:13

Hoppala,

ich hoffe das es nun richtig ist... Sorry!

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-18 21:00:56
-----------------------------
21:00:56.782    OS Version: Windows x64 6.1.7600
21:00:56.783    Number of processors: 4 586 0x2505
21:00:56.783    ComputerName: EURONICS-VAIO  UserName: Euronics
21:01:00.516    Initialize success
21:01:04.998    AVAST engine defs: 12071700
21:01:32.336    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:01:32.337    Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
21:01:32.339    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
21:01:32.341    Disk 1 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
21:01:32.383    Disk 0 MBR read successfully
21:01:32.386    Disk 0 MBR scan
21:01:32.390    Disk 0 Windows 7 default MBR code
21:01:32.404    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        13693 MB offset 2048
21:01:32.424    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 28045312
21:01:32.462    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      463145 MB offset 28250112
21:01:32.500    Disk 0 scanning C:\Windows\system32\drivers
21:01:53.692    Service scanning
21:02:31.337    Modules scanning
21:02:31.671    Disk 0 trace - called modules:
21:02:31.694    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
21:02:31.699    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80063a2060]
21:02:31.703    3 CLASSPNP.SYS[fffff88001a3643f] -> nt!IofCallDriver -> [0xfffffa80043416f0]
21:02:31.707    5 ACPI.sys[fffff88000d75781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800434a050]
21:02:33.444    AVAST engine scan C:\Windows
21:02:39.744    AVAST engine scan C:\Windows\system32
21:07:39.810    AVAST engine scan C:\Windows\system32\drivers
21:07:55.522    AVAST engine scan C:\Users\Euronics
21:11:12.797    Disk 0 MBR has been saved successfully to "C:\Users\Euronics\Desktop\MBR.dat"
21:11:12.804    The log file has been saved successfully to "C:\Users\Euronics\Desktop\aswMBR´2.txt"

Grüße

cosinus 19.07.2012 15:00

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

PuritySH 21.07.2012 11:11

Hallo,

habe es nun endlich geschafft die Programme auszuführen. Hätte ich mein Antivir ausstellen sollen? Bei beiden Durchläufen kam folgende Fehlermeldung von Antivir:

Code:


Avira AntiVir Personal
Erstellungsdatum der Reportdatei: Freitag, 20. Juli 2012  21:32

Es wird nach 3901355 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (plain)  [6.1.7600]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : EURONICS-VAIO

Versionsinformationen:
BUILD.DAT      : 10.2.0.707    36070 Bytes  25.01.2012 12:53:00
AVSCAN.EXE    : 10.3.0.7      484008 Bytes  28.06.2011 17:53:19
AVSCAN.DLL    : 10.0.5.0      57192 Bytes  28.06.2011 17:53:19
LUKE.DLL      : 10.3.0.5      45416 Bytes  28.06.2011 17:53:20
LUKERES.DLL    : 10.0.0.0      13672 Bytes  14.01.2010 09:59:47
AVSCPLR.DLL    : 10.3.0.7      119656 Bytes  28.06.2011 17:53:21
AVREG.DLL      : 10.3.0.9      88833 Bytes  12.07.2011 16:48:55
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 07:05:36
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 12:36:27
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 21:28:19
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 19:30:19
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 16:23:47
VBASE005.VDF  : 7.11.34.116  4034048 Bytes  29.06.2012 17:50:24
VBASE006.VDF  : 7.11.34.117    2048 Bytes  29.06.2012 17:50:24
VBASE007.VDF  : 7.11.34.118    2048 Bytes  29.06.2012 17:50:24
VBASE008.VDF  : 7.11.34.119    2048 Bytes  29.06.2012 17:50:24
VBASE009.VDF  : 7.11.34.120    2048 Bytes  29.06.2012 17:50:24
VBASE010.VDF  : 7.11.34.121    2048 Bytes  29.06.2012 17:50:24
VBASE011.VDF  : 7.11.34.122    2048 Bytes  29.06.2012 17:50:24
VBASE012.VDF  : 7.11.34.123    2048 Bytes  29.06.2012 17:50:24
VBASE013.VDF  : 7.11.34.124    2048 Bytes  29.06.2012 17:50:24
VBASE014.VDF  : 7.11.34.201  169472 Bytes  02.07.2012 17:50:24
VBASE015.VDF  : 7.11.35.19    122368 Bytes  04.07.2012 19:33:33
VBASE016.VDF  : 7.11.35.87    146944 Bytes  06.07.2012 16:38:47
VBASE017.VDF  : 7.11.35.143  126464 Bytes  09.07.2012 17:19:59
VBASE018.VDF  : 7.11.35.235  151552 Bytes  12.07.2012 19:15:32
VBASE019.VDF  : 7.11.36.45    118784 Bytes  13.07.2012 19:15:33
VBASE020.VDF  : 7.11.36.107  123904 Bytes  16.07.2012 18:59:34
VBASE021.VDF  : 7.11.36.147  238592 Bytes  17.07.2012 18:59:34
VBASE022.VDF  : 7.11.36.148    2048 Bytes  17.07.2012 18:59:34
VBASE023.VDF  : 7.11.36.149    2048 Bytes  17.07.2012 18:59:34
VBASE024.VDF  : 7.11.36.150    2048 Bytes  17.07.2012 18:59:34
VBASE025.VDF  : 7.11.36.151    2048 Bytes  17.07.2012 18:59:34
VBASE026.VDF  : 7.11.36.152    2048 Bytes  17.07.2012 18:59:34
VBASE027.VDF  : 7.11.36.153    2048 Bytes  17.07.2012 18:59:34
VBASE028.VDF  : 7.11.36.154    2048 Bytes  17.07.2012 18:59:34
VBASE029.VDF  : 7.11.36.155    2048 Bytes  17.07.2012 18:59:34
VBASE030.VDF  : 7.11.36.156    2048 Bytes  17.07.2012 18:59:34
VBASE031.VDF  : 7.11.36.194  102912 Bytes  18.07.2012 18:59:35
Engineversion  : 8.2.10.114
AEVDF.DLL      : 8.1.2.10      102772 Bytes  10.07.2012 17:20:02
AESCRIPT.DLL  : 8.1.4.32      455034 Bytes  05.07.2012 20:18:33
AESCN.DLL      : 8.1.8.2      131444 Bytes  21.03.2012 19:30:26
AESBX.DLL      : 8.2.5.12      606578 Bytes  17.06.2012 21:15:00
AERDL.DLL      : 8.1.9.15      639348 Bytes  11.09.2011 20:05:55
AEPACK.DLL    : 8.3.0.14      807287 Bytes  15.07.2012 19:15:36
AEOFFICE.DLL  : 8.1.2.40      201082 Bytes  28.06.2012 21:46:12
AEHEUR.DLL    : 8.1.4.72    5038455 Bytes  15.07.2012 19:15:35
AEHELP.DLL    : 8.1.23.2      258422 Bytes  28.06.2012 21:46:10
AEGEN.DLL      : 8.1.5.32      434548 Bytes  08.07.2012 16:38:48
AEEXP.DLL      : 8.1.0.62      86389 Bytes  11.07.2012 20:17:00
AEEMU.DLL      : 8.1.3.2      393587 Bytes  10.07.2012 17:20:01
AECORE.DLL    : 8.1.27.2      201078 Bytes  10.07.2012 17:20:01
AEBB.DLL      : 8.1.1.0        53618 Bytes  04.03.2011 12:36:00
AVWINLL.DLL    : 10.0.0.0      19304 Bytes  04.03.2011 12:36:13
AVPREF.DLL    : 10.0.3.2      44904 Bytes  28.06.2011 17:53:19
AVREP.DLL      : 10.0.0.10    174120 Bytes  18.05.2011 08:47:20
AVARKT.DLL    : 10.0.26.1    255336 Bytes  28.06.2011 17:53:19
AVEVTLOG.DLL  : 10.0.0.9      203112 Bytes  28.06.2011 17:53:19
SQLITE3.DLL    : 3.6.19.0      355688 Bytes  17.06.2010 12:27:02
AVSMTP.DLL    : 10.0.0.17      63848 Bytes  04.03.2011 12:36:12
NETNT.DLL      : 10.0.0.0      11624 Bytes  17.06.2010 12:27:01
RCIMAGE.DLL    : 10.0.0.35    2589544 Bytes  28.06.2011 17:53:19
RCTEXT.DLL    : 10.0.64.0      98664 Bytes  28.06.2011 17:53:19

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: avguard_async_scan
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_50346e3a\guard_slideup.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: quarantäne
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: aus
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: vollständig

Beginn des Suchlaufs: Freitag, 20. Juli 2012  21:32

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'listener.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorDataMgrSvc.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbam.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'RunDll32.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamgui.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBVolumeWatcher.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'AdobeARM.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.bin' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ISBMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAStorIcon.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamservice.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VCSpt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgrSub.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'DllHost.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'VESMgr.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'uCamMonitor.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'PMBDeviceInfoProvider.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'mysqld.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ICQ Service.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht

Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe'
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
  [0] Archivtyp: HIDDEN
  --> FIL\\\?\C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
      [FUND]      Ist das Trojanische Pferd TR/FakeAV.nfiv

Beginne mit der Desinfektion:
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E30DD24C-3942-FD8B-8FEA-295CA49BE026}-jsswnnqxb.exe
  [FUND]      Ist das Trojanische Pferd TR/FakeAV.nfiv
  [WARNUNG]  Die Datei wurde ignoriert.


Ende des Suchlaufs: Freitag, 20. Juli 2012  21:32
Benötigte Zeit: 00:06 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      0 Verzeichnisse wurden überprüft
    33 Dateien wurden geprüft
      1 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
    32 Dateien ohne Befall
      0 Archive wurden durchsucht
      1 Warnungen
      0 Hinweise


Die Suchergebnisse werden an den Guard übermittelt.

Hier nun der Log von Malware:

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.21.04

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Euronics :: EURONICS-VAIO [Administrator]

Schutz: Aktiviert

21.07.2012 09:10:29
mbam-log-2012-07-21 (09-10-29).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 391010
Laufzeit: 56 Minute(n), 15 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Und der von SuperAntispyware:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/21/2012 at 12:03 PM

Application Version : 5.5.1006

Core Rules Database Version : 8938
Trace Rules Database Version: 6750

Scan type      : Complete Scan
Total Scan Time : 00:55:29

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC On - Administrator

Memory items scanned      : 834
Memory threats detected  : 0
Registry items scanned    : 66303
Registry threats detected : 0
File items scanned        : 80128
File threats detected    : 484

Adware.Tracking Cookie
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@adtech[1].txt [ /adtech ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@adx.chip[2].txt [ /adx.chip ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@atwola[1].txt [ /atwola ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\euronics@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\B1ZRGWEQ.txt [ /www.zanox-affiliate.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\6KAQ2M10.txt [ /smartadserver.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\KBHIYJY8.txt [ /ru4.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\1ZORBFML.txt [ /zanox-affiliate.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\3HJ8R0T5.txt [ /specificclick.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\RA7HCIED.txt [ /zanox.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8FSAZRRK.txt [ /adserv.kwick.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8P9S7A1T.txt [ /www.usenext.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\U6LHCM2E.txt [ /webmasterplan.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\JVV5TQEB.txt [ /tradedoubler.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8EHF9ET1.txt [ /server.adform.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\NN3F431S.txt [ /atdmt.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\A0E5P5XP.txt [ /doubleclick.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\TABS2DU3.txt [ /tracking.mlsat02.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\QX1KZ7VK.txt [ /traffictrack.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\BUGFC8FK.txt [ /tracking.quisma.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\PBU149ND.txt [ /questionmarket.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\8T44T119.txt [ /adform.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\184SXX0Q.txt [ /yieldmanager.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\JU4PL5Z5.txt [ /adbrite.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\HU6DRV5X.txt [ /advertising.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\25H721X4.txt [ /adviva.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\9Q49WXH7.txt [ /lucidmedia.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\SZJJGHSY.txt [ /eas.apm.emediate.eu ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\WTB0ZT8B.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\HO4U728W.txt [ /dyntracker.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\4TGDECA3.txt [ /track.adform.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\T2W982SX.txt [ /ad.adc-serv.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\6P15Z0YW.txt [ /mediaplex.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\OSSQK6N4.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\CCRSU5WR.txt [ /apmebf.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\YP5C3XGY.txt [ /invitemedia.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\VSRYKAWK.txt [ /www.windowsmedia.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\NAYYEX74.txt [ /media6degrees.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\T23YXTUJ.txt [ /microsoftwllivemkt.112.2o7.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\M6ZCRQ44.txt [ /snapfish.112.2o7.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\ULD9TOIZ.txt [ /serving-sys.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\5AKCAD40.txt [ /ad.123-template.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\7ROSIKU8.txt [ /fastclick.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\A8FEEPAX.txt [ /atdmt.combing.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\XZLVQG0L.txt [ /ad.dyntracker.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\H7M8UG2J.txt [ /adfarm1.adition.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\95X07YTW.txt [ /ads.creative-serving.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\Q5LJOTYO.txt [ /im.banner.t-online.de ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\9JYXC02P.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\CE0N0VVN.txt [ /content.yieldmanager.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\YASA40GB.txt [ /ad.yieldmanager.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\ZXA1EMV0.txt [ /ad3.adfarm1.adition.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\EOS1U2JR.txt [ /adserver.adtechus.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\OXD107DG.txt [ /counter.hitslink.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\BUS1KO9E.txt [ /ad.zanox.com ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\TV4W2JEN.txt [ /ad.movad.net ]
        C:\Users\Euronics\AppData\Roaming\Microsoft\Windows\Cookies\13L23KYV.txt [ /ads.audience2media.com ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\AVWSKR4H.txt [ Cookie:euronics@stati.mobilcom-debitel.de/track/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\F9360VLE.txt [ Cookie:euronics@specificclick.net/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\EB922BGH.txt [ Cookie:euronics@zanox.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\L3LW61FL.txt [ Cookie:euronics@webmasterplan.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7XED73T.txt [ Cookie:euronics@tradedoubler.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\L77QTG2V.txt [ Cookie:euronics@atdmt.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\S0YCPE7Q.txt [ Cookie:euronics@doubleclick.net/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\T7SMVAYH.txt [ Cookie:euronics@traffictrack.de/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\euronics@statse.webtrendslive[1].txt [ Cookie:euronics@statse.webtrendslive.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\AOUHS314.txt [ Cookie:euronics@adfarm1.adition.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\MHQJVG2J.txt [ Cookie:euronics@hightraffic.hugoboss.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZXJCI0OH.txt [ Cookie:euronics@ad2.adfarm1.adition.com/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\CGZMU23L.txt [ Cookie:euronics@yadro.ru/ ]
        C:\USERS\EURONICS\AppData\Roaming\Microsoft\Windows\Cookies\Low\WR7H1QVQ.txt [ Cookie:euronics@ad.zanox.com/ ]
        C:\USERS\EURONICS\Cookies\B1ZRGWEQ.txt [ Cookie:euronics@www.zanox-affiliate.de/ ]
        C:\USERS\EURONICS\Cookies\6KAQ2M10.txt [ Cookie:euronics@smartadserver.com/ ]
        C:\USERS\EURONICS\Cookies\KBHIYJY8.txt [ Cookie:euronics@ru4.com/ ]
        C:\USERS\EURONICS\Cookies\1ZORBFML.txt [ Cookie:euronics@zanox-affiliate.de/ ]
        C:\USERS\EURONICS\Cookies\3HJ8R0T5.txt [ Cookie:euronics@specificclick.net/ ]
        C:\USERS\EURONICS\Cookies\RA7HCIED.txt [ Cookie:euronics@zanox.com/ ]
        C:\USERS\EURONICS\Cookies\8FSAZRRK.txt [ Cookie:euronics@adserv.kwick.de/ ]
        C:\USERS\EURONICS\Cookies\U6LHCM2E.txt [ Cookie:euronics@webmasterplan.com/ ]
        C:\USERS\EURONICS\Cookies\JVV5TQEB.txt [ Cookie:euronics@tradedoubler.com/ ]
        C:\USERS\EURONICS\Cookies\8EHF9ET1.txt [ Cookie:euronics@server.adform.net/ ]
        C:\USERS\EURONICS\Cookies\NN3F431S.txt [ Cookie:euronics@atdmt.com/ ]
        C:\USERS\EURONICS\Cookies\euronics@sevenoneintermedia.112.2o7[1].txt [ Cookie:euronics@sevenoneintermedia.112.2o7.net/ ]
        C:\USERS\EURONICS\Cookies\A0E5P5XP.txt [ Cookie:euronics@doubleclick.net/ ]
        C:\USERS\EURONICS\Cookies\TABS2DU3.txt [ Cookie:euronics@tracking.mlsat02.de/tmobile/ ]
        C:\USERS\EURONICS\Cookies\QX1KZ7VK.txt [ Cookie:euronics@traffictrack.de/ ]
        C:\USERS\EURONICS\Cookies\BUGFC8FK.txt [ Cookie:euronics@tracking.quisma.com/ ]
        C:\USERS\EURONICS\Cookies\PBU149ND.txt [ Cookie:euronics@questionmarket.com/ ]
        C:\USERS\EURONICS\Cookies\184SXX0Q.txt [ Cookie:euronics@yieldmanager.net/ ]
        C:\USERS\EURONICS\Cookies\JU4PL5Z5.txt [ Cookie:euronics@adbrite.com/ ]
        C:\USERS\EURONICS\Cookies\HU6DRV5X.txt [ Cookie:euronics@advertising.com/ ]
        C:\USERS\EURONICS\Cookies\9Q49WXH7.txt [ Cookie:euronics@lucidmedia.com/ ]
        C:\USERS\EURONICS\Cookies\SZJJGHSY.txt [ Cookie:euronics@eas.apm.emediate.eu/ ]
        C:\USERS\EURONICS\Cookies\HO4U728W.txt [ Cookie:euronics@dyntracker.com/ ]
        C:\USERS\EURONICS\Cookies\6P15Z0YW.txt [ Cookie:euronics@mediaplex.com/ ]
        C:\USERS\EURONICS\Cookies\OSSQK6N4.txt [ Cookie:euronics@ad4.adfarm1.adition.com/ ]
        C:\USERS\EURONICS\Cookies\CCRSU5WR.txt [ Cookie:euronics@apmebf.com/ ]
        C:\USERS\EURONICS\Cookies\YP5C3XGY.txt [ Cookie:euronics@invitemedia.com/ ]
        C:\USERS\EURONICS\Cookies\VSRYKAWK.txt [ Cookie:euronics@www.windowsmedia.com/ ]
        C:\USERS\EURONICS\Cookies\NAYYEX74.txt [ Cookie:euronics@media6degrees.com/ ]
        C:\USERS\EURONICS\Cookies\T23YXTUJ.txt [ Cookie:euronics@microsoftwllivemkt.112.2o7.net/ ]
        C:\USERS\EURONICS\Cookies\M6ZCRQ44.txt [ Cookie:euronics@snapfish.112.2o7.net/ ]
        C:\USERS\EURONICS\Cookies\ULD9TOIZ.txt [ Cookie:euronics@serving-sys.com/ ]
        C:\USERS\EURONICS\Cookies\A8FEEPAX.txt [ Cookie:euronics@atdmt.combing.com/ ]
        C:\USERS\EURONICS\Cookies\XZLVQG0L.txt [ Cookie:euronics@ad.dyntracker.de/ ]
        C:\USERS\EURONICS\Cookies\euronics@atwola[1].txt [ Cookie:euronics@atwola.com/ ]
        C:\USERS\EURONICS\Cookies\H7M8UG2J.txt [ Cookie:euronics@adfarm1.adition.com/ ]
        C:\USERS\EURONICS\Cookies\Q5LJOTYO.txt [ Cookie:euronics@im.banner.t-online.de/ ]
        C:\USERS\EURONICS\Cookies\9JYXC02P.txt [ Cookie:euronics@ad2.adfarm1.adition.com/ ]
        C:\USERS\EURONICS\Cookies\CE0N0VVN.txt [ Cookie:euronics@content.yieldmanager.com/ak/ ]
        C:\USERS\EURONICS\Cookies\YASA40GB.txt [ Cookie:euronics@ad.yieldmanager.com/ ]
        C:\USERS\EURONICS\Cookies\EOS1U2JR.txt [ Cookie:euronics@adserver.adtechus.com/ ]
        C:\USERS\EURONICS\Cookies\AVWSKR4H.txt [ Cookie:euronics@stati.mobilcom-debitel.de/track/ ]
        C:\USERS\EURONICS\Cookies\BUS1KO9E.txt [ Cookie:euronics@ad.zanox.com/ ]
        C:\USERS\EURONICS\Cookies\13L23KYV.txt [ Cookie:euronics@ads.audience2media.com/ ]
        .smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .sonyeurope.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adserver.adtechus.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.robert-half-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.robert-half-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlyqpdjcgo.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjliwpajecq.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wnmyeld5clq.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wjlocpcpgap.stats.esomniture.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ice.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .stepstone.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.domainorganizer.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.yopi.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .komtrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .c.gigcount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .findojobs.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .hansenet.122.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .server.cpmstar.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ox-d.w00tmedia.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .hairfinder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.dyntracker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        s2.trafficmaxx.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .game-advertising-online.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        tracking.gameforge.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adserver.gs [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        s2.trafficmaxx.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.mmoga.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.mmoga.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .mediabrandsww.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserving.versaneeds.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.tiervermittlung.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        tracking.hostgator.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .affiliates.commissionaccount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .affiliates.commissionaccount.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        stats.justhost.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        pw1.nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        counters.gigya.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        uk.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adt.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .superstats.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads20.wwe-media.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.ep-solutions.org [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.ep-solutions.org [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .loccitane.solution.weborama.fr [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .sevenoneintermedia.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.layermedia-adserver.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .xm.xtendmedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .nordclick.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .kollermedia.at [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .kollermedia.at [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver2.clipkit.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.adreactor.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .moviepilot.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        media.gan-online.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .nextag.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.mitfahrzentrale.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.mikinimedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .microsoftsto.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ads.sealmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .viewablemedia.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .autoscout24.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .www.burstnet.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .gmeurope.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .audiag.112.2o7.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        fl01.ct2.comclick.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        adserver.bravado.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        studivz.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .secmedia.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.adserver01.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .insightexpressai.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\EURONICS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YHXMH8XV.DEFAULT\COOKIES.SQLITE ]

Viele Grüße

Janina

cosinus 23.07.2012 12:57

Code:

C:\ProgramData\Microsoft\Windows Defender\LocalCopy
Das sind nur Funde in der Q vom Windows-Defender!

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

PuritySH 25.07.2012 15:49

Suuuper, vielen Dank, ich kann dir gar nicht genug danken!

Ich werde das mit dem CookieCuller ab sofort so machen, ist ja doch schon ne Menge.

Noch mals vielen Dank für deine Geduld und Mühen, ich werb für euch!

Viele Grüße

Janina

cosinus 26.07.2012 09:38

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:40 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131